Skip to main content
Threat IntelligenceEmerging Threats

US Recharges Indictment Against Iranian Hackers Tied to Mabna Institute

Government briefing room with podium, documents, and agency seals in background.

The institute has compromised more than 100,000 professors’ email accounts globally, the indictment alleges.

An expanded federal case: 17 defendants, eight newly charged

Federal prosecutors in the Southern District of New York on Tuesday unsealed an indictment charging 17 Iranians affiliated with the Tehran-based tech firm Mabna Institute. The new filing replaces and expands a 2018 indictment that named nine of the defendants and adds eight additional individuals, the U.S. Attorney’s Office said. Jamie McDonald, U.S. Attorney for the Southern District of New York, framed the move as part of sustained pursuit: “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.”

Founders and the alleged mission: Rafatnejad, Mohammadi, and hired hackers

According to the Justice Department, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013. Prosecutors say the institute’s stated goal was to help Iranian universities and scientific and research organizations “to steal from foreign scientific efforts,” and that it paid hackers-for-hire identified in the indictment. The complaint alleges the group used stolen credentials to exfiltrate academic journals, dissertations and e-books across all fields of research and sometimes sold the stolen data.

Alleged scale of theft: accounts, terabytes, and economic impact

The indictment quantifies the alleged scale in several stark figures. Mabna is accused of compromising more than 100,000 professors’ email accounts worldwide, including roughly 8,000 accounts at 144 U.S. universities and 178 universities elsewhere. Prosecutors say the group removed at least 31.5 terabytes of academic material and intellectual property. A press release on the indictment states: “Through the course of the conspiracy, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property.”

Targets beyond academia: agencies, companies, and a named entertainment firm

The indictment alleges the campaign reached beyond universities. Prosecutors say the defendants compromised and stole from email accounts tied to at least five U.S. federal and state government agencies, 42 U.S. companies and 11 foreign companies. The filing specifically names HBO among the companies affected.

Legal exposure and a rewards offer

The indictment brings 14 separate — and sometimes overlapping — charges against the 17 defendants, with statutory sentences for each offense ranging from two to 20 years. In parallel, the State Department’s Rewards for Justice program is offering up to $10 million for information that leads to the location of four of the defendants named in the indictment. The charges arrive amid what the U.S. Attorney framed as a broader strategic context: “Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength,” McDonald said in announcing the filing.

What this means for U.S. universities, government agencies, and affected companies

  • U.S. universities: The indictment documents alleged direct financial harms — approximately $3.4 billion in procurement and access costs — and large-scale compromise of faculty email accounts. University leaders will face pressure to inventory exposures tied to credentials and acquired content and to reassess how purchased research is protected and accounted for.
  • U.S. federal and state government agencies: With at least five agencies named as having had email accounts compromised, the case underscores continued concern about credential-based intrusions into government correspondence and data repositories.
  • Affected companies (including HBO): The inclusion of 42 U.S. companies and 11 foreign firms, and a named entertainment company, highlights commercial reputational and intellectual-property risks tied to credential theft and resale of stolen materials.

Eight years after the original 2018 indictment, prosecutors have widened the net and placed a financial reward on locating several alleged participants. The filing ties a broad pattern of credential theft and data exfiltration to a Tehran-based firm founded around 2013 and alleges both market activity — the sale of stolen data — and state-directed intent to accumulate foreign research. Whether the expansion of charges and the Rewards for Justice offer will lead to arrests or recovery of stolen material depends on steps outside the indictment: locating defendants and disrupting the networks prosecutors describe. For now, the indictment and its numbers place a dollar figure and a terabyte count on a campaign that prosecutors say reached into universities, governments and the private sector.

Read the original CyberScoop report