Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
DOJ charges 17 Iranians in massive cyber theft campaign targeting US institutions
00

DOJ charges 17 Iranians in massive cyber theft campaign targeting US institutions

Aug 18, 2026

The U.S. Department of Justice unsealed a 14-count superseding indictment charging 17 Iranian nationals associated with the Mabna Institute for a massive, state-sponsored cyber theft campaign. Backed by Iran's Islamic Revolutionary Guard Corps, the hackers compromised 8,000 academic email accounts across 144 U.S. and 178 foreign universities, stealing 31.5 terabytes of intellectual property valued at $3.4 billion. The State Department is offering a $10 million reward to locate five of the defendants.

DOJ indictment of Iranian hackers

  • ▪The unsealed indictment adds eight new defendants to the prosecution, while nine of the 17 defendants were previously indicted under seal in February 2018 and unsealed in March 2018.
  • ▪The U.S. Department of Justice unsealed a 14-count superseding indictment on August 18, 2026, charging 17 Iranian nationals with conducting a massive cyber theft campaign.
  • ▪The charges in the superseding indictment include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud, wire fraud, and aggravated identity theft.

Mabna Institute cyber campaign scope

  • ▪The defendants are accused of working with the Tehran-based Mabna Institute, which Gholamreza Rafatnejad and Ehsan Mohammadi founded in approximately 2013 to steal non-Iranian scientific resources.
  • ▪The Mabna Institute hackers targeted more than 100,000 academic accounts worldwide and successfully compromised approximately 8,000 professor email accounts.
  • ▪The Mabna Institute's cyber campaign, running from 2013 to at least December 2017, targeted 144 U.S. universities, 178 foreign universities, 42 U.S. private companies, 11 foreign firms, five U.S. government agencies, and two NGOs.

IRGC state-sponsored hacking operations

  • ▪Defendant Amir Barati allegedly tracked spear-phishing progress, exchanged compromised credentials, created targeting lists, conducted network reconnaissance, and crafted spear-phishing messages.
  • ▪The Mabna Institute carried out its coordinated hacking campaigns on behalf of Iran's Islamic Revolutionary Guard Corps and other Iranian government and university clients.
  • ▪The hackers utilized password-spraying attacks, unauthorized system access, and spear-phishing campaigns, resulting in more than $20 million in investigation and remediation costs for victims.

Stolen academic intellectual property

  • ▪The hackers stole approximately 31.5 terabytes of academic data and intellectual property, including academic journals, theses, dissertations, and electronic books.
  • ▪The stolen academic data and intellectual property was worth an estimated $3.4 billion, representing the amount U.S. universities spent to procure and access the targeted resources.
  • ▪The stolen academic resources and compromised university account credentials were sold to customers in Iran through websites linked to the operation.

Federal reward offer

  • ▪The U.S. State Department's Rewards for Justice program announced a reward of up to $10 million for information leading to the location of five of the defendants.
  • ▪The five defendants targeted by the $10 million reward are Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

8 sources

Bbc
US charges 17 Iranians over 'massive' cyber theft campaign
View source article
Washingtonexaminer
DOJ charges 17 with cyber theft on behalf of Iranian government
View source article
Reuters
DOJ unseals new charges against 17 hackers in Iran-backed campaign | Reuters
View source article
Timesofindia
US charges 17 Iranians over hacking campaign targeting 144 universities, firms
View source article
Thehill
DOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaign
View source article

Featured stories

View more in Crypto theft

OpenAI and 100+ companies warn AI-powered cyberattacks are imminent

Aug 27, 2026 · 6 sources

CrowdStrike and Okta surge on earnings as AI threats boost cybersecurity spending

Aug 26, 2026 · 6 sources

Chinese hackers integrate DeepSeek and open-source AI models into cyberattacks

Aug 24, 2026 · 2 sources

Story comments

Loading comments…

Related entities

IranUnited StatesCybersecurity

Topics

Crypto theftIran WarCybersecurityNational security

Featured stories

View more in Crypto theft

OpenAI and 100+ companies warn AI-powered cyberattacks are imminent

Aug 27, 2026 · 6 sources

CrowdStrike and Okta surge on earnings as AI threats boost cybersecurity spending

Aug 26, 2026 · 6 sources

Chinese hackers integrate DeepSeek and open-source AI models into cyberattacks

Aug 24, 2026 · 2 sources