Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Sakura Internet Breach Exposes 1.36 Million Customer Records
August 21, 2026
OpenAI Rolls Out Zero Data Retention for Enterprise ChatGPT
August 21, 2026
DOJ Charges 17 Iranian Hackers in Massive Data Theft Campaign
August 21, 2026
Home/CyberSecurity News/DOJ Charges 17 Iranian Hackers in Massive Data Theft Campaign
CyberSecurity News

DOJ Charges 17 Iranian Hackers in Massive Data Theft Campaign

Key Takeaways The U.S. Department of Justice has charged 17 individuals associated with the Iran-based Mabna Institute for a widespread cyber espionage campaign. The operation allegedly stole over...

Marcus Rodriguez
Marcus Rodriguez
August 21, 2026 4 Min Read
3 0

Key Takeaways

  • The U.S. Department of Justice has charged 17 individuals associated with the Iran-based Mabna Institute for a widespread cyber espionage campaign.
  • The operation allegedly stole over 31.5 terabytes of academic research and intellectual property from hundreds of universities and various organizations globally.
  • Victims included 144 U.S. universities, 178 international universities, numerous private companies, and government agencies, including the U.S. Department of Labor.
  • The accused group allegedly worked on behalf of Iranian government entities, including the Islamic Revolutionary Guard Corps (IRGC), and monetized stolen data through illicit websites.

The U.S. Department of Justice (DOJ) has unsealed a comprehensive 14-count superseding indictment against 17 individuals, all reportedly affiliated with the Mabna Institute, an Iran-based organization. These charges stem from a prolonged cyber espionage campaign that allegedly resulted in the theft of at least 31.5 terabytes of sensitive research data and intellectual property.

Table Of Content

  • Key Takeaways
  • DOJ Charges 17 Iranian Hackers
  • Widespread Academic Compromise
  • Monetization of Stolen Data
  • Broader Impact Beyond Academia
  • What You Should Do

According to the indictment, the sophisticated operation commenced around 2013 and persisted until at least December 2017. Prosecutors contend that the group operated under the direction of Iranian government and university clients, notably including the Islamic Revolutionary Guard Corps (IRGC).

The cyber campaign systematically targeted a diverse array of entities, encompassing universities, private corporations, governmental bodies, and non-governmental organizations across the United States and other nations.

The Mabna Institute was reportedly founded by Gholamreza Rafatnejad and Ehsan Mohammadi with the stated objective of facilitating Iranian institutions’ access to foreign scientific resources.

DOJ Charges 17 Iranian Hackers

The indictment describes the Mabna Institute as employing or collaborating with “hackers-for-hire” who executed a range of malicious activities. These included sophisticated phishing attacks, reconnaissance efforts, credential theft, password spraying, and extensive data exfiltration operations.

Widespread Academic Compromise

The group’s primary focus was academic institutions, where they targeted more than 100,000 professor accounts worldwide. This led to the alleged compromise of approximately 8,000 academic email accounts. The victims included 144 U.S. universities and 178 universities situated outside the United States.

Affected educational institutions spanned multiple continents, including Australia, Canada, China, Europe, the Middle East, Asia, and the United Kingdom. The attackers predominantly employed spearphishing emails to illicitly obtain professor login credentials.

Once access was gained to university networks and online library portals, the perpetrators exploited these vulnerabilities to access a vast trove of academic resources. This included academic journals, dissertations, theses, electronic books, research papers, and other protected materials. The stolen data encompassed a wide range of fields, such as scientific, engineering, medical, social science, technology, and various professional research areas.

The stolen intellectual property was subsequently exfiltrated to infrastructure controlled by the alleged conspirators located outside the United States. Prosecutors estimate that U.S. universities alone had invested over $3.4 billion to acquire access to the research and intellectual property that became targets of this campaign.

Monetization of Stolen Data

Beyond direct theft, the operation also allegedly leveraged stolen academic access for financial gain. Two Iran-based websites, Megapaper.ir and Gigapaper.ir, were reportedly utilized to sell the purloined resources and access to compromised university accounts.

Megapaper allegedly facilitated the sale of stolen academic content directly to customers within Iran. Concurrently, Gigapaper offered buyers direct access to online university library systems by exploiting hijacked professor accounts.

Broader Impact Beyond Academia

The indictment further reveals that the Mabna Institute’s operators extended their targeting beyond academia. They allegedly compromised at least 42 U.S. private-sector companies, 11 foreign companies, five U.S. federal and state government agencies, and several international organizations.

Among the named victims were prominent entities such as the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and UNICEF.

This expanded indictment adds eight new defendants to a case initially announced in 2018. Several of the defendants are also purportedly linked to the 2017 intrusion into HBO, where stolen data was used in an attempted extortion scheme seeking approximately $6 million in Bitcoin.

The charges levied against the accused include conspiracy to commit computer intrusions, wire fraud, unauthorized access for private financial gain, and aggravated identity theft.

The DOJ said that the intrusions into some private-sector and government entities alone incurred over $20 million in investigation and remediation costs for the victims.

The State Department’s Rewards for Justice program is currently offering a reward of up to $10 million for information that leads to the location of five specific defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. It is important to note that the indictment represents an allegation, and all defendants are presumed innocent until proven guilty in a court of law.

What You Should Do

  • Implement robust multi-factor authentication (MFA) for all accounts, especially for academic and high-privilege users.
  • Conduct regular cybersecurity awareness training for all staff and students, emphasizing the dangers of phishing and social engineering.
  • Patch and update all systems and software diligently to protect against known vulnerabilities.
  • Monitor network traffic for unusual activity, especially large data exfiltration, and implement intrusion detection/prevention systems.
  • Review and strengthen access controls to sensitive research data and intellectual property.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerphishing

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers

Next Post

OpenAI Rolls Out Zero Data Retention for Enterprise ChatGPT

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TrueConf Server Flaws Let Attackers Push Malware via Updates
August 21, 2026
Critical Chrome CVE-2023-151 Allows Remote Code Execution
August 21, 2026
Critical Microsoft Entra ID RCE Vulnerability Exploited In The Wild
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us