The U.S. Justice Department unsealed charges against 17 members of Iran's Mabna Institute, a hacking-for-hire operation tied to the IRGC that stole 31.5 terabytes of academic data.
The U.S. Justice Department unsealed charges against 17 members of Iran's Mabna Institute, a hacking-for-hire operation tied to the IRGC that stole 31.5 terabytes of academic data.

The U.S. Justice Department unsealed charges against 17 members of Iran's Mabna Institute, a hacking-for-hire operation tied to the IRGC that stole 31.5 terabytes of academic data.
The U.S. Justice Department charged 17 members of Iran's Mabna Institute for a state-sponsored hacking campaign that stole 31.5 terabytes of data from 322 universities, including 144 in the United States.
"These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government," Brett Leatherman, FBI Cyber Division assistant director, said.
The 14-count superseding indictment, unsealed Tuesday, alleges the group compromised roughly 8,000 professor email accounts out of more than 100,000 targeted globally. Victims also included 42 U.S. private-sector companies, 11 foreign companies, the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and UNICEF. Some victims incurred more than $20 million in investigation and remediation costs.
The charges expand a 2018 indictment that named nine defendants, adding eight newly identified members. The State Department's Rewards for Justice program is offering up to $10 million for information leading to five defendants still at large, including Behzad Mesri, who allegedly hacked HBO and attempted to extort the company for $6 million in Bitcoin.
The Mabna Institute, founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, contracted with Iranian government and private entities to conduct hacking activities, according to the indictment. Prosecutors said the group conducted the university spear-phishing campaign specifically on behalf of the IRGC.
The hackers gathered publicly available data on potential targets to assess their areas of expertise, then sent emails disguised as messages from colleagues directing victims to fake login pages that mimicked their own university's websites. For private-sector targets, the group relied on password spraying.
Beyond serving the Iranian government, the defendants sold stolen credentials through two websites linked to defendant Abdollah Karima through his company, Falinoos. Megapaper.ir sold stolen academic resources directly to Iran-based public universities, functioning as a black-market academic publishing house for the Iranian government. Gigapaper.ir let customers in Iran pay for a subscription-style service that allowed them to use compromised professor accounts to access the online library systems of specific U.S. and foreign universities.
The indictment details how defendant Behzad Mesri hacked Home Box Office, stole proprietary data, and attempted to extort roughly $6 million in Bitcoin. The State Department's Rewards for Justice program is offering up to $10 million for information leading to the location of five defendants: Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
The charges come as Iranian-linked cyber operations have intensified since U.S. and Israeli forces struck Iran in February. Tehran was allegedly behind recent attacks targeting water systems in at least 12 states, and the government took credit for cyberattacks on a prominent medical device company and the personal email account of the FBI director.
For cybersecurity vendors and enterprises, the indictment shows the persistent threat of state-sponsored credential theft and the importance of multi-factor authentication and phishing-resistant identity controls. The case also highlights how stolen academic data feeds into broader intelligence-gathering operations, with implications for research institutions, defense contractors, and companies with valuable intellectual property. Security teams at universities and research-intensive firms should treat credential-based attacks as a top-tier risk, given the scale of this operation and the demonstrated willingness of Iranian state actors to monetize stolen access through commercial channels.
This article is for informational purposes only and does not constitute investment advice.