
The Justice Department this week unsealed sweeping new charges against 17 Iranian nationals accused of running a years-long, state-sponsored cyber theft campaign that hacked into hundreds of American universities, private companies, and government agencies on behalf of Iran’s Islamic Revolutionary Guard Corps.
The 14-count superseding indictment, unsealed in federal court in Manhattan, expands a case originally brought against nine defendants back in 2018, adding eight newly charged individuals and incorporating additional criminal conduct that prosecutors say continued well beyond the original filing.
According to the Justice Department, all 17 defendants are alleged members of the Mabna Institute, a Tehran-based company founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. Prosecutors describe Mabna as having been established for the explicit purpose of penetrating foreign computer networks and stealing valuable scientific research and intellectual property for the benefit of the Iranian government, the IRGC, and Iranian universities.
The scale of the alleged operation is staggering. Prosecutors say the group targeted computer systems belonging to at least 144 U.S.-based universities and 178 additional universities overseas, spanning countries including Australia, Canada, China, Germany, Israel, Italy, Japan, the Netherlands, and South Korea, among others.
Beyond academia, the indictment alleges the hackers also targeted at least 42 U.S.-based private sector companies, 11 foreign companies, five U.S. federal and state government agencies, and two nongovernmental organizations, casting an extraordinarily wide net across American institutions over the course of more than a decade.
The sheer volume of stolen material is difficult to fully grasp. Prosecutors allege the group successfully stole more than 31 terabytes of academic data and intellectual property, including academic journals, theses, dissertations, and electronic books, representing years of American research and scholarship funneled directly to a hostile foreign government.
To pull this off, prosecutors say the hackers targeted more than 100,000 professor accounts worldwide, ultimately compromising an estimated 8,000 email accounts belonging to professors specifically at U.S. institutions, using stolen login credentials to gain unauthorized access into university library and research systems.
Once inside, the operation reportedly functioned like a criminal enterprise, not merely an espionage effort. Prosecutors say the Mabna Institute then turned around and sold the stolen academic material to paying customers back in Iran, operating one website that sold materials directly and another that sold buyers direct access to compromised professor accounts, which customers could use to browse university library systems as though they were legitimate students or faculty.
U.S. Attorney Jamie McDonald for the Southern District of New York did not mince words in announcing the expanded charges, stating that they “reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions.” McDonald emphasized that more than eight years after the original indictment became public, the passage of time would not deter continued pursuit of those responsible.
FBI Cyber Division Assistant Director Brett Leatherman echoed that sentiment, noting that the defendants “allegedly built and profited from a sprawling hacking-for-hire operation,” and that the FBI’s “memory is long,” with time doing nothing to blunt the bureau’s resolve to pursue justice against those targeting American institutions from abroad.
The indictment also connects several of the defendants to the notorious 2017 hack of HBO, in which attackers stole proprietary company data and attempted to extort the network for roughly $6 million worth of Bitcoin, illustrating that this network’s criminal reach extended well beyond academic espionage and into direct financial extortion against major American corporations.
Victims identified in court filings include some genuinely alarming targets for a foreign hacking operation to have compromised, among them the U.S. Department of Labor, the Federal Energy Regulatory Commission, and state government systems in both Hawaii and Indiana, alongside international bodies including the United Nations and UNICEF.
The State Department’s Rewards for Justice program has separately announced rewards of up to $10 million for information leading to the location of five of the 17 defendants, an acknowledgment that most, if not all, of those charged remain outside U.S. jurisdiction and unlikely to face arrest anytime soon absent extraordinary circumstances.
The defendants face an array of serious federal charges, including conspiracy to commit computer intrusions, conspiracy to commit wire fraud, unauthorized computer access, wire fraud, and aggravated identity theft. Several of these charges carry maximum sentences of up to 20 years in prison, while aggravated identity theft counts carry mandatory minimum prison terms upon conviction.