Tuesday, September 29, 2026

17 Iranian Hackers Charged in Massive U.S. University Cybertheft

Related

A massive cyber‑theft ring linked to Iran’s Islamic Revolutionary Guard Corps has just been indicted, charging 17 members in a sweeping indictment that spans three continents. Prosecutors say the operation stole more than 31 terabytes of academic data and intellectual property from hundreds of universities worldwide.

Massive Cyber‑Theft Ring Charged

The 14‑count superseding indictment unsealed Tuesday in New York reveals a campaign that began around 2013 and continued through late 2017, targeting over 100,000 professor accounts at 144 U.S. universities and 178 institutions abroad. Roughly 8,000 of those accounts were compromised, giving the hackers access to research papers, theses, dissertations and journals.

U.S. universities alone spent more than $3.4 billion licensing the stolen research and IP, according to prosecutors. The theft also hit private firms, government agencies and international bodies, expanding the scope of the crime.

Nine defendants were first charged in 2018, and the updated indictment adds eight more names, exposing a larger network behind the Mabna Institute. Rafatnejad and Mohammadi created the firm in 2013 to assist Iranian groups in stealing foreign scientific resources.

Hackers used stolen credentials to breach university library systems and transferred the data to servers outside the United States, a tactic described by Assistant Attorney General John A. Eisenberg as ‘[A]t the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value.’ This allowed them to exfiltrate research materials without detection.

Some of the stolen material later appeared on two websites run by a defendant, one selling the data directly and another letting buyers use compromised professor accounts to access library systems. These platforms facilitated the sale of the data to customers inside Iran.

The network also compromised employee email accounts at private companies and government offices, affecting at least 42 U.S. firms, 11 foreign firms, five U.S. agencies and two NGOs. Victims included the Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF.

Several defendants are also tied to the 2017 HBO hack, where they stole proprietary data and demanded $6 million in bitcoin. Behzad Mesri, previously charged in that case, is among those named in the new indictment.

In additional attacks on private firms and government entities, prosecutors say the group’s techniques cost victims more than $20 million in investigation and remediation expenses. The total financial impact underscores the scale of the espionage operation.

The State Department’s Rewards for Justice program offers up to $10 million for information leading to the location of five of the indicted individuals. Authorities hope the reward will spur tips that lead to arrests.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article