US Charges 17 Iranians in Massive Cyber Theft Targeting Universities Including Israel
The US Department of Justice has indicted 17 Iranians accused of orchestrating a global cyberattack campaign on behalf of Iran's Revolutionary Guards and other Iranian entities. Since 2013, operatives from Mabna Institute, a Tehran-based company founded by two of the accused, infiltrated approximately 8,000 academic accounts across 144 US universities and 178 institutions worldwide, including in Israel. They stole over 31 terabytes of research papers, books, academic works, and intellectual property. The hackers also breached email accounts of employees at 42 American companies, 11 European firms, and various governmental and international organizations.
Among the victims was HBO, from which scripts and materials related to the series Game of Thrones were stolen. The hackers attempted to extort $6 million in Bitcoin from HBO. The US State Department has offered up to $10 million for information leading to the capture of five suspects. Mabna Institute operated as a sophisticated hacking-for-hire service, dividing tasks such as target identification, phishing message creation, fake website setup, password theft, and selling access to stolen databases. The operation primarily served the Revolutionary Guards but also other Iranian clients.
The hackers targeted a broad range of academic fields beyond sensitive security or technology research, including social sciences and professional disciplines. US universities reportedly spent $3.4 billion on academic materials and database access that the hackers illicitly obtained. The FBI estimates the stolen data volume was three times the size of the Library of Congress's print collection.
The hackers used personalized phishing tactics, researching victims’ work to craft convincing emails with fake login pages to steal credentials. Stolen materials were sold commercially on Iranian websites, and some accounts were used to access foreign university libraries. For corporate and government targets, the hackers employed "password spraying," trying common passwords to gain access, sometimes downloading entire mailboxes and setting up automatic forwarding rules.
Targets included US tech, consulting, marketing, banking, biotech, and health companies, as well as US government agencies and international bodies like the UN and UNICEF. Investigation and remediation costs exceeded $20 million for some victims. One suspect, Amir Barati, was arrested in Montenegro in June 2023 and is awaiting extradition to the US. The indictment includes charges of conspiracy, computer intrusion, identity theft, and extortion, with potential sentences of up to 20 years per fraud count. The DOJ and FBI emphasize their long memory and ongoing pursuit of cyber adversaries.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.