The US Department of Justice has charged 17 Iranian nationals accused of participating in a long-running hacking operation that targeted universities, companies, government agencies, and other organizations in the United States and abroad.
The defendants are alleged to be members or associates of the Iran-based Mabna Institute, which prosecutors describe as a hacking-for-hire organization. Nine of the 17 defendants were originally charged in 2018, while a newly unsealed superseding indictment adds eight more individuals to the case.
According to prosecutors, Mabna Institute has operated since approximately 2013. The organization allegedly carried out cyber intrusions for clients that included Iranian universities, government entities, and the Islamic Revolutionary Guard Corps (IRGC). The allegations include theft of academic research, intellectual property, corporate information, and employee email accounts.
The academic campaign was particularly extensive. US authorities say the hackers targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000. The affected institutions included 144 universities in the United States and 178 universities in other countries.
Once accounts were compromised, the attackers allegedly used stolen credentials to obtain research materials and other academic documents. The campaign resulted in the theft of more than 31 terabytes of academic data and intellectual property, including journals, dissertations, theses, electronic books, and research materials. US universities had spent approximately $3.4 billion to procure and access the information targeted by the operation, according to the Justice Department.
The eight newly charged defendants are Saeid Houshyar, Behzad Mesri, Manouchehr Hashemloo, Keyvan Fayaz, Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi. Several are also identified by online aliases in the indictment.
Authorities allege that Mabna Institute’s activities extended well beyond universities. The operation targeted at least 42 US private-sector companies, 11 foreign companies, multiple US government agencies, and two non-governmental organizations. Some attacks allegedly involved password spraying, unauthorized system access, and data exfiltration. Prosecutors say victims suffered more than $20 million in investigation and remediation costs from certain intrusions.
The superseding indictment also connects several defendants to the attack against HBO. Behzad Mesri was previously charged separately with compromising HBO’s systems, stealing proprietary information, and attempting to extort the company for approximately $6 million in Bitcoin. Prosecutors now allege that Houshyar, Hashemloo, Fayaz, Ballojeh, and Kahzadian were also directly involved in the intrusion.
The defendants face multiple federal charges, including conspiracy to commit computer intrusions and wire fraud. Some of the alleged offenses carry maximum prison sentences of 20 years. The charges are allegations, and the defendants are presumed innocent unless proven guilty in court.
Alongside the criminal case, the US State Department’s Rewards for Justice program is offering rewards of up to $10 million for information leading to the locations of Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh.
