SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach MABNA-INSTITUTE-IR 2026-08-19

Global Universities: Mabna Institute IRGC Directed Cyber Theft

"The U.S. Department of Justice unsealed a 14-count superseding indictment on Tuesday, August 18, 2026, charging 17 members of Iran's Mabna Institute with running a coordinated, multi-year intrusion campaign on behalf of…"

The U.S. Department of Justice unsealed a 14-count superseding indictment on Tuesday, August 18, 2026, charging 17 members of Iran's Mabna Institute with running a coordinated, multi-year intrusion campaign on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. Per the DOJ's own release, the victim set includes 144 U.S.-based universities, 178 foreign universities, at least 42 U.S. private sector companies, at least 11 foreign companies, at least five U.S. federal and state government agencies, and at least two NGOs. The haul: more than 31 terabytes of academic data and intellectual property, plus employee email accounts across the corporate, government, and NGO victims. The State Department's Rewards for Justice program simultaneously posted a reward of up to $10 million for information on five of the defendants who remain at large.

What Happened

This is a second wave, not a new discovery. Nine of the 17 defendants were already charged in a seven-count indictment made public in March 2018; the superseding (S2) indictment replaces it, adds eight new defendants, and expands the count from seven to fourteen. CyberScoop notes the earlier case covered intrusions at the U.S. Labor Department, the United Nations, and networks in Hawaii and Indiana, details echoed by Reuters copy carried in The Straits Times and The Jerusalem Post.

The DOJ says Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute in approximately 2013 as an Iran-based company whose explicit purpose was to help Iranian universities and scientific and research organizations obtain access to foreign scientific resources. It operated as a contractor, paying hackers-for-hire named in the indictment and taking work from Iranian government and private entities. The university-focused spearphishing campaign specifically was conducted at the behest of the IRGC.

Sources differ slightly on the campaign window. The DOJ press release states the activity ran "since at least 2013"; the Reuters-sourced reporting in The Straits Times characterizes the targeting as running from at least 2013 through 2017. Treat 2013 as the confirmed start and the exact end date as unresolved in public reporting.

The case is before U.S. District Judge Jesse M. Furman in the Southern District of New York. IBTimes UK reports the UK's National Crime Agency is credited as an investigative partner, and that the Rewards for Justice tip channel is Tor-based, a nod to the fact that the named fugitives are believed to be inside Iran. The five named in the reward notice, per IBTimes UK, are Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. That reward does not extend to the other 12 defendants.

What Was Taken

The volume figure varies marginally by source and it is worth stating both: the DOJ release says "more than 31 terabytes," while CyberScoop and Anadolu Agency both cite 31.5 terabytes from the indictment. The difference is rounding, not a dispute.

The stolen material was overwhelmingly academic: journals, theses, dissertations, and e-books spanning effectively every research discipline, taken through library systems using stolen professor credentials. Alongside that, the defendants took the contents of employee email accounts at private companies, government agencies, and NGOs, a materially different and more sensitive category of data than licensed journal content.

Account compromise numbers are consistent across CyberScoop, Cybersecurity Dive, and IBTimes UK: more than 100,000 professor email accounts targeted globally, with roughly 8,000 successfully compromised across the 144 U.S. and 178 foreign institutions. IBTimes UK adds that the foreign victim institutions included universities in the UK, Germany, Japan, and Israel.

Two cost figures circulate, both attributed to the DOJ but appearing only in OTHER-tier coverage. Anadolu Agency and IBTimes UK both report roughly $3.4 billion as what U.S. universities spent to procure or re-access the compromised data and IP over the life of the conspiracy. Anadolu alone reports more than $20 million in remediation costs borne by victims, and separately reports that the defendants allegedly hacked HBO and attempted to extort $6 million in Bitcoin. That HBO allegation appears in only one OTHER-tier source in this set and should be treated as reported, not confirmed, until the indictment text is read directly. Note that Behzad Mesri, one of the five reward targets, was the defendant charged in the original 2017 HBO case, which makes the linkage plausible but still single-sourced here.

Why It Matters

Indictments against people sitting in Tehran do not put anyone in a cell. What they do is publish tradecraft, name infrastructure, and impose friction on travel and finance. The defensive value here is the pattern, not the prosecution.

The pattern is that higher education is treated as a soft entry point into national research output. Universities hold pre-publication research, grant data, dual-use engineering work, and federated identity systems that bridge into national lab and agency environments, all while running the most permissive network culture of any sector. Mabna did not need zero-days. It needed a professor to type a password into a convincing page.

The second point is the contractor model. Mabna was a company with founders, clients, and a payroll of contract hackers. That structure gives the IRGC deniability and gives the operators a revenue stream from non-state work on the side, which is the most likely explanation for a state-tasked academic theft crew also allegedly running a Bitcoin extortion attempt against a media company. Defenders should stop assuming that state-directed and criminally motivated activity come from separate rosters.

Third, the timing is not neutral. As CyberScoop points out, unlike 2018 the United States is currently at war with Iran, following a 60-day negotiation deadline that passed without progress. Cybersecurity Dive notes these charges land amid an ongoing investigation into a coordinated compromise of water systems across 12 U.S. states, where no charges have been filed but federal and state investigators have drawn links to recent Iran-associated activity. Sectors with any Iranian nexus in their threat model should read this indictment as a statement of intent about the current period, not a retrospective on 2013.

The Attack Technique

The core technique described across the DOJ release and the reporting is credential-harvesting spearphishing at scale, not malware-heavy intrusion.

Operators researched professors at targeted institutions and sent tailored messages, typically posing as academic correspondence referencing the target's own published work or research interests, directing them to a spoofed university login portal. Captured credentials were then used to authenticate directly to library and journal systems and to email, which is why the reported ratio matters: over 100,000 accounts targeted, roughly 8,000 compromised, an approximately 8 percent success rate sustained across hundreds of institutions and multiple years. Once inside, the crews systematically exfiltrated licensed content and, at the corporate and government victims, the contents of mailboxes.

The DOJ further alleges the stolen academic material was resold through Iranian websites, meaning exfiltration was followed by commercial distribution rather than being consumed solely by state clients.

Detection notes worth carrying forward: this activity looks like a valid user logging in. The signals are behavioral, not signature-based, and they are exactly the signals most university SOCs are not resourced to watch.

What Organizations Should Do

  1. Enforce phishing-resistant MFA on faculty and staff identity, not just administrators. The entire campaign depended on a reusable password reaching an attacker. FIDO2/WebAuthn breaks that chain; SMS and TOTP only slow it. Faculty exemptions from MFA policy are the specific gap this indictment describes.

  2. Instrument library proxy and journal-access systems for bulk download behavior. Rate-limit and alert on per-account volume anomalies, off-hours access, and downloads spanning disciplines unrelated to the account holder's field. Thirty-one terabytes left through normal-looking sessions because nobody was counting.

  3. Alert on impossible-travel and anomalous-ASN authentication for academic accounts. Correlate logins against expected geography and known VPN/proxy infrastructure. Sustained access from foreign-hosted infrastructure to a domestic faculty account is the highest-signal indicator available for this pattern.

  4. Audit mailbox forwarding rules and OAuth grants across the tenant. Email theft was a named objective at companies, agencies, and NGOs. Auto-forward rules and consented third-party app tokens are the standard persistence mechanisms after credential compromise, and they survive a password reset.

  5. Run academic-themed phishing simulations against research staff. Generic corporate templates do not measure exposure to lures built around a target's own citations, conference invitations, or co-author correspondence. Test what was actually used.

  6. Treat identity federation between universities, national labs, and agency partners as in-scope. Map which downstream systems a compromised faculty credential can reach, and apply step-up authentication at those boundaries rather than trusting the upstream assertion.

  7. For organizations with Iran-nexus exposure, re-baseline now. Given the concurrent water-sector investigation and the active conflict, treat this indictment as current-period threat intelligence: review perimeter authentication logs for the past 90 days, not the past decade.

Sources: Office of Public Affairs 17 Iranians Charged with Conducting Mass... | Eight years later, federal authorities re-up charges against ... | DOJ unseals new charges against 17 hackers in Iran-backed campaign... | DOJ charges 17 people in Iran-backed hacking campaign ... | US charges 17 in alleged massive Iranian cybertheft ring | DOJ secures indictment of 17 Iranians accused of ‘massive’ cyber th... | US Charges 17 Iranian Hackers, Offers $10 Million Bounty for 5 Fugi... | US Justice Department charges 17 hackers working for IRGC The Jeru...