The U.S. Justice Department unsealed a 14-count superseding indictment on Tuesday, August 18, 2026, charging 17 members of the Iran-based Mabna Institute over a coordinated intrusion campaign that ran from at least 2013 through at least December 2017. According to the DOJ, the group breached 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, at least 11 foreign companies, at least five U.S. federal and state government agencies, and at least two NGOs, exfiltrating more than 31 terabytes of academic data and intellectual property. The case sits in the Southern District of New York before U.S. District Judge Jesse M. Furman, and the State Department is offering rewards of up to $10 million through Rewards for Justice for information on five of the defendants.
What Happened
The DOJ alleges that Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 with the explicit purpose of helping Iranian universities and scientific and research organizations obtain non-Iranian scientific resources, and that the firm paid hackers-for-hire to do the work. Much of the activity was conducted on behalf of Iran's Islamic Revolutionary Guard Corps, with additional work for other Iranian government bodies, Iranian universities, and paying commercial customers.
This is the second wave of charges against the same operation. The 2018 indictment was a 7-count case; the new S2 indictment replaces and expands it. There is a discrepancy in the reporting on the overlap: the DOJ press release states that nine of the 17 defendants were previously charged in March 2018, and BleepingComputer, CyberScoop, Help Net Security and SecurityWeek all follow that figure, describing eight newly added names. The Record reports instead that eight of those charged were previously indicted in 2018. The primary DOJ statement carries the weight here, so treat nine prior defendants plus eight new ones as the operative count.
The eight defendants named as newly charged by BleepingComputer are Saeid Houshyar, Behzad Mesri (aka "Skote Vahshat"), Manouchehr Hashemloo, Keyvan Fayaz (aka "Achilles," "The Joker," "bc.monster"), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (aka "Mojtaba Ghaleh Koui"). SecurityWeek lists the fuller roster including Abdollah Karima (aka Vahid Karima), Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam and Sajjad Tahmasebi. The $10 million rewards apply to Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.
U.S. Attorney Jamie McDonald framed the timing directly: "More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad." FBI Assistant Director in Charge James C. Barnacle Jr. called the campaign "a serious threat to our national security." CyberScoop notes the geopolitical backdrop that did not exist in 2018: the United States is currently engaged in a war with Iran, following the expiry of a 60-day negotiation deadline with no progress.
What Was Taken
The headline volume is more than 31 terabytes of academic data and intellectual property. Figures differ slightly by source: the DOJ, BBC, The Record, Help Net Security and SecurityWeek all state "more than 31 terabytes," while CyberScoop puts the figure at "at least 31.5 terabytes." The material included academic journals, research papers, theses, dissertations and academic e-books spanning science, engineering, medicine and the social sciences, effectively across all fields of research.
Beyond academic content, the group took email accounts and their contents from private-sector companies, government agencies and NGOs. The Record reports that compromised accounts included ones connected to the Department of Labor, the Federal Energy Regulatory Commission, multiple United Nations organizations including the U.N. Children's Fund, and state government agencies in Hawaii and Indiana. The U.N. did not respond to The Record's request for comment.
The $3.4 billion figure deserves precision, because sources characterise it differently. The DOJ language quoted by Help Net Security is that "U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property," meaning it is a measure of what the stolen material cost its rightful licensees, not an appraised value of the loss. BBC News renders the same number more loosely as academic data and IP "worth approximately $3.4bn (£2.5bn)." Assistant Attorney General John Eisenberg, quoted by both the DOJ and The Record, avoided a number entirely, describing the haul as "intellectual property of untold value." Defenders quoting this figure should use the procurement-cost framing.
Why It Matters
This is a state-directed intelligence operation running on a commercial services model, and that hybrid is the durable lesson. Mabna was not a unit inside the IRGC; it was a company that sold access and stolen research to the IRGC, to other Iranian government entities, and to Iranian universities as paying clients. Help Net Security reports that the operation ran two websites selling stolen material to buyers inside Iran, including public universities, and that one of those sites let paying customers log directly into compromised professor accounts to reach U.S. and foreign university library systems themselves. That is a resale channel with recurring revenue, not a smash-and-grab.
The targeting logic follows from that. Universities are soft-perimeter organisations holding hard-value data, with large populations of credentialed users, federated library access to commercial research databases, and a culture of open collaboration. A single compromised professor account is simultaneously an intelligence asset, a pivot into a research network, and a resellable subscription. UNDERCODE NEWS, which is a lower-confidence source, frames this as the attackers turning compromised academic identities into a long-term intelligence and commercial ecosystem; that reading is consistent with the DOJ's own description of the resale sites.
The eight-year gap between indictments also matters operationally. None of the defendants are in custody, and the charges are allegations. The practical output of this action is attribution, name-and-shame pressure, and a $10 million bounty, not disruption. Organisations should not read an indictment as the end of a threat.
The Attack Technique
The tradecraft described in the indictment is unglamorous and effective: spearphishing at industrial scale, followed by credential reuse. The DOJ says the group targeted the email accounts of more than 100,000 professors worldwide and successfully compromised roughly 8,000 of them, across the 144 U.S. and 178 foreign universities. That is an approximately 8 percent success rate sustained over four-plus years.
Once inside a professor's mailbox, the operators used the stolen credentials to authenticate to university library systems and download licensed academic content in bulk. There was no single spectacular exploit; the campaign scaled by repetition of account compromise. UNDERCODE NEWS additionally characterises the activity as including password spraying and financially motivated exploitation. Password spraying is consistent with the pattern the DOJ describes and with the known Mabna profile, but as a single OTHER-tier claim it is not independently confirmed by the primary indictment summary or the established security press, so treat it as reported rather than established.
Notably, no malware family, no zero-day and no novel implant appears anywhere in the sourcing. The entire 31-terabyte loss traces back to phished credentials and the standing access those credentials unlocked.
What Organizations Should Do
- Enforce phishing-resistant MFA on faculty, researcher and contractor mail. The entire campaign hinges on password-only or weakly-protected email access. FIDO2 or hardware-token MFA on mailboxes, VPN and library federation would have broken the primary kill chain. Prioritise accounts with library or research-database entitlements, not just administrators.
- Instrument library and research-database access for bulk-download behaviour. Alert on anomalous volume, off-hours retrieval, novel geolocation and impossible-travel patterns against journal and repository proxies. A single account pulling thousands of PDFs is the detection signal that would surface this class of theft, and it is a licensing-compliance control as much as a security one.
- Audit mailbox forwarding rules, OAuth grants and delegated access. Long-dwell mailbox campaigns persist through auto-forward rules and third-party app consent that survive password resets. Sweep for these across the whole tenant and set alerts on new external-forwarding rules.
- Treat academic and R&D identity as high-value. Apply conditional access, session-length limits and re-authentication to accounts holding pre-publication research, grant data or licensed corpora, and extend the same controls to visiting researchers and joint-appointment staff whose accounts often escape standard policy.
- Run credential-stuffing and password-spray defences at the identity provider. Smart lockout, per-IP and per-tenant rate limiting on authentication endpoints, and blocking of legacy protocols that bypass MFA. Legacy IMAP and POP endpoints are a common gap in university tenants.
- Build the mailbox-compromise playbook now. Define containment steps for a compromised faculty account: token revocation, forced re-auth, forwarding-rule removal, downstream library-access review, and notification to research partners whose data may have been reachable through the account.
- Extend the review beyond your own perimeter. The victim set here included federal agencies, state agencies and U.N. bodies reached through the same technique. Map which external partners hold your research or grant data and confirm equivalent controls apply there.
Sources: US charges Iranian hackers over $3.4 billion intellectual property... | 17 Iranians Charged with Conducting Massive Cyber Theft ... | US charges 17 Iranians over 'massive' cyber theft campaign - BBC News | US charges Iranians for sprawling hacking campaign on government ag... | US charges 17 Iranian hackers over 31-terabyte academic ... | Eight years later, federal authorities re-up charges against ... | US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of... | Eight Years Later, the Mabna Institute Case Expands: A State-Linked...