US Indicts Iranian Hackers for $3.4B IP Theft
US government officials have filed criminal charges against 17 individuals from Iran linked to a cyber espionage operation that targeted academic institutions, private enterprises, and government entities over multiple years.
Charges and Defendants
The defendants are alleged to have operated under the guise of a hacking-for-hire organization known as Mabna Institute, which facilitated cyber intrusions for state and non-state actors. The Justice Department (DoJ) revealed that nine of the accused were previously indicted in 2018 for similar activities involving over 300 universities and corporations. The latest charges include eight additional individuals who are accused of stealing academic research, intellectual property, email communications, and other confidential data.
Coordination with Iranian Government Agencies
According to the DoJ, these defendants allegedly worked in coordination with the Islamic Revolutionary Guard Corps (IRGC), other Iranian government agencies, and private clients. The individuals named in the indictment include Saeid Houshyar, Behzad Mesri, Manouchehr Hashemloo, Keyvan Fayaz, Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi.
Operation Scope and Impact
The operation, which the DoJ claims began around 2013, targeted accounts belonging to over 100,000 academic professionals globally. Attackers compromised approximately 8,000 of these accounts, exfiltrating 31.5 terabytes of data. This included journals, theses, dissertations, e-books, and research materials across various fields, with an estimated value of $3.4 billion. The breach affected 178 universities, 144 of which are located in the United States, along with 53 private companies (42 in the U.S.), two non-governmental organizations, and at least 10 U.S. state agencies.
One notable victim of the campaign was the entertainment company HBO, which reportedly faced extortion demands of $6 million in Bitcoin.
Legal Consequences and Rewards
The defendants now face multiple counts, including conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. If convicted, they could receive up to 20 years in prison for each offense. The State Department has also issued rewards of up to $10 million for information leading to the location of five of the accused: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. A secure Tor-based submission portal has been established to facilitate anonymous tips.
Security Implications
All defendants are presumed innocent until proven guilty in a court of law. The DoJ emphasized that the charges underscore the U.S. commitment to holding foreign actors accountable for cyberattacks, regardless of the time elapsed since the initial incidents. The agency highlighted that the operation’s scale and duration demonstrate the persistent threat posed by state-sponsored and commercial hacking groups. The case follows a broader pattern of cyber espionage targeting intellectual property and academic institutions, with attackers leveraging compromised credentials to access sensitive systems.
Security researchers note that once malicious actors obtain valid login credentials, only 37% of their activities are typically blocked by existing defenses. This underscores the importance of multi-factor authentication and continuous monitoring of user behavior.
Conclusion
The DoJ emphasized that the charges underscore the U.S. commitment to holding foreign actors accountable for cyberattacks, regardless of the time elapsed since the initial incidents. The agency highlighted that the operation’s scale and duration demonstrate the persistent threat posed by state-sponsored and commercial hacking groups.
