U.S. prosecutors accuse members of Iran-based Mabna Institute of hacking hundreds of universities, companies, and government institutions and stealing more than 31 terabytes of academic data and intellectual property.
The U.S. Department of Justice has charged 17 Iranian nationals in a major cyber theft campaign allegedly conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients.
A superseding 14-count indictment was unsealed on August 18, 2026, accusing members of the Iran-based Mabna Institute of carrying out coordinated cyber intrusions against hundreds of universities, private companies, government agencies, and nongovernmental organizations around the world. According to the indictment, the campaign resulted in the theft of more than 31 terabytes of academic data and intellectual property.
The Justice Department said the Mabna Institute had operated since at least 2013 and targeted 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, at least 11 foreign companies, five U.S. federal and state government agencies, and at least two NGOs.
U.S. officials described the operation as a state-sponsored campaign designed to acquire valuable academic research, proprietary information, login credentials and other data.
Mabna Institute and the IRGC
According to the indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 to assist Iranian universities and scientific and research organizations in gaining unauthorized access to non-Iranian scientific resources.
The institute allegedly employed or contracted hackers-for-hire and other personnel to conduct cyber intrusions. The indictment states that Mabna contracted with Iranian governmental and private entities and specifically carried out the university spearphishing campaign on behalf of the IRGC.
Assistant Attorney General for National Security John A. Eisenberg said the defendants allegedly hacked universities and research institutions worldwide at the direction of entities including the IRGC, stealing at least 31 terabytes of information and intellectual property.
U.S. Attorney Jamie McDonald said the expanded charges expose what prosecutors characterize as a broader network behind a state-sponsored campaign targeting American universities, businesses and government institutions. He emphasized that the passage of time would not prevent U.S. authorities from pursuing those responsible.
FBI Cyber Division Assistant Director Brett Leatherman likewise described the defendants as allegedly operating a sprawling hacking-for-hire network targeting American and allied institutions for the benefit of the Iranian government.
Thousands of Academic Accounts Compromised
The university hacking campaign reportedly targeted more than 100,000 professor accounts worldwide. According to the indictment, approximately 8,000 professor email accounts were successfully compromised at 144 U.S. universities and 178 universities in countries around the world.
The campaign operated from approximately 2013 through at least December 2017 and targeted academic information across virtually every major field of research.
Using stolen credentials, the defendants allegedly accessed professor accounts and obtained academic journals, theses, dissertations, electronic books and other research materials. The stolen information covered science and technology, engineering, social sciences, medicine and other professional disciplines.
The indictment estimates that at least 31.5 terabytes of academic data and intellectual property were stolen and transferred to servers outside the United States controlled by members of the alleged conspiracy.
The stolen material was allegedly not only obtained for Iranian government and university clients but was also commercially exploited. Prosecutors say stolen academic resources were sold through websites known as Megapaper.ir and Gigapaper.ir, including services that enabled customers in Iran to use compromised university accounts to access foreign university library systems.
Government Agencies and Private Companies Targeted
The alleged cyber campaign extended well beyond academia.
According to the Justice Department, the defendants compromised employee email accounts belonging to at least five U.S. federal and state government agencies, 42 U.S.-based private companies, approximately 11 foreign companies, and various governmental and nongovernmental organizations.
Among the named victims were the U.S. Department of Labor, Federal Energy Regulatory Commission, State of Hawaii, State of Indiana, United Nations, and UNICEF.
The superseding indictment also adds eight defendants and details alleged attacks against additional organizations. One prominent case involved Home Box Office (HBO). Prosecutors allege that Behzad Mesri and other defendants hacked HBO’s systems, stole proprietary information and attempted to extort the company for approximately $6 million in Bitcoin.
Other alleged operations involved password-spraying attacks, unauthorized access, data exfiltration, network reconnaissance and spearphishing campaigns. Prosecutors estimate that some victims incurred more than $20 million in costs associated with investigating and remediating the intrusions.
$10 Million Reward Offered
Alongside the unsealing of the superseding indictment, the U.S. Department of State’s Rewards for Justice program announced rewards of up to $10 million for information leading to the location of five of the defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh.
Nine of the 17 defendants had already been charged in a seven-count indictment announced in March 2018. The new indictment adds eight defendants and expands the allegations concerning the broader network.
The case underscores the growing role of cyber operations as an instrument of state power and intelligence gathering. U.S. authorities have indicated that they intend to continue pursuing Iranian cyber actors even when the alleged attacks occurred years earlier.
The Justice Department’s latest action therefore represents not only a renewed effort to prosecute individuals accused of cyber theft, but also a broader warning that Iranian state-linked cyber operations targeting research, intellectual property, businesses and government institutions can carry long-term legal and financial consequences.
