US Charges 17 Iranian Hackers in Alleged $3.4 Billion Intellectual Property Theft Campaign
The United States has charged 17 Iranian nationals allegedly linked to the Mabna Institute, an Iranian hacking organization accused of conducting a years-long cyber espionage campaign targeting universities, businesses, and government agencies worldwide.
Nine of the defendants were previously indicted in March 2018 for allegedly hacking more than 300 universities and private companies to steal academic research, intellectual property, and other sensitive data.
The U.S. Department of Justice has announced rewards of up to $10 million for information that could help locate five of the Iranian defendants.
According to the U.S. government, the eight newly indicted individuals stole academic research, intellectual property, emails, and other confidential information from victims across multiple industries.
The Department of Justice alleges that the defendants conducted cyber operations on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government agencies, universities, and paying customers.
- Saeed Fouchal
- Behzad Mesri, also known as “Sukote Vashat”
- Manuchel Hashemloo
- Keevan Fayaz, also known as “Achilles,” “Joker,” and “BC.Monster”
- Amir Bharati
- Saber Shabaji Baloje
- Armand Kazadian
- Mojtaba Garekhi, also known as “Mojtaba Garekhi”
“Today’s indictment, which includes eight additional defendants, reveals an extensive network allegedly behind a widespread state-sponsored campaign to steal research and intellectual property from U.S. universities, businesses, and government agencies,” U.S. Attorney Jamie MacDonald said.
“More than eight years have passed since we released the first indictment, but these charges make clear that time will not deter us from identifying and pursuing those who target the United States from abroad.”
The alleged hacking campaign began around 2013 and targeted the accounts of more than 100,000 professors worldwide. Investigators say the attackers successfully compromised approximately 8,000 of those accounts.
Using access to compromised university accounts, the hackers allegedly stole 31.5 terabytes of academic information valued at approximately $3.4 billion. The stolen data reportedly included journals, research papers, dissertations, e-books, and other scholarly material covering numerous fields.
The cyber espionage operation affected 178 universities, including 144 in the United States, as well as at least 53 private companies, 42 of them located in the U.S. The alleged victims also included two nongovernmental organizations and at least 10 U.S. state agencies.
HBO was among the organizations named in the announcement. The company was reportedly extorted for $6 million in Bitcoin after the attackers obtained access to its systems.
The defendants face charges including conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. If convicted, some of the charges could result in maximum prison sentences of up to 20 years.
The U.S. State Department is offering rewards of up to $10 million for information leading to the whereabouts of Behzad Mesri, Mojtaba Ghalekhi, Arman Kazadian, Keevan Fayaz, and Saber Shabaji Baloje.
The Rewards for Justice program has also provided Tor links for anonymous submissions. All defendants are presumed innocent unless and until proven guilty in court.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




