The US Justice Department has charged 17 Iranian nationals in an expanded indictment over a years-long hacking campaign that stole 31 terabytes of data from universities, companies, and government agencies around the world.

 

What happened

Prosecutors unsealed a superseding indictment this week, adding eight new names to a case first made public eight years ago. The indictment charges 17 members of the Mabna Institute, an Iran-based hacking operation that has run campaigns since at least 2013 on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and other government and university clients. The group compromised systems at 144 US universities and 178 foreign universities, breached at least 42 US private companies and 11 foreign companies, and hit five federal and state government agencies plus two nongovernmental organizations. The hackers extracted more than 31 terabytes of academic data and intellectual property, along with employee email accounts wherever they gained access. Nine of the 17 defendants were previously charged in a seven-count indictment announced in March 2018.

 

Going deeper

The hackers targeted more than 100,000 professor accounts globally and successfully broke into about 8,000 of them across roughly 24 countries. They used the stolen credentials to pull research papers, theses, dissertations, and academic journals, then resold that material through websites including Megapaper.ir and Gigapaper.ir, where customers could buy academic resources outright or purchase access to compromised professor accounts to reach university libraries directly. Separately, other defendants in the case ran password spray attacks against private companies and at least two government entities. One newly added defendant, Behzad Mesri, was previously charged on his own for breaking into HBO's systems, stealing proprietary data, and attempting to extort the company for about $6 million in Bitcoin. This indictment now connects Mesri and four co-defendants to that HBO intrusion as part of the wider Mabna Institute operation.

 

What was said

U.S. Attorney Jamie McDonald for the Southern District of New York said the new charges show that time will not stop prosecutors from pursuing people who "target the United States from abroad," adding that cyber operations have become "a central instrument of national power" with direct consequences for US security and economic strength.

 

By the numbers

  • 17 total defendants charged in the superseding indictment, 8 newly added
  • 31+ terabytes of academic data and intellectual property stolen
  • 144 US universities and 178 foreign universities compromised
  • 42 US private companies and 11 foreign companies breached
  • 5 federal/state government agencies and 2 NGOs targeted
  • 100,000+ professor accounts targeted, 8,000 successfully breached across 24 countries
  • $20+ million spent by victims investigating and cleaning up the intrusions
  • $10 million reward offered by the State Department's Rewards for Justice program for information on five of the defendants (Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh)
  • 8 years between the original indictment and this expanded version

 

Why it matters

This case shows how a state-linked hacking operation can include espionage, academic theft, and commercial extortion. The Mabna Institute didn't just target government or research institutions on behalf of the IRGC, it also ran a commercial resale business for stolen academic credentials and turned that access into profit through sites like Megapaper.ir and Gigapaper.ir.

The case also matters for healthcare organizations. Universities are frequent hosts of medical schools, hospitals, and biomedical research programs, so stolen academic credentials and compromised professor accounts of the kind described in this case can open a path to sensitive health-related research and data, not just general coursework. The password spray attacks used against private companies and government entities in this campaign are also a tactic that targets healthcare organizations, since weak or reused credentials remain a common way attackers gain access in hospital and health system networks.

Learn more: Causes and prevention strategies for healthcare email breaches in 2026

 

The bottom line

This case shows that when credential theft and account compromise are involved, the exposure can go across universities, private companies, government agencies, and healthcare-adjacent research long after the initial breach, and prosecutors may keep building a case for years. Organizations that rely on individual account credentials as a primary safeguard, healthcare entities included, should treat sustained campaigns like this one as a reason to strengthen authentication and monitoring.

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is the Mabna Institute?

It is an Iran-based hacking operation named in this indictment as the group behind the campaign.

 

What is a password spray attack?

It is a hacking technique where attackers try commonly used passwords across many accounts to gain unauthorized access.

 

What does it mean for a case to be a "superseding indictment"?

It means a new indictment has replaced or expanded an earlier one, by adding charges or defendants.