The US Department of Justice (DOJ) on Tuesday unsealed updated charges against 17 individuals linked to Iran’s Mabna Institute, accusing them of conducting a state-sponsored cyber theft campaign on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian entities.
The indictment alleges the group targeted 144 US universities, 178 foreign universities, 42 US private-sector companies, 11 foreign companies, five US government agencies, and two NGOs since at least 2013. Prosecutors claim the hackers stole more than 31 terabytes of academic data, intellectual property, and sensitive emails, resulting in over $20 million in investigative costs for victims.
Nine of the 17 defendants were previously charged in a 2018 indictment, which included allegations of hacking the US Labor Department, the United Nations, and state agencies in Hawaii and Indiana. The updated charges expand the scope of the alleged conspiracy, describing a broader network of cyber intrusions.
Key Allegations and Legal Actions
The DOJ’s 14-count superseding indictment details multiple methods used in the cyber campaign, including password-spraying attacks, unauthorized system access, and data exfiltration. Prosecutors allege the hackers operated under contracts with the IRGC, Iranian intelligence agencies, and university clients, targeting research and proprietary information.
A $10 million reward was also announced by the State Department’s Rewards for Justice program, offering compensation for information leading to the location of several defendants. The DOJ emphasized the national security threat posed by such operations, with FBI Assistant Director James C. Barnacle Jr. stating that the campaign reflected a coordinated effort to target US institutions and global partners.
Targets and Impact
The alleged victims span academic, corporate, and governmental sectors, with the hackers focusing on research institutions and private companies to obtain sensitive data. The $20 million in investigative costs cited by prosecutors underscores the financial burden on affected organizations.
Among the targets were employees’ email accounts at private companies and government agencies, as well as academic databases at universities worldwide. The DOJ did not specify whether any classified or national security-related data was compromised, though the scale of the theft suggests potential long-term implications for intellectual property and research security.
Iranian Response and Broader Context
The Iranian government’s representatives at the United Nations did not immediately respond to requests for comment, and contact information for the Mabna Institute was unavailable. The case follows a pattern of state-sponsored cyber operations attributed to Iran, which US officials have linked to broader espionage and intellectual property theft efforts.
The indictment aligns with previous US actions targeting foreign cyber threats, including sanctions and diplomatic pressure. Analysts note that such operations often serve dual purposes: advancing scientific research for Iranian institutions while undermining foreign competitors. The DOJ’s announcement reinforces the US government’s stance on deterring cyber-enabled espionage, particularly when linked to military or intelligence entities like the IRGC.
Background: The Mabna Institute and Prior Indictments
The Mabna Institute, an Iran-based entity, has been accused of facilitating cyber intrusions since at least 2013. The 2018 indictment named nine individuals, including Gholamreza Rafatnejad, Ehsan Mohammadi, and Behzad Mesri, who were charged with hacking US government agencies and private companies.
The updated charges expand the list of defendants and detail additional methods and targets, suggesting a more extensive operation than previously disclosed. The DOJ’s Southern District of New York is leading the prosecution, with officials framing the case as part of a larger effort to disrupt state-sponsored cyber threats.