The United States charged 17 Iranians allegedly linked to the Mabna Institute, an entity U.S. authorities describe as a “hacker-for-hire” company, over a years-long campaign targeting the theft of research, intellectual property, and private data from U.S. and international institutions.
The U.S. Department of Justice said eight defendants were added to the case, while nine others had previously been charged in an indictment announced in March 2018, when they were accused of hacking more than 300 universities and private companies. According to the department, the operations began around 2013 and targeted the accounts of more than 100,000 university professors worldwide, compromising approximately 8,000 of them.
Extent of the Data and Affected Entities
The U.S. government says the attackers used the compromised accounts to access 31.5 terabytes of academic data, including scientific journals, theses, doctoral dissertations, electronic books, and research in multiple fields. Authorities estimated the value of these materials at approximately $3.4 billion.
According to the Justice Department announcement, the operation affected 178 universities, including 144 universities in the United States, as well as at least 53 private companies, 42 of them American, two nongovernmental organizations, and at least 10 government agencies belonging to U.S. states. The department said HBO was among the victims after, according to the announcement, it was subjected to a $6 million extortion demand in Bitcoin.
Charges and Rewards for Information
The charges include conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. Some of these charges carry a maximum penalty of up to 20 years in prison.
The U.S. Department of State announced rewards of up to $10 million for information leading to the identification or location of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. It also provided a link through the Tor network to allow information to be submitted anonymously.
The list of other defendants includes Saeid Houshyar, Manouchehr Hashemloo, and Amir Barati, as well as Behzad Mesri, known as “Skote Vahshat”; Keyvan Fayaz, also known by the names “Achilles” and “The Joker” and the username “bc.monster”; and Mojtaba Galekuhi, known as “Mojtaba Ghaleh Koui”.
Why Does This News Matter?
The case reveals that the theft of academic research is not limited to a single hacking incident but can develop into an organized operation targeting large numbers of accounts to access data of scientific and commercial value. The announcement also shows that the use of valid credentials may allow attackers to move within systems for a long period before being detected, making the protection of researchers’ and employees’ accounts and monitoring access to data an essential part of institutional defense.
U.S. authorities say the operations were carried out on behalf of Iran’s Islamic Revolutionary Guard Corps, Iranian government entities, universities, and paying customers. However, all defendants are presumed innocent until proven guilty in court.