Iran-Based Mabna Institute Charged for Stealing 31TB of Academic Data; $10M Reward Offered
The U.S. Department of Justice has charged 17 members of Iran's Mabna Institute for a decade-long cyber espionage campaign that stole over 31TB of academic data and intellectual property from universities worldwide.

The U.S. Department of Justice has unsealed charges against 17 individuals associated with the Mabna Institute, an Iran-based entity accused of orchestrating a vast cyber intrusion campaign spanning from at least 2013 to December 2017. The institute allegedly targeted computer systems at 144 U.S. universities, 178 international universities, 42 U.S. private sector companies, 11 foreign private sector companies, five U.S. government agencies, and two non-governmental organizations. The primary objective of these intrusions was the theft of academic data and intellectual property, amassing over 31 terabytes of sensitive information.
Beyond academic institutions, the Mabna Institute also targeted email accounts of employees within private sector companies, government agencies, and NGOs. In total, the campaign compromised approximately 8,000 accounts out of over 100,000 targeted professor accounts globally. These operations were reportedly carried out on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), highlighting a significant instance of state-sponsored cyber espionage conducted through a private entity.
The Mabna Institute, founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, not only stole data for the benefit of the Iranian government but also monetized its illicit gains. The stolen data was sold through two websites, Megapaper.ir and Gigapaper.ir, indicating a commercial aspect to the state-backed espionage. This privatization of state espionage blurs the lines between cybercrime and state-sponsored activities, with capable, deniable, commercially-run crews undertaking state-level operations.
In response to the scale and impact of these operations, the U.S. Department of State has announced a substantial $10 million reward for information leading to the arrest or conviction of five of the named defendants, or any associated individuals or entities. This significant reward underscores the U.S. government's commitment to dismantling sophisticated cybercrime networks and holding perpetrators accountable.
Security experts note that this case exemplifies a growing trend where state actors leverage private contractors to conduct cyber operations, offering a degree of plausible deniability. Universities, with their vast intellectual property and often less stringent security controls compared to critical infrastructure, remain prime targets for such campaigns. The open-access culture within academia can also be exploited by phishing and social engineering tactics.
The Mabna Institute's activities represent a sophisticated model of cyber-enabled theft and espionage, where intellectual property is treated as a commodity. The involvement of the IRGC suggests a strategic effort by Iran to acquire advanced research and technological knowledge through illicit means, potentially bolstering its own capabilities.
This case also highlights the evolving nature of cyber threats, where nation-state actors are increasingly employing complex, multi-faceted strategies that combine espionage, data theft, and commercial exploitation. The ability of the Mabna Institute to operate for years and target such a wide array of institutions points to the challenges faced by law enforcement and cybersecurity professionals in tracking and mitigating these advanced persistent threats.
The charges and reward offer a potential pathway to disrupting this network and preventing future similar operations. The DoJ's action sends a clear message that such large-scale cyber intrusions, even when conducted through third parties, will be met with significant legal and financial repercussions.