US DOJ Charges 17 Iranians in Decade-Long Hacking Campaign Targeting Research and IP
The U.S. Department of Justice has indicted 17 Iranian nationals for a decade-long hacking campaign that stole over 31 terabytes of research and intellectual property from hundreds of global institutions.

The U.S. Department of Justice has unsealed a superseding indictment against 17 Iranian nationals, accusing them of orchestrating a vast, decade-long hacking campaign that pilfered more than 31 terabytes of sensitive research and intellectual property. The operation, allegedly conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian government entities, targeted hundreds of universities, companies, and government agencies worldwide.
Prosecutors allege that the Tehran-based Mabna Institute, established around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, served as the front for these illicit activities. The institute's purported mission was to acquire foreign scientific resources for Iranian universities and research organizations. However, it employed and contracted hackers-for-hire to execute spear-phishing campaigns and other intrusions, a model that has reportedly continued to shape Iranian cyber operations against U.S. targets.
The indictment details a significant impact on academia, with Mabna Institute hackers compromising an estimated 8,000 professor accounts across 144 U.S. universities and 178 foreign universities in 22 countries. The stolen data includes academic journals, dissertations, and electronic books, representing material that U.S. universities collectively spent over $3.4 billion to procure and provide access to. The campaign specifically targeted over 100,000 professor accounts globally.
Beyond academia, the group's reach extended to government agencies and private sector companies. Victims included at least five U.S. federal and state agencies, 42 U.S. companies, and 17 foreign companies. Notable government victims mentioned are the U.S. Department of Labor, the Federal Energy Regulatory Commission, and the states of Hawaii and Indiana, alongside international organizations like the United Nations and UNICEF.
Furthermore, the indictment links six defendants to the 2017 breach of HBO. Behzad Mesri is specifically accused of hacking HBO's systems, stealing proprietary data, and attempting to extort the company for approximately $6 million in bitcoin. Other defendants are alleged to have been directly involved in this incident.
The stolen research and intellectual property were allegedly monetized within Iran through two websites: Megapaper.ir and Gigapaper.ir. Megapaper reportedly sold the illicitly obtained academic resources to Iranian public universities and institutions. Gigapaper offered a service allowing paying customers to use compromised professor accounts to directly access the online library systems of targeted universities.
In addition to the academic and corporate espionage, the indictment also charges three defendants with using password spray attacks against private sector companies and government entities, resulting in over $20 million in victim costs for investigation and remediation. The charges brought by federal prosecutors include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud, wire fraud, and aggravated identity theft, carrying potential maximum sentences of 20 years for wire fraud and mandatory two-year terms for identity theft.
The charges underscore ongoing concerns from security leaders regarding Iran's cyber activities, which are often described as opportunistic and difficult to predict, with targets frequently selected based on access rather than strategic importance. The FBI emphasized its long-term commitment to pursuing justice in cybercrime cases.