Pull to refresh
Logo
US widens case against Iranian university-hacking network

US widens case against Iranian university-hacking network

Force in Play

A 2018 indictment of the Mabna Institute grows to 17 defendants accused of stealing 31 terabytes of research

August 20th, 2026: Superseding indictment adds eight defendants

Overview

Updated Aug 21

For four years starting in 2013, Iranian operators used professors' stolen passwords to slip into US university networks and copy their research. On August 20, prosecutors expanded a 2018 case against the group behind it, adding eight names and bringing the total charged to 17.

The group, called the Mabna Institute, allegedly stole about 31.5 terabytes of academic data for Iran's Islamic Revolutionary Guard Corps. The State Department now offers up to $10 million for tips on five defendants, including Behzad Mesri, tied to the 2017 HBO hack and its $6 million Bitcoin extortion demand. None of the 17 defendants is in US custody, and all are believed to be in Iran.

Why it matters

The research behind US industry and defense sits on university networks, and this case shows a foreign state copied 31 terabytes of it with little fear of arrest.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

31.5 TB
Academic data stolen
Research and intellectual property copied from university networks, per prosecutors.
17
People charged
Nine were charged in 2018; the new indictment adds eight more.
320+
Universities targeted
144 in the US and 178 abroad, across 22 countries.
$3.4B
Value of stolen access
What the targeted universities paid to license and access the data taken, per the 2018 case.
$10M
Reward for five fugitives
State Department Rewards for Justice offer for information on Behzad Mesri and four co-defendants.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

January 2013 August 2026

7 events Latest: August 20th, 2026 · 3 weeks ago
Tap a bar to jump to that date
  1. Mabna Institute founded and campaign begins

    Origin

    Gholamreza Rafatnejad and Ehsan Mohammadi found the firm, which starts phishing university staff to reach research databases.

Scenarios

1

All 17 stay in Iran, case stays on paper

Likely Resolves by Aug 20, 2027

Discussed by: Cybersecurity reporters at CyberScoop and Defense One noting the defendants' location

Iran does not extradite its nationals to the US, and all 17 are believed to be there. The most likely path is that the indictment stands as a public accusation and a travel constraint, with no defendant ever entering a US courtroom, much as the 2018 charges have gone unenforced for eight years.

2

Treasury sanctions the newly named defendants

Possible Resolves by End of 2026

Discussed by: Precedent from the 2018 case, when Treasury sanctions accompanied the indictment

In 2018 the charges came paired with Treasury sanctions on the institute and individuals. The government could repeat that step for the eight people added in 2026, freezing any US-reachable assets and barring US persons from dealing with them. This is a low-cost move the US often takes alongside cyber indictments.

3

A charged member is arrested outside Iran

Unlikely Resolves by Aug 20, 2027

Discussed by: Pattern of past cyber cases resolved when suspects traveled to cooperating countries

State-linked hackers are occasionally caught when they travel to a country with a US extradition treaty. If one of the 17 leaves Iran and is detained abroad, the case could turn from symbolic to real. This has happened in other cyber prosecutions but is rare for IRGC-linked defendants.

4

State Department posts a reward for the defendants

Possible Resolves by Feb 20, 2027

Discussed by: State's Rewards for Justice program, used for other foreign cyber suspects

The State Department's Rewards for Justice program has offered payouts for information on foreign cyber actors, including in the parallel Russian case. It could post a reward tied to the Mabna defendants to try to shake loose leads or locations, a common follow-on to high-profile indictments.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

May 2014

PLA Unit 61398 indictment (2014)

The US charged five officers of China's People's Liberation Army with hacking Westinghouse, US Steel, Alcoa, and others to steal trade secrets. It was the first time the US criminally charged uniformed state actors for cyber theft.

Then

China denied the charges and suspended a cyber working group with the US. The five officers were never arrested.

Now

The case set the template of 'name and shame' indictments against hackers the US cannot reach, now standard practice.

Why this matters now

Like the Mabna case, it charged foreign state agents who stayed home. The value was public attribution, not a trial.

March 2016

Iranian DDoS and Bowman Dam indictment (2016)

The US charged seven Iranians tied to IRGC contractors with flooding 46 banks with denial-of-service attacks and breaching the controls of a small New York dam. The attacks ran from 2011 to 2013.

Then

None of the seven was arrested. The charges drew attention to Iranian contractors working for the IRGC.

Now

It established a pattern of US prosecutors targeting IRGC-linked front companies, the same structure alleged in the Mabna case.

Why this matters now

Same sponsor, same model: private Iranian firms doing cyber work for the IRGC, charged but out of reach.

October 2020

GRU Sandworm indictment (2020)

The US charged six officers of Russia's GRU military intelligence for the NotPetya malware, attacks on Ukraine's power grid, and disruption of the 2018 Winter Olympics. Damages ran into the billions.

Then

The officers remained in Russia and were never tried. Allies issued coordinated condemnations.

Now

It confirmed that even sweeping, well-documented indictments of state hackers rarely produce arrests.

Why this matters now

Shows the ceiling on these cases: strong evidence and serious charges, but enforcement depends on the suspect leaving home soil.

Sources

(12)