Cyberwarfare / Nation-State Attacks,
Fraud Management & Cybercrime
Justice Department Unveils Charges Against Iranian Firm for Selling Stolen Research

In a significant legal development, U.S. federal prosecutors have charged 17 Iranian nationals for their involvement in a decade-long hacking campaign that resulted in the theft of over 31 terabytes of research and intellectual property. This extensive data breach targeted hundreds of universities, companies, and government entities worldwide.
A 14-count superseding indictment was unsealed on a Tuesday in federal court in Manhattan, accusing members of the Tehran-based Mabna Institute of orchestrating the cyber intrusions on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC) and various other governmental clients. Among the accused, eight individuals face new charges while nine others were previously named in an indictment revealed in March 2018.
According to prosecutors, the hackers from the Mabna Institute infiltrated 144 U.S. universities, at least five federal and state agencies, 42 U.S. companies, 178 foreign universities, and 11 foreign corporations. The indictment indicates that the Iranian nationals pilfered information and intellectual property deemed “of untold value,” as articulated by Assistant Attorney General for National Security John Eisenberg.
It was reported that Gholamreza Rafatnejad and Ehsan Mohammadi established the Mabna Institute around 2013 with the intention of aiding Iranian universities and research organizations in acquiring foreign scientific resources. The institute employed hackers-for-hire and conducted a spear-phishing campaign targeting universities, positioning itself as a contractor for the IRGC. This model has evidently influenced subsequent Iranian cyber operations directed at U.S. targets.
Throughout the campaign, which persisted until December 2017, the group focused on more than 100,000 professor accounts globally. They successfully compromised approximately 8,000 accounts across universities in 22 different countries, including notable nations such as Australia, Canada, Germany, Israel, Japan, Saudi Arabia, and the United Kingdom. The hacking operation extracted academic journals, dissertations, and electronic books pertaining to nearly every research discipline, materials that U.S. educational institutions had spent upwards of $3.4 billion to access and procure.
Moreover, the indictment detailed that two websites—Megapaper.ir and Gigapaper.ir—were utilized to distribute the stolen materials within Iran. Megapaper marketed stolen academic resources to Iranian public universities and institutions, while Gigapaper offered a service allowing paying customers to utilize compromised professor accounts for direct access to online library systems of specific U.S. universities and others.
The breach’s impact extended beyond academia, affecting notable organizations such as the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, and international entities like the United Nations and UNICEF. Additionally, foreign corporate victims were identified in Germany, Italy, Sweden, Switzerland, and the United Kingdom.
Significantly, the indictment also connects six defendants to the major 2017 breach of HBO. Behzad Mesri faces accusations of hacking into HBO’s systems, stealing proprietary information, and attempting to extort the company for around $6 million in bitcoin. Prosecutors assert that Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian were complicit in these activities.
In another aspect of the ongoing investigation, three defendants employed password spray attacks targeting private sector companies and at least two government entities. This resulted in more than $20 million in victim costs related to investigation and remediation efforts.
Assistant Director Brett Leatherman from the FBI’s cyber division reaffirmed the agency’s commitment to pursuing justice, stating, “The FBI’s memory is long, and time will not blunt our resolve to pursue justice.” Among the various charges, conspiracy to commit computer intrusions and wire fraud could incur maximum sentences of 20 years, while identity theft counts mandate a two-year minimum sentence.
The unsealing of this indictment comes amidst ongoing warnings from security leaders regarding Iranian targeting of U.S. organizations. Such activities have been characterized as opportunistic and challenging to predict, with victims chosen more for their accessibility rather than any strategic advantage. Experts continue to highlight the evolving nature of cyber threats emanating from state-sponsored actors, underscoring the necessity for vigilance and preparedness in safeguarding critical information.

