DOJ Charges 17 Iranian Hackers in IRGC-Linked Campaign That Stole 31.5TB of Research Data

August 21, 2026

The U.S. Department of Justice has unsealed a 14-count superseding indictment against 17 alleged members of the Iran-based Mabna Institute, accusing them of conducting a long-running cyber espionage campaign that stole at least 31.5TB of research data and intellectual property.

According to the indictment, the operation began around 2013 and continued through at least December 2017. Prosecutors allege that the group worked for Iranian government and university clients, including the Islamic Revolutionary Guard Corps, or IRGC.

The campaign allegedly targeted universities, private companies, government agencies, and non-governmental organizations in the United States and other countries.

Gholamreza Rafatnejad and Ehsan Mohammadi reportedly founded the Mabna Institute to provide Iranian institutions with access to foreign scientific resources.

DOJ Charges 17 Iranian Hackers

It allegedly employed or worked with hackers-for-hire who conducted phishing, reconnaissance, credential theft, password spraying, and data exfiltration operations.

The group targeted more than 100,000 professor accounts globally and allegedly compromised about 8,000 academic email accounts. Victims included 144 U.S. universities and 178 universities outside the United States.

Affected institutions were located across Australia, Canada, China, Europe, the Middle East, Asia, and the United Kingdom. Attackers reportedly used spearphishing emails to steal professor login credentials.

Once inside university networks and online library portals, they accessed academic journals, dissertations, theses, electronic books, research papers, and other protected resources. The theft covered scientific, engineering, medical, social science, technology, and professional research fields.

The stolen material was exfiltrated to infrastructure controlled by the alleged conspirators outside the United States. Prosecutors said U.S. universities had spent more than $3.4 billion to obtain access to the research and intellectual property targeted by the campaign.

The operation also allegedly monetized stolen academic access. Two Iran-based websites, Megapaper.ir and Gigapaper.ir, were used to sell stolen resources and access to compromised university accounts.

Megapaper allegedly sold stolen academic content to customers in Iran. At the same time, Gigapaper offered buyers direct access to online university library systems through hijacked professor accounts.

Beyond academia, the indictment alleges that Mabna Institute operators targeted at least 42 U.S. private-sector companies, 11 foreign companies, five U.S. federal and state government agencies, and several international organizations.

Named victims included the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and UNICEF.

The expanded indictment adds eight defendants to a case first announced in 2018. Several defendants were also allegedly tied to the 2017 intrusion at HBO, in which stolen data was used in an attempted extortion scheme targeting approximately $6 million in Bitcoin.

The charges include conspiracy to commit computer intrusions, wire fraud, unauthorized access for private financial gain, and aggravated identity theft.

The DOJ said the victims incurred more than $20 million in investigation and remediation costs due to some private-sector and government intrusions.

The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. The indictment remains an allegation, and all defendants are presumed innocent unless proven guilty in court.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Original article can be found here