The U.S. Department of Justice unsealed a 14-count superseding indictment charging 17 Iranian nationals tied to the Tehran-based Mabna Institute with conducting a long-running cyber intrusion and theft campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian government and university clients. Prosecutors allege the operation, active since at least 2013, compromised more than 100,000 professors’ email accounts worldwide, including about 8,000 accounts across 144 U.S. universities and 178 foreign universities, and stole at least 31.5 terabytes of academic research, intellectual property, and email contents.
Authorities said the campaign also targeted at least five U.S. federal and state agencies, dozens of companies in the United States and abroad, NGOs, and media targets including HBO, with several defendants linked to the separate HBO hack-and-extortion case. The superseding indictment expands a 2018 case by adding eight defendants and alleges the stolen academic materials were monetized through Megapaper.ir and Gigapaper.ir; U.S. officials said American universities alone spent roughly $3.4 billion to procure and access the stolen data, while the State Department is offering up to $10 million for information leading to several of the accused.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
The U.S. State Department's Rewards for Justice program announced up to $10 million for information leading to the location of five defendants named in the superseding indictment.
On August 18, 2026, the U.S. Department of Justice unsealed a 14-count superseding indictment charging 17 Iranian nationals affiliated with the Mabna Institute over a long-running cybertheft campaign. The new case expands and replaces the 2018 indictment, adding eight defendants and alleging broader targeting of universities, companies, government agencies, and NGOs.
The superseding indictment alleges the Mabna Institute's cyber-enabled theft campaign continued until at least March 2022, extending the previously documented timeline well beyond 2017. The filing also ties this longer-running operation to large-scale theft from universities worldwide.
The DOJ previously announced a 7-count indictment in March 2018 charging nine of the 17 defendants later named in the superseding case.
The indictment alleges the university-focused hacking operation ran from approximately 2013 through at least December 2017, compromising thousands of professor accounts and stealing academic data.
The DOJ alleges the Mabna Institute began a coordinated cyber intrusion campaign in or around 2013, including spearphishing against universities and intrusions targeting professors, companies, government agencies, and NGOs.
According to the superseding indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 to help Iranian universities and research organizations steal foreign scientific materials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
17 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcego.rewardsforjustice.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.