The U.S. Department of Justice unsealed a 14-count superseding indictment charging 17 Iranian nationals tied to the Tehran-based Mabna Institute with conducting a long-running cyber intrusion and theft campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian government and university clients. Prosecutors allege the operation, active since at least 2013, compromised more than 100,000 professors’ email accounts worldwide, including about 8,000 accounts across 144 U.S. universities and 178 foreign universities, and stole at least 31.5 terabytes of academic research, intellectual property, and email contents.
Authorities said the campaign also targeted at least five U.S. federal and state agencies, dozens of companies in the United States and abroad, NGOs, and media targets including HBO, with several defendants linked to the separate HBO hack-and-extortion case. The superseding indictment expands a 2018 case by adding eight defendants and alleges the stolen academic materials were monetized through Megapaper.ir and Gigapaper.ir; U.S. officials said American universities alone spent roughly $3.4 billion to procure and access the stolen data, while the State Department is offering up to $10 million for information leading to several of the accused.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The U.S. State Department's Rewards for Justice program announced up to $10 million for information leading to the location of five defendants named in the superseding indictment.
On August 18, 2026, the U.S. Department of Justice unsealed a 14-count superseding indictment charging 17 Iranian nationals affiliated with the Mabna Institute over a long-running cybertheft campaign. The new case expands and replaces the 2018 indictment, adding eight defendants and alleging broader targeting of universities, companies, government agencies, and NGOs.
The superseding indictment alleges the Mabna Institute's cyber-enabled theft campaign continued until at least March 2022, extending the previously documented timeline well beyond 2017. The filing also ties this longer-running operation to large-scale theft from universities worldwide.
The DOJ previously announced a 7-count indictment in March 2018 charging nine of the 17 defendants later named in the superseding case.
The indictment alleges the university-focused hacking operation ran from approximately 2013 through at least December 2017, compromising thousands of professor accounts and stealing academic data.
The DOJ alleges the Mabna Institute began a coordinated cyber intrusion campaign in or around 2013, including spearphishing against universities and intrusions targeting professors, companies, government agencies, and NGOs.
According to the superseding indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 to help Iranian universities and research organizations steal foreign scientific materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcebleepingcomputer.com
Open sourcesecurityweek.com
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.