US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
The US charged 17 members of Iran's Mabna Institute for a massive cyber espionage campaign targeting over 144 US universities, 178 international universities, private companies, government agencies, and NGOs The hackers compromised approximately 8,000 professor email accounts worldwide, exfiltrating over 31 terabytes of academic data, intellectual property, and research across engineering, medical, and technology fields The operation was conducted on behalf of Iran's Islamic Revolutionary Guard
Analysis
TL;DR
- The US charged 17 members of Iran's Mabna Institute for a massive cyber espionage campaign targeting over 144 US universities, 178 international universities, private companies, government agencies, and NGOs
- The hackers compromised approximately 8,000 professor email accounts worldwide, exfiltrating over 31 terabytes of academic data, intellectual property, and research across engineering, medical, and technology fields
- The operation was conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), with stolen data allegedly sold through affiliated companies Megapaper and Gigapaper
- The DOJ is offering up to $10 million in rewards through the Rewards for Justice program for information leading to the arrest of five key defendants
- The campaign also included a $6 million extortion attempt against HBO and targeted organizations across at least 23 countries
Why It Matters
This case represents one of the largest state-sponsored academic espionage campaigns ever prosecuted, highlighting how universities and research institutions remain prime targets for nation-state actors seeking intellectual property and scientific breakthroughs. For AI practitioners and researchers, it underscores the critical importance of credential security and the growing intersection between cyber espionage and the race for technological supremacy.
Technical Details
- Mabna Institute was founded in 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi as a front organization to facilitate the theft of non-Iranian scientific resources for Iranian universities and research bodies
- The primary attack vector involved compromising professor email accounts through credential theft, which were then used as trusted entry points to exfiltrate sensitive research data across multiple disciplines
- Stolen data was monetized through two affiliated companies, Megapaper and Gigapaper, operated by Abdollah Karima (aka Vahid Karima), indicating a structured commercialization pipeline for espionage-derived intellectual property
- The indictment covers 14 counts and names 17 defendants with multiple aliases, including Keyvan Fayaz (aka Achilles, The Joker, bc.monster) and Behzad Mesri (aka Skote Vahshat), suggesting long-standing operational tradecraft
- The geographic scope spanned 144 US universities and 178 institutions across Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey, and the UK
Industry Insight
- Universities and research institutions should urgently audit their email security postures, implementing multi-factor authentication and monitoring for credential compromise, as academic email remains a high-value, often underprotected entry point for nation-state actors
- The commercialization of stolen research through entities like Megapaper and Gigapaper reveals an emerging model where state-sponsored espionage is directly monetized, suggesting that research institutions should treat intellectual property theft as both a security and a financial risk
- The $10 million reward structure signals increased US government prioritization of disrupting state-sponsored academic espionage networks, and organizations should expect more aggressive prosecution and international cooperation in this domain going forward
Disclaimer: The above content is generated by AI and is for reference only.