Summary

  • U.S. authorities have indicted 17 individuals linked to the Iranian Mabna Institute for a prolonged hacking operation.
  • Six of the accused were reportedly involved in the HBO breach, which sought to extort $6 million in Bitcoin.
  • The hacking group allegedly acquired over 31.5 terabytes of academic data and intellectual property.

Seventeen alleged Iranian hackers have been charged by U.S. prosecutors for their involvement in a protracted cyber campaign, which included the notorious HBO breach in 2017 where they attempted to extort approximately $6 million in Bitcoin.

The Justice Department announced on Tuesday that these individuals are part of the Mabna Institute, which is said to have conducted hacking operations on behalf of Iran's Islamic Revolutionary Guard Corps and various Iranian governmental and academic institutions. Prosecutors indicated that the group targeted a wide range of entities, including universities, businesses, and government bodies across the globe.

Behzad Mesri had previously faced charges for hacking HBO and stealing sensitive data. Prosecutors stated that five other defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—were directly implicated in the HBO breach.

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” remarked Assistant Attorney General for National Security John A. Eisenberg.

The Department of Justice reported that the Mabna Institute targeted over 100,000 professor accounts globally, compromising around 8,000 accounts across 144 U.S. universities and 178 international universities. The hackers allegedly employed spearphishing techniques and utilized stolen credentials to access and steal research papers, academic journals, theses, dissertations, ebooks, and other valuable materials.

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” stated Brett Leatherman, Assistant Director of the FBI Cyber Division.

Amid rising tensions between Washington and Tehran, the U.S. has intensified efforts to disrupt cryptocurrency networks that it claims are used by Iran and the IRGC to manage finances and evade sanctions.

In June, the U.S. Treasury imposed sanctions on four Iranian cryptocurrency exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion, linking Nobitex to transactions involving ransomware groups affiliated with the IRGC.

In July, the Treasury froze over $131 million across four cryptocurrency wallets associated with Iran's central bank and military forces, including the IRGC. In August, additional sanctions were placed on two more exchanges accused of laundering millions for the IRGC and other sanctioned Iranian entities.

The State Department is offering rewards up to $10 million for information leading to the capture of five of the defendants.

“More than eight years after first making the indictment public, these charges demonstrate that we will continue to identify and pursue those who target the United States from abroad,” stated U.S. Attorney Jamie McDonald for the Southern District of New York.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos, and more.