In Rare Move, Alleged Iranian State Hacker Extradited to US
Alleged Iranian state hacker extradited to US from Montenegro.
Summary
Amir Barati, an alleged member of Iran's Mabna Institute and linked to the IRGC, has been extradited from Montenegro to the US to face charges for a decade-long hacking spree. The group is accused of targeting hundreds of universities, private companies, and government agencies, stealing over 31 terabytes of data and causing billions in losses. This extradition is considered rare for Iranian state-linked hackers.
Full text
An Iranian national indicted in the US for hacking hundreds of organizations was extradited from Montenegro this week. Acting on an arrest warrant issued by the FBI, Montenegrin authorities arrested the individual, a dual citizen of Turkey and Iran, on June 25. The suspect is accused of involvement in numerous cyberattacks against US organizations starting in 2013. The attacks caused losses of more than $3.4 billion. The Montenegrin authorities did not name the individual, but mentioned his initials, A.B., and that he is 40 years old. In August, the US unsealed a 14-count superseding indictment charging 17 members of the Iran-based company Mabna Institute for hacking activities targeting hundreds of entities in the US and abroad. The indictment names Amir Barati as one of the Mabna Institute members who performed the intrusions on behalf of both the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC) and private organizations.Advertisement. Scroll to continue reading. According to the indictment, the suspects launched attacks against 144 universities in the US and 178 abroad, 42 private companies in the US and 11 abroad, five US government agencies, and at least two NGOs. The individuals stole over 31 terabytes of scientific resources, including academic data and intellectual property, as well as employee email accounts. The stolen information was handed over to the Iranian government and sold to Iranian universities. The US government is offering rewards of up to $10 million for information on five of the Iranian hackers, namely Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh. Extraditions of Iranian state-linked hackers to face trial in the US are extremely rare, as threat actors affiliated with the regime typically operate from inside Iran and avoid traveling to jurisdictions with US extradition treaties. According to Iran International, Barati moved to Turkey in 2021, where he later became a citizen and legally changed his first and last names. Related: Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader Related: Treasury Blacklists Most-Wanted ATM Malware Developer and His Network Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Zimbra Vulnerability Exploited in the Wild Prior to Public DisclosureZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityChrome, Firefox Updates Patch Over 100 VulnerabilitiesRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come Forward Latest News Crypto Scammers Hijack Microsoft’s Official X AccountWarlock Expands SharePoint Exploitation in Critical Infrastructure AttacksAI Agents Aimed SQL Injection at US and Canadian Government SitesExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email