US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them
US charges 17 Iranian hackers from Mabna Institute and offers rewards for 5.
Summary
The US has charged 17 individuals associated with Iran's Mabna Institute for a widespread hacking campaign targeting hundreds of universities and organizations globally. The group allegedly stole over 31 terabytes of academic data and intellectual property, along with employee email accounts, acting on behalf of Iran's Islamic Revolutionary Guard Corps. The US is offering up to $10 million in rewards for information leading to the arrest of five of the indicted individuals.
Full text
The US this week announced charges against 17 members of the Iran-based company Mabna Institute for hacking into hundreds of organizations in the US and abroad. According to a 14-count superseding indictment, Mabna Institute was founded in 2013 to help universities and research organizations in the country steal non-Iranian scientific resources. It has targeted universities in the US (144) and abroad (178), private companies in the US (42) and abroad (11), five government agencies in the US, and at least two NGOs, stealing over 31 terabytes of academic data and intellectual property, as well as employee email accounts. The 17 defendants charged over these intrusions acted on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), the Justice Department says. According to the indictment, the Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi, and employed, contracted, and affiliated with Abdollah Karima (aka Vahid Karima), Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri (aka Skote Vahshat), Manouchehr Hashemloo, Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (aka Mojtaba Ghaleh Koui). The Mabna Institute allegedly conducted cyber intrusions on behalf of both the Iranian government and private organizations.Advertisement. Scroll to continue reading. Through the Rewards for Justice program (RFJ), the US government is offering rewards of up to $10 million for information leading to the arrest of Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh. According to the superseding indictment, the defendants targeted over 100,000 professors worldwide and successfully compromised roughly 8,000 professor email accounts at 144 universities in the US and 178 institutions in Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey, the United Kingdom, and other countries. Using stolen credentials, the hackers accessed the victim professors’ accounts and used them to exfiltrate data and documents across engineering, medical, technology, and other fields of research and academic disciplines. The defendants, the indictment alleges, also sold the stolen data through Megapaper and Gigapaper, two companies affiliated with Abdollah Karima. Additionally, the defendants targeted various other private and government agencies, including HBO in a $6 million extortion attempt. Related: Snowflake Hacker Pleads Guilty in US Court Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Related: Two Scattered Spider Hackers Sentenced to Jail in UK Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Xpander Raises $7.5 Million for AI Management and Governance300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawHeights Finance Data Breach Impacts at Least 1.2 Million IndividualsGitLab Patches Critical Code Injection VulnerabilityDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates680,000 Impacted by French Tax Authority Data Breach40,000 Impacted by SafePal Data BreachRecent macOS Screen Sharing Vulnerability Exploited in Attacks Latest News Prevalent AI Raises $22 Million to Expand Data Fabric PlatformCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of VulnerabilitiesCareCloud Data Breach Impact Grows to 3.7 Million IndividualsWebinar Today: Rethinking Cyber Defense for AI-Speed AttacksCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDali Rajic is joining OpenAI as Chief Revenue Officer.Erika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- domain — megapaper.com
- domain — gigapaper.com