Back to Feed
Nation-stateAug 19, 2026

US charges Iranian hackers over $3.4 billion intellectual property theft

US charges 17 Iranians from Mabna Institute for $3.4B IP theft and espionage.

Summary

The U.S. Justice Department has charged 17 Iranians, allegedly members of the Mabna Institute hacking-for-hire company, for a multi-year operation that stole over $3.4 billion in intellectual property and academic research. The group targeted over 100,000 professors globally, compromising 8,000 accounts and exfiltrating 31.5 terabytes of data. The operation is believed to have been sponsored by Iran's Islamic Revolutionary Guard Corps (IRGC).

Full text

US charges Iranian hackers over $3.4 billion intellectual property theft By Bill Toulas August 19, 2026 11:56 AM 0 The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. Nine of the defendants were previously charged in a March 2018 indictment for hacking more than 300 universities and private companies. The U.S. Justice Department (DoJ) has also announced rewards of up to $10 million for information leading to the location of five of the 17 Iranian defendants. According to the U.S. government, the newly charged eight individuals stole academic research, intellectual property, emails, and other proprietary information. The DoJ says that the Iranians listed below were involved in cyber operations for the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and paying customers. Saeid Houshyar Behzad Mesri, aka “Skote Vahshat” Manouchehr Hashemloo Keyvan Fayaz, aka “Achilles,” “The Joker,” and “bc.monster” Amir Barati Saber Shahbazi Ballojeh Arman Kahzadian Mojtaba Galekuhi, aka “Mojtaba Ghaleh Koui” “Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” stated U.S. Attorney Jamie McDonald. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.” The DoJ's announcement says the operation is believed to have begun around 2013 and targeted the accounts of more than 100,000 professors worldwide, successfully compromising roughly 8,000 of them. Using access to these accounts, the hackers reportedly stole 31.5 terabytes of academic data, including journals, theses, dissertations, ebooks, and research across numerous disciplines, valued at approximately $3.4 billion. This activity has impacted 178 universities, 144 of which are in the U.S., at least 53 private firms, 42 of which are in the U.S., two NGOs, and at least 10 U.S. state agencies. One of the victims highlighted in the announcement was HBO, which was reportedly extorted for $6 million worth of Bitcoin. The defendants now face charges related to conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft, which can incur maximum penalties of up to 20 years in prison. The State Department has also announced it is offering rewards of up to $10,000,000 for information leading to the whereabouts of Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. A Tor link has also been provided to allow anonymous submissions. All defendants are presumed innocent until proven guilty in a court of law. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Police seize “First VPN” service used in ransomware, data theft attacksDOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN ActHackers arrested over €30M bank fraud exploiting service provider flawPolice dismantle Kratos phishing platform, arrest developerNew HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Indicators of Compromise

  • malware — Mabna Institute

Entities

Mabna Institute (threat_actor)Islamic Revolutionary Guard Corps (IRGC) (threat_actor)Bitcoin (product)