[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7-slDjkBxfq9DA-BW-81lSHSUSsq59jEdNu82bZkLYc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"9d7872c8-988d-420a-9d5c-d417815a3e9a","state-sponsored-iranian-hackers-stole-315tb-from-100000-academic-accounts","eaaf4fbe-8792-47d8-a52b-a6de72eb519e","State-Sponsored Iranian Hackers Stole 31.5TB from 100,000+ Academic Accounts","The Mabna Institute campaign succeeded largely because academic institutions failed to enforce strong authentication controls and monitor for credential-based attacks targeting faculty email accounts. Spear-phishing and password spraying against professor accounts granted attackers persistent access to vast repositories of research and intellectual property. The sheer scale — 100,000 compromised accounts across multiple countries — highlights how a single weak authentication layer can expose enormous volumes of sensitive data. This matters because stolen academic and government research has long-term geopolitical and economic consequences that extend well beyond the initial breach.","**Immediate actions:**\n- Enforce multi-factor authentication (MFA) on all faculty, staff, and student email accounts without exception.\n- Audit and disable dormant or unused accounts that represent unnecessary attack surface.\n\n**Long-term improvements:**\n- Implement a Data Loss Prevention (DLP) solution to detect and block large-scale exfiltration of research data and intellectual property.\n- Classify sensitive research data and apply role-based access controls so only authorized personnel can access high-value datasets.\n- Establish a security awareness training program specifically tailored to phishing threats targeting academic researchers.\n\n**Detection measures:**\n- Deploy behavioral analytics and SIEM rules to flag anomalous login patterns such as impossible travel, credential stuffing, or bulk email access.\n- Monitor and alert on large outbound data transfers exceeding baseline thresholds for any user or department.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4 - Controlled Use of Administrative Privileges","CIS Control 6 - Access Control Management","CIS Control 14 - Security Awareness and Skills Training","CIS Control 13 - Network Data Protection","NIST SP 800-171 3.5.3 - Multi-Factor Authentication","NIST AC-2 - Account Management","NIST AC-17 - Remote Access","NIST SI-4 - System Monitoring","NIST SP 800-53 IA-5 - Authenticator Management","GDPR Article 32 - Security of Processing","FERPA - Protection of Student and Research Records","published","2026-08-18T22:20:52.005621+00:00","2026-08-18T22:20:51.905+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fcyberscoop.com\u002Fmabna-institute-iranian-hackers-indictment\u002F","eight-years-later-federal-authorities-re-up-charges-against-alleged-iranian-hack-b38c5c","Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]