Pull to refresh
Logo
US widens case against Iranian university-hacking network

US widens case against Iranian university-hacking network

Force in Play

A 2018 indictment of the Mabna Institute grows to 17 defendants accused of stealing 31 terabytes of research

Yesterday: Superseding indictment adds eight defendants

Overview

Updated Yesterday

For four years, Iranian operators logged into US university networks using professors' stolen passwords and copied their research. This week, prosecutors expanded a 2018 case against the group behind it, adding eight names and bringing the total charged to 17.

The group, called the Mabna Institute, allegedly stole about 31.5 terabytes of academic data for Iran's Islamic Revolutionary Guard Corps. None of the 17 defendants is in US custody, and all are believed to be in Iran. The indictment is a public accusation, not a path to a trial.

Why it matters

The research behind US industry and defense sits on university networks, and this case shows a foreign state copied 31 terabytes of it with little fear of arrest.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

31.5 TB
Academic data stolen
Research and intellectual property copied from university networks, per prosecutors.
17
People charged
Nine were charged in 2018; the new indictment adds eight more.
320+
Universities targeted
144 in the US and 178 abroad, across 22 countries.
$3.4B
Value of stolen access
What the targeted universities paid to license and access the data taken, per the 2018 case.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 4 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

January 2013 August 2026

5 events Latest: Yesterday
Tap a bar to jump to that date
  1. Mabna Institute founded and campaign begins

    Origin

    Gholamreza Rafatnejad and Ehsan Mohammadi found the firm, which starts phishing university staff to reach research databases.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

May 2014

PLA Unit 61398 indictment (2014)

The US charged five officers of China's People's Liberation Army with hacking Westinghouse, US Steel, Alcoa, and others to steal trade secrets. It was the first time the US criminally charged uniformed state actors for cyber theft.

Then

China denied the charges and suspended a cyber working group with the US. The five officers were never arrested.

Now

The case set the template of 'name and shame' indictments against hackers the US cannot reach, now standard practice.

Why this matters now

Like the Mabna case, it charged foreign state agents who stayed home. The value was public attribution, not a trial.

March 2016

Iranian DDoS and Bowman Dam indictment (2016)

The US charged seven Iranians tied to IRGC contractors with flooding 46 banks with denial-of-service attacks and breaching the controls of a small New York dam. The attacks ran from 2011 to 2013.

Then

None of the seven was arrested. The charges drew attention to Iranian contractors working for the IRGC.

Now

It established a pattern of US prosecutors targeting IRGC-linked front companies, the same structure alleged in the Mabna case.

Why this matters now

Same sponsor, same model: private Iranian firms doing cyber work for the IRGC, charged but out of reach.

October 2020

GRU Sandworm indictment (2020)

The US charged six officers of Russia's GRU military intelligence for the NotPetya malware, attacks on Ukraine's power grid, and disruption of the 2018 Winter Olympics. Damages ran into the billions.

Then

The officers remained in Russia and were never tried. Allies issued coordinated condemnations.

Now

It confirmed that even sweeping, well-documented indictments of state hackers rarely produce arrests.

Why this matters now

Shows the ceiling on these cases: strong evidence and serious charges, but enforcement depends on the suspect leaving home soil.

Sources

(7)