HackMyIP
← Back to News
2026-08-19 SecurityWeek

US Charges 17 Iranian Hackers, Offers $10M Reward for 5

APTData BreachRegulation

The US Department of Justice has charged 17 members of the Iran-based Mabna Institute with conducting a massive cyber-espionage campaign that compromised roughly 8,000 professor email accounts across 144 US universities and 178 institutions in 22 foreign countries. According to a 14-count superseding indictment, the defendants — acting on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) — stole over 31 terabytes of academic data, intellectual property, and credentials in fields spanning engineering, medicine, and technology. The intrusions, which began after the institute's 2013 founding by Gholamreza Rafatnejad and Ehsan Mohammadi, also targeted 42 US private companies, 11 foreign firms, five US government agencies, and at least two NGOs.

Five of the 17 defendants — Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh — are now the subject of up to $10 million Rewards for Justice bounties for information leading to their arrest. Fayaz, who operated under the handles "Achilles," "The Joker," and "bc.monster," is among the most prolific named suspects. The group allegedly monetized stolen academic materials through two front companies, Megapaper and Gigapaper, both affiliated with defendant Abdollah Karima. Mesri also stands separately accused of a $6 million extortion attempt against HBO.

Researchers and academics concerned about credential exposure from state-sponsored campaigns like Mabna's can verify their accounts using an email breach checker, while institutions investigating suspicious domains tied to the Megapaper and Gigapaper front companies can leverage a WHOIS lookup to trace registrant history. The Mabna Institute's playbook — spear-phishing professors, harvesting credentials, and exfiltrating research en masse — underscores why university networks remain prime targets for APT groups and why stolen academic credentials frequently resurface on dark-web markets years after the original intrusion.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →