HackMyIP
← Back to News
2026-08-19 The Record

US Charges 17 Iranians in Decade-Long Government and University Hacking Campaign

APTData BreachThreat Intel

The U.S. Department of Justice unsealed a 14-count superseding indictment on Tuesday charging 17 individuals linked to Iran's Islamic Revolutionary Guard Corps (IRGC) with running a sprawling hacking-for-hire operation through a Tehran-based company called the Mabna Institute. Prosecutors say the campaign, active from around 2013 through at least 2017, compromised employee accounts at the Department of Labor, the Federal Energy Regulatory Commission, the U.N. Children's Fund (UNICEF), and state agencies in Hawaii and Indiana. Assistant Attorney General John Eisenberg said the defendants "hacked into universities and other research institutions worldwide," stealing at least 31 terabytes of intellectual property and academic data.

The indictment details how the hackers used stolen credentials to breach approximately 8,000 professor email accounts across 144 U.S. universities, 178 foreign universities, 42 U.S. companies, and at least 11 foreign organizations. From those inboxes they exfiltrated academic journals, theses, dissertations, and electronic books spanning dozens of research fields. The stolen documents were allegedly funneled to the Iranian government and resold through two websites to domestic universities, with one portal granting direct access to compromised U.S. university library systems using hijacked professor logins. The DOJ estimated U.S. universities spent roughly $20 million on investigations and remediation. Anyone concerned about exposed academic or corporate credentials can verify their exposure with an email breach checker and confirm account hygiene with a password checker.

Five named defendants — Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh — remain at large, and the State Department has announced a $10 million reward for information leading to their arrest or conviction. Eight others were previously indicted in 2018 for a related intrusion campaign. Mesri was separately charged in 2017 for his alleged role in the HBO breach. "These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government," said FBI Assistant Director Brett Leatherman. Researchers tracking the group's infrastructure or the sale-front domains used to monetize stolen credentials can run a WHOIS lookup to assist in mapping adversary assets.

The case underscores the persistent threat posed by state-aligned APT groups that monetize stolen research through dual-purpose front companies, blending espionage with criminal revenue streams. Organizations in academia, government, and the private sector should treat credential theft as a long-term exposure problem — not a one-time incident — by enforcing phishing-resistant multi-factor authentication, monitoring dark-web credential dumps, and segmenting access between email, library systems, and research repositories.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →