The U.S. Justice Department has indicted 17 Iranians accused of operating a sprawling global hacking campaign on behalf of the Islamic Revolutionary Guard Corps and other Iranian interests, targeting universities, companies, government agencies and international organizations.
According to the indictment, members of the Tehran-based Mabna Institute operated from 2013 and compromised about 8,000 accounts belonging to academics at 144 U.S. universities and another 178 universities around the world, including institutions in Israel. The hackers allegedly stole more than 31 terabytes of research, books, academic papers and intellectual property, and also breached email accounts belonging to employees at 42 U.S. companies, 11 European companies and several government and international organizations.
Among the victims was HBO, from which hackers stole scripts and other material connected to “Game of Thrones.” Members of the network later allegedly attempted to extort the company for about $6 million in Bitcoin. The U.S. State Department is offering rewards of up to $10 million for information leading to the location of five of the defendants.
A hacking operation built like a business
Mabna Institute was founded in 2013 by two of the defendants. Prosecutors say its corporate identity concealed an organized network of employees, contractors and hackers-for-hire that accepted assignments from Iranian government bodies and private clients. The university operation was carried out for the Revolutionary Guards, according to prosecutors, while other projects were commissioned by additional Iranian customers.
Members of the network divided responsibilities among themselves, identifying targets, preparing phishing messages, registering fake internet domains, storing stolen passwords and selling access to compromised databases. The Justice Department described Mabna as an organized hacking service that worked both for the Iranian state and for profit.
More than 100,000 academic accounts worldwide were allegedly marked as potential targets, about half of them belonging to academics in the United States. The names of the Israeli universities affected, as well as the number of compromised accounts at each institution, were not disclosed.
The hackers did not limit themselves to defense research or sensitive technology. Prosecutors say they sought material in science, engineering and medicine, as well as the social sciences and other professional fields. U.S. universities had spent an estimated $3.4 billion acquiring the academic material and database access exploited by the hackers, according to prosecutors, while the FBI estimated that the volume of information stolen was three times larger than the Library of Congress’ entire print collection.
How the hackers got inside
The campaign relied heavily on detailed research into individual victims. Members of the network allegedly searched online for information about academics, reviewed their areas of expertise and published work, and then sent messages appearing to come from researchers at other universities. The fake sender would claim to have read one of the academic’s papers and ask to see additional work.
A link in the message led to a fraudulent login page designed to closely resemble the university’s real website. Anyone entering a username and password was effectively handing the credentials to the hackers, who then used them to enter academic accounts and download journal articles, electronic books, dissertations and other material.
The stolen information was not kept solely for the Revolutionary Guards or other government customers. Some was turned into a commercial product. The website Megapaper.ir allegedly sold stolen articles and books, while Gigapaper.ir allowed customers in Iran to use compromised academic accounts to enter the online libraries of foreign universities directly.
Against companies and government bodies, the hackers allegedly used password spraying, collecting employee names and email addresses online and attempting to access large numbers of accounts using common or default passwords. Once inside, they sometimes downloaded entire mailboxes and created automatic forwarding rules so new messages would continue reaching them without the employee’s knowledge.
Targets included companies in technology, consulting, marketing, banking, biotechnology and health care, as well as the U.S. Labor Department, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. Prosecutors say investigation and system-recovery costs for some victims exceeded $20 million.
HBO, Bitcoin and the Night King
According to the new indictment, Behzad Mesri and five other members of the network were directly involved in the HBO breach. Mesri had previously worked on cyberattacks against military systems, nuclear software and Israeli infrastructure on behalf of Iran’s military, prosecutors allege.
The ransom demand to HBO began at $5.5 million in Bitcoin and later rose to $6 million. One message reportedly included an image of the Night King from “Game of Thrones” alongside the threatening signoff, “Good luck to HBO.” After the company refused to pay, some of the stolen material was published online and a social media account was created to publicize the leaks.
‘The FBI has a long memory’
The case first became public in 2018, but the new indictment consolidates the alleged activity into 14 counts, expands the number of defendants to 17 and links additional members of the network to the HBO intrusion and attacks against companies and government entities.
The charges include conspiracy to commit computer intrusions, fraud, aggravated identity theft and extortion. When the case was first exposed, the U.S. Treasury Department sanctioned Mabna Institute and 10 Iranians linked to its operations, froze assets under U.S. jurisdiction and barred Americans from doing business with them.
A senior FBI cyber official said the new indictment was intended to remind U.S. adversaries that “the FBI has a long memory” and that the passage of years would not stop authorities from pursuing those responsible.
One defendant is already in custody. Amir Barati, 39, an Iranian and Turkish citizen, was arrested in June in Kotor, Montenegro, in an operation involving local police and the FBI. The United States submitted a formal extradition request in July, and Barati remains in extradition custody.
Prosecutors accuse him of tracking phishing campaigns, preparing target lists, scanning networks and exchanging stolen login credentials with other members of the network. If captured and convicted, defendants could face up to 20 years in prison for each fraud count.



