US charges Iranian hackers over $3.4 billion intellectual property theft

A massive cyber-heist orchestrated by Iranian hackers has come to light, with US authorities charging 17 individuals over the theft of intellectual property and academic research worth a staggering $3.4 billion. The operation, which spanned several years and involved multiple organizations, highlights the ongoing threat posed by state-sponsored hacking groups.

According to the US Justice Department (DoJ), the hackers, allegedly members of the Mabna Institute, targeted over 100,000 professors worldwide, compromising around 8,000 accounts. Using this access, they stole a massive 31.5 terabytes of academic data, including journals, theses, dissertations, ebooks, and research across various disciplines.

The victims of these hacking operations include not only universities but also private companies, NGOs, and even US state agencies. HBO is one notable example, with hackers reportedly extorting $6 million worth of Bitcoin from the media giant. The full extent of the damage remains unclear, but it’s evident that this was a sophisticated and far-reaching operation.

The Mabna Institute is believed to have been working on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC) and other Iranian government bodies, as well as paying customers. This raises questions about the involvement of state actors in cybercrime and highlights the need for increased vigilance against such activities.

The charges filed by the DoJ include conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. If convicted, the defendants could face up to 20 years in prison. The US State Department has also announced rewards of up to $10 million for information leading to the location of five of the accused individuals.

This case serves as a stark reminder that state-sponsored hacking groups continue to pose a significant threat to global security and intellectual property. It’s essential for organizations, particularly those in academia and research, to remain vigilant against these types of attacks and implement robust cybersecurity measures to protect themselves from similar breaches.

In light of this incident, it’s crucial for individuals and organizations to prioritize cybersecurity best practices, including regular password rotations, multi-factor authentication, and employee education on phishing and social engineering tactics. By staying informed and proactive, we can better mitigate the risks associated with these types of attacks and safeguard our intellectual property for years to come.


Source: Bleeping Computer — 2026-08-19