The United States has taken a significant step in combating cybercrime by charging 17 members of an Iran-based hacking group with conducting massive attacks on universities, private companies, and government agencies worldwide. The Mabna Institute, founded in 2013, was allegedly established to facilitate the theft of non-Iranian scientific resources, including academic data and intellectual property.
According to a superseding indictment, the defendants targeted hundreds of organizations across the globe, stealing over 31 terabytes of sensitive information. This included email accounts belonging to professors at 144 universities in the US and 178 institutions abroad. The hackers used stolen credentials to access these accounts, exfiltrating data and documents from various fields of research, including engineering, medicine, and technology.
The indictment reveals that the Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi, with several others acting as employees or affiliates. The group allegedly conducted cyber intrusions on behalf of both the Iranian government and private organizations. In some cases, the hackers sold stolen data through affiliated companies.
The US Justice Department has charged five individuals with particularly egregious offenses: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. These defendants are accused of being involved in the targeting of over 100,000 professors worldwide and compromising around 8,000 email accounts.
The US government is now offering rewards of up to $10 million through its Rewards for Justice program (RFJ) for information leading to the arrest of these five individuals. The RFJ offers substantial incentives for tips that result in the capture or conviction of high-priority targets, and this case is a prime example of how it can be used to combat cybercrime.
The Mabna Institute’s activities are not limited to academic institutions; they also targeted various other private companies, including HBO, in a $6 million extortion attempt. The scope of these attacks highlights the significant impact that nation-state-sponsored hacking groups can have on global cybersecurity.
This case serves as a stark reminder of the ongoing threat posed by state-sponsored hackers. As governments and organizations worldwide work to strengthen their defenses against cyber threats, it’s essential to acknowledge the role of nation-states in facilitating large-scale hacking operations. By pursuing justice through indictments like this one, the US is sending a clear message that such activities will not be tolerated.
In light of these developments, individuals and organizations should remain vigilant about cybersecurity risks. This case emphasizes the importance of robust security measures, including regular updates, strong passwords, and multi-factor authentication. Moreover, staying informed about emerging threats and collaborating with law enforcement can help prevent future attacks. As the cyber threat landscape continues to evolve, it’s crucial that we all take proactive steps to safeguard our digital lives.
Source: SecurityWeek — 2026-08-19