Skip to main content
Get our mobile app
Download on the App StoreGet it on Google Play

IRGC's academic espionage exposed

DOJ Indicts 17 Iranians in Massive Cyber Theft Campaign Targeting Universities

U.S. charges 17 members of Iran's Mabna Institute for stealing 31 terabytes from 144 U.S. universities, foreign universities including Israeli institutions, and companies.

Department of Justice

The U.S. Department of Justice unsealed a 14-count superseding indictment Tuesday charging 17 Iranian nationals with conducting a coordinated cyber theft campaign on behalf of Iran's Islamic Revolutionary Guard Corps since at least 2013. The Mabna Institute, an Iran-based company founded to assist Iranian universities and research organizations in stealing access to non-Iranian scientific resources, targeted 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations.

The campaign yielded more than 31 terabytes of stolen academic data and intellectual property, along with employee email accounts from targeted companies and government agencies. Israeli universities and research institutions were among the foreign targets, according to the indictment.

Nine of the 17 defendants were previously charged in the original 2018 indictment, which had charged nine members with penetrating the email accounts of nearly 8,000 professors at 320 universities worldwide. The new indictment expands charges and incorporates additional hacking activity that prosecutors say continued well after the original filing.

Defendants conducted many of the intrusions on behalf of the Islamic Revolutionary Guard Corps, as well as other Iranian government and university clients. Prosecutors say the Mabna Institute operated explicitly to penetrate foreign computer networks and steal intellectual property for the benefit of the Iranian government and Iranian universities unable to access the material through legitimate means.

The defendants allegedly conducted spear-phishing campaigns against selected targets, sending emails appearing to come from colleagues or other researchers with links designed to compromise victim accounts. U.S. Attorney Jamie McDonald stated: "Today's charges show that neither sophistication nor geographic boundaries will deter us from protecting the national security of our country from those who target the United States from abroad."

The indictment was unsealed in Manhattan federal court.

Ready for more?

Join our newsletter to receive updates on new articles and exclusive content.

We respect your privacy and will never share your information.

Enjoyed this article?

Yes (8)
No (0)
Follow Us:

Unmissable content


Loading comments...

Also of Interest