LIVE · cybersecurity feed
Live wire
security

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.

zeroday.news ·

Federal authorities have unsealed a superseding indictment against 17 Iranian individuals affiliated with the Mabna Institute, a tech firm based in Tehran. The charges allege a widespread cybertheft campaign conducted on behalf of the Iranian government, targeting universities, governments, and companies globally. This new indictment expands upon and replaces an initial indictment from 2018, which had named nine of the current defendants. The updated charges include eight additional defendants.

According to Jamie McDonald, U.S. Attorney for the Southern District of New York, the new charges reveal a broader network allegedly responsible for a state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions. McDonald emphasized that the passage of time would not deter authorities from pursuing those who target the United States from abroad.

The Justice Department states that Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013. Its stated objective was to assist Iranian universities and scientific and research organizations in acquiring foreign scientific materials, often by employing hackers-for-hire.

The indictment alleges that the Mabna Institute compromised over 100,000 email accounts belonging to professors worldwide. Specifically, it successfully breached 8,000 accounts at 144 U.S. universities and 178 universities in other countries. Using stolen credentials, the hackers reportedly exfiltrated academic journals, dissertations, and e-books across various fields of research, totaling at least 31.5 terabytes of data. The institute is also accused of sometimes selling the stolen data.

U.S.-based universities collectively spent approximately $3.4 billion to procure and access the type of data and intellectual property that was stolen during the conspiracy. Beyond academic institutions, the defendants are also accused of compromising and stealing from email accounts belonging to at least five U.S. federal and state government agencies, 42 U.S. companies, and 11 foreign companies, including HBO.

The superseding indictment brings 14 separate, sometimes overlapping charges against the 17 defendants. Sentences for each offense range from two to 20 years. In conjunction with the indictment, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of four of the named defendants.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Expired credit cards revived by researchers to make unauthorized payments

Gaps in expiry checks could let dead plastic make purchases again

ai

'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.

security

Comcast turns your Xfinity WiFi into a home motion detector

Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]

aicritical

OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue

The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.

cybersecurity

CISOs Break Their Silence in 'Declassified' Docuseries

A new docuseries titled 'Declassified' offers an unprecedented look into the high-pressure world of Chief Information Security Officers (CISOs). The series features candid accounts from CISOs detailing the immense stress, burnout, and personal toll that comes with managing an organization's cybersecurity defenses, including instances of significant financial loss and career disruption.

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [