LIVE · cybersecurity feed
Live wire
security

US charges Iranian hackers over $3.4 billion intellectual property theft

The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]

zeroday.news ·

The U.S. Justice Department has announced charges against 17 Iranian individuals, alleged members of a hacking-for-hire entity known as Mabna Institute, for their involvement in a multi-year operation to steal data from American organizations. This latest indictment, made public on August 19, 2026, includes eight new defendants, expanding upon a March 2018 indictment that previously charged nine individuals for hacking over 300 universities and private companies.

According to U.S. Attorney Jamie McDonald, these charges reveal a broader, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions. The Justice Department states that the accused individuals conducted cyber operations on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private clients.

The newly charged individuals are Saeid Houshyar, Behzad Mesri (also known as Skote Vahshat), Manouchehr Hashemloo, Keyvan Fayaz (also known as Achilles, The Joker, and bc.monster), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (also known as Mojtaba Ghaleh Koui). The U.S. State Department has offered rewards of up to $10 million for information leading to the location of five of these defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh, with a Tor link provided for anonymous submissions.

The operation is believed to have commenced around 2013, targeting the accounts of over 100,000 professors globally and successfully compromising approximately 8,000 of them. Through this access, the hackers reportedly exfiltrated 31.5 terabytes of academic data, including journals, theses, dissertations, ebooks, and research across various disciplines, with an estimated value of $3.4 billion.

The cyberattacks impacted 178 universities worldwide, with 144 located in the U.S. Additionally, at least 53 private firms (42 in the U.S.), two non-governmental organizations, and at least 10 U.S. state agencies were affected. One notable victim highlighted in the announcement was HBO, which was reportedly extorted for $6 million in Bitcoin.

The defendants face charges including conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. These charges carry potential maximum penalties of up to 20 years in prison. All defendants are presumed innocent until proven guilty.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

phishing

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.

CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew

security

Flock surveillance backlash mounts as fiendish Halloween plans circulate

CEO apologizes for police misuse as activists call for vandal action against license plate cameras