LIVE · cybersecurity feed
Live wire
breach

US charges Iranians for sprawling hacking campaign on government agencies, universities

The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

zeroday.news ·

The U.S. Justice Department has unsealed a 14-count indictment against 17 individuals, accusing them of participating in a wide-ranging hacking campaign on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The campaign, which allegedly began around 2013, targeted numerous U.S. and international entities, including government agencies, universities, and private companies.

Prosecutors allege that the hackers operated through an Iranian company identified as the Mabna Institute. Eight of the individuals named in the current indictment had previously been charged in 2018 for their involvement in a separate hacking operation. The State Department has offered a reward of up to $10 million for information leading to the apprehension of five individuals—Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh—who are accused of being employed by or affiliated with the Mabna Institute to conduct cyber intrusions.

The indictment details breaches of employee email accounts at several U.S. government entities, including the Department of Labor and the Federal Energy Regulatory Commission. State government agencies in Hawaii and Indiana were also reportedly affected. Internationally, the campaign targeted multiple United Nations organizations, specifically mentioning the U.N. Children’s Fund. The U.N. has not publicly commented on these allegations.

Beyond government targets, the group is accused of compromising 144 U.S.-based universities and 42 U.S. companies, alongside 178 foreign universities and at least 11 foreign companies. The university attacks allegedly involved successfully compromising approximately 8,000 email accounts belonging to professors between 2013 and 2017. The hackers reportedly used stolen credentials to gain access to these accounts.

The stolen data, which prosecutors estimate to be at least 31 terabytes, included academic journals, theses, dissertations, and electronic books across dozens of fields. This intellectual property was allegedly provided to the Iranian government and also sold through two websites to universities within Iran. One of these websites reportedly allowed Iranian customers to use stolen professor accounts to access the online library systems of various U.S. universities. Universities impacted by these breaches are estimated to have spent around $20 million on investigation and remediation efforts.

One of the indicted individuals, Behzad Mesri, was previously charged for an attack on the media company HBO, from which he allegedly attempted to extort $6 million.

Assistant Attorney General John Eisenberg stated that the defendants, at the behest of entities including the IRGC, hacked into universities and research institutions worldwide, stealing intellectual property of "untold value." FBI Assistant Director Brett Leatherman described the operation as a "sprawling hacking-for-hire operation" that targeted intellectual property for the benefit of the Iranian government.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle

security

Virtual Event Today: CodeSecCon – Secure Your Code and Applications

CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.

security

Comcast gives its Wi-Fi motion detector a security makeover

Rebranded feature promises household alerts without video, but mind the small print

ai

Prevalent AI Raises $22 Million to Expand Data Fabric Platform

The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on SecurityWeek.

ai

OpenAI Tightens AI Safeguards Following Hugging Face Incident

OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities

security

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeared first on SecurityWeek.