FirstAlerts

17 Iranian Nationals Charged in Cyber Theft Campaign; Case Undecided

Federal prosecutors unsealed a 14-count superseding indictment charging 17 members of the Mabna Institute with cyber intrusions targeting universities, government agencies and private companies. The matter is at the charging stage only: no defendant has been tried or convicted, and the case remains pending.

3 reports on this incident · first at Aug 19, 2026, 10:41 a.m. ET

By AI ReporterWritten Aug 19, 2026, 11:23 a.m. ET
On August 18, 2026, the U.S. Attorney's Office for the Southern District of New York announced the unsealing of a 14-count Superseding ("S2") Indictment charging 17 members of the Mabna Institute, an Iran-based company, over an alleged cyber theft campaign. The account here comes from the office's press release, numbered , published on the Department of Justice website. The proceeding is at the charging stage: an indictment is an accusation, and the record announcing it reports no plea, trial, verdict or other resolution for any of the 17 defendants. According to that release, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute in approximately 2013 to assist Iranian universities and scientific and research organizations in stealing access to non-Iranian scientific resources. The indictment alleges the group targeted more than 100,000 professor accounts worldwide and compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 universities in foreign countries, stealing at least approximately 31.5 terabytes of academic data and intellectual property. Prosecutors allege the campaign began in approximately 2013 and continued through at least December 2017, and that stolen material was also sold within Iran through two websites, Megapaper.ir and Gigapaper.ir. The release states that the defendants also targeted and compromised employee email accounts at at least five U.S. federal and state government agencies, at least 42 U.S.-based private sector companies, at least approximately 11 foreign companies, and various governmental and non-governmental organizations, including the U.S. Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the United Nations and the United Nations Children's Fund. Many of the intrusions were allegedly conducted on behalf of Iran's Islamic Revolutionary Guard Corps and other Iranian government and university clients. Nine of the 17 defendants were previously in a 7-count Indictment announced in March 2018; the S2 Indictment adds eight defendants. It alleges that Behzad Mesri as well as Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian were involved in the hack of the systems of Home Box Office, Inc. Mesri was separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking into HBO's computer systems, stealing proprietary data and then attempting to extort HBO for approximately $6 million worth of Bitcoin. The 17 individuals are Rafatnejad, Mohammadi, Abdollah Karima, Mostafa Sadeghi, Seyed Ali Mirkarimi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri, Manouchehr Hashemloo, Keyvan Fayaz, Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian and Mojtaba Galekuhi. Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh. The case is assigned to U.S. District Judge Jesse M. Furman and, on the record as released, has not been decided. The maximum penalties listed in the release including 20 years in prison on each wire fraud count and a mandatory sentence of two years on each aggravated identity theft count are prescribed by Congress and provided for informational purposes only; any sentencing would be determined by the judge, and no defendant has reached that stage. As the U.S. Attorney's Office states: "" The release further notes that the entirety of the text of the Indictment and the description of it constitute only allegations, and every fact described should be treated as an allegation. Readers encountering this report later should not assume the matter has been resolved; nothing in the record cited here reports an outcome.

Earlier reports

  1. Aug 19, 2026, 11:19 a.m. ET

    17 Iranian Nationals Charged in Superseding Indictment Over Alleged Cyber Theft Campaign

    On August 18, 2026, the U.S. Attorney's Office for the Southern District of New York announced the unsealing of a 14-count superseding indictment charging 17 members of the Iran-based Mabna Institute in federal district court. According to official court records, the defendants are accused of conducting coordinated cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps and other entities, stealing over 31 terabytes of data from 144 U.S. universities, 178 foreign universities, at least 42 U.S. private sector companies, and multiple government agencies. The charges contained in the indictment are merely allegations, and the defendants are presumed innocent unless and until proven guilty in a court of law.

    According to court documents, the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. Prosecutors allege the defendants compromised approximately 8,000 professor email accounts across targeted academic institutions and exfiltrated research across multiple disciplines. In addition to academic targets, the indictment alleges intrusions into private sector companies—including Home Box Office, Inc.—and government entities, resulting in over $20 million in remediation and investigation costs. Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment.

    The case is assigned to U.S. District Judge Jesse M. Furman. Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of five named defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

  2. Aug 19, 2026, 10:41 a.m. ETFirst report

    17 Iranians Charged in Cyber Theft Campaign, U.S. Indictment Says

    On August 18, 2026, the U.S. Attorney's Office for the Southern District of New York announced the unsealing of a 14-count superseding indictment charging 17 Iranian nationals with conducting a massive cyber theft campaign. The criminal case remains developing. The charges contained in the indictment are accusations, and all defendants are presumed innocent unless and until proven guilty.

    According to official records from the Department of Justice, the defendants were founders, employees, or contractors of the Iran-based Mabna Institute. Authorities allege that between 2013 and at least December 2017, the institute conducted targeted cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps and other Iranian entities. The campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, exfiltrating at least 31 terabytes of academic data and intellectual property.

    In addition to academic institutions, the indictment alleges that the defendants targeted employee email accounts at five U.S. federal and state government agencies, 42 U.S.-based private companies, and 11 foreign private sector companies. U.S. Attorney Jamie McDonald stated that the charges reveal the broader network behind a state-sponsored campaign to steal research and intellectual property. Concurrent with the indictment, the U.S. Department of State's Rewards for Justice program offered a reward of up to $10 million for information leading to the location of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

Was this report accurate and useful?

Sources

Revision history

  1. Version 119 Aug 2026, 15:19current

    First published.

  2. Version 119 Aug 2026, 14:41current

    First published.

  3. Version 119 Aug 2026, 15:23current

    First published.

How we work

This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.

Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.

Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.

None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.