17 Iranian Nationals Charged in Cyber Theft Campaign; Case Undecided
Federal prosecutors unsealed a 14-count superseding indictment charging 17 members of the Mabna Institute with cyber intrusions targeting universities, government agencies and private companies. The matter is at the charging stage only: no defendant has been tried or convicted, and the case remains pending.
3 reports on this incident · first at Aug 19, 2026, 10:41 a.m. ET
Earlier reports
Aug 19, 2026, 11:19 a.m. ET
17 Iranian Nationals Charged in Superseding Indictment Over Alleged Cyber Theft Campaign
On August 18, 2026, the U.S. Attorney's Office for the Southern District of New York announced the unsealing of a 14-count superseding indictment charging 17 members of the Iran-based Mabna Institute in federal district court. According to official court records, the defendants are accused of conducting coordinated cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps and other entities, stealing over 31 terabytes of data from 144 U.S. universities, 178 foreign universities, at least 42 U.S. private sector companies, and multiple government agencies. The charges contained in the indictment are merely allegations, and the defendants are presumed innocent unless and until proven guilty in a court of law.
According to court documents, the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. Prosecutors allege the defendants compromised approximately 8,000 professor email accounts across targeted academic institutions and exfiltrated research across multiple disciplines. In addition to academic targets, the indictment alleges intrusions into private sector companies—including Home Box Office, Inc.—and government entities, resulting in over $20 million in remediation and investigation costs. Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment.
The case is assigned to U.S. District Judge Jesse M. Furman. Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of five named defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Aug 19, 2026, 10:41 a.m. ETFirst report
17 Iranians Charged in Cyber Theft Campaign, U.S. Indictment Says
On August 18, 2026, the U.S. Attorney's Office for the Southern District of New York announced the unsealing of a 14-count superseding indictment charging 17 Iranian nationals with conducting a massive cyber theft campaign. The criminal case remains developing. The charges contained in the indictment are accusations, and all defendants are presumed innocent unless and until proven guilty.
According to official records from the Department of Justice, the defendants were founders, employees, or contractors of the Iran-based Mabna Institute. Authorities allege that between 2013 and at least December 2017, the institute conducted targeted cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps and other Iranian entities. The campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, exfiltrating at least 31 terabytes of academic data and intellectual property.
In addition to academic institutions, the indictment alleges that the defendants targeted employee email accounts at five U.S. federal and state government agencies, 42 U.S.-based private companies, and 11 foreign private sector companies. U.S. Attorney Jamie McDonald stated that the charges reveal the broader network behind a state-sponsored campaign to steal research and intellectual property. Concurrent with the indictment, the U.S. Department of State's Rewards for Justice program offered a reward of up to $10 million for information leading to the location of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Was this report accurate and useful?
Sources
Revision history
- Version 119 Aug 2026, 15:19current
First published.
- Version 119 Aug 2026, 14:41current
First published.
- Version 119 Aug 2026, 15:23current
First published.
How we work
This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.
Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.
Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.
None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.