FirstAlerts

17 Iranians Charged Over Alleged Cyber Theft Campaign for Iranian Government

A 14-count superseding indictment unsealed in the Southern District of New York accuses 17 members of the Iran-based Mabna Institute of stealing academic data and intellectual property from universities, companies and government agencies. All defendants are presumed innocent.

3 reports on this incident · first at Aug 18, 2026, 8:20 p.m. ET

By AI ReporterFirst reported Aug 18, 2026, 8:00 a.m. ETUpdated Aug 19, 2026, 9:57 a.m. ET
Seventeen members of the Iran-based Mabna Institute have been in a 14-count superseding (S2) indictment unsealed in the U.S. District Court for the , according to a U.S. Department of Justice announcement dated Aug. 18, 2026 (release ). The case is at the charging stage and undecided. Nine of the 17 defendants were previously in a 7-count indictment announced in March 2018; the superseding indictment adds eight defendants. The case is assigned to U.S. District Judge Jesse M. Furman. According to the allegations in the S2 indictment, the Mabna Institute — founded in approximately 2013 by defendants Gholamreza Rafatnejad and Ehsan Mohammadi, according to the department, to help Iranian universities and research organizations obtain access to non-Iranian scientific resources — conducted a coordinated campaign of cyber intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least approximately 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations. The government alleges the group targeted more than 100,000 professor accounts worldwide, successfully compromised approximately 8,000 professor email accounts, and stole at least approximately 31.5 terabytes of academic data and intellectual property, which was exfiltrated to servers outside the United States controlled by members of the conspiracy. The department says the university spearphishing campaign began in approximately 2013, continued through at least December 2017, and was conducted on behalf of Iran's Islamic Revolutionary Guard Corps, along with other Iranian government and university clients. Through the course of the conspiracy, according to the announcement, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property. The indictment further alleges that the defendants sold stolen academic material within Iran through two websites, Megapaper.ir and Gigapaper.ir. Megapaper was operated by Falinoos Company, which the department says was controlled by defendant Abdollah Karima, and Gigapaper was also affiliated with Karima. Gigapaper, according to the allegations, sold customers in Iran a service that let them use compromised university professor accounts to access the online library systems of particular U.S.-based and foreign universities directly. Beyond the universities, the department alleges the defendants compromised and exfiltrated employee email accounts at entities including the U.S. Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the United Nations and the United Nations Children's Fund, as well as foreign companies based in Germany, Italy, Switzerland, Sweden and the United Kingdom. Separately, the S2 indictment alleges that three defendants — Mojtaba Galekuhi, Keyvan Fayaz and Saber Shahbazi Ballojeh — took part in the institute's efforts to hack private sector companies and at least two governmental entities, including through password spray attacks, unauthorized access to victim systems and data exfiltration, causing victims to suffer an excess of $20 million in costs to investigate and remediate the intrusions. The announcement also describes alleged targeting of Home Box Office, Inc. (HBO), the New York-headquartered media and entertainment company. According to the department, defendant Behzad Mesri was separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking into HBO's computer systems, stealing proprietary data and then attempting to extort HBO for approximately $6 million worth of Bitcoin. The S2 indictment alleges that defendants Saeid Houshyar, Manouchehr Hashemloo, Fayaz, Ballojeh and Arman Kahzadian were also directly involved in the hack of HBO's systems along with Mesri. The department does not allege that those five defendants participated in the extortion attempt against Mesri in the separate case. The indictment also alleges that defendant Amir Barati tracked the progress of the spearphishing campaigns, exchanged login credentials for compromised accounts with co-conspirators, created targeting lists, conducted computer network reconnaissance and crafted phishing messages. "The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value," said Assistant Attorney General for National Security John A. Eisenberg. U.S. Attorney Jamie McDonald for the said the charges "reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions," adding that "more than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us." Assistant Director Brett Leatherman of the FBI's Cyber Division said the defendants "allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government." Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh. Tips may be submitted through the program's Tor-based channel at he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion. The FBI investigated, with assistance from the United Kingdom's National Crime Agency and support from OFAC and the Rewards for Justice program; the Justice Department's Office of International Affairs is providing assistance. Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati are leading the prosecution, with assistance from Trial Attorney Jacques Singer-Emery and former Trial Attorney Matthew Chang of the National Security Division's National Security Cyber Section. The counts include conspiracy to commit computer intrusions (18 U.S.C. § 371), conspiracy to commit wire fraud (18 U.S.C. § 1349), computer fraud – unauthorized access for private financial gain (18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), (c)(2)(B)(iii) and 2), wire fraud (18 U.S.C. §§ 1343 and 2), aggravated identity theft (18 U.S.C. §§ 1028A(a)(1), 1028A(b), and 2) and computer intrusion (18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), and (c)(2)(B)(iii)). Maximum penalties per count include five years in prison for the conspiracy-to-commit-computer-intrusions and computer fraud counts, 20 years in prison for wire fraud and conspiracy to commit wire fraud, and a mandatory sentence of two years in prison for aggravated identity theft. The department notes those maximums are prescribed by Congress and provided for informational purposes only; any sentencing would be determined by the judge. An indictment is merely an allegation. All defendants — Gholamreza Rafatnejad, Ehsan Mohammadi, Abdollah Karima, also known as "Vahid Karima," Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri, also known as "Skote Vahshat," Manouchehr Hashemloo, Keyvan Fayaz, also known as "Achilles," also known as "The Joker," also known as "bc.monster," Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi, also known as "Mojtaba Ghaleh Koui" — are presumed innocent until proven guilty beyond a reasonable doubt in a court of law. The Justice Department announcement is the sole source for this account; it does not identify lawyers for the defendants.

Earlier reports

  1. Aug 18, 2026, 8:53 p.m. ET

    17 Iranian Nationals Charged in 14-Count Superseding Cyber Theft Indictment

    A 14-count superseding (S2) indictment was unsealed on August 18, 2026, in the U.S. District Court for the Southern District of New York, charging 17 members of the Mabna Institute, an Iran-based company, in connection with an alleged global campaign of computer intrusions, according to U.S. Department of Justice press release 26-940. Nothing has been proven or found against any defendant at this stage: the case is at the charging stage only, and it has not been decided.

    The release states the department's position on that point directly: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law."

    According to the allegations set out in the release, the Mabna Institute was founded in approximately 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to help Iranian universities and research organizations obtain access to non-Iranian scientific resources. Prosecutors allege the institute employed and contracted hackers-for-hire and conducted a coordinated campaign of intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations. The indictment further alleges that many of these intrusions were carried out on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients.

    The indictment alleges the defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, exfiltrating it to servers outside the United States. It also alleges the campaign targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000 of them, and that stolen material was sold within Iran through two websites, Megapaper.ir and Gigapaper.ir. Prosecutors allege intrusions at private companies and government entities caused victims to incur more than $20 million in investigation and remediation costs. These are accusations that the government would have to prove at trial.

    Eight defendants are newly charged in the S2 indictment; nine were previously charged in a 7-count indictment announced in March 2018. Among the new allegations, the release says defendant Behzad Mesri — separately charged in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking Home Box Office, Inc. and attempting to extort approximately $6 million worth of Bitcoin — was joined by Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian in the alleged HBO intrusion. Those separate charges likewise remain unproven.

    The 14 counts include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud for private financial gain, wire fraud and aggravated identity theft. The release notes that the maximum penalties it lists are prescribed by Congress and provided for informational purposes only, as any sentencing would be determined by the judge.

    The prosecution is led by Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati for the Southern District of New York, with the FBI, the National Security Division and the Justice Department's Office of International Affairs involved. Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.

    The case is assigned to U.S. District Judge Jesse M. Furman. As of the department's announcement, no plea, verdict or other resolution has been recorded, and the outcome remains open. Readers encountering this report later should not treat the allegations described above as findings.

  2. Aug 18, 2026, 8:20 p.m. ETFirst report

    17 Iranian Nationals Charged in Multi-Year Cyber Theft Campaign, Official Records Show

    According to official federal court records unsealed on August 18, 2026, 17 Iranian members of the Mabna Institute have been charged in a 14-count superseding indictment for conducting a cyber theft campaign. The case, assigned to U.S. District Judge Jesse M. Furman in the U.S. District Court for the Southern District of New York, remains open and at the charging stage. The indictment is merely an allegation, the matter remains undecided, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

    Official records state that the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to conduct cyber intrusions on behalf of Iranian government entities, including the Islamic Revolutionary Guard Corps. Investigators allege the campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, stealing at least approximately 31.5 terabytes of academic data and intellectual property. The indictment also outlines intrusions targeting at least 42 U.S.-based private sector companies, 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations.

    Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment. U.S. Attorney Jamie McDonald for the Southern District of New York said, "Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

Was this report accurate and useful?

Sources

Revision history

  1. Version 219 Aug 2026, 13:57current

    Removed forbidden pipeline vocabulary 'record' and reinforced explicit statements on the presumption of innocence and undecided charging status.

  2. Version 119 Aug 2026, 00:23

    First published.

  3. Version 119 Aug 2026, 00:20current

    First published.

  4. Version 119 Aug 2026, 00:53current

    First published.

How we work

This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.

Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.

Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.

None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.