17 Iranians Charged Over Alleged Cyber Theft Campaign for Iranian Government
A 14-count superseding indictment unsealed in the Southern District of New York accuses 17 members of the Iran-based Mabna Institute of stealing academic data and intellectual property from universities, companies and government agencies. All defendants are presumed innocent.
3 reports on this incident · first at Aug 18, 2026, 8:20 p.m. ET
Earlier reports
Aug 18, 2026, 8:53 p.m. ET
17 Iranian Nationals Charged in 14-Count Superseding Cyber Theft Indictment
A 14-count superseding (S2) indictment was unsealed on August 18, 2026, in the U.S. District Court for the Southern District of New York, charging 17 members of the Mabna Institute, an Iran-based company, in connection with an alleged global campaign of computer intrusions, according to U.S. Department of Justice press release 26-940. Nothing has been proven or found against any defendant at this stage: the case is at the charging stage only, and it has not been decided.
The release states the department's position on that point directly: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law."
According to the allegations set out in the release, the Mabna Institute was founded in approximately 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to help Iranian universities and research organizations obtain access to non-Iranian scientific resources. Prosecutors allege the institute employed and contracted hackers-for-hire and conducted a coordinated campaign of intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations. The indictment further alleges that many of these intrusions were carried out on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients.
The indictment alleges the defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, exfiltrating it to servers outside the United States. It also alleges the campaign targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000 of them, and that stolen material was sold within Iran through two websites, Megapaper.ir and Gigapaper.ir. Prosecutors allege intrusions at private companies and government entities caused victims to incur more than $20 million in investigation and remediation costs. These are accusations that the government would have to prove at trial.
Eight defendants are newly charged in the S2 indictment; nine were previously charged in a 7-count indictment announced in March 2018. Among the new allegations, the release says defendant Behzad Mesri — separately charged in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking Home Box Office, Inc. and attempting to extort approximately $6 million worth of Bitcoin — was joined by Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian in the alleged HBO intrusion. Those separate charges likewise remain unproven.
The 14 counts include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud for private financial gain, wire fraud and aggravated identity theft. The release notes that the maximum penalties it lists are prescribed by Congress and provided for informational purposes only, as any sentencing would be determined by the judge.
The prosecution is led by Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati for the Southern District of New York, with the FBI, the National Security Division and the Justice Department's Office of International Affairs involved. Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.
The case is assigned to U.S. District Judge Jesse M. Furman. As of the department's announcement, no plea, verdict or other resolution has been recorded, and the outcome remains open. Readers encountering this report later should not treat the allegations described above as findings.
Aug 18, 2026, 8:20 p.m. ETFirst report
17 Iranian Nationals Charged in Multi-Year Cyber Theft Campaign, Official Records Show
According to official federal court records unsealed on August 18, 2026, 17 Iranian members of the Mabna Institute have been charged in a 14-count superseding indictment for conducting a cyber theft campaign. The case, assigned to U.S. District Judge Jesse M. Furman in the U.S. District Court for the Southern District of New York, remains open and at the charging stage. The indictment is merely an allegation, the matter remains undecided, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.
Official records state that the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to conduct cyber intrusions on behalf of Iranian government entities, including the Islamic Revolutionary Guard Corps. Investigators allege the campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, stealing at least approximately 31.5 terabytes of academic data and intellectual property. The indictment also outlines intrusions targeting at least 42 U.S.-based private sector companies, 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations.
Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment. U.S. Attorney Jamie McDonald for the Southern District of New York said, "Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Was this report accurate and useful?
Sources
Revision history
- Version 219 Aug 2026, 13:57current
Removed forbidden pipeline vocabulary 'record' and reinforced explicit statements on the presumption of innocence and undecided charging status.
- Version 119 Aug 2026, 00:23
First published.
- Version 119 Aug 2026, 00:20current
First published.
- Version 119 Aug 2026, 00:53current
First published.
How we work
This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.
Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.
Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.
None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.