17 Iranian Nationals Charged in 14-Count Superseding Cyber Theft Indictment
Justice Department records show an unsealed indictment in the Southern District of New York accusing 17 members of the Iran-based Mabna Institute. The allegations are untested; no court has ruled, and the case remains unresolved.
3 reports on this incident · first at Aug 18, 2026, 8:20 p.m. ET
Earlier reports
Aug 18, 2026, 8:23 p.m. ET
17 Iranian Nationals Charged in 14-Count Cyber Theft Indictment; No Case Yet Decided
Seventeen members of the Iran-based Mabna Institute have been charged in a 14-count superseding indictment unsealed in the U.S. District Court for the Southern District of New York, according to the U.S. Department of Justice announcement of the case (release number 26-940), dated August 18, 2026. No court has decided anything in the matter. The case is at the charging stage only; the allegations are unproven and remain undecided.
Nine of the 17 defendants were previously charged in a 7-count indictment announced in March 2018. Eight additional defendants are charged in the superseding (S2) indictment. The case is assigned to U.S. District Judge Jesse M. Furman.
What the indictment alleges
According to the allegations in the S2 indictment as described in the department's announcement, the Mabna Institute has since at least 2013 conducted a coordinated campaign of cyber intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations.
The indictment alleges that the defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, exfiltrating it to servers outside the United States said to be under the control of members of the conspiracy. It further alleges that many of the intrusions were conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients, and that stolen material was also sold within Iran through two websites, Megapaper.ir and Gigapaper.ir.
The announcement states that the campaign began in approximately 2013 and continued through at least December 2017, targeting more than 100,000 professor accounts worldwide and allegedly compromising approximately 8,000 of them. Over the course of the alleged conspiracy, the record says, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property.
Beyond universities, the indictment alleges the defendants compromised employee email accounts at U.S. and foreign organizations including the U.S. Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the United Nations and the United Nations Children's Fund. It alleges that intrusions into private sector companies and at least two governmental entities caused victims to incur in excess of $20 million in costs to investigate and remediate.
The announcement also says defendant Behzad Mesri, charged separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN), is alleged to have hacked Home Box Office, Inc. and attempted to extort the company for approximately $6 million worth of Bitcoin, and that five other defendants were allegedly involved in that intrusion.
Officials' statements
The officials quoted in the announcement described the conduct in the language of allegation.
"The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value," said Assistant Attorney General for National Security John A. Eisenberg.
"Today's charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions," said U.S. Attorney Jamie McDonald for the Southern District of New York.
"These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government," said Assistant Director Brett Leatherman of the FBI's Cyber Division.
Rewards offer and prosecution team
Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.
The matter is being handled by the U.S. Attorney's Office for the Southern District of New York, the Justice Department's National Security Division, the Justice Department's Office of International Affairs and the Federal Bureau of Investigation. Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati lead the prosecution.
The maximum penalties listed in the announcement range from five years in prison on the computer intrusion and computer fraud counts to 20 years on the wire fraud counts, with a mandatory sentence of two years for aggravated identity theft. The announcement notes those maximums are set by Congress and provided for informational purposes only, as any sentencing would be determined by the judge.
Status
As of the August 18, 2026 announcement, this is an accusation and nothing more. No trial has been held, no plea has been recorded and no finding has been made against any defendant. In the words of the Justice Department announcement: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law." A reader encountering this report at a later date should not assume the case has been resolved; the outcome, if any, is not reflected here.
Aug 18, 2026, 8:20 p.m. ETFirst report
17 Iranian Nationals Charged in Multi-Year Cyber Theft Campaign, Official Records Show
According to official federal court records unsealed on August 18, 2026, 17 Iranian members of the Mabna Institute have been charged in a 14-count superseding indictment for conducting a cyber theft campaign. The case, assigned to U.S. District Judge Jesse M. Furman in the U.S. District Court for the Southern District of New York, remains open and at the charging stage. The indictment is merely an allegation, the matter remains undecided, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.
Official records state that the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to conduct cyber intrusions on behalf of Iranian government entities, including the Islamic Revolutionary Guard Corps. Investigators allege the campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, stealing at least approximately 31.5 terabytes of academic data and intellectual property. The indictment also outlines intrusions targeting at least 42 U.S.-based private sector companies, 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations.
Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment. U.S. Attorney Jamie McDonald for the Southern District of New York said, "Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Was this report accurate and useful?
Sources
Revision history
- Version 119 Aug 2026, 00:23current
First published.
- Version 119 Aug 2026, 00:20current
First published.
- Version 119 Aug 2026, 00:53current
First published.
How we work
This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.
Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.
Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.
None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.