FirstAlerts

17 Iranian Nationals Charged in 14-Count Superseding Cyber Theft Indictment

Justice Department records show an unsealed indictment in the Southern District of New York accusing 17 members of the Iran-based Mabna Institute. The allegations are untested; no court has ruled, and the case remains unresolved.

3 reports on this incident · first at Aug 18, 2026, 8:20 p.m. ET

By AI ReporterWritten Aug 18, 2026, 8:53 p.m. ET
A 14-count superseding (S2) indictment was unsealed on August 18, 2026, in the U.S. District Court for the Southern District of New York, charging 17 members of the Mabna Institute, an Iran-based company, in connection with an alleged global campaign of computer intrusions, according to U.S. Department of Justice press release . Nothing has been proven or found against any defendant at this stage: the case is at the charging stage only, and it has not been decided. The release states the department's position on that point directly: "" According to the allegations set out in the release, the Mabna Institute was founded in approximately 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to help Iranian universities and research organizations obtain access to non-Iranian scientific resources. Prosecutors allege the institute employed and contracted hackers-for-hire and conducted a coordinated campaign of intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations. The indictment further alleges that many of these intrusions were carried out on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. The indictment alleges the defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, exfiltrating it to servers outside the United States. It also alleges the campaign targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000 of them, and that stolen material was sold within Iran through two websites, Megapaper.ir and Gigapaper.ir. Prosecutors allege intrusions at private companies and government entities caused victims to incur more than $20 million in investigation and remediation costs. These are accusations that the government would have to prove at trial. Eight defendants are newly in the S2 indictment; nine were previously in a 7-count indictment announced in March 2018. Among the new allegations, the release says defendant Behzad Mesri — separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking Home Box Office, Inc. and attempting to extort approximately $6 million worth of Bitcoin — was joined by Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian in the alleged HBO intrusion. Those separate charges likewise remain unproven. The 14 counts include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud for private financial gain, wire fraud and aggravated identity theft. The release notes that the maximum penalties it lists are prescribed by Congress and provided for informational purposes only, as any sentencing would be determined by the judge. The prosecution is led by Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati for the Southern District of New York, with the FBI, the National Security Division and the Justice Department's Office of International Affairs involved. Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh. The case is assigned to U.S. District Judge Jesse M. Furman. As of the department's announcement, no plea, verdict or other resolution has been recorded, and the outcome remains open. Readers encountering this report later should not treat the allegations described above as findings.

Earlier reports

  1. Aug 18, 2026, 8:23 p.m. ET

    17 Iranian Nationals Charged in 14-Count Cyber Theft Indictment; No Case Yet Decided

    Seventeen members of the Iran-based Mabna Institute have been charged in a 14-count superseding indictment unsealed in the U.S. District Court for the Southern District of New York, according to the U.S. Department of Justice announcement of the case (release number 26-940), dated August 18, 2026. No court has decided anything in the matter. The case is at the charging stage only; the allegations are unproven and remain undecided.

    Nine of the 17 defendants were previously charged in a 7-count indictment announced in March 2018. Eight additional defendants are charged in the superseding (S2) indictment. The case is assigned to U.S. District Judge Jesse M. Furman.

    What the indictment alleges

    According to the allegations in the S2 indictment as described in the department's announcement, the Mabna Institute has since at least 2013 conducted a coordinated campaign of cyber intrusions into computer systems at 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations.

    The indictment alleges that the defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, exfiltrating it to servers outside the United States said to be under the control of members of the conspiracy. It further alleges that many of the intrusions were conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients, and that stolen material was also sold within Iran through two websites, Megapaper.ir and Gigapaper.ir.

    The announcement states that the campaign began in approximately 2013 and continued through at least December 2017, targeting more than 100,000 professor accounts worldwide and allegedly compromising approximately 8,000 of them. Over the course of the alleged conspiracy, the record says, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property.

    Beyond universities, the indictment alleges the defendants compromised employee email accounts at U.S. and foreign organizations including the U.S. Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the United Nations and the United Nations Children's Fund. It alleges that intrusions into private sector companies and at least two governmental entities caused victims to incur in excess of $20 million in costs to investigate and remediate.

    The announcement also says defendant Behzad Mesri, charged separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN), is alleged to have hacked Home Box Office, Inc. and attempted to extort the company for approximately $6 million worth of Bitcoin, and that five other defendants were allegedly involved in that intrusion.

    Officials' statements

    The officials quoted in the announcement described the conduct in the language of allegation.

    "The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value," said Assistant Attorney General for National Security John A. Eisenberg.

    "Today's charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions," said U.S. Attorney Jamie McDonald for the Southern District of New York.

    "These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government," said Assistant Director Brett Leatherman of the FBI's Cyber Division.

    Rewards offer and prosecution team

    Concurrent with the unsealing, the State Department's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.

    The matter is being handled by the U.S. Attorney's Office for the Southern District of New York, the Justice Department's National Security Division, the Justice Department's Office of International Affairs and the Federal Bureau of Investigation. Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang and Adam Sowlati lead the prosecution.

    The maximum penalties listed in the announcement range from five years in prison on the computer intrusion and computer fraud counts to 20 years on the wire fraud counts, with a mandatory sentence of two years for aggravated identity theft. The announcement notes those maximums are set by Congress and provided for informational purposes only, as any sentencing would be determined by the judge.

    Status

    As of the August 18, 2026 announcement, this is an accusation and nothing more. No trial has been held, no plea has been recorded and no finding has been made against any defendant. In the words of the Justice Department announcement: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law." A reader encountering this report at a later date should not assume the case has been resolved; the outcome, if any, is not reflected here.

  2. Aug 18, 2026, 8:20 p.m. ETFirst report

    17 Iranian Nationals Charged in Multi-Year Cyber Theft Campaign, Official Records Show

    According to official federal court records unsealed on August 18, 2026, 17 Iranian members of the Mabna Institute have been charged in a 14-count superseding indictment for conducting a cyber theft campaign. The case, assigned to U.S. District Judge Jesse M. Furman in the U.S. District Court for the Southern District of New York, remains open and at the charging stage. The indictment is merely an allegation, the matter remains undecided, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

    Official records state that the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to conduct cyber intrusions on behalf of Iranian government entities, including the Islamic Revolutionary Guard Corps. Investigators allege the campaign compromised approximately 8,000 professor email accounts across 144 U.S.-based universities and 178 foreign universities, stealing at least approximately 31.5 terabytes of academic data and intellectual property. The indictment also outlines intrusions targeting at least 42 U.S.-based private sector companies, 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations.

    Nine of the 17 defendants were previously charged in a March 2018 indictment, while eight additional defendants were added in the superseding indictment. U.S. Attorney Jamie McDonald for the Southern District of New York said, "Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." Concurrently, the U.S. Department of State's Rewards for Justice program is offering a reward of up to $10 million for information leading to the location of defendants Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

Was this report accurate and useful?

Sources

Revision history

  1. Version 119 Aug 2026, 00:23current

    First published.

  2. Version 119 Aug 2026, 00:20current

    First published.

  3. Version 119 Aug 2026, 00:53current

    First published.

How we work

This site models an investigative reporter rather than a wire desk. The aim is the most complete, accurate and timely account we can assemble — all three, not a trade between them. Reports go out within minutes of the coverage they are built from, carrying context a newsroom would otherwise need a day and a records request to gather: what has happened at this place before, what the operator’s record is, which aircraft it actually was.

Reports are built from primary sources — accident and court records, official registries, weather observations, agency statements — and from reputable news organisations, each named where their reporting is used. Facts are extracted before anything is written, and every one must be supported by a quotation found in the source itself; the model that writes the report is given only those verified facts and never sees the article, so it cannot introduce a detail no source stated.

Where sources disagree we publish the disagreement, attributed, rather than picking a figure. Where a fact comes from a record rather than a reporter, we say so, and the language matches: an instrument reading is never described as something anyone confirmed. Some things are deliberately withheld — a suspect is not named until an agency names them on the record, victims until families or officials release them — and corrections appear as visible revisions, never as silent edits.

None of that makes a report true. A quotation check proves a source said something, not that it was right, and an automated system can be confidently wrong in ways the checks do not catch. If something here is wrong, the feedback above is how it gets found. The full methodology, including what we refuse to publish.