Drooid Logo
Back to story perspectives

Full Breakdown

U.S. Justice Department Indicts 17 Iranians for Multi-Year Cyber Theft Campaign

8/19/2026, 9:49:02 PM

Core Event: Federal Indictment of Mabna Institute Operatives

In August 2026 a Manhattan federal court unsealed a 14-count superseding indictment charging 17 Iranian nationals affiliated with the Tehran-based Mabna Institute. Prosecutors allege the group ran a coordinated cyber-intrusion campaign from 2013 through at least December 2017, targeting U.S. universities, private-sector firms, government agencies and international organizations. The indictment adds eight defendants to a prior 2018 case that charged nine members of the same network.

Background & Context

The Mabna Institute was founded in 2013 to assist Iranian academic institutions in obtaining “non-Iranian scientific resources.” U.S. authorities say the firm operated as a hacking-for-hire service, carrying out phishing attacks and credential-trading on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. The 2018 indictment first exposed the network; the 2026 superseding indictment expands the alleged scope and identifies additional participants.

Data & Statistics

  • Universities targeted: 144 U.S. universities and 178 foreign universities.
  • Accounts compromised: Over 100,000 faculty accounts worldwide; about 8,000 email accounts.
  • Corporate and government victims: At least 42 U.S. private-sector companies, 11 foreign companies, five U.S. federal or state agencies, and two NGOs.
  • Data exfiltrated: At least 31 terabytes of academic journals, dissertations, e-books and other research.
  • Valuation: U.S. universities collectively spent more than $3.4 billion to acquire or access the stolen materials.
  • Reward: The State Department’s Rewards for Justice program offers up to $10 million for information leading to the location of five defendants.

Official Statements & Responses

FBI Assistant Director James C. Barnacle Jr. said the indictment demonstrates a “state-sponsored effort to steal research and intellectual property.” The Department of State reiterated the $10 million reward offer and named several high-profile defendants. The Justice Department framed the case as evidence of a coordinated IRGC-backed operation targeting American research infrastructure.

Conflicting Reports & Gaps

  • Data volume: Some sources cite “more than 31 terabytes,” while filings specify “at least 31.5 terabytes.”
  • Foreign university count: Outlets vary between the precise figure of 178 and vague references to “hundreds.”
  • Monetary loss vs. valuation: The Justice Department notes the $3.4 billion spent by universities but does not label the entire amount as a direct loss from the theft.

Why It Matters

The indictment highlights the use of cyber operations by the IRGC to exploit vulnerabilities in academic and research systems. Compromised professor credentials gave attackers access to subscription-based journals and proprietary research, facilitating the transfer of advanced knowledge to Iranian entities. The case also underscores the link between cybercrime and geopolitical tension.

What’s Next

Defendants face charges including conspiracy to commit computer intrusions, wire fraud and aggravated identity theft, with maximum penalties of up to 20 years per count. The Rewards for Justice program remains active for information on five accused. Federal prosecutors indicated investigations will continue into related cyber incidents, including recent attacks on U.S. water-system controls suspected to be tied to Iran-aligned groups.