Feds charge 17 in Iran-backed hacking scheme
Prosecutors say members of the sanctioned Tehran-based firm the Mabna Institute compromised emails for more than 100,000 college professors worldwide.
by Erik Uebelacker, Court House News, August 18, 2026
MANHATTAN (CN) — Federal prosecutors on Tuesday unsealed a 14-count superseding indictment that charged more than a dozen people with a far-reaching hacking scheme targeting United States computer systems on behalf of the Iranian government.
According to investigators, 17 members of Iran-based firm the Mabna Institute, since at least 2013, conducted a coordinated campaign of cyber intrusions against at least 144 colleges stateside and 178 international universities. They reportedly also targeted private sector companies, both U.S.-based and abroad, as well as government agencies and non-governmental organizations.
Prosecutors say they stole more than 31 terabytes of academic data and intellectual property from the universities. At the other institutions, the hackers supposedly obtained email accounts of employees.
It’s the second wave of charges against the sanctioned Mabna Institute. Nine of the 17 people charged in the superseding indictment were also swept up in an initial 2018 indictment, accusing the Tehran-based company of using spoofed websites and fake login pages to steal data from organizations in the United States, Canada and a dozen other countries.
“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” Assistant Director Brett Leatherman of the FBI’s Cyber Division said in a statement. “Today’s charges make clear to cyber adversaries everywhere: the FBI’s memory is long, and time will not blunt our resolve to pursue justice. The FBI will continue working with law enforcement and private sector partners to identify malicious cyber actors, disrupt their operations, and impose real cost on them, wherever they operate.”
U.S. Attorney for the Southern District of New York Jamie McDonald said in a statement that the charges reveal “the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions.”
In Tuesday’s 51-page superseder, the federal government claimed the perpetrators used personalized phishing emails to swindle unsuspecting professors into clicking harmful links. The emails would often purport to be from professors at other universities, the government claims.
“In general, those spearphishing emails indicated that the sender had read an article the victim professor had recently published, and expressed an interest in several other articles,” prosecutors claim in the filing. “The sender provided links to those additional articles.”
If the victim clicked on certain links, they may be directed to a “malicious internet domain named to appear confusingly similar to the authentic domain of the recipient professor’s university.” The victim would then log in to the phony site using their credentials, which would then be in the hands of the hackers.
The government claims the defendants and their co-conspirators targeted over 100,000 professors worldwide with these personalized phishing messages, approximately half of which were in the U.S. On the private side, the hackers supposedly victimized tech companies, consulting firms, defense contractors, financial firms and entertainment companies — one of them being HBO.
The Department of Labor, the United Nations, Hawaii and Indiana were also targeted, according to prosecutors.
The State Department is offering a reward of up to $10 million for information leading to the location of five defendants named in the indictment.
According to the government, the Mabna Institute was founded around 2013 to steal data on behalf of Iranian universities and other research groups. Many of the defendants in the indictment were hackers-for-hire, prosecutors claim.
Many of the charges in the superseding indictment overlap between defendants. The charges include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud and identity theft. The maximum sentences for each crime range between two and 20 years in prison.