17 Iranians Indicted for $3.4 Billion Academic Hack Targeting 22 Countries, Including Poland

17 Iranians Indicted for $3.4 Billion Academic Hack Targeting 22 Countries, Including Poland

2026-08-19

The Mabna Institute, an Iranian company working for the Revolutionary Guard, penetrated more than three hundred universities worldwide and sold stolen research through commercial websites in Tehran. A federal grand jury has now named seventeen of its members.

On August 18, 2026, federal prosecutors in the Southern District of New York unsealed a fourteen-count superseding indictment charging seventeen Iranian nationals with running one of the largest documented state-sponsored academic espionage operations in history. The organization at the center of the case, the Mabna Institute, was founded in Tehran around 2013 and operated under contract to Iran’s Islamic Revolutionary Guard Corps. Over the following decade, its members penetrated the computer systems of at least a hundred and forty-four American universities and a hundred and seventy-eight institutions in twenty-one other countries, including Poland. What they took, roughly thirty-one and a half terabytes of academic research valued at approximately three point four billion dollars, was not merely stolen. It was packaged, invoiced, and sold back to Iranian universities through two commercial websites operating openly in Tehran.

The August indictment expands a 2018 case that initially charged nine members of the same network. Eight of the seventeen defendants now named were never in custody. Several continued hacking after the first indictment was unsealed, compromising a COVID-19 vaccine developer in December 2020 and selling stolen credentials on dark-web forums until at least March 2022. The State Department has announced a ten-million-dollar reward for information leading to the location of five of the principal accused. Poland appears in the indictment not as a footnote but as a named target: its universities subscribed to the same Western research databases that the Mabna Institute systematically plundered.

 

A Company with a Mission

The Mabna Institute was founded in Tehran around 2013 by two men named Gholamreza Rafatnejad and Ehsan Mohammadi. Mohammadi served as managing director and oversaw the organization’s finances. The stated purpose of the enterprise, the purpose that the founders might have offered to a curious neighbor or a customs official, was a sympathetic one: to help Iranian universities and scientific organizations gain access to foreign academic resources.

The sympathetic part is worth pausing on. Western sanctions had effectively cut Iranian institutions off from the subscription databases that power modern research, platforms like JSTOR, Elsevier, and Web of Science, services that major universities elsewhere pay for through multi-million-dollar licensing agreements. The Mabna Institute proposed to solve this problem. Its solution, efficient and entirely without scruple, was simply to steal what it could not buy. Treasury Department sanctions later designated the Mabna Institute and all nine original defendants, effectively blocking their assets.

The client, for much of the operation, was the Islamic Revolutionary Guard Corps, the IRGC, the arm of the Iranian government responsible for intelligence gathering. The organizational structure of the Mabna Institute, however, bore a closer resemblance to a mid-size tech firm than to an intelligence agency: founders, a managing director, contractors, hackers retained for specific assignments, affiliates paid by the credential. Espionage, organized with a CFO.

 

The Most Dangerous Message in Academia

The indictment, which runs to fifty pages in the Southern District of New York’s precise federal prose, describes the hacking campaign in three phases. The first was reconnaissance. Analysts at the Mabna Institute would profile individual professors, studying their recent publications, identifying their intellectual neighborhoods, sometimes working through footnotes to map their academic circles. The goal was not merely an email address but a portrait.

The second phase was the email itself. It arrived from what appeared to be a colleague at another university, someone who had just finished reading your most recent article with genuine enthusiasm and wanted to share a few related papers. Links were helpfully included. If the professor clicked, he was directed to a domain whose name differed from his own university’s address by a single character, or by a different top-level extension, the kind of discrepancy invisible to anyone not specifically looking for it. The page looked exactly like his university’s login portal, because it had been built to. It asked for a username and password. The professor typed them. The page refreshed. Nothing seemed to have happened.

The third phase was extraction. Using the stolen credentials, affiliates of the institute logged into victim accounts and transferred everything accessible: academic journals, doctoral dissertations, monographs, raw data, electronic books. By the time prosecutors assembled the accounting, more than thirty-one and a half terabytes of academic data had been exfiltrated from a hundred and forty-four American universities and a hundred and seventy-eight institutions in twenty-two other countries. More than a hundred thousand professor accounts worldwide had been targeted; roughly eight thousand were successfully compromised, of which three thousand seven hundred and sixty-eight belonged to faculty at American institutions. The value of what was taken came to approximately three point four billion dollars.

 

Theft by Subscription

There is an aspect of the Mabna operation that the indictment’s flat federal language cannot quite contain, which is the commercial tidiness of what happened to the stolen data once it left Western servers. The material was not delivered exclusively to the IRGC. It was also sold openly through two Iranian websites: Megapaper.ir and Gigapaper.ir. Megapaper, operated through a company called Falinoos and controlled by defendant Abdollah Karima, also known as Vahid Karima, sold stolen academic articles to Iranian universities and public institutions with actual invoices and contracts. Gigapaper offered a subscription through which paying Iranian customers received access to a compromised Western professor’s university account, and could browse that institution’s digital library as though they were tenured faculty. State-sponsored intellectual property theft, monetized and invoiced.

 

The Policeman, the Hacker, and the Supreme Leader’s Website

Among the seventeen defendants named in the superseding indictment are several whose professional histories illuminate how the Iranian government organizes its cyber activities. Saeid Houshyar and Manouchehr Hashemloo were simultaneously contractors for the Mabna Institute and members of FATA, Iran’s internal cyber police force. Hashemloo, whose portfolio apparently ranged without limit, conducted cybersecurity work on behalf of the IRGC, performed services for FATA, and, according to the indictment, developed a website for the Supreme Leader of the Islamic Republic of Iran. Whether the Supreme Leader’s web presence employed adequate password hygiene is not a matter the document addresses.

Behzad Mesri, known in relevant circles as Skote Vahshat, presented himself as an expert in attacking military systems and nuclear software, and conducted network intrusions against Israeli infrastructure on behalf of the Iranian military. Keyvan Fayaz operated under the pseudonyms Achilles, The Joker, and bc.monster, managing server infrastructure for password-spray campaigns against private-sector companies. For corporate targets, affiliates collected employee email addresses through ordinary internet searches, then attempted to log into those accounts using the most commonly set default passwords. When they succeeded, they established automated forwarding rules that quietly duplicated every subsequent email to servers under the conspiracy’s control. Persistent surveillance, derived from a single afternoon’s work.

 

The HBO Episode

In June of 2017, members of theabna network turned their attention to HBO. What came out of the network’s servers proved considerably more marketable than a professor’s journal subscription: unaired episodes of original series, including Game of Thrones; unproduced scripts; confidential cast and crew contact lists; financial documents. Mesri, separately charged for this intrusion, subsequently demanded approximately six million dollars in Bitcoin. He received nothing, except a federal indictment filed in absentia in a courthouse he will presumably never enter.

 

What Happened After the Indictment

The first indictment, announced on March 23, 2018, charged nine Iranian nationals. Iran did not respond. The nine defendants did not appear in court. The operation did not stop. Keyvan Fayaz, Saber Shahbazi Ballojeh, and Mojtaba Galekuhi simply continued working. Their post-indictment target list included a developer of the COVID-19 vaccine, compromised in December of 2020; three American defense contractors; a public utility; an energy company; and one of the largest commercial airlines in the world. The remediation costs borne by victims in this second wave exceeded twenty million dollars. Fayaz was selling stolen credentials on dark-web forums at least until March of 2022, four years after the Justice Department had publicly identified him by name. The superseding indictment unsealed this August names seventeen defendants across fourteen counts.

 

What the Strategy Is Worth

None of the seventeen defendants is in custody. Iran does not extradite its own nationals. The distance between an indictment and a conviction is, in cases of this kind, a political distance rather than a legal one.

Treasury Department sanctions against the Mabna Institute and its principals complicate their financial lives considerably; Rafatnejad’s passport is of limited use outside Iran and a small number of friendly states. The counterargument is embedded in the timeline: the members of the conspiracy who continued operating after 2018 did not find the public naming particularly deterrent.

The jurisdictional boilerplate in the new indictment contains a sentence explaining the basis for venue in Manhattan. The court is the appropriate court, the document states, because the defendants “will first enter the United States in the Southern District of New York.” Seventeen people in Tehran. Seventeen open indictments and seventeen open doors in lower Manhattan. Somewhere in a federal courthouse above Foley Square, a grand jury holds the position.

Poland’s universities did not appear in the indictment because they were marginal targets. They appeared because they are good universities, with expensive databases, and professors who receive a great deal of email from colleagues they have met, or almost met, or might plausibly have met, at conferences in other countries. The Silent Librarian does not return to libraries because it appreciates the atmosphere. It returns because that is where the books are.

 

Further reading

The Second Laundromat on Bartycka Street. How a Shell Company With $1,400 in Capital Landed on America’s Terrorism Sanctions List

The Shadow States: How Iran, Russia, and North Korea Turned Cryptocurrency Into the Infrastructure of Sanctions Evasion