At a glance
| Actor or group | Mabna Institute (Iran-based), allegedly for the IRGC |
| Activity type | Spearphishing, credential theft, data exfiltration (hacking-for-hire) |
| Targets | Universities, private companies, government agencies, NGOs |
| Scale | More than 31 terabytes stolen; about 8,000 professor accounts (alleged) |
| Status | 17 charged; five carry up to $10M Rewards for Justice bounties; no arrests |
| Source | U.S. Department of Justice |
TL;DR
The U.S. Department of Justice unsealed a 14-count superseding indictment on August 18, 2026. It charges 17 members of Iran’s Mabna Institute cyber theft operation. Prosecutors say the group stole research and data for the IRGC since at least 2013.
What happened
The indictment describes a long-running hacking campaign. The Mabna Institute allegedly targeted more than 100,000 professor accounts worldwide. It compromised roughly 8,000 of them across 144 U.S. and 178 foreign universities.
The alleged haul is large. Prosecutors say the group stole at least 31.5 terabytes of academic data and intellectual property. The DOJ states the Mabna Institute cyber theft campaign also hit 42 U.S. companies, five government agencies, and two NGOs. Victims include the U.S. Department of Labor and the United Nations.
Selling the stolen research
The defendants allegedly resold what they took. Two Iranian websites, Megapaper and Gigapaper, offered the stolen material. One service let buyers use hijacked professor accounts to reach university libraries directly.
Who is behind it
Prosecutors name the Iran-based Mabna Institute and 17 members. Gholamreza Rafatnejad and Ehsan Mohammadi allegedly founded it in 2013. The group allegedly ran the university campaign for the IRGC.
These are allegations, and no defendant has been convicted. As the DOJ notes, the defendants “hacked into universities and other research institutions worldwide,” stealing data “of untold value.” The full Justice Department announcement lists all charges. Independent outlets, including The Hill and JNS, corroborate the filing.
Impact or scale
The costs cited are steep. U.S. universities spent more than $3.4 billion to procure the targeted data, per the indictment. Private-sector and government victims suffered over $20 million in remediation costs, prosecutors claim. These figures come from the DOJ and remain allegations.
What comes next
Most defendants remain at large abroad. The State Department’s Rewards for Justice program offers up to $10 million for information locating five of them. Institutions should enforce multi-factor authentication to blunt spearphishing. Staff training on phishing emails also lowers the risk.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.