Monday, 24 August 2026

Cyberhacking Indictment Unsealed Involving Alleged Theft of University IP

On August 18, 2026, the US Department of Justice unsealed an indictment concerning cyberhacking campaigns conducted against universities around the world, governmental entities and companies by an Iranian hacking group.  The press release states, in part:  

Mabna Institute Hackers Attacked Systems Belonging to Hundreds of Universities, Companies, and Other Victims to Steal Research, Academic and Proprietary Data, and Intellectual Property

A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. The defendants conducted many of these intrusions on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), one of several entities within the government of Iran responsible for gathering intelligence, as well as other Iranian government and university clients. Nine of the 17 defendants charged in the S2 indictment were previously charged in a 7-count indictment announced in March 2018. The case is assigned to U.S. District Judge Jesse M. Furman.

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” said Assistant Attorney General for National Security John A. Eisenberg. “The National Security Division is committed to protecting the United States from such predators and will pursue those who perpetrate such crimes for as long as it takes to bring them to justice.”

“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” said U.S. Attorney Jamie McDonald for the Southern District of New York. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad. Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength. This office and our partners will continue to protect American innovation and pursue accountability for the individuals behind these attacks.”

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Today’s charges make clear to cyber adversaries everywhere: the FBI’s memory is long, and time will not blunt our resolve to pursue justice. The FBI will continue working with law enforcement and private sector partners to identify malicious cyber actors, disrupt their operations, and impose real cost on them, wherever they operate.”

. . . University Hacking Campaign

The Mabna Institute, through the activities of the defendants, targeted more than 100,000 accounts of professors around the world. They successfully compromised approximately 8,000 professor email accounts across 144 U.S.-based universities, and 178 universities located in foreign countries, including Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey and the United Kingdom. The campaign started in approximately 2013, continued through at least December 2017, and broadly targeted all types of academic data and intellectual property from the systems of compromised universities. Through the course of the conspiracy, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property.

The members of the conspiracy used stolen account credentials to obtain unauthorized access to victim professor accounts, which they used to steal research, and other academic data and documents, including, among other things, academic journals, theses, dissertations, and electronic books. The defendants targeted data across all fields of research and academic disciplines, including science and technology, engineering, social sciences, medical, and other professional fields. The defendants stole at least approximately 31.5 terabytes of academic data and intellectual property, which they exfiltrated to servers outside the United States that were under the control of members of the conspiracy.

In addition to stealing academic data and login credentials for the benefit of the Government of Iran, the defendants also sold the stolen data through two websites, Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper). Megapaper was operated by Falinoos Company, a company controlled by Abdollah Karima, and Gigapaper was also affiliated with Karima. Megapaper sold stolen academic resources to customers within Iran, including Iran-based public universities and institutions, and Gigapaper sold a service to customers within Iran whereby purchasing customers could use compromised university professor accounts to directly access the online library systems of particular U.S.-based and foreign universities.

Private Sector and Governmental and Non-Governmental Organization Hacking Campaigns

In addition to targeting and compromising universities, the defendants targeted and compromised and exfiltrated employee email accounts for at least five U.S. federal and state government agencies, at least 42 U.S. based private sector companies, at least approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom, and various governmental and non-governmental organizations within the U.S., including the U.S. Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the United Nations, and the United Nations Children’s Fund.

No comments: