Crypto

U.S. Charges 17 Iranian Operatives Over Global Cyber Campaign and $6M HBO Bitcoin Extortion

Federal prosecutors expand charges against Mabna Institute over massive intellectual property heist and crypto-linked state intelligence operations.

Federal prosecutors expanded their crackdown on state-aligned cyber espionage by charging 17 alleged Iranian operatives in connection with a global intrusion campaign that stole massive amounts of academic research and attempted to extort entertainment giant HBO for $6 million in Bitcoin.

On Tuesday, the Justice Department disclosed that the defendants operated as members of the Iran-based Mabna Institute, performing hacking operations on behalf of Iran’s Islamic Revolutionary Guard Corps along with other government and university clients. Prosecutors said the syndicate targeted hundreds of universities, corporate entities, government agencies, and organizations globally.

While Behzad Mesri was previously charged with infiltrating HBO and stealing proprietary data, prosecutors named five additional defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—who were directly involved in the intrusion.

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” Assistant Attorney General for National Security John A. Eisenberg said in a statement.

DOJ prosecutors said the Mabna Institute targeted more than 100,000 professor accounts globally, successfully compromising roughly 8,000 accounts across 144 U.S. universities and 178 foreign universities. Investigators alleged the operatives relied on spearphishing tactics and stolen credentials to steal research data, academic journals, theses, dissertations, ebooks, and other proprietary materials.

Academic and research institutions have increasingly become focal points for state-sponsored cyber espionage, as university networks store cutting-edge technological and scientific research while typically operating under more open network sharing protocols than traditional defense or corporate networks.

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” FBI Cyber Division Assistant Director Brett Leatherman said in a statement.

The charges arrive as geopolitical tensions between Washington and Tehran remain high, prompting U.S. authorities to step up enforcement against digital asset networks that Iran and the IRGC use to move funds and evade international sanctions.

In June, the U.S. Treasury sanctioned four Iranian crypto exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion. Treasury also linked Nobitex to transactions involving IRGC-affiliated ransomware actors.

In July, Treasury froze more than $131 million across four crypto wallets the agency linked to Iran’s central bank and armed forces, including the IRGC. In August, Treasury sanctioned two more crypto exchanges that it accused of laundering millions of dollars for the IRGC and other sanctioned Iranian entities.

The State Department is offering rewards of up to $10 million for information leading to the location of five defendants.

“More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad,” U.S. Attorney Jamie McDonald for the Southern District of New York said in a statement.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button