Crypto

US Unseals Charges in $6 Million Extortion Scheme Linked to Iranian Cyber Spies

Indictments highlight HBO extortion plot and 31 terabytes of stolen academic intellectual property.

An extortion demand seeking roughly $6 million in Bitcoin after a high-profile breach of entertainment giant HBO anchors new federal charges against 17 alleged Iranian hackers involved in an extensive cyber campaign.

On Tuesday, the Department of Justice stated that the accused were members of the Iran-based Mabna Institute, which allegedly executed cyber intrusions for Iran’s Islamic Revolutionary Guard Corps alongside other Iranian government and university clients. Prosecutors noted that the group targeted hundreds of universities, private companies, government bodies, and additional organizations across the globe.

Behzad Mesri was previously charged with infiltrating entertainment company HBO to steal proprietary data. Federal prosecutors stated that five additional defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—were directly involved in that compromise.

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” Assistant Attorney General for National Security John A. Eisenberg said in a statement.

According to federal prosecutors, the Mabna Institute aimed spearphishing operations and stolen login credentials at more than 100,000 university faculty accounts worldwide. DOJ records indicate that operatives compromised approximately 8,000 accounts across 144 U.S. universities and 178 foreign universities to siphon academic journals, research files, theses, dissertations, ebooks, and related materials.

To put the scale into perspective, 31 terabytes of data is equivalent to tens of millions of digital document pages, making this operation one of the largest state-sponsored intellectual property thefts targeted at academic research.

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” FBI Cyber Division Assistant Director Brett Leatherman said in a statement.

Tensions between Washington and Tehran have escalated amid the ongoing war, while the U.S. has stepped up efforts to disrupt crypto networks it says Iran and the IRGC use to move money and evade sanctions.

In June, the U.S. Treasury sanctioned four Iranian crypto exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion. Treasury also linked Nobitex to transactions involving IRGC-affiliated ransomware actors.

In July, Treasury froze more than $131 million across four crypto wallets the agency linked to Iran’s central bank and armed forces, including the IRGC. In August, Treasury sanctioned two more crypto exchanges that it accused of laundering millions of dollars for the IRGC and other sanctioned Iranian entities.

The State Department is offering rewards of up to $10 million for information leading to the location of five defendants.

Federal law enforcement continues to assert long-arm reach against foreign cyber operatives, with U.S. Attorney Jamie McDonald for the Southern District of New York stating, “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button