DOJ charges 17 Iranians in cybertheft campaign

Mojito_mak/Getty Images

Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.

Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.

The 14-count superseding indictment, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients.

The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.

The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.

Prosecutors said the university campaign targeted more than 100,000 professors’ accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.

All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.

Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors’ accounts to enter university library systems directly, according to the indictment.

Prosecutors said Mabna’s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.

The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.

The charges come amid concerns about Iran’s use of cyber operations during the ongoing war.

Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a disruptive attack against medical technology company Stryker, the compromise of FBI Director Kash Patel’s personal email and attacks against industrial-control systems across several U.S. sectors.

More than 30 Minnesota water systems and water infrastructure in several other states have been targeted in the last month in activity some officials suspect may be tied to Iran. U.S. officials previously told Nextgov/FCW that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.