Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > US Offers $10M Reward for Iranian Hackers Linked to 31.5TB Data Theft

US Offers $10M Reward for Iranian Hackers Linked to 31.5TB Data Theft

By: Jordan Vector Cybersecurity Expert

Last updated: August 19, 2026

Human Written
US Offers $10M Reward for Iranian Hackers Linked to 31.5TB Data Theft
  • US authorities have charged 17 Iranians involved in a cyber theft operation that stole a massive 31.5 terabytes of data.

  • The Mabna Institute, the group behind the operation, targeted over 100,000 accounts belonging to professors and succeeded in accessing around 8,000.

  • There’s a $10 million bounty for anyone who can provide information that’ll help track down five of the defendants.

Seventeen Iranian nationals are facing charges for running a cyber theft operation with ties to Iran’s Islamic Revolutionary Guard Corps (IRGC).

According to the U.S. Department of Justice, the alleged offenders were operating from the Mabna Institute based in Iran. They were allegedly targeting universities, corporations, governmental institutions, and other types of institutions in the U.S. and around the world during their campaign.

On August 18, the Justice Department released a new indictment that charged a total of 14 defendants, including nine persons who were charged in 2018.

The scheme lasted from roughly 2013 till at least December 2017. During that time, according to the indictment, hackers stole 31.5 terabytes worth of academic materials and intellectual property. This case is an example of how a scheme initiated over a decade ago can result in new charges.

The Scheme Compromised Thousands of Professor Accounts 

The Mabna Institute allegedly built its campaign around university professors. Prosecutors said the group went after more than 100,000 email accounts of professors around the world. It successfully compromised about 8,000 of those accounts belonging to professors at 144 US universities and 178 foreign universities.

State-backed phishing campaigns have also targeted U.S. government officials, diplomatic personnel, and journalists. The U.S. identified UNC5792 and UNC4221, Russian-linked groups that targeted Signal and WhatsApp accounts, and offered a $10 million reward for information on the groups’ members, infrastructure, and financial networks.

The targets were schools in the United Kingdom, Australia, Japan, Germany, Canada, Italy, South Korea, Israel, Switzerland, etc.

The stolen information covered many fields. It included science, technology, engineering, medicine, social sciences, and other areas. Hackers also took academic journals, books, theses, dissertations, and other research material.

The Justice Department says U.S. universities spent more than $3.4 billion to obtain and access the data that the group targeted.

Stolen Research Was Also Sold

The alleged operation was not limited to government-directed intelligence gathering. Prosecutors say the hackers also turned stolen research and account access into a business.

The Mabna Institute allegedly sold stolen academic material through websites called Megapaper and Gigapaper. Megapaper sold stolen research resources to customers in Iran. Its customers included Iranian public universities and other institutions.

Gigapaper offered another service. Customers could use stolen professor accounts to access online library systems at universities in the U.S. and other countries. That created a second source of value from the stolen accounts. The hackers could use them for Iranian government interests while also selling access.

The U.S. Treasury had already described Mabna in 2018 as an Iranian company that helped research organizations obtain access to foreign scientific resources.

Companies and Government Agencies Also Took a Hit

Universities were not the only targets. The indictment says the group also compromised employee email accounts at at least 42 U.S. companies and 11 foreign companies. The foreign victims include organizations in Germany, Switzerland, Italy, Sweden, and the UK.

The operation targeted the Federal Energy Regulatory Commission and U.S. Department of Labor. It also targeted state governments in Hawaii and Indiana. The United Nations and UNICEF were also among the targets.

Prosecutors say some of the attacks used password spraying. This method involves trying common passwords against many accounts rather than focusing on one person.

The alleged attackers also created phishing messages and targeting lists. They tracked stolen credentials and studied networks before attempting further access. The Justice Department says the attacks on private companies and government bodies caused more than $20 million in investigation and recovery costs.

HBO Attack Adds Another Chapter

The expanded indictment also links a lot of defendants to the 2017 HBO hack. Behzad Mesri was already under charges regarding the attack. He was charged with theft of corporate information and extortion of $6 million from HBO using Bitcoin.

The new indictment says five other defendants had direct involvement in the HBO operation. That case became widely known after cybercriminals stole HBO material and unaired television content from the company.

Most Defendants Remain Out of Reach

The charges don’t automatically mean these people are guilty. The Justice Department says everyone is innocent until the court proves otherwise.

However, the indictment comes with serious implications. Some of these charges could land a suspect in prison for five or even twenty years. Plus, aggravated identity theft comes with a guaranteed two-year sentence.

Currently, it looks like the U.S. government hasn’t actually arrested the defendants. The State Department’s Rewards for Justice program is offering up to $10 million for information that helps locate five of them: Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.

Such a reward reflects the practical problem the U.S. prosecutors face. The hackers are allegedly based in Iran, and hence arresting and extraditing them is a daunting task.

However, U.S. authorities argue that the case will not be closed. FBI noted that the new charges reflect the ability of investigators to pursue suspected cyber criminals many years after the incident.

For the Justice Department, the case is also about more than old university breaches. It shows that stolen research, corporate data, and account access can serve the interests of the state and profit-making.

The indictment in question, therefore, shows an old case in a much broader scope: the scope of Iran-backed cyber espionage. The victims span multiple universities, government agencies, and businesses all over the world.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.