Listen to this Post

A Cyber Espionage Case Refuses to Disappear
Eight years after U.S. prosecutors first exposed the alleged Mabna Institute hacking operation, the case has returned with a much larger cast of defendants and an even clearer picture of the campaign’s scale. What initially appeared to be a major academic hacking operation has evolved into a sprawling indictment alleging years of cyber espionage, credential theft, intellectual-property theft, password spraying, and financially motivated exploitation.
According to the U.S. Department of Justice, prosecutors have now charged 17 individuals allegedly connected to the Iran-based Mabna Institute, an operation accused of conducting hacking campaigns on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC), Iranian government organizations, and university clients.
The numbers are staggering.
Investigators say the operation targeted 144 U.S. universities, 178 universities overseas, at least 42 U.S. companies, 11 foreign companies, five government agencies, and two nongovernmental organizations.
More than 31 terabytes of academic information and intellectual property were allegedly stolen.
But the most important part of the story may not be the amount of data taken. It is the way the attackers allegedly turned compromised academic identities into a long-term intelligence and commercial ecosystem.
The Mabna Institute Allegations Go Back to 2013
A Campaign Built Over Years
According to the indictment described by the Justice Department, the Mabna Institute operation was active from at least 2013.
Rather than relying on a single spectacular attack, the alleged campaign appears to have operated through repeated credential theft and account compromise. Researchers, professors, universities, companies, and government organizations became targets because their accounts provided access to valuable information.
This is an important distinction.
Cyber espionage does not always require breaking through the most sophisticated technical defenses. Sometimes the easiest route into a highly protected institution is through a legitimate account belonging to someone who already has access.
17 Defendants Now Face Charges
Eight New Names Expand the Case
Nine of the 17 defendants had already been charged in a seven-count indictment announced in March 2018.
The superseding indictment adds eight additional defendants, significantly expanding the alleged network behind the operation.
The case has been assigned to U.S. District Judge Jesse M. Furman in the Southern District of New York.
The Justice Department says the defendants allegedly worked on intrusions serving different Iranian government and university interests, including intelligence-gathering activities associated with the IRGC.
As always with criminal indictments, these are allegations rather than convictions. Every defendant is legally presumed innocent unless proven guilty in court.
31 Terabytes of Academic Knowledge Allegedly Stolen
Universities Became Intelligence Targets
The sheer volume of stolen information is one of the most striking elements of the case.
U.S. prosecutors allege that Mabna-linked hackers extracted more than 31 terabytes of academic data and intellectual property from targeted universities.
That could include years of research, unpublished academic work, technical documentation, scientific studies, theses, dissertations, research papers, and other specialized material.
For a nation seeking technological or scientific advantages, university networks can represent an extraordinary intelligence resource.
More Than 100,000 Professor Accounts Targeted
The Attackers Cast a Wide Net
The operation allegedly targeted more than 100,000 professor accounts around the world.
Approximately 8,000 accounts were reportedly compromised, spanning roughly 24 countries.
That represents an enormous credential-harvesting campaign.
The attackers did not need to successfully compromise every professor. They needed only a fraction of those accounts to gain access to valuable research ecosystems.
This is one of the fundamental principles of large-scale credential attacks: maximize the number of targets, because even a relatively small success rate can produce an enormous amount of access.
Stolen Credentials Became the Gateway
Legitimate Accounts Were More Valuable Than Malware
Once credentials were obtained, the attackers could allegedly access university libraries and research systems while appearing to be legitimate users.
That makes these attacks particularly difficult to detect.
An administrator watching network traffic may immediately investigate an unknown executable or suspicious server connection. A professor logging into an academic database, however, can look completely normal.
The danger therefore lies in the difference between identity and behavior.
A stolen password can transform an attacker from an obvious outsider into a user who appears to belong inside the organization.
The Academic Underground Turned Stolen Access Into Money
Research Was Allegedly Resold Online
The Mabna operation allegedly went beyond intelligence collection.
According to prosecutors, stolen academic material was offered through websites including Megapaper.ir and Gigapaper.ir.
Customers could allegedly purchase academic resources or use compromised professor accounts to gain access to university libraries.
That creates a particularly troubling business model.
The same stolen credentials could potentially serve two purposes: intelligence collection for government-linked clients and commercial exploitation through the academic underground.
The Real Target Was More Than Data
Knowledge Can Be Strategic Infrastructure
Academic research is often treated as less sensitive than military information.
That assumption can be dangerously misleading.
Universities frequently conduct research involving artificial intelligence, engineering, medicine, aerospace, chemistry, materials science, energy, cybersecurity, telecommunications, and other strategically important fields.
A stolen research paper may not look valuable by itself.
But thousands of papers, laboratory documents, research databases, correspondence, and unpublished findings can collectively provide a detailed map of technological development.
The strategic value is therefore cumulative.
Behzad Mesri Connects the Case to the HBO Hack
A Familiar Name Appears Again
One of the most recognizable names in the expanded indictment is Behzad Mesri.
Mesri was previously charged in connection with the 2017 intrusion into HBO’s computer systems.
That case became famous after attackers allegedly stole proprietary HBO information and attempted to extort the entertainment company for approximately $6 million in Bitcoin.
The new indictment connects Mesri and four co-defendants to the HBO intrusion as part of the broader Mabna operation.
That connection gives the expanded case an unusual dimension.
What once appeared to be a high-profile entertainment-industry hacking incident is now being presented by prosecutors as part of a much larger cyber operation.
From Universities to Corporate Networks
Password Spraying Expanded the Attack Surface
The alleged campaign was not limited to academic institutions.
According to the indictment, other defendants conducted password-spraying attacks against private companies and at least two government organizations.
Password spraying differs from traditional brute-force attacks.
Instead of repeatedly trying many passwords against one account, attackers generally test a small number of commonly used or previously obtained passwords across many accounts.
That approach can reduce the likelihood of triggering account-lockout protections while still producing valuable compromises.
The Cleanup Bill Exceeded $20 Million
Cyberattacks Create Costs Long After the Intrusion
The financial consequences allegedly went far beyond the value of the stolen information.
Prosecutors say victims spent more than $20 million investigating and remediating intrusions associated with the campaign.
This illustrates a critical reality of cybercrime.
The cost of an intrusion is rarely limited to whatever information the attacker steals.
Organizations may have to investigate compromised accounts, rebuild systems, rotate credentials, examine historical logs, notify affected parties, strengthen defenses, hire external specialists, and monitor networks for months or years afterward.
The cleanup can become more expensive than the initial breach.
Eight Years Did Not Close the Case
Time Became Part of the Message
Perhaps the most politically significant aspect of the announcement is the timing.
The original indictment became public in 2018.
The new indictment arrives roughly eight years later.
For international cybercrime cases involving suspects who remain outside U.S. jurisdiction, investigators face enormous practical obstacles.
Evidence must be preserved.
Infrastructure must be attributed.
Identities must be established.
Victims must be interviewed.
International intelligence must be evaluated.
And prosecutors must build a case strong enough to withstand scrutiny.
The passage of time does not necessarily mean investigators stopped working.
In this case, prosecutors are sending the opposite message.
The United States Is Treating Cyber Operations as National Power
Hacking Has Become Part of Geopolitical Competition
The Justice
Cyberattacks are no longer treated merely as digital versions of burglary.
They can become instruments of intelligence gathering, economic competition, political pressure, military preparation, and technological development.
Research stolen from a university may ultimately have implications far beyond academia.
Corporate intellectual property can influence industrial competition.
Government credentials can provide access to sensitive information.
And compromised identities can become stepping stones into entire networks.
Millions in Rewards, But Few Immediate Arrests
The Defendants May Never See a U.S. Courtroom
Five newly charged defendants, including Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh, are associated with a combined reward offering through the State Department’s Rewards for Justice program.
The program offers up to $10 million for information leading to their location, according to the article.
That highlights one of the central problems in international cybercrime prosecution.
An indictment creates legal consequences, but it does not automatically create physical custody.
If suspects remain in a country that will not extradite them to the United States, American prosecutors have limited ability to bring them before a U.S. court.
The case can therefore remain active for years.
Deep Analysis: How a Campaign Like Mabna Exploits Trust
Identity Became the Attack Surface
The alleged operation demonstrates why cybersecurity has increasingly moved away from simply protecting machines.
Modern attackers want identities.
A username and password can provide more useful access than a sophisticated malware implant.
Attacker
|
v
Stolen Credentials
|
v
Legitimate Account
|
+-> Research Library | +-> Email | +-> Cloud Services | +-> Internal Systems
The key problem is that legitimate credentials can make malicious activity look legitimate.
Password Spraying in Practice
Organizations should monitor authentication patterns rather than simply failed login counts.
A simplified defensive investigation could begin with authentication logs:
grep -Ei "failed|invalid|authentication" /var/log/auth.log
Security teams can then look for repeated authentication attempts involving multiple accounts from the same source.
For centralized environments, administrators should correlate:
Source IP
Username
Timestamp
Geographic location
Device fingerprint
Authentication method
Failure count
Successful login
The objective is not merely to identify failed passwords.
It is to identify abnormal authentication behavior.
Detecting Impossible Travel
A compromised academic account may suddenly authenticate from two geographically distant locations.
A defensive query could conceptually look like:
same_user
+ successful_login
+ unusual_IP
+ impossible_time_gap
= investigate_account
An unusual login does not automatically mean compromise.
Researchers travel.
VPNs exist.
Cloud networks change.
But an unexpected login combined with unusual downloads, new forwarding rules, or unfamiliar devices becomes significantly more suspicious.
Email Is an Intelligence Gold Mine
If attackers compromise a
They can potentially discover:
Research collaborators
Grant proposals
Unpublished research
Passwords
Cloud links
Conference invitations
Laboratory information
Internal documents
Contact lists
This is why email compromise can become an intelligence multiplier.
One mailbox may contain references to dozens of systems and hundreds of people.
Academic Environments Require Specialized Security
Universities face a difficult cybersecurity problem.
Their mission encourages openness.
Researchers need collaboration.
Students need access.
External partners need connectivity.
International cooperation is fundamental to science.
A security architecture designed like a closed corporate network can therefore conflict with the academic mission.
The answer cannot simply be “lock everything down.”
Universities need intelligent segmentation, strong identity controls, phishing-resistant authentication, behavioral monitoring, and carefully controlled research environments.
MFA Is Important, But Not Every MFA Method Is Equal
Multi-factor authentication significantly raises the difficulty of credential attacks.
However, security teams should distinguish between basic MFA and phishing-resistant authentication.
Where possible, organizations should move toward modern authentication mechanisms such as hardware-backed credentials and passkeys.
The goal is to make stolen passwords insufficient by themselves.
Research Data Needs Classification
Not every academic file deserves identical security controls.
A university could classify information into categories such as:
Public
Internal
Sensitive Research
Restricted Research
Export-Controlled
Highly Confidential
Higher-risk information can then receive stronger controls.
This approach is more practical than attempting to apply maximum restrictions to every document.
Monitoring Large Data Transfers
The alleged theft of 31 terabytes demonstrates why data-volume monitoring matters.
A professor account downloading a few research papers is normal.
A single account suddenly transferring hundreds of gigabytes is not automatically malicious, but it deserves investigation.
Security teams can establish behavioral baselines:
Normal:
10-100 MB/day
Unusual:
5-20 GB/day
Critical anomaly:
100+ GB/day
These values are only examples.
Every institution needs its own baseline.
Cloud Services Change the Equation
Modern universities increasingly rely on cloud storage, collaboration platforms, research repositories, and SaaS applications.
That creates additional identity boundaries.
A compromised password can potentially provide access to multiple services if single sign-on is involved.
This makes centralized identity protection one of the most important defensive investments.
Protecting Against Credential Reuse
Users should never reuse passwords across university and personal accounts.
Security teams can reduce risk through:
Password managers
+
Phishing-resistant MFA
+
Credential monitoring
+
Conditional access
+
Device verification
+
Session monitoring
Together, these controls create multiple barriers.
Detection Should Focus on Behavior
Traditional antivirus detection would be of limited value against an attacker using legitimate credentials.
Behavioral detection is more important.
Security teams should ask:
Is this user behaving differently from their normal pattern?
That question can expose compromise even when no malware is present.
Universities Should Assume Long-Term Persistence
A sophisticated espionage campaign may not immediately reveal itself.
Attackers may steal credentials, collect information slowly, and avoid obvious behavior.
Organizations therefore need historical logging.
Keeping logs for only a short period can make retrospective investigations extremely difficult.
Logs Are Evidence
Useful telemetry includes:
Identity provider logs
VPN logs
Email authentication
Cloud access logs
Endpoint telemetry
DNS records
Proxy logs
Firewall logs
Database activity
File-access records
The more independent sources investigators can correlate, the easier it becomes to reconstruct an attack.
Defenders Should Watch for Account Takeover Signals
Potential warning signs include:
New country login
New device
Unexpected MFA enrollment
Password reset
Suspicious forwarding rule
Mass email access
Large file downloads
New OAuth application
Unusual API activity
None of these indicators alone proves compromise.
Together, however, they can form a strong detection signal.
The Academic Underground Changes the Motivation
If stolen credentials can be monetized, attackers do not necessarily need a government intelligence requirement to justify targeting universities.
The same credential can have multiple forms of value.
It can provide:
Research access.
Library access.
Email access.
Commercial resale value.
Intelligence value.
This makes academic identities attractive targets for both cybercriminals and state-linked operators.
The HBO Connection Is Strategically Important
Mesri’s alleged involvement demonstrates how different motivations can overlap.
A single actor may participate in activities involving espionage, theft, extortion, or financially motivated cybercrime.
Cyber operations do not always fit neatly into one category.
That makes attribution and risk assessment increasingly complicated.
International Attribution Takes Time
Attribution is one of the hardest problems in cybersecurity.
Investigators must connect:
Infrastructure
+
Malware
+
Accounts
+
Payments
+
Victimology
+
Human identities
+
Communications
A suspicious IP address alone proves almost nothing.
A compelling attribution comes from multiple independent pieces of evidence.
The Eight-Year Timeline Matters
The expanded indictment demonstrates something important for attackers.
A cyber operation can be technically successful while remaining legally unresolved.
But unresolved does not necessarily mean forgotten.
Investigators can preserve evidence, connect new intelligence to old incidents, and eventually identify additional participants.
The Threat Has Evolved Since 2013
The Mabna allegations began in an era when cloud security was less mature, MFA adoption was lower, and universities relied heavily on traditional identity systems.
Today’s environment is even more interconnected.
Researchers use cloud platforms.
AI systems process sensitive datasets.
Laboratories share digital infrastructure.
Universities collaborate globally.
This increases both productivity and attack surface.
AI Will Increase the Value of Research Data
The strategic value of academic information may become even greater as AI development accelerates.
Large datasets, specialized scientific knowledge, technical papers, experimental results, and proprietary research can potentially improve AI systems and accelerate technological development.
That means academic cybersecurity should increasingly be treated as part of national technological security.
Why the Case Matters Beyond Iran
The broader lesson is not limited to one country or one hacking group.
State-linked cyber operations are becoming increasingly persistent.
Attackers can remain active for years.
They can reuse credentials.
They can exploit legitimate services.
They can operate across jurisdictions.
And they can target institutions that historically were not treated as high-value intelligence targets.
What Undercode Say:
The Real Weapon Was Access
The most revealing aspect of this case is not the malware.
It is identity.
The attackers allegedly built access by compromising people rather than simply machines.
That strategy remains highly relevant today.
Universities Are Soft Targets With Hard Data
Universities often possess extraordinarily valuable information while maintaining relatively open environments.
That combination makes them attractive.
A laboratory may have millions of dollars of intellectual property but still need to support hundreds of external collaborators.
31 Terabytes Is a Strategic Number
Thirty-one terabytes is not simply a large collection of files.
It represents years of human knowledge.
The value of that information depends on what was stolen.
Some research may have little practical value.
Other material could potentially provide significant technological advantages.
Credentials Were the Multiplier
Compromising one professor can unlock far more than one mailbox.
The account may provide access to research systems, cloud applications, databases, collaboration platforms, and institutional relationships.
The Attack Was Scalable
Targeting more than 100,000 professor accounts shows the advantage of automation.
Attackers do not need to manually research every victim.
They can cast a huge net and focus attention on successful compromises.
The Business Model Is Especially Dangerous
Selling academic access changes the economics of cyber espionage.
A stolen account can potentially generate revenue while also providing intelligence.
That creates multiple incentives for attackers.
Password Spraying Remains Relevant
The technique described in the indictment is old, but it remains effective when organizations fail to enforce strong authentication.
Cybersecurity defenses may become technologically advanced while basic identity weaknesses remain.
MFA Is No Longer Optional
Organizations holding valuable research should consider strong MFA a baseline requirement.
More importantly, phishing-resistant authentication should increasingly become the target.
Email Security Matters
A compromised mailbox can reveal an
Attackers can learn who works with whom, which projects exist, and where sensitive information is stored.
Data Loss Prevention Has a Role
Organizations should know which users are accessing large amounts of sensitive information.
Behavioral baselines can help distinguish ordinary academic work from suspicious mass collection.
Segmentation Can Limit Damage
Even if one professor account is compromised, it should not automatically provide unrestricted access to every research environment.
Segmentation reduces the blast radius.
Long-Term Logging Is Essential
Eight years is an extreme timeline, but the lesson applies to ordinary incidents too.
Without historical evidence, investigators may never understand how an attacker entered an environment.
Cybersecurity Is Becoming National Security
The case illustrates how academic research, corporate intellectual property, and government information can become interconnected strategic assets.
Cybersecurity therefore cannot be treated solely as an IT department problem.
Attribution Requires Patience
Investigators need time to connect infrastructure, accounts, financial activity, and human identities.
The expanded indictment suggests that prosecutors believe additional evidence has allowed them to broaden the case.
The HBO Connection Changes the Narrative
Mesri’s alleged involvement demonstrates how an individual intrusion can potentially sit inside a much larger operational ecosystem.
That is why incident response should examine context, not only immediate damage.
Attackers Do Not Need to Destroy Anything
Cyber espionage can be remarkably quiet.
An attacker may steal information without disrupting operations.
From the
Theft Can Be More Valuable Than Sabotage
Destroying a research database creates immediate alarms.
Quietly copying it may remain invisible.
For intelligence operations, the second outcome can be far more useful.
Research Theft Has Compounding Effects
A stolen discovery can help another organization avoid years of research.
The economic damage is therefore difficult to calculate.
Intellectual Property Is an Invisible Asset
A company can insure hardware.
It is much harder to calculate the value of an unpublished invention, research breakthrough, or engineering design.
Government Agencies Are Not Isolated
The alleged password-spraying activity against government entities demonstrates how attackers can move between sectors.
A campaign can simultaneously target academia, business, and government.
Attackers Follow Opportunity
They do not necessarily care whether a victim is a university or company.
They care about what the identity can unlock.
The Cloud Makes Identity More Important
As organizations migrate systems into cloud environments, identity becomes the primary security perimeter.
That makes account protection increasingly critical.
Modern Defenses Need Context
Blocking malware is not enough.
Security teams need to understand user behavior, data movement, authentication patterns, and access relationships.
Zero Trust Is Particularly Relevant
Every authentication request should be evaluated rather than automatically trusted because it comes from an apparently legitimate user.
Universities Need Security Without Destroying Openness
Academic institutions cannot operate like military installations.
Their security architecture must support collaboration while protecting high-value research.
Research Data Should Be Prioritized
Not every file requires the same controls.
Sensitive research should receive stronger protections than publicly available academic material.
Incident Response Should Assume Credentials Are Compromised
After a major intrusion, changing one password is rarely enough.
Organizations need to examine sessions, tokens, applications, MFA settings, forwarding rules, and connected services.
Attackers Can Return
If an attacker has learned an
Defenders must verify that persistence has been eliminated.
The Case Sends a Deterrence Message
The United States is signaling that international cyber operations can remain prosecutable long after the initial intrusion.
That may influence future attackers calculating the risks of state-sponsored hacking.
Jurisdiction Remains the Biggest Problem
An indictment does not guarantee an arrest.
If suspects remain beyond practical extradition reach, prosecution becomes dependent on future opportunities.
Rewards Become a Tool of Cyber Diplomacy
Financial rewards cannot replace arrests, but they create incentives for information from people who may know where suspects are located.
Cybercrime Cases Can Outlive Technology
Servers disappear.
Domains expire.
Malware changes.
But evidence and intelligence can survive.
Old Attacks Still Matter
Organizations should not assume historical incidents are irrelevant.
Old credentials, infrastructure, and compromise patterns can provide clues to current threats.
The Threat Is Larger Than One Organization
The Mabna case demonstrates how attackers can operate across entire sectors.
Security must therefore extend beyond individual companies.
The Most Dangerous Compromise May Look Normal
A legitimate user downloading legitimate information can be almost invisible.
That is why behavioral security is increasingly important.
The Future Will Be More Identity-Centric
As passwordless authentication expands, attackers will increasingly target sessions, tokens, devices, recovery mechanisms, and identity infrastructure.
The Core Lesson Is Simple
Trust must be earned continuously, not granted permanently.
That is perhaps the most important cybersecurity lesson hidden inside this eight-year-old case.
✅ The indictment expanded to 17 defendants
The article accurately describes a superseding indictment involving 17 alleged Mabna Institute members, with nine having previously been charged in 2018. An indictment represents allegations, not a criminal conviction.
✅ The campaign allegedly targeted universities, companies, government agencies, and NGOs
The reported figures include 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, 11 foreign companies, five government agencies, and two NGOs. These figures are attributed to the Justice Department’s allegations.
✅ More than 31 terabytes of data were allegedly stolen
The Justice
⚠️ The
The allegations should not be presented as proven criminal conduct. The defendants remain legally presumed innocent unless convicted in court.
Prediction
(+1) The Case Will Remain Relevant for Years
The expanded indictment suggests that U.S. investigators intend to keep pursuing individuals associated with the alleged operation even when suspects remain outside American jurisdiction.
(+1) Universities Will Face Greater Pressure to Harden Identity Security
Academic institutions are likely to place greater emphasis on phishing-resistant MFA, identity monitoring, conditional access, and protection of high-value research.
(+1) Historical Cyber Cases Will Continue Reappearing
As investigators connect new intelligence with older incidents, additional defendants and relationships may emerge years after the original attack.
(+1) Academic Research Will Become a Higher-Priority Cybersecurity Asset
As AI, biotechnology, advanced computing, engineering, and semiconductor research become increasingly strategic, universities will increasingly be treated as critical targets rather than peripheral cybersecurity environments.
(-1) International Arrests May Remain Difficult
If many defendants remain outside U.S. jurisdiction, indictments and rewards may produce accountability without necessarily resulting in immediate arrests or courtroom proceedings.
(-1) Credential-Based Espionage Will Not Disappear
Even as security technology improves, stolen identities will remain attractive because legitimate accounts can bypass many traditional security assumptions.
The Bigger Picture
The Mabna Institute case is ultimately about more than an Iranian hacking organization, more than universities, and more than an indictment filed eight years after the original charges.
It is about the changing value of information.
A professor’s account can become an intelligence asset. A research paper can become intellectual property. An email inbox can become a map of an institution. A stolen password can become the first step into a much larger network.
And perhaps the most uncomfortable lesson is that none of this requires an attacker to destroy anything.
Sometimes the most damaging cyberattack is the one that quietly copies everything worth knowing and leaves the victim wondering how long it was happening.
Eight years after the original indictment, U.S. prosecutors are making one point unmistakably clear: cyber investigations do not necessarily expire simply because the attackers remain beyond the reach of the courtroom.
▶️ Related Video (72% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




