The U.S. Department of Justice has indicted 17 Iranian nationals for a years-long, state-sponsored cyber theft campaign that allegedly stole over 31 terabytes of academic data and intellectual property valued at $3.4 billion. The attacks, linked to Iran's Islamic Revolutionary Guard Corps (IRGC), targeted hundreds of universities, private firms, and government agencies across the U.S. and internationally, posing a significant threat to national security.

  • US DoJ charged 17 Iranians for a massive cyber theft campaign.
  • The campaign, linked to Iran's IRGC, stole over 31 terabytes of data worth $3.4 billion.
  • Targets included 144 US universities, 42 private firms, and government agencies globally.
  • A $10 million reward has been offered for information on five key alleged hackers.

The United States Department of Justice (DoJ) has announced charges against 17 Iranian nationals for their alleged involvement in a sophisticated, state-sponsored cyber theft campaign spanning several years. This extensive operation is accused of siphoning off more than 31 terabytes of valuable academic data and intellectual property, estimated to be worth approximately $3.4 billion. The DoJ asserts that these coordinated cyber attacks posed a grave threat to U.S. national security and economic interests.

According to the DoJ, members of the Iran-based Mabna Institute were behind the systematic targeting of computer systems belonging to 144 American universities and 42 private sector firms, with the campaign active from at least 2013 to December 2017. The group reportedly compromised 8,000 professor email accounts across 144 U.S.-based universities and an additional 178 academic institutions globally, targeting the accounts of 100,000 academics worldwide.

The indictment highlights that many of these illicit activities were conducted on behalf of Iran's powerful Islamic Revolutionary Guard Corps (IRGC), alongside other Iranian government and university clients. FBI Assistant Director in Charge James C Barnacle, Jr., underscored the seriousness of the threat, stating, "Backed by the IRGC, this operation reflects a broader, organized effort to target US institutions and global partners." This suggests a strategic, government-backed initiative rather than isolated criminal acts.

Beyond academic institutions, the Mabna Institute's reach extended to compromising employee email accounts from at least five U.S. federal and state government agencies. The campaign also targeted 11 foreign companies based in countries including Germany, Italy, Switzerland, Sweden, and the UK, indicating a broad international scope of operations aimed at acquiring sensitive information and intellectual property.

Why This Matters

BozokMedia analysis shows that this indictment underscores the escalating threat of state-sponsored cyber warfare, where digital intrusions are increasingly used as tools of national power. The sheer volume and value of stolen data, coupled with the targeting of critical infrastructure like academic research and government agencies, highlight the profound implications for intellectual property rights, national security, and international relations. Such campaigns can erode trust, compromise competitive advantages, and potentially fund further illicit activities, making robust cybersecurity defenses and international cooperation paramount.

US Attorney for the Southern District of New York, Jamie McDonald, emphasized that "cyber operations have become a central instrument of national power," underscoring the profound and dangerous impact these attacks have on both U.S. security and its economy.

Historical Background

The Mabna Institute, founded in 2013, was specifically established to assist Iranian academic organizations in "stealing access to non-Iranian scientific resources," according to the DoJ. This background reveals a clear, premeditated strategy by Iranian entities to bypass international sanctions and acquire valuable scientific and technological knowledge through illicit means. The ongoing nature of these cyber threats has been a persistent concern for U.S. intelligence agencies, with previous indictments, including nine of the current 17 individuals in March 2018, illustrating a continuous pattern of such state-sponsored activities.

Did You Know?: The 31 terabytes of stolen data from this single campaign is equivalent to over 15 million high-definition movies, showcasing the immense scale of information illicitly acquired.

Frequently Asked Questions

1. What is the significance of the Islamic Revolutionary Guard Corps (IRGC) involvement?
The IRGC's alleged backing elevates these cyber attacks from mere criminal activity to state-sponsored espionage, indicating a strategic effort by the Iranian government to acquire intellectual property and sensitive data for national interests, potentially for military or economic gain.

2. What measures is the U.S. taking to counter such cyber threats?
Beyond indictments and public warnings, the U.S. Department of Justice and intelligence agencies actively engage in tracking, prosecuting, and disrupting state-sponsored hacking groups, often imposing sanctions and offering rewards, such as the $10 million for information on the five alleged hackers in this case, to dismantle these networks.