Charges Unsealed
The U.S. Department of Justice unsealed new and updated charges on Tuesday against 17 individuals allegedly working with an Iranian company, the Mabna Institute, in a hacking and data theft campaign. The charges, reported by BBC and Al-Monitor, allege that the Tehran-based firm conducted extensive cyber intrusions against U.S. universities, companies, and government agencies on behalf of Iran's Islamic Revolutionary Guard Corps and other Iranian government and university clients.
According to the DOJ statement, as cited by Al-Monitor, the campaigns targeted hundreds of U.S. and international universities, dozens of U.S. companies, and at least five U.S. state and federal government agencies. The BBC reported that the DOJ said members of the Mabna Institute had targeted the computer systems of 144 American universities and 42 private sector firms since at least 2013.
The Campaign's Scope
Both BBC and Al-Monitor reported that the alleged campaign spanned from at least 2013 through 2017. The DOJ statement, covered by both outlets, said the group targeted more than 100,000 professor accounts worldwide and successfully compromised roughly 8,000 professor email accounts across 144 U.S.-based universities and 178 international institutions.
The BBC additionally reported that the stolen data was valued at approximately $3.4 billion, with the group allegedly stealing over 31 terabytes of academic data and intellectual property. The DOJ described the campaign as "massive," according to the BBC.
Governance Response and Official Comment
U.S. Attorney for the Southern District of New York Jamie McDonald was quoted in both the BBC and Al-Monitor reports, saying the charges reveal "the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." The BBC also reported McDonald's warning that cyber operations have "become a central instrument of national power."
FBI Assistant Director in Charge James C. Barnacle Jr., in a statement reported by the BBC, described the coordinated cyber attacks as "a serious threat to our national security" and said the operation reflects "a broader, organised effort to target US institutions and global partners."
Links to Previous Charges and Treasury Sanctions
Both BBC and Monitor noted that a previous indictment in March 2018 had already charged nine of the 17 individuals (BBC said nine, Al Monitor said nine of the 17, in a seven-count indictment) with a hacking campaign targeting the U.S. Labor Department, the United Nations, and computer networks in Hawaii and Indiana. The BBC said the nine members charged on Tuesday were previously charged in that indictment.
Meanwhile, the U.S. Treasury Department sanctioned five Iranian citizens on Monday over alleged cyberattacks and theft aimed at U.S. critical infrastructure, government offices, and digital assets, as reported by Defense One. The Treasury accused four of the five — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, and Mojtaba Ghal'eh-Kuhi — of being part of a hacking operation directed by Iran's Ministry of Intelligence and Security. Defense One reported that the three of the four, Blagh, Balujeh, and Kadkhoda'i, allegedly carried out most of the group's intrusions, breaching and stealing data from U.S. energy companies, defense contractors, health care institutions, technology firms, and financial institutions since late 2023. The three are also believed to have compromised local, state, and federal government offices during summer 2024.
According to Defense One, Treasury officials said Ghal'eh-Kuhi and Behzad Mesri, previously sanctioned in 2018, have led the group since at least 2023, and they regularly conducted operations for the intelligence ministry, though personal profit also played a role. The department separately sanctioned Arman Kahzadian, another alleged member focusing on digital asset theft, after he allegedly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023. Defense One also reported that Ghal'eh-Kuhi and Balujeh allegedly stole data from an Iranian telecom company in 2025, which Treasury said reflected willingness to put their own financial interests ahead of work benefiting Tehran.
Defense One noted that four of the five sanctioned Monday were also charged last week in the Justice Department's expanded case against the 17 Iranian cyber actors affiliated with the Mabna Institute. The Treasury's cyber sanctions were part of a broader package targeting nearly 60 people, companies, and vessels tied to Iran's nuclear and missile programs, oil trade, and hacking operations, according to Defense One. Treasury Secretary Scott Bessent called the package an "economic D-Day" aimed at isolating Iran and cutting off revenue during the ongoing war, Defense One reported. The sanctions block assets under U.S. control and generally prohibit Americans from doing business with the designated, and Treasury also expanded sanctions to cover digital assets, technology, gold, aviation, and shipping sectors.
Reward and Iranian Response
The State Department's Rewards for Justice program announced a $10 million reward for information leading to the location of several individuals included in Tuesday's charges, as reported by both BBC and Al-Monitor.
Iranian government representatives at the United Nations in New York did not immediately respond to requests for comment, according to Al-Monitor, and contact information for the Mabna Institute was not immediately available.
Conclusion: Multiple U.S. Actions Overlap
The DOJ and Treasury actions, seemingly coordinated or at least sequential, underscore the U.S. government's intensified legal and financial measures against alleged Iran-linked hacking. Investigating officials attributed these issues to a broader network operating on behalf of Iran's intelligence services and the IRGC, indicating a persistent state-sponsored cyber threat.