Iran
Image: sina drakhshani / Unsplash

US charges Iranians for sprawling hacking campaign on government agencies, universities

The Justice Department accused hackers connected to Iran’s military of breaching employee email accounts connected to the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. 

The campaign, which started around 2013, also involved accounts connected to state government agencies in Hawaii and Indiana. 

The DOJ unsealed a 14-count indictment on Tuesday charging 17 people in relation to an expansive campaign prosecutors believe was run through an Iranian company known as the Mabna Institute on behalf of the Islamic Revolutionary Guard Corps (IRGC). 

Eight of the people charged were previously indicted in 2018 for their alleged roles in another hacking campaign. 

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” said Assistant Attorney General John Eisenberg. 

Prosecutors said the hackers targeted the U.N. Children’s Fund alongside five federal and state government agencies. The U.N. did not respond to requests for comment about the allegations.

Alongside the attacks on government institutions, the DOJ accused the group of breaching 144 U.S.-based universities and 42 U.S. companies, as well as 178 foreign universities and at least 11 foreign companies. 

The State Department also offered a reward of $10 million for information on Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh, who are accused of being employed, contracted or affiliated with the Mabna Institute to conduct “cyber intrusions to steal academic data, intellectual property, email inboxes, and other proprietary data.” 

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” said FBI Assistant Director Brett Leatherman. 

The university hacking campaign allegedly involved the successful targeting of about 8,000 email accounts belonging to professors between 2013 and 2013.They allegedly used stolen account credentials to breach the professor accounts. 

The hackers are accused of stealing academic journals, theses, dissertations, and electronic books, targeting data across dozens of fields.  

The documents were given to the government of Iran and were sold through two websites to universities in the country, the DOJ said. One website allowed customers in Iran to use stolen professor accounts to access the online library systems of multiple U.S. universities. 

Prosecutors said the universities spent about $20 million to investigate and remediate the breaches.

The indictment also noted that one of the hackers, Mesri, was previously indicted for an attack on the media company HBO — which he allegedly extorted for $6 million. 

Iranian actors have been accused of launching several hacking campaigns since the U.S. began conducting airstrikes against the country in February. 

Tehran was allegedly behind a recent campaign of attacks targeting water systems in at least 12 states and the government took credit for cyberattacks on a prominent medical device company and the personal email account of the FBI director

Last year, the State Department issued another $10 million reward for the Iranian hackers behind CyberAv3ngers — a group that gained prominence in 2023 and 2024 for a string of cyberattacks on U.S. and Israeli water utilities. 

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.