Iranian Hackers Tied to $6 Million Bitcoin Extortion Charged in Massive Cyber Campaign

Seventeen alleged members of Iran-based Mabna Institute were charged over hacks targeting hundreds of universities, companies, and government agencies.

By Jason Nelson

3 min read

U.S. prosecutors charged 17 alleged Iranian hackers involved in a years-long cyber campaign that included the 2017 HBO breach and an attempt to extort the company for roughly $6 million in Bitcoin.

On Tuesday, the Justice Department said the defendants were members of Iran-based Mabna Institute, which allegedly carried out hacks for Iran's Islamic Revolutionary Guard Corps and other Iranian government and university clients. The group targeted hundreds of universities, companies, government agencies, and other organizations worldwide, prosecutors said.

Myriad: Will the Clarity Act be signed into law in 2026? Click to make your prediction.

Behzad Mesri was previously charged with hacking entertainment giant HBO, stealing proprietary data. Prosecutors said five other defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—were directly involved in the hack.

“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” Assistant Attorney General for National Security John A. Eisenberg said in a statement.

According to the DOJ, the Mabna Institute also targeted more than 100,000 professor accounts worldwide and compromised roughly 8,000 accounts across 144 U.S. universities and 178 foreign universities, according to prosecutors. The hackers allegedly used spearphishing and stolen credentials to steal research, academic journals, theses, dissertations, ebooks, and other material.

“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” FBI Cyber Division Assistant Director Brett Leatherman said in a statement.

Tensions between Washington and Tehran have escalated amid the ongoing war, while the U.S. has stepped up efforts to disrupt crypto networks it says Iran and the IRGC use to move money and evade sanctions.

In June, the U.S. Treasury sanctioned four Iranian crypto exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion. Treasury also linked Nobitex to transactions involving IRGC-affiliated ransomware actors.

In July, Treasury froze more than $131 million across four crypto wallets the agency linked to Iran’s central bank and armed forces, including the IRGC. In August, Treasury sanctioned two more crypto exchanges that it accused of laundering millions of dollars for the IRGC and other sanctioned Iranian entities.

The State Department is offering rewards of up to $10 million for information leading to the location of five defendants.

“More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad,” U.S. Attorney Jamie McDonald for the Southern District of New York said in a statement.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News