# US Charges Iranian Hackers in $3.4B Intellectual Property Theft

> US charges 17 Iranian hackers from Mabna Institute for a state-sponsored campaign stealing 31.5 TB of academic and corporate intellectual property since 2013.

- Published: 2026-08-19T16:22:00.000Z
- Severity: high
- Category: Threat Intel
- Tags: Iran, Cyber Espionage, DOJ, Mabna Institute, Intellectual Property Theft
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-over-34-billion-intellectual-property-theft/
- Canonical: https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft

## Key points

- State-sponsored Iranian hackers stole 31.5 TB of IP from universities and companies.
- Over 178 universities (144 US) and 53 private firms (42 US) were targeted globally.
- Organizations must strengthen identity and access management, and conduct user awareness training.

The U.S. government has announced charges against 17 Iranian individuals, identified as members of the hacking-for-hire entity known as Mabna Institute, for their alleged involvement in a decade-long campaign of intellectual property theft. This extensive operation is accused of stealing over 31.5 terabytes of sensitive academic research, proprietary data, and emails from numerous organizations, with an estimated value of $3.4 billion, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-over-34-billion-intellectual-property-theft/).

## Campaign Details and Scope of Compromise

The U.S. Department of Justice (DoJ) states that the cyber operations, believed to have commenced around 2013, were conducted on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government entities, universities, and private paying clients. The campaign systematically targeted more than 100,000 professors globally, successfully compromising approximately 8,000 accounts. The stolen data encompassed journals, theses, dissertations, e-books, and various research materials across a multitude of disciplines.

The breadth of this compromise is significant, impacting 178 universities worldwide, with 144 located in the United States. Additionally, at least 53 private firms (42 U.S.-based), two non-governmental organizations (NGOs), and a minimum of 10 U.S. state agencies were affected. A notable victim mentioned in the DoJ announcement was HBO, which reportedly faced a $6 million Bitcoin extortion attempt. These charges build upon a previous March 2018 indictment against nine of the defendants, further revealing the expanded network behind this state-sponsored effort to acquire sensitive information. The DoJ and State Department are offering significant rewards for information leading to the apprehension of five of the newly charged individuals, underscoring the severity of these alleged cybercrimes. This continued pursuit demonstrates the US government's long-term commitment to addressing nation-state cyber threats, highlighting the ongoing challenge of **Iranian state-sponsored cyber espionage detection**.

### Targeting and Impact of Iranian Cyber Espionage

The modus operandi involved gaining unauthorized access to accounts, likely through [phishing](/glossary#phishing) or [credential stuffing](/glossary#credential-stuffing) techniques, to exfiltrate vast quantities of data. The focus on academic institutions and private companies suggests a clear intent to pilfer research and development, trade secrets, and other valuable intellectual property that could serve strategic national interests or be monetized by clients. The scale of the [data exfiltration](/glossary#data-exfiltration) – 31.5 terabytes – underscores a sophisticated and persistent effort to compromise target networks over an extended period. This long-term data acquisition strategy demonstrates how adversaries seek to gain competitive advantages and undermines the investment in research and innovation made by affected organizations.

## Attacker Modus Operandi

The Mabna Institute hackers focused on compromising credentials, allowing them to bypass initial perimeter defenses and access internal systems as legitimate users. This method highlights a common tactic where attackers prioritize obtaining valid credentials to maintain [persistence](/glossary#persistence) and facilitate data exfiltration. Once inside, they could leverage their access to navigate networks, identify valuable data stores, and systematically steal information over time. The use of a "hacking-for-hire" structure also indicates a plausible blending of state-directed objectives with financially motivated cybercrime, broadening the [threat landscape](/glossary#threat-landscape) for potential victims. Understanding these attack patterns is crucial for organizations looking to improve their defenses.

## Actionable Recommendations for Defenders

Organizations, particularly those in academia, research, and technology sectors, must prioritize enhancing their cybersecurity posture against sophisticated nation-state actors. Effective defense strategies should focus on identity and access management, continuous monitoring, and employee education.

### Mitigating Intellectual Property Theft

*   **Implement Multi-Factor Authentication ([MFA](/glossary#mfa)):** Enforce MFA for all user accounts, especially for access to sensitive systems, email, and intellectual property repositories. This significantly reduces the risk of successful account compromise, even if credentials are stolen.
*   **Strengthen Password Policies:** Mandate strong, unique passwords and regularly remind users about the dangers of credential reuse.
*   **Conduct Phishing Awareness Training:** Regularly train employees to recognize and report phishing attempts, which are a primary vector for [credential theft](/glossary#credential-theft). Emphasize the risks associated with suspicious emails and unverified links.
*   **Monitor for Anomalous Activity:** Implement advanced threat detection systems to identify unusual login patterns, large data transfers, or access to sensitive files by accounts at odd hours or from unusual locations. Tools capable of detecting **Mabna Institute intellectual property theft mitigation** attempts based on known TTPs are valuable.
*   **Segment Networks and Enforce [Least Privilege](/glossary#least-privilege):** Limit [lateral movement](/glossary#lateral-movement) for compromised accounts by segmenting networks and ensuring users and systems only have access to resources strictly necessary for their function.
*   **Audit Access Logs Regularly:** Periodically review logs for suspicious activities, unauthorized access attempts, and data exfiltration indicators.
*   **Secure Research Data:** Implement specific controls for datasets containing valuable academic research and proprietary information. This includes [encryption](/glossary#encryption) at rest and in transit, strict access controls, and [data loss prevention (DLP)](/glossary#data-loss-prevention-dlp) solutions. Proactive measures are essential for **protecting academic research from nation-state actors**.

By adopting these comprehensive measures, organizations can significantly bolster their defenses against persistent and well-resourced adversaries aiming to steal intellectual property.

**Related:** [Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities](/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities), [Iranian APT33 Targets Aviation with Updated MimicC2 and PowerLess](/blog/iranian-apt33-targets-aviation-with-updated-mimicc2-and-powerless)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft
