Seventeen alleged members of an Iran-based hacking group face federal charges over a cyber campaign that included a roughly $6 million bitcoin extortion attempt against HBO. U.S. prosecutors unsealed the superseding indictment on Tuesday, escalating a years-long pursuit of state-linked actors.
The defendants operated through the Mabna Institute. They carried out intrusions at the behest of Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients, according to the Justice Department. The group targeted hundreds of universities, companies, and government agencies worldwide. Prosecutors say they compromised roughly 8,000 accounts across 144 U.S. universities and 178 foreign institutions, stealing at least 31 terabytes of academic data and intellectual property.
The campaign ran from 2013 through at least 2018, according to Bitcoin Magazine. One defendant, Behzad Mesri, was previously charged in 2018 over the 2017 HBO breach. Five others were named as directly involved in that hack: Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian. Proprietary data was stolen and a roughly $6 million bitcoin ransom demanded.
“The superseding indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” said John A. Eisenberg, Assistant Attorney General for National Security, in a statement.
The State Department is offering up to $10 million for information leading to the location of five of the defendants. A grand jury in the Southern District of New York returned the charges: conspiracy to commit computer intrusions, wire fraud, and extortion, along with money laundering and access device fraud. The original indictment was filed under seal on September 12, 2018.
“More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad,” said Jamie McDonald, U.S. Attorney for the Southern District of New York.
“These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government,” said Brett Leatherman, FBI Cyber Division Assistant Director.
Mabna Institute operatives used spearphishing and stolen credentials to harvest research, academic journals, theses, dissertations, and ebooks, prosecutors said. They targeted more than 100,000 professor accounts worldwide.
The case arrives amid a sustained U.S. enforcement push against Iranian crypto infrastructure. The Treasury sanctioned four Iranian crypto exchanges in June, including Nobitex, for facilitating terrorist financing and sanctions evasion. The following month, it froze more than $131 million across four wallets linked to Iran’s central bank and the IRGC. In August, two more exchanges were sanctioned for laundering funds for the IRGC.
Current whereabouts of the defendants were not stated. The specific criminal statutes referenced in the superseding indictment were not detailed by either outlet.


