
THE United States Department of Justice has unsealed an indictment charging seventeen Iranian nationals with carrying out a cyber theft campaign on behalf of the Islamic Revolutionary Guard Corps. The indictment alleges that the group, operating as the Mabna Institute, infiltrated the networks of 144 American universities, 178 foreign higher education institutions and 42 US‑based private companies, as well as additional government agencies and non‑governmental organisations. The case was first reported by Databreaches (Databreaches.net) and follows the official DOJ announcement (Department of Justice).
Although no specific CVE identifiers are attached to the operation, court documents describe a sustained credential‑harvesting effort that relied on spear‑phishing emails mimicking legitimate university login pages. Victims were lured into divulging usernames and passwords, which the actors then used to access internal research repositories and exfiltrate datasets. The scheme is said to have compromised roughly eight thousand professor accounts and removed about thirty‑one terabytes of proprietary scientific material, ranging from engineering papers to pharmaceutical research, over several years of activity.
The Mabna Institute, founded in 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, is accused of maintaining the intrusion since its inception and targeting more than one hundred thousand accounts in total. Stolen data appears to have been resold through Iranian websites, depriving US institutions of an estimated 3.4 billion dollars in research value and imposing roughly twenty million dollars in remediation expenses on affected private firms and government bodies. These figures were highlighted in coverage by SecurityOnline (SecurityOnline.info).
No arrests have been made in connection with the indictment, although the US State Department has announced rewards for information leading to the capture of the accused individuals. The indictment does not name any specific malware family or exploit kit, instead attributing the activity to a broader IRGC‑directed espionage apparatus that seeks to accelerate Iran’s scientific and technological development through the illicit acquisition of foreign research.
Defenders should prioritize the enforcement of multi‑factor authentication on all remote access points, especially those used by faculty and researchers, and monitor authentication logs for logins originating from atypical locations or at unusual hours. Password reuse between personal and institutional accounts must be prohibited, and security teams should conduct regular reviews of privileged account activity to detect any unauthorized data retrieval attempts.
Network segmentation is advisable, ensuring that research servers housing sensitive data are isolated from public‑facing web portals and email gateways. Applying the principle of least privilege limits what any single account can access, while sharing observed indicators of compromise with trusted information sharing and analysis centres improves collective awareness. Finally, ongoing awareness programmes that teach staff to recognise spear‑phishing attempts that copy legitimate university login screens can reduce the likelihood of successful credential theft.