U.S. Charges 17 Members of Iran-Backed Hacking Group in Massive Cyber Campaign
Justice Department indicts alleged Mabna Institute operatives for targeting universities and corporations worldwide, including HBO, while attempting to extract Bitcoin ransoms.
Mass Indictment of Iran-Based Cyber Operations
Federal prosecutors have brought charges against 17 individuals alleged to be part of the Mabna Institute, an Iran-based cybercriminal organization accused of conducting a prolonged hacking operation spanning multiple years. According to the Justice Department, the defendants operated on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC) and other entities within the Iranian government and academic institutions.
The indictment marks a significant enforcement action against a group that authorities say orchestrated intrusions into hundreds of targets across educational institutions, private companies, government agencies, and other organizations globally. Among the most notable incidents was a 2017 breach of media giant HBO, during which the attackers allegedly sought a $6 million Bitcoin payment in exchange for stolen proprietary data.
Scale of Data Theft and Targeted Attacks
The scope of the alleged cyber campaign is substantial. Prosecutors stated that the group pilfered at least 31.5 terabytes of sensitive information and intellectual property. The hackers directed their focus toward academic institutions particularly aggressively, targeting in excess of 100,000 professor email accounts. The group successfully compromised approximately 8,000 accounts distributed among 144 universities within the United States and 178 institutions internationally.
The attackers employed conventional techniques including spearphishing and the deployment of stolen login credentials to gain unauthorized access. Once inside systems, they extracted research materials, academic publications, dissertations, theses, digital books, and other valuable intellectual assets. Six of the charged defendants—including Behzad Mesri, Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—are specifically alleged to have participated in the HBO intrusion.
Crypto Connection and Recent Sanctions Activity
The charges arrive amid intensifying U.S. efforts to disrupt financial flows and cryptocurrency infrastructure that authorities contend Iran leverages to circumvent economic sanctions. This enforcement push has extended beyond criminal prosecutions to direct actions against financial platforms. In June, the Treasury Department sanctioned four Iranian cryptocurrency exchanges, with particular focus on Nobitex, which Treasury linked to conduct facilitating terrorist financing and sanctions violations. According to Treasury findings, Nobitex also maintained connections to ransomware actors affiliated with the IRGC.
The escalating crackdown continued into July, when Treasury immobilized over $131 million held across four cryptocurrency wallets that the agency traced to Iran’s central banking authority and military forces, notably including IRGC-controlled accounts.
Source: U.S. Justice Department, via Decrypt. Not financial advice.
Why it matters for crypto: The aggressive sanctions and enforcement against Iranian crypto infrastructure underscore how governments are weaponizing cryptocurrency surveillance and asset freezes—a regulatory precedent with implications for the broader digital asset ecosystem.