DOJ expands Mabna hacking case to 17 defendants
The superseding indictment exposes an IRGC-linked intelligence pipeline that extracted 31.5 terabytes from U.S. universities and defense contractors, and it will almost certainly end in default judgments, not trials.
TL;DR
Federal prosecutors unsealed a superseding indictment Tuesday adding eight defendants to the 2018 Mabna Institute case, bringing the total to 17 Iranian nationals. The group allegedly stole at least 31.5 terabytes of research and intellectual property from 144 U.S. universities, 42 U.S. companies (including unnamed defense contractors) and at least five federal and state government agencies over roughly a decade. The expanded charges tie the operation directly to Iran's Islamic Revolutionary Guard Corps. The defendants remain in Iran; the State Department is offering up to $10 million for information on five of them.
The superseding indictment unsealed Tuesday doubles the defendant count in a case that has been building since 2018, when federal prosecutors first charged nine members of the Tehran-based Mabna Institute. The new charges add eight more and expose what prosecutors describe as a broader network conducting cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps, a detail that shifts the case from intellectual property theft into the national security register.
The scale is industrial. Between roughly 2013 and the present, Mabna operatives targeted 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, and five federal and state government agencies. They compromised approximately 8,000 professor accounts out of more than 100,000 targeted, using the stolen credentials to vacuum up journals, dissertations, e-books, and research data. The haul: at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or access the targeted materials.
The contractor dimension
Among the 42 U.S. companies and 11 foreign companies named as victims, prosecutors specifically flagged unnamed technology firms and defense contractors. That's the piece our readers need to track. The indictment doesn't detail what was taken from those contractors, but the targeting pattern suggests an intelligence collection operation dressed as academic piracy. The Mabna Institute's business model, hacking universities to steal research and then selling access through two storefront websites, also gave Iranian government clients a backdoor into research with dual-use applications across engineering, medicine, and the sciences.
Indictment as signal, not trial
None of the 17 defendants are in U.S. custody. The State Department is offering up to $10 million for information leading to the location of five of them, a reward structure that acknowledges the practical reality. These charges will almost certainly resolve in default judgments, not courtroom confrontations. That doesn't make them empty. Indictments name individuals, constrain travel, enable sanctions designations, and build the public record. But for the compliance director at a defense contractor reading this, the operational takeaway isn't about DOJ's case. It's about the targeting pattern: a Tehran-based firm with IRGC connections spent a decade systematically extracting U.S. research and contractor data, and the indictment is a lagging indicator of a threat that hasn't stopped.
The war context
The charges land during an active conflict. Since U.S. and Israeli strikes against Iran began in February, suspected Iran-aligned groups have been linked to a disruptive attack on medical device maker Stryker and the compromise of FBI Director Kash Patel's personal email. Attacks on industrial control systems across multiple U.S. sectors have also been attributed to Iran-linked actors. More than 30 Minnesota water systems were targeted in the last month alone. U.S. officials told NextGov they expect Iranian cyber operations to continue regardless of whether the kinetic conflict subsides. The Mabna indictment is a reminder that Iran's cyber infrastructure predates the current war and is built for the long game.
Published ·Updated ·Deep Fathom