DOJ expands Mabna Institute cybertheft charges to 17
The superseding indictment adds defendants and detail but doesn't solve the problem that sank the 2018 charges: Iran doesn't extradite, and the defendants aren't leaving Tehran.
TL;DR
The Justice Department unsealed a superseding indictment Tuesday against 17 Iranian nationals affiliated with the Tehran-based Mabna Institute, expanding the 2018 case that charged nine. The indictment alleges a state-directed campaign that compromised more than 100,000 professor email accounts across 144 U.S. universities and 178 institutions abroad, exfiltrating 31.5 terabytes of academic research and intellectual property. U.S. universities spent approximately $3.4 billion to procure the type of data targeted. The State Department's Rewards for Justice program offers up to $10 million for information on four defendants. None of the 17 are in U.S. custody, and Iran doesn't extradite, the practical effect is unchanged from 2018.
The superseding indictment, unsealed in the Southern District of New York, adds eight defendants to the nine originally charged in March 2018. Gholamreza Rafatnejad and Ehsan Mohammadi allegedly founded Mabna Institute around 2013 as a vehicle for Iranian universities and research organizations to systematically steal foreign scientific work, employing the other defendants as hackers-for-hire. The operation targeted professor credentials: hackers compromised more than 100,000 email accounts globally, then used those credentials to access academic journals, dissertations, e-books, and unpublished research across 144 U.S. universities and 178 institutions abroad, accumulating 31.5 terabytes of stolen data.
The scope extended beyond academia. The indictment also names 42 U.S. companies and five federal and state agencies as victims, plus 11 foreign firms including HBO. The institute sometimes resold the stolen data. DOJ pegged U.S. university spending on the type of research data targeted at approximately $3.4 billion. That figure describes the procurement cost of the research ecosystem rather than direct losses from the theft, but it signals the value of what was taken.
The timing is impossible to ignore. The expanded charges land as the U.S. is engaged in active military operations against Iran and a 60-day negotiation deadline on Iran's nuclear program passed without progress. U.S. Attorney Jamie McDonald framed the charges in those terms, calling cyber operations "a central instrument of national power." The State Department's Rewards for Justice program separately offered up to $10 million for information leading to the location of four of the defendants.
The 14 counts carry potential sentences of two to 20 years. But the operational reality hasn't shifted since 2018. None of the defendants are in U.S. custody. Iran doesn't extradite its nationals, and the Mabna Institute continues to operate in Tehran. The expanded indictment is a more detailed attribution, not a more actionable one.
For practitioners at U.S. research universities, the reminder is familiar: the same credential-harvesting playbook that worked against professors in 2013 works now. Multi-factor authentication, phishing-resistant credentials, and segmentation of research networks remain the controls that matter. An indictment naming 17 people instead of nine doesn't change the defensive posture.
Published ·Updated ·Deep Fathom