The United States Department of Justice on Tuesday, August 18, filed charges against 17 Iranians, accusing them of launching large-scale cyber attacks on behalf of the Islamic Revolutionary Guard Corps (IRGC), infiltrating hundreds of universities, businesses, and government institutions in the United States and abroad, stealing over 31TB of data and intellectual property.
The Department of Justice released a supplemental indictment on Tuesday containing 14 charges. The 17 defendants are all members of the Mabna Institute in Iran, with 9 of them previously indicted in 2018 and 8 new defendants added this time.
According to the Department of Justice, the institutions targeted include 144 U.S. universities, 178 foreign universities, at least 42 U.S. private companies, 11 foreign companies, at least 5 U.S. federal and state government agencies, and at least 2 non-governmental organizations.
The defendants are also accused of stealing email accounts of employees from businesses, government agencies, and NGOs.
Jamie McDonald, the federal prosecutor in the Southern District of New York, stated, “Today’s indictment adds 8 more defendants, exposing a larger network that allegedly, in a state-sponsored broad operation, stole research results and intellectual property from universities, businesses, and government agencies in the United States.”
He continued, “Cyber actions have become a core tool of state power, and attacks on U.S. and ally institutions directly threaten our security and economic strength.”
The Mabna Institute was established around 2013 to assist Iranian universities, scientific, and research institutions in gaining access to non-Iranian scientific resources. The organization was hired by the Iranian government and private entities to engage in hacking activities, including spearphishing attacks against universities, purportedly on behalf of the Islamic Revolutionary Guard Corps.
The Department of Justice stated that this operation targeted over 100,000 professors worldwide, successfully breaching around 8,000 professor email accounts. The attacks reportedly persisted from around 2013 to at least December 2017, involving the theft of academic journals, master’s and doctoral theses, e-books, as well as research data in the fields of science, engineering, social sciences, and medicine.
The defendants are alleged to have stolen approximately 31.5TB of academic data and intellectual property, transferring the data overseas to servers controlled by co-conspirators.
The Department of Justice mentioned that during this period, U.S. universities spent over $3.4 billion to purchase and access this information and intellectual property.
Furthermore, the Department of Justice also accused some of the stolen data of being sold through two websites, Megapaper.ir and Gigapaper.ir. The former sold stolen academic resources to customers within Iran, while the latter allowed paying customers to use compromised professor accounts to directly access the online library systems of specific U.S. and foreign universities.
Entities targeted also included the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and the United Nations Children’s Fund. Some defendants were further accused of involvement in infiltrating the U.S. media and entertainment company HBO, stealing proprietary information, and attempting to extort approximately $6 million worth of bitcoins.
Meanwhile, the U.S. State Department’s “Rewards for Justice” program announced a reward of up to $10 million, seeking information to locate the whereabouts of 5 of the defendants.
According to Reuters, the Iranian mission to the United Nations in New York did not immediately respond to requests for comment, and Reuters was also unable to immediately obtain contact information for the Mabna Institute.
It should be noted by the Department of Justice that the indictment only represents charges; all defendants are presumed innocent until proven guilty in a court of law.
