US Charges 17 Iranians in Billion-Dollar Cyber Theft Campaign Backed by IRGC

The US Department of Justice unsealed new and updated charges on August 18, 2026 against 17 Iranians for allegedly running a years-long cyber theft campaign targeting US organizations, according to Reuters. The DoJ's official press release describes the group as having attacked systems belonging to hundreds of universities, companies, and other victims to steal research and academic material on behalf of Iran's Islamic Revolutionary Guard Corps, or IRGC (DoJ). The IRGC is a powerful branch of Iran's military that also oversees significant economic and political operations.
Nine of the 17 individuals charged were previously indicted in March 2018 by the US Attorney's Office for the Southern District of New York for conducting a massive cyber theft campaign on behalf of the IRGC (DoJ SDNY).
The campaign centers on the Mabna Institute, founded in 2013 to help Iranian academic organizations steal access to non-Iranian scientific resources, according to the DoJ. Members of the Iran-based organization targeted the computer systems of 144 US universities and 42 private sector firms from at least 2013 through December 2017. The group allegedly stole more than 31 terabytes of academic data and intellectual property worth approximately $3.4 billion over the course of the campaign (BBC News). To put that in perspective, 31 terabytes is roughly the equivalent of 15 million books.
The scale of targeting extends well beyond US universities. The DoJ said Mabna targeted the accounts of 100,000 academics worldwide and successfully compromised 8,000 professor email accounts at 144 US-based universities and an additional 178 academic institutions internationally. The group also allegedly compromised employee email accounts from at least five US federal and state government agencies. At least 42 US-based private companies and 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the UK were also targeted. Many of the attacks were conducted on behalf of the IRGC, as well as for other Iranian government and university clients, the DoJ said.
The DoJ has announced a $10 million reward for information leading to the location of five of the alleged hackers-for-hire who were charged. FBI Assistant Director in Charge James C Barnacle, Jr described the coordinated cyber attacks as a serious threat to US national security. US Attorney for the Southern District of New York Jamie McDonald said cyber operations have become a central instrument of national power.
The August 2026 unsealing builds on a layered prosecutorial history. In March 2016, the Manhattan US Attorney announced charges against seven Iranians, including Ahmad Fathi, for conducting a coordinated cyberattack campaign (DoJ SDNY). In September 2020, two Iranian nationals — Hooman Heidarian, also known as "neo," aged 30, and Mehdi Farhadi, also known as "Mehdi Mahdavi" and "Mohammad Mehdi Farhadi Ramin," aged 34, both of Hamedan, Iran — were charged in a cyber theft and defacement campaign against computer systems (DoJ NJ). Reuters reported that the 17 individuals charged in the current action worked with an Iranian company in the Iran-backed hacking campaign.
The broader context here is the institutionalization of cyber-enabled intellectual property theft as a state-aligned tool. The Mabna Institute was not a loose collective of opportunistic hackers; the DoJ's account describes it as a purpose-built entity founded in 2013 with the explicit mission of stealing non-Iranian scientific resources, operating on behalf of the IRGC and other Iranian government clients. The campaign's targeting of 100,000 academic accounts across 322 universities in multiple countries, with a claimed 8,000 successful compromises, reflects a systematic, well-resourced operation rather than intermittent intrusion attempts. The $3.4 billion valuation placed on the stolen material by the DoJ, while necessarily an estimate, points to the gap between the cost of producing frontier research and the near-zero cost of stealing it once access is gained.
The prosecutorial timeline itself is worth noting. The 2016 charges against seven Iranians, the 2018 indictment of nine Mabna members, the 2020 charges against Heidarian and Farhadi, and now the consolidated 17-defendant unsealing in August 2026 reveal a deliberate accumulation of cases rather than a single decisive intervention. Each iteration has expanded the defendant pool, the scope of alleged conduct, and the geographic breadth of identified victims. The $10 million reward component signals that the individuals remain outside US custody, as is typical in Iran-linked cyber cases where extradition is effectively impossible. The charges function as a combination of legal record, sanctions-enabling mechanism, and deterrent signal to both the accused and any similar actors operating in the same ecosystem.
McDonald's characterization of cyber operations as "a central instrument of national power" is a framing that extends well beyond this case. It positions state-aligned cyber theft not as criminal conduct alone but as an element of statecraft, which carries implications for how subsequent incidents of this type are likely to be prosecuted, sanctioned, and diplomatically addressed.


