NEW YORK — August 18, 2026 — Seventeen members of the Iran-based Mabna Institute have been charged in a 14-count superseding federal indictment accusing them of participating in a coordinated cyber intrusion campaign that targeted hundreds of universities, private companies, government agencies, international organizations, and other victims across the United States and abroad.
The superseding indictment alleges the operation dates to at least 2013 and resulted in the theft of more than 31 terabytes of academic data and intellectual property, along with employee email accounts and other proprietary information. Federal authorities say many of the intrusions were conducted on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps, or IRGC, as well as other Iranian government and university clients.
The defendants are accused of targeting computer systems belonging to 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private-sector companies, at least 11 foreign private-sector companies, at least five U.S. federal and state government agencies, and at least two nongovernmental organizations.
Nine of the 17 defendants were previously charged in a seven-count indictment announced in March 2018. The superseding indictment adds eight defendants and provides a broader account of the network, its targets, and alleged operations. The case is assigned to U.S. District Judge Jesse M. Furman.
Assistant Attorney General for National Security John A. Eisenberg said the superseding indictment accuses the defendants of hacking universities and research institutions around the world at the direction of entities that included the IRGC and stealing at least 31 terabytes of information and intellectual property. Eisenberg said the National Security Division intends to continue pursuing individuals responsible for such operations regardless of how much time passes.
U.S. Attorney Jamie McDonald for the Southern District of New York said the eight additional defendants reveal a broader network accused of participating in a state-sponsored campaign targeting research and intellectual property belonging to American universities, businesses, and government institutions. McDonald said cyber operations have become an instrument of national power and that attacks directed against American and allied institutions can affect national security and economic strength.
FBI Cyber Division Assistant Director Brett Leatherman described the defendants as participants in an alleged hacking-for-hire operation that targeted intellectual property belonging to American and allied universities, companies, and government agencies for the benefit of the Iranian government. Leatherman said the FBI intends to continue identifying malicious cyber actors, disrupting their operations, and pursuing accountability regardless of where they operate.
According to the superseding indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 to assist Iranian universities and scientific and research organizations in obtaining unauthorized access to scientific resources outside Iran.
The institute allegedly employed, contracted with, or affiliated itself with hackers-for-hire and other personnel, including Abdollah Karima, also known as “Vahid Karima”; Mostafa Sadeghi; Seyed Ali Mirkarmi; Mohammed Reza Sabahi; Roozbeh Sabahi; Abuzar Gohari Moqadam; Sajjad Tahmasebi; Saeid Houshyar; Behzad Mesri, also known as “Skote Vahshat”; Manouchehr Hashemloo; Keyvan Fayaz, also known as “Achilles,” “The Joker,” and “bc.monster”; Amir Barati; Saber Shahbazi Ballojeh; Arman Kahzadian; and Mojtaba Galekuhi, also known as “Mojtaba Ghaleh Koui.”
Federal authorities allege those individuals participated in cyber intrusions intended to obtain academic data, intellectual property, email inboxes, login credentials, and other proprietary information.
The Mabna Institute allegedly contracted with Iranian governmental and private entities to conduct hacking operations on their behalf. The university spearphishing campaign was specifically carried out on behalf of the IRGC, according to the indictment.
The institute is identified in the federal case as being located at Tehran, Sheikh Bahaii Shomali, Koucheh Dawazdeh Metri Sevom, Plak 14, Vahed 2, Code Posti 1995873351.
The FBI has publicly tracked the Mabna Institute case since the original charges were announced in March 2018. At that time, the bureau identified approximately 144 U.S. universities, 176 foreign universities, five federal and state government agencies, 36 U.S. private companies, 11 foreign private companies, and two international nongovernmental organizations as victims. The new allegations raise the publicly identified totals to 178 foreign universities and at least 42 U.S. private-sector companies, reflecting the expanded scope described in the superseding case.
The university campaign allegedly targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000 professor email accounts.
The affected universities included 144 institutions in the United States and 178 foreign universities located across Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, the Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey, and the United Kingdom.
The campaign began around 2013 and continued through at least December 2017. Its targets covered a broad range of academic disciplines and research fields.
Members of the conspiracy allegedly obtained professor login credentials and used them to gain unauthorized access to university accounts and systems. The stolen material included academic journals, theses, dissertations, electronic books, research documents, and other academic information.
The defendants are accused of targeting research in science and technology, engineering, social sciences, medicine, and other professional disciplines.
Approximately 31.5 terabytes of academic data and intellectual property were allegedly stolen and transferred to servers outside the United States that were controlled by members of the conspiracy.
The FBI’s original investigation described the scheme as one in which attackers researched professors and their academic specialties and then used targeted phishing messages to obtain usernames and passwords. The bureau reported in 2018 that more than 100,000 professor accounts had been targeted and approximately 8,000 were successfully compromised.
U.S.-based universities spent approximately $3.4 billion to procure and access the academic data and intellectual property targeted during the conspiracy. The FBI cited the same approximate figure when announcing the original Mabna Institute case, explaining that the defendants had obtained access to resources universities had spent billions of dollars to acquire.
The alleged operation also contained a commercial component.
Federal prosecutors say stolen academic data and login credentials were sold through two websites, Megapaper.ir, known as Megapaper, and Gigapaper.ir, known as Gigapaper.
Megapaper was operated by Falinoos Company, which authorities say was controlled by Abdollah Karima. Gigapaper was also allegedly affiliated with Karima.
Megapaper allegedly sold stolen academic resources to customers inside Iran, including Iranian public universities and institutions. Gigapaper allegedly sold access that allowed customers in Iran to use compromised professor accounts to enter online library systems belonging to selected U.S. and foreign universities.
The FBI has previously described the Mabna Institute as an Iranian organization whose members allegedly obtained unauthorized access to computer systems, stole proprietary data, and sold or supplied that material to Iranian customers, including Iranian universities and the Iranian government. The bureau continues to identify members charged in the original case through its cyber wanted program.
The campaign extended beyond academic institutions.
Federal authorities allege the defendants targeted, compromised, and exfiltrated information from employee email accounts belonging to at least five U.S. federal and state government agencies, at least 42 U.S.-based private-sector companies, approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom, and multiple governmental and nongovernmental organizations.
Named targets included the U.S. Department of Labor, Federal Energy Regulatory Commission, State of Hawaii, State of Indiana, United Nations, and United Nations Children’s Fund.
The FBI’s original case also documented intrusions against government agencies and private companies and classified the charged Mabna Institute members as international flight risks.
The superseding indictment charges eight additional defendants and describes further alleged activity involving American and international institutions.
One of the targets was Home Box Office Inc., or HBO, the media and entertainment company headquartered in New York City.
Behzad Mesri was separately charged in United States v. Behzad Mesri, 17 Cr. 689 (AJN), with hacking HBO’s computer systems, stealing proprietary information, and attempting to extort the company for approximately $6 million worth of Bitcoin.
The new indictment alleges Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian also participated directly in the HBO intrusion with Mesri.
Mojtaba Galekuhi, Fayaz, and Ballojeh are accused of participating in Mabna Institute efforts targeting private-sector companies and at least two governmental entities.
Those operations allegedly included password-spray attacks, unauthorized access to victim systems, and data exfiltration. Federal authorities say the affected organizations suffered more than $20 million in costs associated with investigating and remediating the intrusions.
Amir Barati is accused of tracking the progress of spearphishing campaigns, exchanging compromised account credentials with co-conspirators, creating targeting lists, conducting computer-network reconnaissance, and crafting phishing messages.
Concurrent with the unsealing of the superseding indictment, the U.S. Department of State’s Rewards for Justice program announced rewards of up to $10 million for information leading to the location of Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
The Rewards for Justice program seeks information concerning individuals who, while acting at the direction or under the control of a foreign government, engage in specified malicious cyber activity in violation of the Computer Fraud and Abuse Act.
Information concerning the five defendants or associated individuals and entities can be submitted through the Rewards for Justice Tor-based reporting channel at he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion. Additional information concerning the reward is available through the Rewards for Justice program.
The superseding indictment contains 14 counts involving computer intrusions, wire fraud, aggravated identity theft, and related conspiracies.
Count 1 — Conspiracy to Commit Computer Intrusions, 18 U.S.C. § 371: Gholamreza Rafatnejad, Ehsan Mohammadi, Abdollah Karima, Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri, Manouchehr Hashemloo, Keyvan Fayaz, Amir Barati, Saber Shahbazi Ballojeh, and Arman Kahzadian. The maximum potential penalty is five years in prison.
Count 2 — Conspiracy to Commit Wire Fraud, 18 U.S.C. § 1349: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Fayaz, Barati, Ballojeh, and Kahzadian. The maximum potential penalty is 20 years in prison.
Count 3 — Computer Fraud, Unauthorized Access for Private Financial Gain, 18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), (c)(2)(B)(iii), and 2: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Fayaz, Barati, and Kahzadian. The maximum potential penalty is five years in prison.
Count 4 — Wire Fraud, 18 U.S.C. §§ 1343 and 2: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Barati, and Kahzadian. The maximum potential penalty is 20 years in prison.
Count 5 — Computer Fraud, Unauthorized Access for Private Financial Gain, 18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), (c)(2)(B)(iii), and 2: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Barati, and Kahzadian. The maximum potential penalty is five years in prison.
Count 6 — Wire Fraud, 18 U.S.C. §§ 1343 and 2: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Barati, and Kahzadian. The maximum potential penalty is 20 years in prison.
Count 7 — Aggravated Identity Theft, 18 U.S.C. §§ 1028A(a)(1), 1028A(b), and 2: Rafatnejad, Mohammadi, Karima, Sadeghi, Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Moqadam, Tahmasebi, Houshyar, Mesri, Hashemloo, Fayaz, Barati, Ballojeh, and Kahzadian. The charge carries a mandatory two-year prison term upon conviction.
Count 8 — Computer Fraud, Unauthorized Access for Private Financial Gain, 18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), (c)(2)(B)(iii), and 2; and 18 U.S.C. § 3238: Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian. The maximum potential penalty is five years in prison.
Count 9 — Wire Fraud, 18 U.S.C. §§ 1343 and 2; and 18 U.S.C. § 3238: Houshyar, Hashemloo, Fayaz, Ballojeh, and Kahzadian. The maximum potential penalty is 20 years in prison.
Count 10 — Aggravated Identity Theft, 18 U.S.C. §§ 1028A(a)(1), 1028A(b), and 2; and 18 U.S.C. § 3238: Houshyar, Hashemloo, Fayaz, Ballojeh, and Kahzadian. The charge carries a mandatory two-year prison term upon conviction.
Count 11 — Conspiracy to Commit Computer Intrusions, 18 U.S.C. § 371 and 18 U.S.C. § 3238: Keyvan Fayaz, Saber Shahbazi Ballojeh, and Mojtaba Galekuhi. The maximum potential penalty is five years in prison.
Count 12 — Computer Intrusion, 18 U.S.C. §§ 1030(a)(2), (c)(2)(B)(i), and (c)(2)(B)(iii): Fayaz, Ballojeh, and Galekuhi. The maximum potential penalty is five years in prison.
Count 13 — Conspiracy to Commit Wire Fraud, 18 U.S.C. § 1349 and 18 U.S.C. § 3238: Fayaz, Ballojeh, and Galekuhi. The maximum potential penalty is 20 years in prison.
Count 14 — Aggravated Identity Theft, 18 U.S.C. §§ 1028A(a)(1), 1028A(b), and 2; and 18 U.S.C. § 3238: Fayaz, Ballojeh, and Galekuhi. The charge carries a mandatory two-year prison term upon conviction.
The listed maximum sentences are established by Congress and do not represent predetermined sentences. Any punishment imposed following a conviction would be determined by the court.
The National Security Division credited the FBI for its investigative work and acknowledged assistance from the United Kingdom’s National Crime Agency. The Office of Foreign Assets Control and the Rewards for Justice program also provided support, while the Justice Department’s Office of International Affairs is providing assistance in the case.
Assistant U.S. Attorneys Nicholas W. Chiuchiolo, Connie L. Dang, and Adam Sowlati for the Southern District of New York are leading the prosecution. Trial Attorney Jacques Singer-Emery and former Trial Attorney Matthew Chang of the National Security Division’s National Security Cyber Section provided additional assistance.
The case represents a major expansion of the Mabna Institute prosecution first made public more than eight years ago. FBI records from the original investigation identify Rafatnejad as a leader of the institute and describe other original defendants as contractors, associates, hackers-for-hire, or affiliates accused of stealing proprietary information for Iranian customers and government interests. Federal arrest warrants were issued in connection with the original charges, and the FBI has continued carrying the defendants through its cyber wanted program.
The 2026 superseding indictment does not establish guilt. All 17 defendants are presumed innocent unless and until proven guilty beyond a reasonable doubt in a court of law.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



