U.S. Indicts 17 Iranians in Alleged State-Backed Cyber Theft Campaign
The U.S. Department of Justice has dramatically expanded a long-running prosecution of alleged Iranian hackers, unsealing a 14-count superseding indictment in the Southern District of New York charging 17 Iranian nationals affiliated with the Mabna Institute in an alleged cyber-theft campaign targeting American universities, companies, government agencies and nongovernmental organizations.
The indictment, unsealed on August 18, 2026, substantially expands upon charges first brought against nine of the defendants in 2018. Prosecutors allege that the Mabna Institute conducted cyber intrusions on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC), Iranian universities and other Iranian government clients.
A campaign spanning hundreds of institutions
According to the Justice Department, the alleged campaign operated principally from approximately 2013 through 2017 and targeted more than 100,000 professor accounts worldwide. Hackers allegedly compromised approximately 8,000 accounts at 144 U.S. universities and 178 universities abroad, stealing at least 31.5 terabytes of academic data and intellectual property.
The stolen material allegedly included academic journals, theses, dissertations, electronic books and other research spanning science and technology, engineering, medicine and the social sciences. Prosecutors say U.S. universities collectively spent more than $3.4 billion to obtain and access the research and intellectual property targeted by the campaign.
The alleged operation extended beyond academia. Prosecutors say the defendants compromised employee email accounts at at least 42 U.S. companies, 11 foreign companies and five U.S. federal or state agencies, as well as organizations including the Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF.
The indictment also alleges that several defendants participated in the 2017 intrusion of Home Box Office (HBO) and an attempted extortion scheme seeking approximately $6 million in Bitcoin.
Who are the defendants?
The 17 defendants named in the superseding indictment are:
- Gholamreza Rafatnejad
- Ehsan Mohammadi
- Abdollah Karima, a/k/a “Vahid Karima”
- Mostafa Sadeghi
- Seyed Ali Mirkarimi
- Mohammed Reza Sabahi
- Roozbeh Sabahi
- Abuzar Gohari Moqadam
- Sajjad Tahmasebi
- Saeid Houshyar
- Behzad Mesri, a/k/a “Skote Vahshat”
- Manouchehr Hashemloo
- Keyvan Fayaz, a/k/a “Achilles,” “The Joker” and “bc.monster”
- Amir Barati
- Saber Shahbazi Ballojeh
- Arman Kahzadian
- Mojtaba Galekuhi, a/k/a “Mojtaba Ghaleh Koui”
Prosecutors allege that Rafatnejad and Mohammadi founded the Mabna Institute in about 2013 to help Iranian universities and scientific organizations obtain access to foreign scientific resources. The government says the institute subsequently employed or contracted hackers to steal academic data, intellectual property, email credentials and other proprietary information.
The defendants have not been convicted. As the Justice Department emphasizes, the charges in the indictment are allegations, and every defendant is presumed innocent unless and until proven guilty.
The federal statutes at issue
The superseding indictment invokes several important federal cybercrime and fraud statutes.
18 U.S.C. § 371 — Conspiracy
Count One charges most of the defendants with conspiracy to commit computer intrusions under 18 U.S.C. § 371. The statutory maximum is five years in prison.
Section 371 generally criminalizes an agreement between two or more people to commit an offense against the United States, coupled with an act in furtherance of that agreement.
18 U.S.C. § 1349 — Conspiracy to commit wire fraud
Count Two alleges conspiracy to commit wire fraud under 18 U.S.C. § 1349. The maximum penalty is 20 years’ imprisonment.
18 U.S.C. § 1030 — Computer Fraud and Abuse Act
Several counts allege unauthorized access to protected computers under the Computer Fraud and Abuse Act (CFAA), principally 18 U.S.C. § 1030(a)(2), with the indictment invoking § 1030(c)(2)(B) and, in certain counts, aiding-and-abetting liability under 18 U.S.C. § 2.
The charged computer-access offenses carry a maximum of five years in prison under the provisions cited by prosecutors.
18 U.S.C. § 1343 — Wire fraud
The indictment also charges wire fraud under 18 U.S.C. § 1343. Each charged count carries a maximum penalty of 20 years in prison.
18 U.S.C. § 1028A — Aggravated identity theft
The indictment alleges aggravated identity theft under 18 U.S.C. § 1028A. This offense carries a mandatory two-year prison term, generally consecutive to the sentence for the underlying felony.
The Justice Department’s charging chart specifies that the identity-theft counts in this case carry mandatory two-year terms.
18 U.S.C. § 3238 — Offenses committed outside the United States
Several of the later counts also invoke 18 U.S.C. § 3238, a federal venue provision governing offenses begun or committed outside the United States. Its inclusion reflects the international nature of the alleged conduct and the fact that the defendants are alleged to have operated from Iran.
How serious are the potential sentences?
The indictment contains overlapping counts, so the maximum penalties should not simply be interpreted as a prediction of the sentence any defendant will receive. The Justice Department expressly notes that the listed maximums are statutory ceilings and that actual sentences will be determined by the court.
The counts carry the following statutory maximums:
| Count | Offense | Maximum penalty |
|---|---|---|
| 1 | Conspiracy to commit computer intrusions, 18 U.S.C. § 371 | 5 years |
| 2 | Conspiracy to commit wire fraud, 18 U.S.C. § 1349 | 20 years |
| 3 | Unauthorized computer access, 18 U.S.C. § 1030 | 5 years |
| 4 | Wire fraud, 18 U.S.C. § 1343 | 20 years |
| 5 | Unauthorized computer access, 18 U.S.C. § 1030 | 5 years |
| 6 | Wire fraud, 18 U.S.C. § 1343 | 20 years |
| 7 | Aggravated identity theft, 18 U.S.C. § 1028A | Mandatory 2 years |
| 8 | Unauthorized computer access, 18 U.S.C. § 1030 | 5 years |
| 9 | Wire fraud, 18 U.S.C. § 1343 | 20 years |
| 10 | Aggravated identity theft, 18 U.S.C. § 1028A | Mandatory 2 years |
| 11 | Conspiracy to commit computer intrusions, 18 U.S.C. § 371 | 5 years |
| 12 | Computer intrusion, 18 U.S.C. § 1030 | 5 years |
| 13 | Conspiracy to commit wire fraud, 18 U.S.C. § 1349 | 20 years |
| 14 | Aggravated identity theft, 18 U.S.C. § 1028A | Mandatory 2 years |
These are per-count statutory maximums, not necessarily the amount of prison time that could ultimately be imposed. The charging structure also differs substantially from defendant to defendant.
For example, the original nine defendants face the core seven counts, while Houshyar, Hashemloo, Fayaz, Ballojeh and Kahzadian face additional counts arising from later alleged activity. Fayaz, Ballojeh and Galekuhi face a further set of counts concerning alleged attacks on private-sector and governmental systems.
The HBO allegations
One particularly notable component involves HBO. Prosecutors allege that Mesri and several other defendants participated in the 2017 compromise of HBO’s computer systems and theft of proprietary information. Mesri had previously been charged separately in connection with the intrusion and alleged attempt to extort approximately $6 million in Bitcoin.
The superseding indictment alleges that Houshyar, Hashemloo, Fayaz, Ballojeh and Kahzadian also participated in the HBO intrusion.
Why the case matters
The case illustrates how U.S. prosecutors are increasingly treating state-linked cyber operations as conventional federal criminal cases, even when the alleged perpetrators are overseas and may never voluntarily appear in a U.S. courtroom.
It also demonstrates the breadth of the potential damage from intellectual-property theft. Rather than targeting a single financial institution or government network, prosecutors allege that the Mabna operation systematically sought access to the global research ecosystem, while allegedly monetizing some of the stolen material through Iranian websites.
The Justice Department has characterized the alleged activity as part of a broader, state-sponsored effort connected to the IRGC. The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of five defendants: Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh.
The case is assigned to U.S. District Judge Jesse M. Furman in the Southern District of New York.
A prosecution years in the making
Perhaps the most significant feature of the new indictment is its timing. Nine of the 17 defendants were first charged in 2018. The new superseding indictment adds eight defendants and expands the alleged conduct to include additional victims and cyber operations.
The result is a case that reaches well beyond a conventional hacking prosecution: federal prosecutors are alleging an organized, years-long enterprise that combined computer intrusion, theft of intellectual property, fraud, identity theft and alleged activity conducted for Iranian governmental interests.
For U.S. companies and universities, the case is also a reminder that cyber risk can extend far beyond ransomware or theft of customer information. Research data, faculty credentials, proprietary communications and access to institutional systems can all become targets in campaigns driven by geopolitical objectives.
Important legal note: The defendants are presumed innocent. The indictment contains allegations only, and the statutory maximums discussed above do not establish what sentences, if any, the defendants ultimately would receive.
Matthew Galluzzo, the author of this article, is an experienced criminal defense attorney and former Manhattan prosecutor. He has successfully defended dozens of individuals in federal criminal cases in the Southern and Eastern Districts of New York, including charges of wire fraud and conspiracy. If you or a loved one have been accused or arrested in connection with this particular indictment, you should strongly consider contacting him about his legal services.







