On 18 August 2026, the US Department of Justice unsealed a 14-count superseding indictment against 17 alleged members of the Mabna Institute, an Iranian contractor accused of conducting computer intrusions for the Islamic Revolutionary Guard Corps, government bodies and university clients. 

Nine defendants appeared in the original 2018 indictment. The revised filing adds eight people and connects the institute to a wider set of operations involving academic institutions, commercial organisations, government agencies and non-governmental bodies. Each charge remains an allegation unless proven in court. 

The scale reported by prosecutors is substantial. Mabna personnel allegedly targeted more than 100,000 professor accounts and compromised approximately 8,000. Victims included 144 US universities and 178 universities in other countries. At least 31.5 terabytes of journals, dissertations, electronic books and other research material were exfiltrated between approximately 2013 and December 2017. 

The activity was not confined to academia. Prosecutors identified at least 42 US companies, 11 foreign companies, five US federal or state agencies and two NGOs among the targets. Named organisations include the US Department of Labor, the Federal Energy Regulatory Commission, the United Nations and UNICEF. 

According to the Justice Department, the operators used spear-phishing, credential theft and password-spraying attacks to obtain access to email accounts and internal systems. Some defendants allegedly prepared target lists, performed network reconnaissance, wrote phishing messages and circulated captured credentials among collaborators. 

Stolen academic material also supported a commercial operation. Prosecutors allege that data was sold through Megapaper.ir and Gigapaper.ir. One service supplied copied research documents, while another gave customers access to university library systems through compromised professor accounts. This arrangement joined intelligence collection with revenue generation: stolen credentials could support both state requirements and domestic resale. 

The superseding indictment further links several defendants to the 2017 intrusion at HBO. That incident involved the theft of proprietary material and an attempted extortion demand valued at roughly $6 million in Bitcoin. Separate operations attributed to three defendants used password spraying against private-sector and government targets, producing more than $20 million in investigation and remediation costs. 

From a defensive perspective, the case illustrates the value of persistent identity-based intrusion methods. Spear-phishing and password spraying require neither novel malware nor exploitation of an undisclosed vulnerability. Success depends on credential reuse, weak authentication, permissive access policies and incomplete monitoring. Once an authorised account is compromised, malicious activity may resemble normal user behaviour. 

Controls should therefore concentrate on phishing-resistant multifactor authentication, removal of legacy authentication protocols, conditional-access policies and detection of low-volume password spraying across multiple accounts. Security teams should correlate identity, email, endpoint and cloud audit records rather than review each source separately. Access to research repositories should follow least-privilege rules, with bulk downloads, unusual mailbox access and atypical geographic sign-ins treated as investigation triggers. 

Universities face a particular exposure. Open collaboration, federated identity, visiting researchers and extensive digital-library holdings complicate access control. Those conditions warrant tighter lifecycle management for dormant accounts, stronger protection for privileged identities and tested procedures for revoking compromised credentials across connected services. 

The indictment also shows the duration of attribution and prosecution work. More than eight years separate the initial charges from the expanded filing. Concurrently, the US State Department announced rewards of up to $10 million for information leading to the location of five defendants. 

The immediate legal outcome remains unresolved. Its security relevance is clearer: research data, institutional email and licensed information services remain espionage targets, while ordinary credential attacks continue to provide an effective route into them. 

Conclusion

The Mabna Institute case shows that cyber risk cannot be measured solely through service disruption or ransom demands. Not every cyberattack involves ransomware. Espionage operations may remain undetected while compromised accounts are used to collect research, intellectual property, correspondence and other sensitive information over extended periods. 

Defence therefore requires more than ransomware controls and recovery planning. Organisations should treat identity systems, email platforms, cloud services and research repositories as primary intelligence targets. Phishing-resistant authentication, strict access controls, continuous monitoring, centralised logging and detection of unusual account activity are necessary for identifying intrusions whose objective is quiet, sustained data collection rather than immediate financial payment. 

Sources: BBC News, US Department of Justice, Security Affairs, National Security News.