All Publications
Cybersecurity

Iranian Hack of Academic Material

August 21, 20267 min read

The U.S. Department of Justice has indicted 17 Iranian hackers from the Mabna Institute for a massive cyber espionage campaign backed by the Islamic Revolutionary Guard Corps (IRGC). The group stole 31 terabytes of academic and corporate data globally, extorted HBO, and compromised thousands of accounts, generating significant illicit profits while prompting a $10 million U.S. reward for their capture.

Background

The origins of this extensive cyber campaign trace back to 2013 with the establishment of the Mabna Institute. Operating as a hacking service provider, Mabna executed cyber operations for the IRGC and private Iranian clients. The hackers targeted over 100,000 academic accounts globally, successfully penetrating approximately 8,000 accounts belonging to professors across 144 American universities and 178 international universities. They stole an estimated 31 terabytes of intellectual property—encompassing research, dissertations, and scientific journals—across fields ranging from hard sciences to social sciences. This stolen information was subsequently monetized into a highly lucrative enterprise on Iranian websites like Megapaper.ir and Gigapaper.ir, generating substantial revenue for the hackers.

The attackers relied on highly tailored spear-phishing techniques against academic targets. By conducting reconnaissance on professors' published works, they crafted convincing emails that directed victims to spoofed university login portals. In parallel, the group targeted corporate and governmental entities—including the UN, UNICEF, and 42 American companies—using "password spraying." By systematically testing common passwords across large volumes of harvested emails, they breached networks and established auto-forwarding rules to continuously siphon sensitive communications, causing over $20 million in damages.

The group also pursued direct financial extortion. They breached HBO, stole unreleased "Game of Thrones" scripts, and demanded a $6 million Bitcoin ransom. When HBO refused, they leaked the materials online. The U.S. indicted 17 individuals, offered a $10 million reward for five suspects, and secured the arrest of one defendant in Montenegro.

Conclusions

Based on the background details, the following conclusions can be drawn:

  1. Blurring of State Espionage and For-Profit Cybercrime: The Mabna Institute operated a dual-purpose cyber model. By executing intelligence operations for the IRGC while simultaneously selling stolen research and extorting HBO, the attackers demonstrated that state sponsorship can provide cover for exceptionally profitable criminal enterprises, turning stolen data into massive financial gain.
  2. Human Trust as a Vulnerability: The operational methodology relied heavily on psychological manipulation. Meticulous reconnaissance and exploiting academic collaboration proved that social engineering effectively bypasses expensive security perimeters.
  3. Mass Aggregation for Profit: The sheer volume of theft across non-military fields indicates a priority on indiscriminate data collection. The objective was building a comprehensive repository to be continually sold for massive financial gain.
  4. Systemic Failures in Basic IT Hygiene: The widespread success of basic password spraying against major entities like the UN and global corporations highlights that these organizations suffered from inadequate password policies and failed to monitor auto-forwarding rules.
  5. Global Reach of Law Enforcement: The United States treats state-sponsored cybercrime as a long-term priority. The indictment, bounty, and Montenegro arrest conclude that authorities rely on prolonged international cooperation to capture threat actors hiding in hostile jurisdictions.

Takeaways

Derived directly from the preceding conclusions, the following actionable takeaways emerge:

  1. Expand Threat Modeling Scopes: Organizations must assume intellectual property is targeted by actors looking to resell data on the black market for substantial financial profit, not just by rival states.
  2. Implement Context-Aware Security Training: Because personalized spear-phishing bypassed perimeters, institutions must deploy advanced cybersecurity training focused on verifying unsolicited emails.
  3. Apply Zero-Trust to All Departments: Given that attackers targeted a wide breadth of academic disciplines to build their profitable data repository, universities must apply uniform security protocols across all departments, abandoning the assumption that only hard-science sectors are valuable.
  4. Enforce Strict Authentication Policies: Due to the success of password spraying, organizations must immediately enforce multi-factor authentication (MFA) across all external-facing portals and actively block unauthorized auto-forwarding rules on corporate email accounts.
  5. Maintain Long-Term Incident Cooperation: Knowing that authorities pursue these cases over many years, victim organizations should prioritize full disclosure to federal authorities. Sustained information sharing contributes to global enforcement efforts that eventually disrupt these networks.

ASERO Worldwide develops tailored security solutions to mitigate evolving physical and cyber threats. By continuously adapting our strategies against complex state-sponsored and financial attacks, ASERO ensures our clients' sensitive data, intellectual property, and technological edge remain fully secure.


* spear-phishing: A highly targeted cyberattack in which hackers send fraudulent emails tailored to specific individuals to trick them into revealing sensitive information.

* spoofed: A deceptive technique where a website or login portal is forged to appear as a legitimate, trusted source.

* password spraying: A brute-force attack attempting to access many accounts by testing a few common passwords, avoiding automated lockouts.

Learn More

Explore how this insight applies to your organization.

Contact ASERO