
The Justice Department announced Tuesday that 17 people connected to an Iran-based hacking operation have been charged in an extensive cyber campaign that allegedly targeted American universities, businesses and government agencies, with some of the attacks carried out for the benefit of Iran’s Islamic Revolutionary Guard Corps.
Federal prosecutors in the Southern District of New York unsealed a 14-count superseding indictment against individuals affiliated with the Tehran-based Mabna Institute, accusing the group of orchestrating a years-long series of cyber intrusions.
According to the Justice Department, the Mabna Institute has been conducting coordinated hacking operations since at least 2013, penetrating computer networks belonging to 144 universities in the United States and another 178 universities abroad.
The alleged operation extended well beyond academia. Prosecutors said the hackers also targeted at least 42 American private-sector companies, 11 foreign companies, five U.S. federal and state government agencies and two nongovernmental organizations.
“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” Jamie McDonald, the U.S. attorney for the Southern District of New York, said in a news release.
“More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.
“Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength.
“This office and our partners will continue to protect American innovation and pursue accountability for the individuals behind these attacks.”
Prosecutors said the hackers attempted to gain access to more than 100,000 professors’ accounts around the world. Approximately 8,000 email accounts belonging to professors at American and foreign universities were successfully compromised.
The operation allegedly resulted in the theft of approximately 31.5 terabytes of academic information and intellectual property. The stolen material included scholarly journals, theses, dissertations and electronic books.
Justice Department officials said members of the hacking group obtained stolen usernames and passwords and then used those credentials to enter university computer systems.
The stolen material was allegedly monetized through websites serving customers in Iran. One site sold academic documents, while another offered customers access to compromised professors’ accounts, enabling them to enter university library systems.
Federal prosecutors said at least part of the hacking campaign was undertaken to benefit the IRGC as well as other Iranian government and university clients.
Nine of the defendants had previously been charged under seal in a seven-count indictment filed in February 2018.
That original indictment was made public the following month.
The newly unsealed superseding indictment charges the defendants with varying combinations of conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud involving unauthorized access for private financial gain, wire fraud and aggravated identity theft.
A conviction on either the computer-intrusion conspiracy charge or computer-fraud charge can carry a maximum prison term of five years. Conspiracy to commit wire fraud and substantive wire fraud each carry potential maximum sentences of 20 years.
Aggravated identity theft carries a mandatory two-year prison sentence.
The State Department’s Rewards for Justice program is also offering rewards of as much as $10 million for information that helps authorities locate five of the defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh.
{Matzav.com}



