The US Department of Justice has indicted 17 members of the Iran-based Mabna Institute following a massive cyber espionage operation.. The group is accused of targeting hundreds of academic institutions to steal vast amounts of sensitive information over a ten-year period.

Advertisement

The decade-long campaign of the Mabna Institute

The Mabna Institute, an organization based in Iran, is at the center of a 14-count indictment revealed by the US Department of Justice on Tuesday. This legal action follows a ten-year period of sustained cyber espionage aimed at global academic networks. This long-term infiltration suggests a high level of patience and technical sophistication, allowing the group to remain undetected while building a massive repository of stolen data.

This pattern of state-sponsored activity reflects a broader trend where intelligence agencies target higher education to bypass the more stringent security of military or government sectors. By infiltrating universities, actors can often gain access to cutting-edge research and sensitive intellectual property with less resistance than traditional defense targets.

31.5 terabytes stolen from 322 universities

The scale of the data breach is immense, with the group allegedly compromising 322 universities across the globe. According to the DOJ, the attackers successfully exfiltrated 31.5 terabytes of data during their operations. of the institutions targeted, 144 were located within the United States, highlighting a specific focus on American research and intellectual property.

The concentration of 144 US-based targets suggests that the Mabna Institute's objectives were closely aligned with national security interests, potentially seeking to undermine American technological advantages through academic theft.. The sheer volume of data indicates a systematic approach to harvesting diverse datasets from various disciplines.

A $10 million bounty for five primary fugitives

To assist in the apprehension of those responsible, the State Department has authorized a reward of up to $10 million. this significant sum is intended to provide information that leads to the location of five primary fugitivves involved in the scheme. This move by the State Department signals that the US government views these specific individuals as a high-priority threat to international stability.

The $20 million cost of digital remediation

Beyond the theft of intellectual property, the cyber campaign has caused significant financial damage to the academic community. The report says the intrusions resulted in more than $20 million in remediation costs for the victims. These expenses represent a significant drain on university budgets, often diverting funds away from actual research and into cybersecurity defense and forensic investigation.

What was contained in the stolen data?

While the volume of stolen information is known, several critical details remain unverified in the current indictment. It is not yet clear what specific types of research, personal data, or proprietary information were included in the 31.5 terabytes of exfiltrated data. Additionally, the source does not specify the identities or current whereabouts of the five fugitives being sought by the State Department. Until the fugitives are located or the full scope of the exfiltration is analyzed, the academic community remains in a state of heightened vulnerability.