U.S. charges 17 Iranian hackers in $6M Bitcoin extortion plot
In brief
- U.S. prosecutors charged 17 alleged Iranian hackers tied to the 2017 HBO breach and a sprawling cyber campaign targeting academic and corporate networks
- Mabna Institute defendants allegedly stole 31 terabytes of research and intellectual property from hundreds of organizations worldwide
- The group targeted over 8,000 accounts across 144 U.S. universities and 178 foreign universities using spearphishing and stolen credentials
- HBO extortion attempt sought $6 million in Bitcoin; State Department offers $10 million reward for information on five defendants
The HBO Breach and Bitcoin Extortion
Behzad Mesri was previously charged with hacking HBO and stealing proprietary data. Five other defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian—were directly involved in the HBO hack. An attempt was made to extort HBO for roughly $6 million in Bitcoin, marking one of the earliest known instances of state-linked ransomware actors seeking cryptocurrency.
Scale of the Academic and Corporate Theft
The scope of the operation stretched far beyond HBO. These defendants hacked into universities and other research institutions worldwide, stealing at least 31 terabytes of information and intellectual property. The Mabna Institute targeted more than 100,000 professor accounts worldwide, while compromising roughly 8,000 accounts across 144 U.S. universities and 178 foreign universities.
The hackers used spearphishing and stolen credentials to steal research, academic journals, theses, dissertations, ebooks, and other material. The operation was methodical and sustained, designed to extract intellectual property of strategic value to Iran's government.
Iran's Crypto Sanctions and Enforcement
The charges arrive amid a broader U.S. crackdown on Iranian use of cryptocurrency to evade sanctions. In June, the U.S. Treasury sanctioned four Iranian crypto exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion. Treasury also linked Nobitex to transactions involving IRGC-affiliated ransomware actors.
The enforcement escalated through the summer. In July, Treasury froze more than $131 million across four crypto wallets the agency linked to Iran's central bank and armed forces, including the IRGC. In August, Treasury sanctioned two more crypto exchanges that it accused of laundering millions of dollars for the IRGC and other sanctioned Iranian entities.
The State Department is offering rewards of up to $10 million for information leading to the location of five defendants. The indictment signals that U.S. authorities view the Mabna operation as a persistent threat, one that years of public charges have not fully contained.
"These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government." — FBI Cyber Division Assistant Director Brett Leatherman


