DOJ charges 17 Iranian nationals in sweeping cyber theft campaign tied to Revolutionary Guard

 August 21, 2026

Federal prosecutors unsealed a 14-count indictment against 17 Iranian nationals accused of stealing more than 31 terabytes of data from American universities, companies, and government agencies on behalf of Iran's Islamic Revolutionary Guard Corps, and the State Department is now offering $10 million for help finding five of them.

The superseding indictment, brought by the U.S. Attorney's Office for the Southern District of New York, charges members and associates of the Mabna Institute, an Iran-based outfit allegedly founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. Prosecutors say the group ran a coordinated spearphishing campaign, sending deceptive emails designed to trick recipients into handing over login credentials, that broke into computer systems at universities, private firms, and federal and state agencies across the United States and abroad.

The scale of the alleged operation is staggering. The Hill reported that the defendants allegedly targeted at least 144 U.S.-based universities, 178 foreign universities, 42 American private companies, 11 foreign private companies, five U.S. federal and state government agencies, and two nongovernmental organizations. The haul: more than 31 terabytes of academic data and intellectual property, plus email accounts belonging to employees at private companies, government agencies, and NGOs.

Nine of the 17 defendants had already been charged in a 2018 grand jury indictment that carried seven counts. The new filing doubles the count total to 14 and adds eight more defendants, widening the net around what prosecutors describe as a state-sponsored hacking network.

Prosecutors say the IRGC bankrolled a hacking-for-hire operation

The Mabna Institute, according to the DOJ, did not operate as a rogue outfit. Prosecutors allege the group contracted directly with Iranian governmental and private entities to carry out hacking on their behalf, with the IRGC, a U.S.-designated foreign terrorist organization, identified as the primary beneficiary of the university spearphishing campaign.

That detail matters. The IRGC is not a fringe militia. It is a core branch of Iran's military and intelligence apparatus, and the U.S. government has long warned that its cyber operations pose a direct threat to American national security. The indictment frames the Mabna Institute as a private contractor doing the IRGC's bidding, a model that lets Tehran outsource its espionage while maintaining a layer of deniability.

The DOJ's track record of pursuing Iranian operatives extends well beyond data theft. In a separate case, Breitbart reported that the DOJ unsealed an indictment against three individuals, including an Iranian asset with IRGC ties, who allegedly plotted to assassinate President-elect Donald Trump. FBI Director Christopher Wray said at the time that "the Islamic Revolutionary Guard Corps, a designated foreign terrorist organization, has been conspiring with criminals and hitmen to target and gun down Americans on U.S. soil and that simply won't be tolerated."

The cyber theft case and the assassination plot share a common thread: the IRGC's willingness to reach across borders to strike at American targets, whether through stolen data or hired guns.

$10 million bounty on five defendants signals DOJ expects a long pursuit

The State Department is now offering a reward of up to $10 million for information leading to the location of five named defendants: Saber Shahbazi Ballojeh, Keyvan Fayaz, Mojtaba Galekuhi, Arman Kahzadian, and Behzad Mesri. The size of the bounty, typically reserved for terrorism-related cases, underscores how seriously Washington views the threat.

None of the 17 defendants appear to be in U.S. custody. The indictment was filed in the Southern District of New York, but with all defendants believed to be in Iran, the case may function more as a public naming-and-shaming exercise and a legal marker than a path to a courtroom trial anytime soon. That is a familiar pattern in federal cases involving foreign state actors.

The charges carry serious potential penalties. Conspiracy to commit computer intrusions carries a maximum sentence of five years in federal prison. Wire fraud and conspiracy to commit wire fraud each carry a maximum of 20 years. Not all 14 counts apply to every defendant.

The Trump administration's DOJ has shown a willingness to use federal legal tools aggressively. Separately, a joint DOJ-Pentagon task force was launched to hunt down leakers of classified material, and federal prosecutors have also pursued cases involving the sale of U.S. equipment to Iran's military and nuclear programs.

Jamie McDonald vows the passage of time will not shield foreign hackers

U.S. Attorney Jamie McDonald, who took over the Southern District of New York last month after Jay Clayton left to become director of national intelligence, framed the expanded indictment as a message to foreign adversaries. McDonald said the charges:

"Reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions."

He added a pointed warning about the DOJ's long memory:

"More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad."

Eight years is a long time between the original indictment and a superseding one that nearly doubles the defendant count and doubles the charges. The gap raises fair questions about whether the pace of federal prosecution keeps up with the speed of foreign cyber operations. But the DOJ's decision to expand the case rather than let it gather dust suggests prosecutors believe they have built a stronger evidentiary record over time.

Federal grand jury proceedings and indictments have been a recurring tool in high-profile cases across the political spectrum. A Hollywood financier was recently indicted on federal wire fraud charges in an alleged $100 million Ponzi scheme, and Sen. Rand Paul has pushed contempt proceedings against Dr. Anthony Fauci after Fauci invoked the Fifth Amendment more than 100 times.

322 institutions targeted, 31 terabytes stolen, and no one is in custody

Add up the numbers in the indictment and the scope of the alleged operation becomes clear. Across all categories, the Mabna Institute allegedly targeted at least 322 universities, 53 private companies, five government agencies, and two NGOs. The 31 terabytes of stolen data represent a massive trove of academic research and intellectual property, the kind of material that takes years and billions of dollars to produce.

American universities are soft targets for state-sponsored hackers. They hold cutting-edge research in fields from artificial intelligence to biomedical science, and their cybersecurity defenses often lag behind those of the private sector and the federal government. The Mabna Institute allegedly exploited that gap systematically, using spearphishing, targeted emails designed to look legitimate, to trick professors and researchers into surrendering their credentials.

The indictment does not detail which specific universities or companies were hit, or what categories of research were stolen. Those gaps may be filled as the case progresses, or they may remain sealed to protect ongoing investigations and the victims themselves.

For now, the 17 defendants remain beyond the reach of U.S. law enforcement. Iran does not extradite its citizens to the United States. The indictment and the $10 million reward serve as legal and diplomatic tools, formal declarations that the United States knows who carried out the operation, and that it will not forget.

When a hostile foreign government can steal 31 terabytes of American research and face nothing but a press release and a bounty poster, the question is not whether the DOJ is doing its job, it is whether the broader U.S. response to state-sponsored cyber theft has any real teeth at all.

Patriot News Alerts delivers timely news and analysis on U.S. politics, government, and current events, helping readers stay informed with clear reporting and principled commentary.