U.S. prosecutors this week unsealed a sweeping indictment charging 17 alleged Iranian hackers tied to a years‑long cyber campaign that included a high‑profile 2017 breach of HBO and an attempted $6 million Bitcoin extortion. The Justice Department says the defendants are members of the Iran‑based Mabna Institute, a hacking‑for‑hire network accused of working for Iran’s Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. Mabna allegedly targeted hundreds of universities, companies, government agencies and other organizations worldwide, stealing research and intellectual property on a massive scale. Highlights from the DOJ announcement - The indictment ties the group to the HBO hack, in which Behzad Mesri and five other named defendants—Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian—are accused of stealing proprietary data and attempting to extort HBO for roughly $6 million in Bitcoin. - Prosecutors say Mabna stole at least 31 terabytes of data and targeted more than 100,000 professor accounts globally. Roughly 8,000 accounts were compromised across 144 U.S. universities and 178 foreign institutions. - The operation allegedly used spearphishing and stolen credentials to harvest research papers, journals, theses, dissertations, ebooks and other academic and intellectual property. “This indictment alleges that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide…stealing at least 31 terabytes of information and intellectual property of untold value,” Assistant Attorney General for National Security John A. Eisenberg said. FBI Cyber Division Assistant Director Brett Leatherman described Mabna as a “sprawling hacking‑for‑hire operation” that profited from targeting the intellectual property of U.S. and allied universities, companies and government agencies for the benefit of the Iranian government. Crypto enforcement context The charges come amid heightened U.S. efforts to disrupt Iran’s use of cryptocurrency to move funds and evade sanctions. In recent months Treasury has ramped up actions against Iranian crypto infrastructure: - June: Treasury sanctioned four Iranian crypto exchanges, including Nobitex, alleging involvement in terrorist financing and sanctions evasion and linking Nobitex to IRGC‑affiliated ransomware transactions. - July: Treasury froze more than $131 million across four crypto wallets tied to Iran’s central bank and armed forces, including the IRGC. - August: Two additional exchanges were sanctioned for allegedly laundering millions for the IRGC and other sanctioned Iranian actors. The State Department is offering rewards of up to $10 million for information leading to the location of five of the defendants. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad,” U.S. Attorney Jamie McDonald for the Southern District of New York said. Why it matters for crypto watchers Beyond the headline grabbing HBO hack and the attempted Bitcoin extortion, the case underscores how state‑linked actors may leverage both cyber intrusions and digital‑asset channels to monetize theft and skirt sanctions. The DOJ and Treasury moves signal continued pressure on platforms and intermediaries that could be used to cash out or move illicit crypto proceeds tied to nation‑state operations. Read more AI-generated news on: undefined/news