- What: Iranian group conducted a decade-long academic espionage campaign
- Impact: Universities worldwide were targeted for stealing research
17 Iranians Indicted for $3.4 Billion Academic Hack Targeting 22 Countries, Including Poland 2026-08-19 The Mabna Institute, an Iranian company working for the Revolutionary Guard, penetrated more than three hundred universities worldwide and sold stolen research through commercial websites in Tehran. A federal grand jury has now named seventeen of its members. On August 18, 2026, federal prosecutors in the Southern District of New York unsealed a fourteen-count superseding indictment charging seventeen Iranian nationals with running one of the largest documented state-sponsored academic espionage operations in history. The organization at the center of the case, the Mabna Institute, was founded in Tehran around 2013 and operated under contract to Iran’s Islamic Revolutionary Guard Corps. Over the following decade, its members penetrated the computer systems of at least a hundred and forty-four American universities and a hundred and seventy-eight institutions in twenty-one other countries, including Poland. What they took, roughly thirty-one and a half terabytes of academic research valued at approximately three point four billion dollars, was not merely stolen. It was packaged, invoiced, and sold back to Iranian universities through two commercial websites operating openly in Tehran. The August indictment expands a 2018 case that initially charged nine members of the same network. Eight of the seventeen defendants now named were never in custody. Several continued hacking after the first indictment was unsealed, compromising a COVID-19 vaccine developer in December 2020 and selling stolen credentials on dark-web forums until at least March 2022. The State Department has announced a ten-million-dollar reward for information leading to the location of five of the principal accused. Poland appears in the indictment not as a footnote but as a named target: its universities subscribed to the same Western research databases that the Mabna Institute systematically plundered. A Company with a Mission The Mabna Institute was founded in Tehran around 2013 by two men named Gholamreza Rafatnejad and Ehsan Mohammadi. Mohammadi served as managing director and oversaw the organization’s finances. The stated purpose of the enterprise, the purpose that the founders might have offered to a curious neighbor or a customs official, was a sympathetic one: to help Iranian universities and scientific organizations gain access to foreign academic resources. The sympathetic part is worth pausing on. Western sanctions had effectively cut Iranian institutions off from the subscription databases that power modern research, platforms like JSTOR, Elsevier, and Web of Science, services that major universities elsewhere pay for through multi-million-dollar licensing agreements. The Mabna Institute proposed to solve this problem. Its solution, efficient and entirely without scruple, was simply to steal what it could not buy. Treasury Department sanctions later designated the Mabna Institute and all nine original defendants, effectively blocking their assets. The client, for much of the operation, was the Islamic Revolutionary Guard Corps, the IRGC, the arm of the Iranian government responsible for intelligence gathering. The organizational structure of the Mabna Institute, however, bore a closer resemblance to a mid-size tech firm than to an intelligence agency: founders, a managing director, contractors, hackers retained for specific assignments, affiliates paid by the credential. Espionage, organized with a CFO. The Most Dangerous Message in Academia The indictment , which runs to fifty pages in the Southern District of New York’s precise federal prose, describes the hacking campaign in three phases. The first was reconnaissance. Analysts at the Mabna Institute would profile individual professors, studying their recent publications, identifying their intellectual neighborhoods, sometimes working through footnotes to map their academic circles. The goal was not merely an email address but a portrait. The second phase was the email itself. It arrived from what appeared to be a colleague at another university, someone who had just finished reading your most recent article with genuine enthusiasm and wanted to share a few related papers. Links were helpfully included. If the professor clicked, he was directed to a domain whose name differed from his own university’s address by a single character , or by a different top-level extension, the kind of discrepancy invisible to anyone not specifically looking for it. The page looked exactly like his university’s login portal, because it had been built to. It asked for a username and password. The professor typed them. The page refreshed. Nothing seemed to have happened. The third phase was extraction. Using the stolen credentials, affiliates of the institute logged into victim accounts and transferred everything accessible: academic journals, doctoral dissertations, monographs, raw data, electron...