DOJ Charges 17 in Iran-Backed Hacking Campaign
PUBLISHED Aug 19, 2026, 3:32 AM ET
Read, Watch or Listen
The U.S. Department of Justice unsealed a superseding indictment charging seventeen individuals linked to the Iran-based Mabna Institute with an extensive state-sponsored cyber intrusion campaign. Operating since 2013 on behalf of the Islamic Revolutionary Guard Corps and other entities, the defendants executed coordinated spearphishing and credential-harvesting operations targeting American and international institutions. Prosecutors stated that the multiyear hacking scheme compromised 144 U.S. universities, 42 private-sector corporations, and multiple government agencies, resulting in the theft of over 31 terabytes of sensitive academic data and proprietary intellectual property. U.S. Attorney Jamie McDonald emphasized that the sweeping operation systematically siphoned critical research from domestic networks. While the suspects remain abroad and outside immediate U.S. jurisdiction, federal law enforcement agencies continue coordinated actions, including financial sanctions and rewards programs, to disrupt their global mobility and deter ongoing state-sponsored intellectual property theft.
By Daniel Hayes | JQJO News
Timeline of Events
- On January 1, 2013, the Mabna Institute began coordinated state-sponsored cyber intrusion operations.
- On March 22, 2018, initial federal indictments targeted members of the hacking organization.
- On December 31, 2017, the primary multiyear data theft conspiracy phase officially concluded.
- On August 17, 2026, federal prosecutors finalized the new expanded superseding indictment files.
- On August 18, 2026, the U.S. Department of Justice officially unsealed charges.
- On August 18, 2026, officials detailed 31 terabytes of stolen academic data.
- On August 18, 2026, investigators highlighted compromises across 144 American universities.
- On August 19, 2026, international news outlets widely analyzed the security implications.
- In future months, federal authorities will maintain travel restrictions on suspects.
- In coming years, targeted institutions will upgrade institutional cybersecurity defenses.
News Intelligence
- Immediate US impact: Federal agencies escalated defensive postures against state-sponsored digital espionage threats.
- Possible long-term US impact: Long-term institutional network resilience against foreign hacking organizations will improve significantly.
- Most affected groups: Affected academic research institutions, technology corporations, and government defense contractors.
- Prioritization: Monitor official Department of Justice announcements and verified cybersecurity advisory bulletins.
- Articles Published:
- 31
- Right Leaning:
- 1
- Left Leaning:
- 3
- Neutral:
- 27
- Distribution:
- Left 10%, Center 87%, Right 3%
Left: Highlighting institutional security failures and corporate vulnerability to foreign threats. Center: Reporting official government indictments and law enforcement case details objectively. Right: Emphasizing foreign aggression and the necessity for aggressive national security deterrence.
Department of Justice unsealed indictments against seventeen hackers on August 18, 2026. https://www.justice.gov/usao-sdny/pr/17-iranian-charged-conducting-massive-cyber-theft-campaign-behalf-islamic
Coverage of Story:
From Left
DOJ indicts 17 individuals in massive Iran-backed intellectual property theft scheme
CNN NBC News The GuardianFrom Center
DOJ Charges 17 in Iran-Backed Hacking Campaign
Cybersecurity Dive Department of Justice Cybersecurity Dive Courthouse News KFI AM 640 Internazionale Reuters US News & World Report The Hill Politico Associated Press Bloomberg Wall Street Journal Washington Post ABC News CBS News CNBC ZDNet Dark Reading Bleeping Computer The Record SecurityWeek Wired Ars Technica Forbes Financial Times BBC NewsFrom Right
Justice Department targets Iran-backed hackers in sweeping intellectual property indictment
Fox News
Comments