US Charges Say Iran’s Academic Espionage Contractors Also Sold the Data They Stole.
A new US superseding indictment alleges that members of Iran’s Mabna Institute stole academic research for the Islamic Revolutionary Guard Corps and other clients while also selling stolen material and compromised university access to paying customers. The allegations describe state espionage and commercial cybercrime as two uses of the same intrusion operation.
The distinction matters because organisations often place nation-state activity and financially motivated crime in separate threat models.
The 14-count indictment unsealed on 18 August does not support such a clean boundary. US prosecutors allege that the same network of contractors served Iranian state intelligence requirements, accepted work from other government and private clients, and monetised the resulting access through commercial websites.
These are allegations. The 17 defendants are presumed innocent unless and until proven guilty.
The new indictment expands an older case
The US Justice Department first announced charges against nine alleged Mabna Institute members in 2018. The new superseding indictment adds eight defendants and sets out a broader network of founders, contractors, hackers-for-hire and affiliates.
Prosecutors say the Tehran-based institute was founded in approximately 2013 to help Iranian universities and research organisations obtain access to scientific resources outside Iran. They allege that Mabna employed or contracted technical personnel to steal academic data, intellectual property, email inboxes and other proprietary information.
The alleged victim set is global. The Justice Department says the campaign reached 144 US universities and 178 foreign universities, at least 42 US private-sector companies, at least 11 foreign companies, at least five US federal and state agencies, and at least two non-governmental organisations.
Named government and NGO targets include the US Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF.
The indictment also connects some of the additional defendants to the intrusion at HBO and to password-spraying campaigns against companies and government entities. Prosecutors say those private-sector and governmental intrusions caused more than $20 million in investigation and remediation costs.
More than 100,000 professor accounts were allegedly targeted
According to prosecutors, the university campaign targeted more than 100,000 professor accounts and successfully compromised approximately 8,000 of them.
The alleged method relied heavily on identity rather than exotic infrastructure exploits. Members of the operation researched academics, crafted messages that appeared to come from colleagues and directed victims to counterfeit university login pages. Stolen credentials were then used to enter professor accounts and university library systems.
The Justice Department says the defendants stole approximately 31.5 terabytes of journals, theses, dissertations, electronic books and other academic data across science, engineering, medicine, social sciences and other fields. US universities had spent more than $3.4 billion to procure and access the affected material, according to the indictment.
That figure is not a valuation of a single secret formula. It reflects the accumulated cost and breadth of institutional access that one compromised identity can unlock.
Universities are particularly exposed to this model. Researchers collaborate across organisational boundaries, receive unsolicited messages about their work and depend on federated access to large collections of licensed material. Those are legitimate academic behaviours. They are also useful camouflage for credential theft.
The stolen material allegedly became a product
The most revealing part of the case is not the volume of data. It is what prosecutors say happened after the theft.
The indictment alleges that academic material and login credentials were used for the benefit of the Iranian government, including the IRGC, and other Iranian government and university clients. It also alleges that stolen material was sold through two commercial websites, Megapaper.ir and Gigapaper.ir.
According to the Justice Department, Megapaper sold stolen academic resources to customers inside Iran, including public universities and institutions. Gigapaper allegedly sold a service that let customers use compromised professor accounts to access US and foreign university libraries directly.
Those are two different forms of monetisation. One treats exfiltrated documents as inventory. The other treats the victim’s live identity and institutional entitlements as a reusable service.
The second model is especially damaging because the account remains valuable until the credential is changed, the session is revoked or the abuse is detected. A customer can request material on demand while the original university continues to pay for the subscription and infrastructure that delivers it.
State tasking and private profit can share infrastructure
Security programmes often assume that an espionage contractor will use access only for the state objective that justified the intrusion. The allegations in this case show why that assumption is dangerous.
A contractor can satisfy a government client, retain credentials, resell documents, provide access to another customer or reuse the same infrastructure for a separate commercial target. The original tasking does not impose a technical boundary on what happens next.
That creates a wider risk than a narrow intelligence collection requirement. Once credentials and data enter a contractor ecosystem, the victim cannot know how many customers, affiliates or later operations may receive them.
It also complicates attribution. A login from Mabna-associated infrastructure might support an IRGC requirement, an Iranian university, a private customer or several of those interests at once. Motivation cannot be inferred safely from infrastructure alone.
The better defensive assumption is that access will be used wherever it has value.
What universities should take from the allegations
- Protect faculty identities with phishing-resistant MFA. Research prominence should be treated as an exposure factor, not a reason to tolerate weaker authentication.
- Separate library access from broad account authority. A credential used to retrieve journals should not automatically provide the same path to email, cloud storage and administrative systems.
- Detect credential use, not only credential theft. Monitor impossible travel, unusual library-download volume, new devices, repeated federated logins and access patterns that do not match the researcher’s normal work.
- Revoke sessions during response. Changing a password without invalidating active sessions or application tokens may leave the commercial access path intact.
- Include publishers and identity providers in investigations. The abuse can cross university, federation, library platform and content-provider logs.
- Prepare researchers for tailored contact. Training should cover messages that cite real papers, colleagues and conferences, because personalisation is part of the alleged method.
- Treat licensed collections as theft targets. Data-loss controls should account for systematic academic downloads as well as conventional confidential files.
The business model is the warning
The Justice Department’s charges are not a finding of guilt. They are, however, a detailed allegation about how an espionage contractor can operate.
The alleged model did not choose between state-sponsored theft and commercial cybercrime. It combined them. Government tasking helped create demand, contractors provided the intrusion capability, and commercial sites turned stolen research and compromised accounts into products.
For defenders, the practical conclusion is simple. A state-linked intrusion does not mean financial motives disappear, and a commercial resale market does not make the state relationship irrelevant.
The same stolen identity can serve both.
Sources and further reading
- US Department of Justice: 17 Iranians Charged With Conducting Massive Cyber Theft Campaign
- US Treasury: Sanctions on Mabna Institute and associated actors
Continue the series: AMER Cyber & Digital Law Series index


