Case Law

US Charges 17 Iran-Backed Hackers Targeting US Colleges

United States·Briefly Analysis⏱️ 3 min read

Summary

  • 17 individuals charged with participating in a massive hacking scheme targeting US colleges and universities on behalf of the Iranian government.
  • Hackers compromised emails for over 100,000 college professors worldwide, stealing more than 31 terabytes of academic data and intellectual property from universities.
  • The State Department is offering a reward of up to $10 million for information leading to the location of five defendants named in the indictment.
  • Private sector companies, including tech giants like HBO, were also targeted by the hackers.
  • The charges highlight the need for increased cybersecurity measures at US-based educational institutions.

What Happened

These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government.

Federal prosecutors have unsealed a superseding indictment charging 17 individuals with participating in a massive hacking scheme targeting US colleges, universities, and private sector companies. The scheme, which began at least as far back as 2013, was allegedly conducted on behalf of the Iranian government through the Tehran-based firm Mabna Institute. According to investigators, the hackers compromised emails for over 100,000 college professors worldwide, stealing more than 31 terabytes of academic data and intellectual property from universities. The indictment also reveals that the hackers targeted private sector companies, including tech giants like HBO, as well as government agencies and non-governmental organizations.

Legal Context

This is the second wave of charges against the Mabna Institute, which was initially indicted in 2018 for using spoofed websites and fake login pages to steal data from organizations in the US, Canada, and other countries. The indictment alleges that the defendants used personalized phishing emails to trick unsuspecting professors into clicking on malicious links, which would then direct them to a phony website where they would enter their credentials. The government claims that the hackers targeted over 100,000 professors worldwide with these phishing messages, approximately half of whom were in the US. The State Department is offering a reward of up to $10 million for information leading to the location of five defendants named in the indictment.

Why It Matters

The charges highlight the need for increased cybersecurity measures at US-based educational institutions to prevent similar phishing attacks. Lawyers advising these institutions should review their protocols to ensure compliance with data protection regulations, such as the Higher Education Act. The case also underscores the ongoing threat of state-sponsored hacking campaigns and the importance of international cooperation in pursuing justice against cyber adversaries.

Practical Implications

Lawyers advising US-based educational institutions should review their cybersecurity protocols to prevent similar phishing attacks and ensure compliance with data protection regulations, such as the Higher Education Act.

Source

Source: Original reporting via Courthouse News

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Wansom is AI and can make mistakes.