Posted on — Leave a comment

State-backed Iranian hacker extradited to US in $3.4B university data heist case

Flag of Iran

An Iranian-Turkish dual national accused of helping run one of Iran’s largest state-backed academic hacking operations has now been flown to New York to face US charges, marking a rare extradition of an alleged Iranian cyber operative.

Montenegrin authorities confirmed that 40-year-old Amir Barati was extradited to the United States on October 1 after his arrest in the coastal town of Kotor in June at the request of the FBI and Interpol.

As first reported by Tom’s Hardware, US prosecutors say Barati’s case stems from a years-long campaign that allegedly stole cutting-edge research from universities and companies around the world.

Barati is one of 17 Iranian nationals charged in a superseding indictment unsealed in August in the Southern District of New York, where he faces counts including conspiracy to commit computer fraud, wire fraud, hacking, and identity theft.

The defendants are described by the US Department of Justice as leaders, contractors, and hackers-for-hire tied to the Mabna Institute, an Iran-based company that allegedly ran coordinated intrusions on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients.

US officials say Mabna functioned as an outsourced cyber unit for Iranian institutions, supplying stolen access to foreign academic databases and research in exchange for funding and political protection.

According to court documents and DOJ statements, the Mabna campaign began around 2013 and continued through at least 2017, targeting more than 100,000 professor accounts worldwide with tailored spear-phishing emails designed to steal university login credentials.

Investigators say the group successfully compromised roughly 8,000 email accounts across 144 US universities and 178 universities in 21 other countries, along with systems at 42 US companies, 11 foreign firms, and at least five government agencies including the Department of Labor and the Federal Energy Regulatory Commission.

Prosecutors estimate that the attackers stole at least 31 terabytes of data and caused over $3.4 billion in losses and remediation costs through the theft of academic articles, intellectual property, and proprietary corporate research.

Targets also reportedly included the United Nations and UNICEF, underscoring how wide-reaching the operation became before it was publicly exposed and indicted.

Our Sponsors

In the grand scheme of the operation, Barati is accused of acting as a coordinator and tracker for active intrusions, helping monitor which spear-phishing waves had succeeded and which targets still needed to be hit.

DOJ filings describe him as exchanging stolen login credentials with co-conspirators, building targeting lists for private-sector victims, conducting reconnaissance of network defenses, and helping craft phishing messages made to look like routine academic communications.

Investigators say Barati and several colleagues operated under online handles such as “bc.monster” as they moved stolen account details and data among Mabna-linked infrastructure.

Despite years of US indictments against alleged Iranian hackers, most have remained out of reach in Iran, so Montenegro’s decision to detain and extradite Barati stands out as a rare instance where an accused state-backed operator will actually stand trial in a US courtroom.

Montenegrin police credit close intelligence sharing with US agencies for Barati’s June arrest, reportedly carried out by the country’s Interpol office and local authorities after he entered the small Balkan nation.

The High Court in Podgorica later approved extradition under a simplified procedure, clearing the way for Barati’s transfer to US custody this week.

The FBI has long framed Mabna as a case study in how governments can weaponize hired hackers to compensate for domestic research gaps and sanctions pressure, blurring the line between espionage and straight-up cybercrime.

Back in 2018, nine other Mabna-linked operatives were charged over the same overarching campaign but were never extradited, leaving those earlier indictments largely symbolic; Barati’s arrival on US soil shifts that calculus by putting a named Mabna defendant directly before a US judge.

For universities, tech companies, and creatives whose work often lives inside institutional networks, the case is a reminder that nation-state threat actors are not just aiming at critical infrastructure but also at the ideas powering tomorrow’s science, entertainment, and technology.

Barati is expected to be arraigned in the coming days in federal court in Manhattan, and if the case proceeds to trial, it could offer a rare public window into how a state-directed cyber mercenary outfit turns stolen logins into strategic advantage for a government on the global stage.

Our Sponsors

Geeks talk back