An Iranian man charged over the Mabna Institute's hacking of universities is now in American hands. Montenegrin police said on Thursday 1 October that a 40-year-old Iranian-Turkish dual national had been extradited to face hacking charges in New York. Police didn't name him. The Associated Press, CNN and The Record have named him as Amir Barati, one of 17 alleged Mabna members named in a superseding indictment.
It's a rare result. US prosecutors have charged Iranian state-linked hackers again and again over the past decade, but those people almost never end up in an American courtroom. Barati was arrested while on holiday in Kotor, on Montenegro's coast, back in June.
Who Barati is and what he's charged with
The Justice Department unsealed the 14-count superseding indictment on 18 August. It charges 17 people tied to the Mabna Institute. That's a company in Tehran that prosecutors say was set up around 2013 to help Iranian universities and research bodies steal access to foreign scientific resources. Nine of the 17 had already been charged in an indictment made public in March 2018. Barati was one of eight new names.
The indictment spells out his alleged role. Prosecutors say Barati "was involved in tracking the progress of the spearphishing campaigns, exchanging login credentials for compromised accounts with other co-conspirators, creating targeting lists, conducting computer network reconnaissance, and crafting phishing messages."
He faces several counts, including conspiracy to commit computer intrusions, conspiracy to commit wire fraud, wire fraud, computer fraud and aggravated identity theft. The department's charge table lists maximum penalties of 20 years for the wire fraud counts, and a mandatory two years for aggravated identity theft. The case is in the Southern District of New York, before US District Judge Jesse M. Furman.
An indictment is only an allegation. Barati is presumed innocent, and CNN said it couldn't reach a lawyer for him.
How the extradition happened
Montenegrin police said the man was arrested by the country's Interpol office and local police in Kotor, at the request of US authorities including the FBI. The Record reported that the arrest happened on 25 June, and that a Montenegrin court made its final decision to extradite him this week.
The Associated Press reported that police called him a "high-profile" target. They said his arrest and extradition came out of operational and intelligence information swapped between Montenegrin and US agencies.
The police statement never used his name. SecurityWeek noted that police gave only his initials, A.B., and his age, and that the indictment names Amir Barati. The AP, CNN and The Record all name him outright, and CNN also cited a person familiar with the case.
The Southern District of New York declined to comment on the extradition, CNN reported. CNN said Barati is expected to face wire and computer fraud charges there.
So why is this unusual? SecurityWeek pointed out that hackers working for Tehran usually stay inside Iran and keep away from countries that have extradition treaties with the US. Barati had moved. Iran International reported that he went to Turkey in 2021, became a citizen there and legally changed his name. Montenegro, where he was holidaying, acted on the FBI's request.
What the Mabna campaign allegedly did
The numbers in the indictment are huge. Prosecutors say the Mabna Institute broke into computer systems at 144 US universities and 178 foreign ones. It also hit at least 42 US companies and at least 11 foreign companies, at least five US federal and state government agencies, and at least two non-governmental organizations.
The university campaign ran from about 2013 to at least December 2017, according to the indictment. The group went after more than 100,000 professors' accounts and got into roughly 8,000 of them. It stole at least about 31.5 terabytes of academic data and intellectual property, including journals, theses, dissertations and e-books, in every field from engineering to medicine.
Australian universities were on the list. Australia is one of 22 countries the Justice Department names as home to targeted universities, along with Canada, Germany, Japan, the UK and others.
One figure has been widely reported as "damage," and it's worth getting right. The department says US universities spent more than about US$3.4 billion "to procure and access" the data and intellectual property the group went after. That's what the material cost the universities to buy and use. It isn't what the hacking cost them.
There's a second figure. Prosecutors say the group's attacks on companies and at least two government bodies left those victims with more than US$20 million in costs to investigate and clean up. Some reports have pinned that sum on the universities, but the Justice Department ties it to the companies and government bodies.
Prosecutors say the stolen material went to Iran's Islamic Revolutionary Guard Corps and other clients. They allege two websites, Megapaper and Gigapaper, sold it inside Iran. One of them, the indictment says, sold customers direct access to US and foreign university library systems through hacked professors' accounts.
Other alleged targets in the private and public sector include the US Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, UNICEF and the network HBO.
Why it matters now
Iran's hackers aren't a cold case. CNN noted that over seven months of war between the US and Iran, Iran has been a key suspect in cyberattacks on US water systems, fuel station tank gauges and a major medical device maker. We've covered the diplomatic side of the conflict too, including Trump's rejection of Iran's Hormuz roadmap.
Charges like these can sit for years when the people charged stay home. The August indictment came with a reminder from the FBI's Cyber Division. "The FBI's memory is long, and time will not blunt our resolve to pursue justice," Assistant Director Brett Leatherman said at the time.
US Attorney Jamie McDonald made the same point in August: "More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad."
This extradition puts one of the Mabna defendants within reach of a US court.
The rest of the list
Sixteen of the 17 are still out of reach. The State Department's Rewards for Justice program is offering up to US$10 million for information that leads to the location of five of them: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh. The reward details are in the Justice Department's release.
For universities, the lesson hasn't changed since 2018. The campaign didn't need clever malware. It ran on phishing emails and stolen passwords for professors' accounts. Phishing-resistant multifactor login on staff email and library systems makes that kind of campaign much harder. I'm not going to rebuild the phishing pages here. The detail in the indictment is there for defenders, and that's who it's for.
Barati's next stop is a federal courtroom in Manhattan.






The paper
Comments
No notes on this story yet.
Sign in to comment