The U.S. Department of Justice has significantly expanded its case against members of the Iran-based Mabna Institute, adding eight new defendants and bringing the total number of individuals charged in the broader cyber-espionage case to 17. The latest indictments, contained in a 14-count second superseding indictment unsealed on August 18, link six of the newly charged defendants directly to the 2017 HBO breach, which included an attempted Bitcoin extortion of approximately $6 million.
According to prosecutors, Mabna operated as a private company carrying out cyber intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and other government, university, and private-sector clients. The defendants linked to the HBO hack include Behzad Mesri, Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian.
The HBO intrusion involved hackers allegedly stealing unreleased television episodes, scripts, and other proprietary material. Prosecutors stated the ransom demand began at $5.5 million and rose to roughly $6 million in Bitcoin before stolen HBO content was leaked online. The Justice Department has not alleged that HBO paid the ransom. Mesri had previously been charged separately over the HBO attack in 2017, and the new indictment brings that episode into the broader Mabna prosecution rather than alleging a fresh breach.
The Mabna operation extended well beyond HBO. Prosecutors allege the group targeted more than 100,000 professor accounts, successfully compromising about 8,000 of them and stealing at least 31.5 terabytes of academic data and intellectual property through activity that continued until at least December 2017. The government also alleges that Galekuhi, Fayaz, and Ballojeh participated in attacks against private-sector and government organizations that caused more than $20 million in investigation and remediation costs.
Alongside the indictment, the State Department's Rewards for Justice program offered rewards of up to $10 million for information leading to the location of key defendants. The case underscores the ongoing threat posed by state-sponsored hacking groups and the increasing use of cryptocurrency in ransom demands. Bitcoin's pseudonymous nature has made it a preferred payment method for ransomware attacks, highlighting the intersection of cybercrime and digital currencies.