US charges eight Iranian nationals in sweeping cyber campaign targeting government agencies and universities

By Daniel Brooks|Global Trade and Policy Correspondent
US charges eight Iranian nationals in sweeping cyber campaign targeting government agencies and universities

The U.S. Justice Department on Tuesday filed charges against eight Iranian nationals, accusing them of playing central roles in a years-long hacking campaign that breached five federal and state agencies, dozens of American universities, and multiple private companies. The indictment portrays the operation as a systematic effort to harvest sensitive data and intellectual property, often for the benefit of Iran's Islamic Revolutionary Guard Corps (IRGC).

According to prosecutors, the group broke into government and corporate email systems and targeted roughly 8,000 email accounts belonging to professors and researchers across the United States, Europe, and elsewhere. The stolen academic material—including research data and other intellectual property—cost U.S. universities an estimated $3.4 billion to procure and access, the indictment says. In several instances, the hackers sold access to the digital libraries of American universities to Iranian buyers, allowing them to bypass paywalls and licensing agreements.

The alleged victims include the Department of Labor, the Federal Energy Regulatory Commission, and the United Nations. Outside of academia and government, the hackers are said to have compromised 11 technology companies and two defense contractors, none of which were publicly named by the Justice Department.

Federal officials described the campaign as a direct extension of Iranian state strategy. “Backed by the IRGC, this operation reflects a broader, organized effort to target U.S. institutions and global partners,” FBI Assistant Director in Charge James C. Barnacle Jr. said in a statement Tuesday.

The hacking activity dates back years, but the charges arrive at a moment of heightened concern over Iranian cyber operations. Over the past six months alone, Tehran has been linked to intrusions targeting American water utilities, gas station payment systems, a major medical device manufacturer, and even the personal email account of FBI Director Kash Patel. The new charges are part of a superseding indictment that now names 17 defendants in total; nine other individuals were charged in 2018.

Analysts say the latest case underscores a persistent threat: Iran's ability to use relatively low-cost cyber operations to impose significant financial and strategic costs on U.S. institutions. The indictment also reveals how deeply the hacking ecosystem is intertwined with the Iranian state. One of the newly charged individuals reportedly worked on a website project linked to Iran's supreme leader. Another is accused of conducting computer network attacks for the Iranian military against military systems, nuclear software, and Israeli infrastructure.

CNN has reached out to Iran's Permanent Mission to the United Nations for comment on the charges. The case adds to a growing list of U.S. actions aimed at exposing and countering Iranian cyber espionage, even as diplomatic tensions between Washington and Tehran remain acute.

Share

This Post Has 0 Comments

No comments yet. Be the first to comment!

Leave a Reply