In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute linked to Iran's IRGC, was extradited to the US from Montenegro. He is charged with cyberattacks targeting hundreds of universities, private companies, government agencies, and NGOs worldwide since 2013, resulting in over $3.4 billion in losses and theft of over 31 terabytes of scientific and intellectual property data. This extradition is notable due to the rarity of Iranian state-linked hackers being brought to trial in the US. Barati reportedly operated from Turkey after 2021, where he gained citizenship and changed his name.
AI Analysis
Technical Summary
Amir Barati, allegedly affiliated with the Iran-based Mabna Institute and the Islamic Revolutionary Guard Corps, was extradited to the US following an FBI arrest warrant executed by Montenegrin authorities. He is indicted for cyber intrusions against 144 US universities, 178 foreign universities, 42 US private companies, 11 foreign companies, five US government agencies, and at least two NGOs. The attacks, ongoing since 2013, involved theft of over 31 terabytes of academic and intellectual property data and employee email accounts, causing financial losses exceeding $3.4 billion. The stolen data was reportedly transferred to the Iranian government and sold to Iranian universities. The US government has issued rewards for information on other Mabna Institute members. The extradition is unusual given typical operational constraints of Iranian state hackers.
Potential Impact
The cyberattacks attributed to Amir Barati and the Mabna Institute caused significant financial losses exceeding $3.4 billion. The theft of over 31 terabytes of scientific resources and intellectual property potentially undermines academic and research institutions' competitive advantage and confidentiality. The compromise of employee email accounts may have led to further information exposure. The attacks targeted a broad range of entities including universities, private companies, government agencies, and NGOs, indicating a wide-reaching impact on multiple sectors.
Mitigation Recommendations
This report concerns a law enforcement action and indictment rather than a specific software vulnerability or exploit. No direct mitigation actions apply. Organizations should continue to follow best practices for protecting sensitive academic and intellectual property data and monitor for indicators of compromise related to Mabna Institute activity as per threat intelligence advisories.
In Rare Move, Alleged Iranian State Hacker Extradited to US
Description
Amir Barati, an alleged member of the Mabna Institute linked to Iran's IRGC, was extradited to the US from Montenegro. He is charged with cyberattacks targeting hundreds of universities, private companies, government agencies, and NGOs worldwide since 2013, resulting in over $3.4 billion in losses and theft of over 31 terabytes of scientific and intellectual property data. This extradition is notable due to the rarity of Iranian state-linked hackers being brought to trial in the US. Barati reportedly operated from Turkey after 2021, where he gained citizenship and changed his name.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Amir Barati, allegedly affiliated with the Iran-based Mabna Institute and the Islamic Revolutionary Guard Corps, was extradited to the US following an FBI arrest warrant executed by Montenegrin authorities. He is indicted for cyber intrusions against 144 US universities, 178 foreign universities, 42 US private companies, 11 foreign companies, five US government agencies, and at least two NGOs. The attacks, ongoing since 2013, involved theft of over 31 terabytes of academic and intellectual property data and employee email accounts, causing financial losses exceeding $3.4 billion. The stolen data was reportedly transferred to the Iranian government and sold to Iranian universities. The US government has issued rewards for information on other Mabna Institute members. The extradition is unusual given typical operational constraints of Iranian state hackers.
Potential Impact
The cyberattacks attributed to Amir Barati and the Mabna Institute caused significant financial losses exceeding $3.4 billion. The theft of over 31 terabytes of scientific resources and intellectual property potentially undermines academic and research institutions' competitive advantage and confidentiality. The compromise of employee email accounts may have led to further information exposure. The attacks targeted a broad range of entities including universities, private companies, government agencies, and NGOs, indicating a wide-reaching impact on multiple sectors.
Defensive Guidance
This report concerns a law enforcement action and indictment rather than a specific software vulnerability or exploit. No direct mitigation actions apply. Organizations should continue to follow best practices for protecting sensitive academic and intellectual property data and monitor for indicators of compromise related to Mabna Institute activity as per threat intelligence advisories.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/","fetched":true,"fetchedAt":"2026-10-02T11:31:08.733Z","wordCount":1017}
Threat ID: 6abf95fca43b0b3b89af88fb
Added to database: 10/02/2026, 11:31:08 UTC
Last enriched: 10/02/2026, 11:31:15 UTC
Last updated: 10/03/2026, 03:53:20 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.