2026-08-20 · view entry permalink →
DOJ's superseding indictment against Iran's Mabna Institute names Switzerland twice — among the countries whose universities were compromised, and among those whose companies had employee mailboxes taken
A 14-count superseding indictment unsealed on 2026-08-18 charges 17 members of the Mabna Institute, an Iran-based company that, in the Department of Justice's words, "since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs)" (U.S. Department of Justice, 2026-08-18). Nine of the seventeen were previously charged in a seven-count indictment announced in March 2018 (U.S. Department of Justice, 2026-08-18); the new filing adds eight defendants (Nextgov/FCW, 2026-08-19). The institute worked on behalf of the Islamic Revolutionary Guard Corps, and the stolen academic material was resold through operator-run websites.
For a European reader the load-bearing detail is in DOJ's own victim breakdown rather than in the headline. The department names the countries hosting the 178 compromised foreign universities — a list that runs from Australia and Canada through Germany, Ireland, Italy, the Netherlands, Norway, Poland, Spain, Sweden and Switzerland to the United Kingdom — and separately describes "at least approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom" whose employee email accounts were compromised (U.S. Department of Justice, 2026-08-18). Swiss universities and Swiss companies are, on the government's own account, inside this campaign's victim set. The conduct is historical — the university campaign is dated from around 2013 through at least December 2017 — so this is not notice of a live intrusion; it is a state-directed collection programme against European academic and corporate research being described, with country-level specificity, in a document published this week.
The tradecraft is worth restating precisely because it is so ordinary. Against universities, DOJ describes members of the conspiracy using stolen account credentials to obtain unauthorised access to professor accounts and using that access to steal research and other academic data; one defendant's specific role was tracking the progress of spearphishing campaigns, exchanging credentials for compromised accounts with co-conspirators, building targeting lists, conducting reconnaissance and crafting phishing messages. Against companies and at least two governmental entities, the new charges name a different method: DOJ alleges three defendants "participated in the Mabana Institute's efforts to hack into private sector companies and at least two governmental entities — including through password spray attacks, obtaining unauthorized access to victim systems, and exfiltrating data — causing victims to suffer an excess of $20 million in costs to investigate and remediate the intrusions" (U.S. Department of Justice, 2026-08-18). Nextgov describes the same operating model from the outside: the institute employed or contracted hackers who ran phishing attacks, looked for vulnerable systems and traded credentials for compromised accounts (Nextgov/FCW, 2026-08-19).
178 universities located in foreign countries, including Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey and the United Kingdom.
at least approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom