DOJ Expands Iran-Linked Mabna Hacking Case to 17 Defendants, Six Tied to HBO Breach
Key Takeaways
- •The 2026 filing adds eight new defendants to the Mabna Institute case, which now includes 17 charged members.
- •Prosecutors allege the group hacked on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian clients.
- •Six defendants are tied to HBO’s 2017 breach, where an extortion demand rose to about $6 million in Bitcoin.
- •The broader campaign allegedly targeted more than 100,000 professor accounts and exfiltrated over 31 terabytes of academic data from universities.
- •The case is backed by earlier OFAC sanctions and a State Department reward of up to $10 million for information on five fugitives.

The US Justice Department has unsealed a 14-count second superseding indictment charging 17 members of the Iran-based Mabna Institute, according to the DOJ. The filing, dated August 18, 2026, expands an existing prosecution rather than opening a fresh standalone case. A superseding indictment formally replaces the prior charging document on the same docket, which is how prosecutors widen a live case without filing a new one.
Nine of the defendants were first charged in March 2018, meaning the 2026 filing added eight new names. Prosecutors allege the group carried out numerous intrusions on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC) as well as other Iranian government and university clients.
Six defendants tied to HBO’s 2017 breach
According to the DOJ, six defendants — Behzad Mesri, Houshyar, Hashemloo, Fayaz, Ballojeh, and Kahzadian — were involved in the hack of HBO, with Mesri (identified in the earlier proceeding by the online handle “Skote Vahshat”) previously charged separately in United States v. Behzad Mesri, 17 Cr. 689 (AJN). The HBO connection gives the sprawling case a concrete, recognizable anchor.
The 2017 Southern District of New York case detailed how Mesri sought roughly $6 million worth of Bitcoin from HBO, with the demand escalating from $5.5 million on July 23, 2017 to the higher figure by July 26, 2017, per the Manhattan US Attorney. The incident stands as one of the earliest high-profile examples of unreleased media content being held hostage for cryptocurrency.
The HBO breach matters to the broader narrative because it shows the campaign was not limited to bulk data theft. It included a targeted, monetized extortion attempt against a marquee content owner, blurring the line between espionage and cybercrime.
Why the case expansion matters for media and digital security
Beyond HBO, the Mabna campaign targeted more than 100,000 professor accounts and compromised approximately 8,000 professor email accounts across 144 US-based universities and 178 foreign universities, exfiltrating more than 31 terabytes of academic data, as reported by Cybersecurity Dive. The enlarged defendant count signals a scope far wider than a single isolated breach.
Check Point’s Shmuel Gihon described Mabna as a state-linked contractor model rather than a purely state-owned espionage unit, framing the group as an outsourced arm of Iranian intelligence.
“Mabna represents the privatization of state espionage.” — Shmuel Gihon, Check Point, via Cybersecurity Dive
The enforcement picture stacks criminal charges on top of earlier sanctions. Treasury’s Office of Foreign Assets Control (OFAC) designated the Mabna Institute and 10 Iranian individuals on March 23, 2018, and separately noted that Mesri attempted to extort a US media company, Treasury said. OFAC designations block property subject to US jurisdiction and generally prohibit US persons from transacting with the named parties, extending financial pressure regardless of where the defendants physically remain.
The case remains active. The State Department’s Rewards for Justice program is offering up to $10 million for information leading to five defendants identified as fugitives.
For media companies, marketplaces, and any platform custodying valuable digital property, the takeaway is plain: creative assets and content pipelines are extortion targets, and Bitcoin’s pseudonymity keeps it a favored settlement rail for ransom demands. That reality shadows the same digital-ownership infrastructure powering deals such as McLaren’s Hedera digital collectibles launch, where provenance and security are core selling points.
The regulatory backdrop is also shifting beneath creators’ feet, with the SEC’s token project securities lifecycle policy reshaping how on-chain assets are classified even as criminal enforcement targets the actors who abuse them. Bitcoin traded near $77,204 at the time of the filing, though analysts framed the indictment as a cybercrime and sanctions story rather than a market catalyst.
The full legal weight of the expanded case will hinge on confirmed court proceedings and any arrests tied to the fugitive bounties. The United States and Iran have no extradition treaty, meaning a defendant would need to be apprehended outside Iran before the charges could be tested in a US courtroom. For now, the enforcement stack — criminal charges, OFAC sanctions, and a renewed reward — keeps a nearly decade-old media hack firmly in the present tense.