NEWS

Iranian Accused of Hacking American Universities Extradited From Montenegro

Amir Barati, accused in a $3.4B IRGC-linked hacking campaign against 144 U.S. universities, was extradited from Montenegro to face charges in New York.

Dylan H.

News Desk

October 1, 2026
7 min read
Iranian Accused of Hacking American Universities Extradited From Montenegro

Iranian Accused of Hacking American Universities Extradited From Montenegro

Amir Barati, a 40-year-old dual Iranian and Turkish national accused by U.S. prosecutors of helping run a years-long hacking campaign against American universities, has been extradited from Montenegro to face charges in the Southern District of New York. Barati was arrested on June 25, 2026, by Montenegro's Police Directorate in the coastal municipality of Kotor after the FBI issued an international arrest warrant, and a Montenegrin court issued a final decision ordering his extradition in late September 2026. He is one of 17 defendants named in a 14-count superseding indictment, unsealed by the Department of Justice in August 2026, accusing members of Iran's Mabna Institute of stealing roughly 31 terabytes of academic data and research on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC).


Incident Details

AttributeValue
DefendantAmir Barati, 40, dual Iranian/Turkish national
Arrest dateJune 25, 2026
Arrest locationKotor, Montenegro
Arresting authorityMontenegro Police Directorate, acting on an FBI-issued warrant
Extradition decisionMontenegrin court, late September 2026
Extradited toUnited States (Southern District of New York)
Indictment14-count superseding indictment, unsealed August 18, 2026
Total defendants charged17 (9 originally charged in a March 2018 indictment, 8 added in the superseding version)
OrganizationMabna Institute (Tehran-based contracting company, founded approximately 2013)
Alleged sponsorIslamic Revolutionary Guard Corps (IRGC) and other Iranian government/university clients
Campaign windowApproximately 2013 through at least December 2017
Presiding judgeU.S. District Judge Jesse M. Furman, SDNY

How the Alleged Campaign Operated

Spearphishing Disguised as Academic Correspondence

Prosecutors allege the Mabna Institute's hackers sent spearphishing emails to professors crafted to look like messages from colleagues at other universities, often flattering the recipient about a recent publication before linking to a spoofed university login page designed to harvest credentials. Investigators say the group targeted more than 100,000 academic email accounts worldwide and successfully compromised roughly 8,000 belonging to professors. Once an account was compromised, the hackers allegedly configured automated forwarding rules so that incoming and outgoing mail was silently copied to the attackers, giving them ongoing access to research communications without needing to log in repeatedly.

A Dual-Purpose Theft and Resale Operation

According to the indictment, the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to help Iranian universities and research organizations obtain access to scientific resources they could not otherwise reach. Beyond funneling stolen material directly to IRGC and Iranian university clients, prosecutors say the group also monetized the operation commercially, selling stolen research and compromised login credentials through two Iran-based websites, Megapaper.ir and Gigapaper.ir. The stolen data reportedly included academic journals, theses, dissertations, and electronic books spanning science, technology, engineering, social sciences, and medicine.

Barati's Alleged Role

Prosecutors described Barati as a key participant who was "involved in tracking the progress of the spearphishing campaigns, exchanging login credentials for compromised accounts with other co-conspirators, creating targeting lists, conducting computer network reconnaissance, and crafting phishing messages." According to reporting on his background, Barati was reportedly detained by Iran's Ministry of Intelligence in 2010 and coerced into working for Iranian hacking operations; he is also linked to earlier hacker groups including "Iran Black Hats Team" and "Digital Boys Underground Team." He later obtained Turkish citizenship and changed his name in 2021 before being arrested while on vacation in Montenegro.

Scope of the Breaches

The superseding indictment accuses the defendants of breaching 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, at least 11 foreign companies, at least 5 U.S. federal and state government agencies — including the Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, and the State of Indiana — and at least 2 nongovernmental organizations, including the United Nations and UNICEF. Assistant Attorney General for National Security John A. Eisenberg said the defendants "hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value." U.S. Attorney Jamie McDonald for the Southern District of New York said the charges "reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions."

Impact Assessment

Impact AreaDescription
Academic data theftApproximately 31 terabytes of research, theses, dissertations, and journal content stolen from compromised accounts
Financial damagesProsecutors estimate the campaign caused $3.4 billion in damages
Remediation costsAffected universities reportedly spent roughly $20 million investigating and remediating the breaches
Credential exposureRoughly 8,000 professor email accounts compromised out of more than 100,000 targeted
Government and NGO exposureAt least 5 U.S. federal/state agencies and 2 international organizations (UN, UNICEF) allegedly breached
Commercial exploitationStolen research and credentials allegedly resold through Megapaper.ir and Gigapaper.ir, extending harm beyond the original victims
Legal precedentA rare extradition in an Iranian state-linked hacking case, given the absence of a U.S.-Iran extradition treaty

Recommendations

For Universities and Research Institutions

  • Enforce multi-factor authentication on all faculty and staff email accounts, particularly for accounts with access to library systems, research databases, and grant-funded data
  • Audit mail-forwarding and mail-filter rules on faculty accounts regularly; unexplained auto-forwarding to external domains is a classic indicator of exactly this style of long-dwell compromise
  • Train faculty to scrutinize unsolicited emails referencing their published work, even when the sender appears to be a known colleague, and to verify login pages before entering credentials
  • Segment and monitor access to licensed academic databases and library portals, which were reportedly a direct target for resale to unauthorized users

For Security Teams

  • Treat credential-harvesting spearphishing aimed at high-value, loosely monitored populations (faculty, researchers, adjuncts) as a distinct risk category from standard corporate phishing programs
  • Hunt for anomalous access patterns to academic library and journal-subscription systems that could indicate use of stolen or resold credentials
  • Review logs for long-lived forwarding rules or OAuth app grants on mailboxes, since this campaign relied on persistent passive access rather than repeated re-exploitation
  • Track this case as a model for securing cooperation from third countries where state-linked cyber suspects travel or hold dual citizenship, given the lack of formal extradition channels with Iran
  • Institutions that believe their data may be among the material resold through the identified marketplaces should coordinate with federal investigators, since recovered evidence from this prosecution may clarify the scope of exposure

Key Takeaways

  1. Amir Barati, a dual Iranian-Turkish national, was extradited from Montenegro to the Southern District of New York after his June 2026 arrest in Kotor, marking a rare successful prosecution route for an Iranian state-linked hacking case.
  2. He is among 17 defendants named in a 14-count superseding indictment tied to Iran's Mabna Institute, which the DOJ says operated on behalf of the IRGC and Iranian university clients.
  3. The campaign allegedly ran from about 2013 through 2017, breaching 144 U.S. universities, 178 foreign universities, dozens of companies, and several U.S. government agencies and NGOs.
  4. Attackers allegedly stole roughly 31 terabytes of academic research and compromised about 8,000 professor email accounts out of more than 100,000 targeted, using spearphishing emails disguised as peer correspondence.
  5. Beyond state use, stolen research and credentials were reportedly resold commercially through the Iran-based sites Megapaper.ir and Gigapaper.ir, extending the campaign's reach well past its original targets.
  6. Prosecutors put total damages at $3.4 billion, with affected universities spending an estimated $20 million on investigation and remediation — underscoring the long tail of cost from academic credential theft.

Sources