Iranian Accused of Hacking American Universities Extradited From Montenegro
Amir Barati, a 40-year-old dual Iranian and Turkish national accused by U.S. prosecutors of helping run a years-long hacking campaign against American universities, has been extradited from Montenegro to face charges in the Southern District of New York. Barati was arrested on June 25, 2026, by Montenegro's Police Directorate in the coastal municipality of Kotor after the FBI issued an international arrest warrant, and a Montenegrin court issued a final decision ordering his extradition in late September 2026. He is one of 17 defendants named in a 14-count superseding indictment, unsealed by the Department of Justice in August 2026, accusing members of Iran's Mabna Institute of stealing roughly 31 terabytes of academic data and research on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC).
Incident Details
| Attribute | Value |
|---|---|
| Defendant | Amir Barati, 40, dual Iranian/Turkish national |
| Arrest date | June 25, 2026 |
| Arrest location | Kotor, Montenegro |
| Arresting authority | Montenegro Police Directorate, acting on an FBI-issued warrant |
| Extradition decision | Montenegrin court, late September 2026 |
| Extradited to | United States (Southern District of New York) |
| Indictment | 14-count superseding indictment, unsealed August 18, 2026 |
| Total defendants charged | 17 (9 originally charged in a March 2018 indictment, 8 added in the superseding version) |
| Organization | Mabna Institute (Tehran-based contracting company, founded approximately 2013) |
| Alleged sponsor | Islamic Revolutionary Guard Corps (IRGC) and other Iranian government/university clients |
| Campaign window | Approximately 2013 through at least December 2017 |
| Presiding judge | U.S. District Judge Jesse M. Furman, SDNY |
How the Alleged Campaign Operated
Spearphishing Disguised as Academic Correspondence
Prosecutors allege the Mabna Institute's hackers sent spearphishing emails to professors crafted to look like messages from colleagues at other universities, often flattering the recipient about a recent publication before linking to a spoofed university login page designed to harvest credentials. Investigators say the group targeted more than 100,000 academic email accounts worldwide and successfully compromised roughly 8,000 belonging to professors. Once an account was compromised, the hackers allegedly configured automated forwarding rules so that incoming and outgoing mail was silently copied to the attackers, giving them ongoing access to research communications without needing to log in repeatedly.
A Dual-Purpose Theft and Resale Operation
According to the indictment, the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi to help Iranian universities and research organizations obtain access to scientific resources they could not otherwise reach. Beyond funneling stolen material directly to IRGC and Iranian university clients, prosecutors say the group also monetized the operation commercially, selling stolen research and compromised login credentials through two Iran-based websites, Megapaper.ir and Gigapaper.ir. The stolen data reportedly included academic journals, theses, dissertations, and electronic books spanning science, technology, engineering, social sciences, and medicine.
Barati's Alleged Role
Prosecutors described Barati as a key participant who was "involved in tracking the progress of the spearphishing campaigns, exchanging login credentials for compromised accounts with other co-conspirators, creating targeting lists, conducting computer network reconnaissance, and crafting phishing messages." According to reporting on his background, Barati was reportedly detained by Iran's Ministry of Intelligence in 2010 and coerced into working for Iranian hacking operations; he is also linked to earlier hacker groups including "Iran Black Hats Team" and "Digital Boys Underground Team." He later obtained Turkish citizenship and changed his name in 2021 before being arrested while on vacation in Montenegro.
Scope of the Breaches
The superseding indictment accuses the defendants of breaching 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, at least 11 foreign companies, at least 5 U.S. federal and state government agencies — including the Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, and the State of Indiana — and at least 2 nongovernmental organizations, including the United Nations and UNICEF. Assistant Attorney General for National Security John A. Eisenberg said the defendants "hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value." U.S. Attorney Jamie McDonald for the Southern District of New York said the charges "reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions."
Impact Assessment
| Impact Area | Description |
|---|---|
| Academic data theft | Approximately 31 terabytes of research, theses, dissertations, and journal content stolen from compromised accounts |
| Financial damages | Prosecutors estimate the campaign caused $3.4 billion in damages |
| Remediation costs | Affected universities reportedly spent roughly $20 million investigating and remediating the breaches |
| Credential exposure | Roughly 8,000 professor email accounts compromised out of more than 100,000 targeted |
| Government and NGO exposure | At least 5 U.S. federal/state agencies and 2 international organizations (UN, UNICEF) allegedly breached |
| Commercial exploitation | Stolen research and credentials allegedly resold through Megapaper.ir and Gigapaper.ir, extending harm beyond the original victims |
| Legal precedent | A rare extradition in an Iranian state-linked hacking case, given the absence of a U.S.-Iran extradition treaty |
Recommendations
For Universities and Research Institutions
- Enforce multi-factor authentication on all faculty and staff email accounts, particularly for accounts with access to library systems, research databases, and grant-funded data
- Audit mail-forwarding and mail-filter rules on faculty accounts regularly; unexplained auto-forwarding to external domains is a classic indicator of exactly this style of long-dwell compromise
- Train faculty to scrutinize unsolicited emails referencing their published work, even when the sender appears to be a known colleague, and to verify login pages before entering credentials
- Segment and monitor access to licensed academic databases and library portals, which were reportedly a direct target for resale to unauthorized users
For Security Teams
- Treat credential-harvesting spearphishing aimed at high-value, loosely monitored populations (faculty, researchers, adjuncts) as a distinct risk category from standard corporate phishing programs
- Hunt for anomalous access patterns to academic library and journal-subscription systems that could indicate use of stolen or resold credentials
- Review logs for long-lived forwarding rules or OAuth app grants on mailboxes, since this campaign relied on persistent passive access rather than repeated re-exploitation
For Policymakers and Legal Teams
- Track this case as a model for securing cooperation from third countries where state-linked cyber suspects travel or hold dual citizenship, given the lack of formal extradition channels with Iran
- Institutions that believe their data may be among the material resold through the identified marketplaces should coordinate with federal investigators, since recovered evidence from this prosecution may clarify the scope of exposure
Key Takeaways
- Amir Barati, a dual Iranian-Turkish national, was extradited from Montenegro to the Southern District of New York after his June 2026 arrest in Kotor, marking a rare successful prosecution route for an Iranian state-linked hacking case.
- He is among 17 defendants named in a 14-count superseding indictment tied to Iran's Mabna Institute, which the DOJ says operated on behalf of the IRGC and Iranian university clients.
- The campaign allegedly ran from about 2013 through 2017, breaching 144 U.S. universities, 178 foreign universities, dozens of companies, and several U.S. government agencies and NGOs.
- Attackers allegedly stole roughly 31 terabytes of academic research and compromised about 8,000 professor email accounts out of more than 100,000 targeted, using spearphishing emails disguised as peer correspondence.
- Beyond state use, stolen research and credentials were reportedly resold commercially through the Iran-based sites Megapaper.ir and Gigapaper.ir, extending the campaign's reach well past its original targets.
- Prosecutors put total damages at $3.4 billion, with affected universities spending an estimated $20 million on investigation and remediation — underscoring the long tail of cost from academic credential theft.