Alleged Iranian Hacker Extradited to U.S. for Massive Academic Data Theft
An Iranian national, **Amir Barati**, accused of orchestrating dozens of breaches to steal academic data and intellectual property on behalf of Iran's **Islamic Revolutionary Guard Corps (IRGC)**, has been extradited from Montenegro to the United States. The alleged campaign targeted universities and research institutions globally, resulting in the theft of vast amounts of sensitive information and an estimated $3.4 billion in damages.
A significant development in the ongoing battle against state-sponsored cyber espionage unfolded recently, as **Amir Barati**, a 40-year-old individual holding both Turkish and Iranian citizenship, was extradited from Montenegro to face charges in the U.S.
**Barati** was apprehended on June 25 by Montenegroβs Police Directorate, following an arrest warrant issued by the **FBI**. His extradition marks a crucial step in a case that has been under investigation for several years.
### The Mabna Institute Connection
In August, the **Justice Department (DOJ)** named **Barati** in a 14-count indictment. The indictment charges 17 individuals in connection with an extensive cyber campaign prosecutors attribute to the **Mabna Institute**, an Iranian company allegedly operating on behalf of the **IRGC**.
**Barati** was detained in the coastal municipality of Kotor during a vacation when a Montenegrin court issued the final decision for his extradition.
### Architect of a Global Data Heist
Prosecutors allege **Barati** was a central figure in an operation that saw Iranian hackers compromise email inboxes at universities and research institutions worldwide. This sophisticated campaign reportedly led to the theft of at least 31 terabytes of information and intellectual property.
The stolen data included academic journals, theses, dissertations, and electronic books across numerous fields. U.S. officials estimate the group's activities caused approximately $3.4 billion in damages.
### Spearphishing and Reconnaissance
According to the **DOJ**, **Barati**'s alleged involvement encompassed tracking spearphishing campaign progress, exchanging compromised account credentials with co-conspirators, creating targeting lists, conducting computer network reconnaissance, and crafting phishing messages.
The group is accused of breaching 144 American universities and 42 U.S. companies, alongside 178 foreign universities and at least 11 foreign companies.
### Compromising Academic Credentials
The university hacking campaign, active between 2013 and 2017, allegedly successfully targeted about 8,000 email accounts belonging to professors. The hackers reportedly used stolen credentials to gain unauthorized access to these accounts.
### Monetization and State Sponsorship
Once stolen, the documents were allegedly provided to the Iranian government and subsequently sold through two websites to universities within Iran. One of these websites reportedly allowed Iranian customers to use stolen professor accounts to access the online library systems of multiple U.S. universities.
The breaches necessitated significant remediation efforts, with universities reportedly spending around $20 million to investigate and address the intrusions.
### Charges and Prior History
**Barati** faces multiple charges, including conspiracy to commit computer intrusions, wire fraud, computer fraud, and identity theft.
Reports from Iran International indicate **Barati** has a long history as a hacker in Iran, having founded prominent groups such as the **Iran Black Hats Team** and **Digital Boys Underground Team**, which were accused of attacking entities like **Microsoft** and **MIT**. The news outlet also reported that he was arrested by Iran's Intelligence Ministry in 2010 and coerced into working for them for several years. He reportedly became a Turkish citizen and changed his name in 2021 after leaving Iran.