U.S. Charges 17 Linked to Iran’s Mabna Institute for $6M Bitcoin HBO Extortion and Global Data Heists
U.S. indicts 17 alleged Mabna Institute hackers tied to the IRGC for the 2017 HBO breach, a $6M Bitcoin extortion attempt, and theft of at least 31.5TB from universities and agencies.

Because Bitcoin
August 20, 2026
The Justice Department has unsealed charges against 17 alleged members of Iran-based Mabna Institute, tying the group to a multi-year intrusion spree that swept across universities, companies, and government agencies worldwide—and included the 2017 breach of HBO and an attempted $6 million Bitcoin shakedown.
Prosecutors say the defendants operated on behalf of Iranian government stakeholders, including the Islamic Revolutionary Guard Corps (IRGC), and ran a credential-theft machine at scale. According to the DOJ, the crew targeted more than 100,000 professor accounts globally and ultimately compromised about 8,000 across 144 U.S. universities and 178 institutions abroad. The haul: at least 31 terabytes of research and intellectual property, with prosecutors’ tallies reaching roughly 31.5 TB—theses, journal articles, ebooks, and proprietary data siphoned by spearphishing and stolen credentials.
Authorities named Behzad Mesri—previously charged in the HBO hack—alongside five defendants alleged to have been directly involved in that incident: Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian. Officials characterized Mabna as a hacking-for-hire shop that funneled sensitive data and operational gains to Iranian state and university clients. U.S. Attorney Jamie McDonald for SDNY underscored that even years after the initial indictment became public, the pursuit of overseas actors would continue. The State Department is offering up to $10 million for information leading to the location of five defendants.
What matters for crypto markets is not the headline dollar figure—it’s the state playbook. Bitcoin remains a negotiation rail for extortion because it settles globally and resists censorship at the base layer. Yet that same immutability turns BTC into evidence: on-chain flows can be traced, liquidity is concentrated at exchanges, and pressure on off-ramps often narrows the exit.
You can see that pressure building. In June, Treasury sanctioned four Iranian crypto exchanges, including Nobitex, accusing them of facilitating terrorist financing and sanctions evasion, and linking Nobitex to transactions with IRGC‑affiliated ransomware actors. In July, the U.S. froze more than $131 million across four crypto wallets it tied to Iran’s central bank and armed forces, including the IRGC. By August, two additional exchanges were designated for allegedly laundering millions for the IRGC and other sanctioned entities. This sequence makes the policy intent clear: starve adversaries by constricting liquidity venues, not by attempting to ban protocols outright.
From a risk lens, this case reinforces a few realities: - Crypto payouts are attractive for speed, but identifiable at the compliance edge. Investigations increasingly hinge on tracing, subpoenas, and exchange KYC. - Hacking operations behave like businesses—specialized labor, scalable phishing, monetization via ransomware and data resale. Interrupting their cash-out points often hits hardest. - Sanctions on domestic exchanges can pressure illicit actors, though they may also catch lawful users in the blast radius. That trade-off is showing up more often as geopolitical tensions persist.
No one should overread this as crypto-specific criminality; the entry vector was classic spearphishing, and the prize was academic IP. Bitcoin was the lever at the end of the chain. The strategic takeaway for builders and institutions is straightforward: invest in credential hygiene and defense-in-depth, and assume adversaries will continue to test the boundaries between permissionless money and permissioned liquidity. Enforcement is closing the off-ramps faster than many threat actors adjust.