The US this week charged 17 Mabna Institute members for intrusions that hit hundreds of universities and organizations in the US and abroad, and paired the case with rewards of up to $10 million for five suspects. The Justice Department says the Iran-based group worked for the IRGC and stole more than 31 terabytes of academic data, intellectual property, and employee email accounts.
According to the indictment, the attackers logged into real professor inboxes, then used those trusted accounts to pull down more documents and send data onward as if it belonged there. The same material was then sold through Megapaper and Gigapaper, turning stolen access into a resale channel instead of a one-time theft.
That leaves a wider problem than a set of breached schools: any research or collaboration environment that depends on staff email as a trust signal can have data and identity reused after the first compromise. The case also shows how long-running espionage can persist as a black-market asset even after the initial inbox theft is old news.