Therecord.Media Iranian Hacker Extradited for University Breaches Causing $3.4 Billion in Damages
Article Content
- •Amir Barati extradited from Montenegro to the U.S. for hacking charges.
- •The hacking campaign targeted over 150 U.S. universities, causing $3.4 billion in damages.
- •Barati is linked to the Mabna Institute and the IRGC, involved in extensive data theft.
Amir Barati, a 40-year-old Iranian national, was extradited from Montenegro to the U.S. on October 1, 2026, to face charges related to a hacking campaign targeting over 150 U.S. universities and companies. Arrested on June 25, 2026, Barati is accused of participating in a conspiracy that began in 2013, resulting in the theft of at least 31 terabytes of academic data and intellectual property. The U.S. Department of Justice has linked Barati to the Mabna Institute, which allegedly operated on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The indictment claims the hacking operation caused damages exceeding $3.4 billion, with Barati involved in spearphishing campaigns and network reconnaissance. The stolen data was reportedly sold to Iranian universities and used to benefit the IRGC. Barati faces multiple charges, including conspiracy to commit computer fraud and identity theft.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Mabna Institute in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What charges does Barati face?
What was the impact of the hacking?
Who else is involved in this case?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…