Security News

Alleged Iranian Hacker Behind Global University Breaches Extradited to US

The Record · 2 Oct 2026
Key Takeaway Train staff to recognise spearphishing emails and enforce multi-factor authentication on email accounts, since stolen credentials remain one of the most common ways attackers gain long-term access.

Amir Barati, a 40 year old dual Turkish and Iranian citizen, has been extradited from Montenegro to the United States following his arrest in June while on vacation. He is accused of playing a key role in a campaign allegedly run through Iran's Mabna Institute on behalf of the Islamic Revolutionary Guard Corps, which targeted universities and research institutions around the world.

Prosecutors say the operation used spearphishing emails to compromise around 8,000 professor email accounts between 2013 and 2017, stealing at least 31 terabytes of academic journals, theses, dissertations and other intellectual property. The group allegedly breached 144 American universities and 42 US companies, along with 178 foreign universities and at least 11 foreign companies, causing an estimated $3.4 billion in damages. Stolen material was reportedly passed to the Iranian government and sold to Iranian universities through dedicated websites.

Barati faces charges including conspiracy to commit computer intrusions, wire fraud, computer fraud and identity theft. US officials say affected universities spent about $20 million investigating and remediating the breaches, highlighting the high cost of credential theft campaigns even for well-resourced institutions.

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.