US prosecutors have expanded a long-running Iran-linked hacking case to 17 defendants, tying six of the newly charged individuals to HBO’s 2017 breach and the attempted $6 million Bitcoin extortion that followed. The Justice Department’s second superseding indictment folds a marquee media hack into a sprawling state-backed cyber theft campaign that spanned universities, companies, and government agencies.
What changed in the expanded US hacking case
On August 18, 2026, the DOJ unsealed a 14-count second superseding indictment charging 17 alleged members of the Iran-based Mabna Institute over a cyber theft campaign carried out on behalf of the Islamic Revolutionary Guard Corps, according to the Justice Department.
The expansion nearly doubles the original prosecution, which charged nine Mabna defendants in 2018, and consolidates the separate HBO extortion case into one IRGC-linked narrative. All charges remain allegations unless proven in court.
The scale of the underlying operation is what sets the case apart. Prosecutors said the Mabna campaign targeted 144 U.S. universities, 178 foreign universities, 42 U.S. companies, and five U.S. federal or state agencies, alongside foreign firms and NGOs.
Why the HBO 2017 breach connection stands out
The most recognizable thread in the indictment is HBO. Prosecutors say six of the newly charged defendants were directly involved in the 2017 intrusion at the media company, while Behzad Mesri had already been charged separately for that attack in 2017.
The original SDNY case remains the clearest window into the extortion mechanics. Mesri first demanded $5.5 million in Bitcoin from HBO and then raised the demand before stolen data was leaked online, the 2017 filing said.
Folding a household-name media hack into a state-espionage indictment broadens the case well beyond academia, connecting a headline-grabbing ransom plot to the same infrastructure that quietly siphoned research data for years.
What the expanded case suggests about cyber enforcement
The numbers underscore why prosecutors are treating this as a durable, high-cost threat. CyberMaxx’s summary of the DOJ filing says the campaign compromised approximately 8,000 professor accounts and exfiltrated at least 31.5 terabytes of material.
The cleanup was expensive too. Victim universities spent about $20 million investigating and remediating the breaches, prosecutors said, a figure that reframes espionage as a direct financial burden on targeted institutions.
The practitioner takeaway is that the intrusions leaned on identity, not exotic malware. “Spear-phishing and password spraying require neither novel malware nor exploitation of an undisclosed vulnerability,” CyberMaxx researcher Connor Jackson wrote, noting how durable those low-tech methods remain at scale.
The Bitcoin angle also lands against a firm market backdrop. Bitcoin traded near $78,530, up about 5.3% on the day, with the Fear & Greed Index at 71, or “Greed.” The escalation to a $6 million Bitcoin ransom is a reminder that crypto’s pseudonymity has long been a fixture of state-linked extortion, even as enforcement steadily catches up. With the defendant roster nearly doubled and the HBO case now absorbed into the broader indictment, the DOJ is signaling that cross-border cyber cases stay open for years.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
