PolicyMedium

Turkish-Iranian hacker tied to IRGC-linked Mabna Institute extradited to US

Montenegro has extradited Amir Barati, an Iranian national who also holds Turkish citizenship, to face US charges over a campaign that allegedly stole 31 TB of university research.

Turkish-Iranian hacker tied to IRGC-linked Mabna Institute extradited to US

At a glance

  • Amir Barati was extradited from Montenegro to the US on October 1 after his arrest in Kotor on June 25.
  • He is one of 17 people charged in an August superseding indictment over the Mabna Institute hacking campaign.
  • Prosecutors say the campaign compromised about 8,000 professor email accounts and stole at least 31 TB of data between 2013 and 2017.
  • Barati faces computer intrusion conspiracy, wire fraud, computer fraud and aggravated identity theft charges in the Southern District of New York.

Montenegro has extradited Amir Barati, an Iranian national who also holds Turkish citizenship, to the United States, where he faces charges over a long-running hacking campaign that US prosecutors say stole academic research and intellectual property on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). According to The Record and CNN, Barati was extradited on October 1 and will face charges in the US Southern District of New York.

What happened

Barati was arrested on June 25 in the Montenegrin coastal town of Kotor in an operation involving local police and the FBI, Iran International reported. The outlet said Montenegro's High Court in Podgorica approved his extradition under a simplified procedure on September 22.

He is one of 17 people charged in a superseding indictment filed in August 2026 over their alleged work with the Tehran-based Mabna Institute, which the Justice Department says carried out hacking operations for Iranian government entities, including the IRGC. According to The Record, he faces charges of conspiracy to commit computer intrusions, wire fraud, computer fraud and aggravated identity theft. Reports differ on his age: The Record and CNN put it at 40, while Iran International said 39.

Alleged role and scope

Court documents cited by CNN say Barati helped track the progress of the university hacks and helped create targeting lists for the private sector. The Record reported that he was also involved in exchanging login credentials for compromised accounts, and Iran International added that he allegedly helped conduct reconnaissance and craft phishing messages.

According to the reports, the campaign ran from 2013 to 2017 and:

  • breached 144 US universities and 178 foreign universities,
  • compromised roughly 8,000 professor email accounts,
  • stole at least 31 terabytes of academic data, journals, theses and dissertations,
  • hit 42 US companies and at least 11 foreign companies, according to The Record.

Court documents cited by CNN say the stolen data cost US universities about $3.4 billion to procure and access. The Record said universities spent about $20 million on investigation and remediation.

Background and Turkish connection

Iran International reported that Barati, born in Mashhad, founded the Iran Black Hats Team in his early twenties and later co-founded the Digital Boys Underground Team under the alias "Kinglet". The outlet said he was arrested by Iran's Intelligence Ministry in 2010 and that multiple sources claimed he was recruited rather than prosecuted, a claim it could not independently verify. According to Iran International, he left Iran in 2021 and changed both his first and last name through Turkish legal proceedings; The Record said he became a Turkish citizen in 2021.

Why it matters

The case is a rare instance of a defendant in a state-sponsored Iranian cyber-espionage indictment being brought before a US court. The Mabna campaign relied heavily on spear-phishing against academics, a reminder for universities and research institutions to enforce phishing-resistant multi-factor authentication on email accounts and to monitor for credential reuse and suspicious mailbox access.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.