The Justice Department unsealed a 14-count indictment on August 18 charging 17 Iranian nationals with running a decade-long hacking campaign against 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, five federal and state agencies, and two non-governmental organizations.
Prosecutors say the defendants (leaders, contractors, and hackers-for-hire tied to the Tehran-based Mabna Institute) stole at least 31.5 terabytes of academic data and intellectual property, much of it at the direction of Iran’s Islamic Revolutionary Guard Corps. The targets were research operations at institutions already cutting back, including schools like MIT.
Nine of the 17 defendants were charged in the original indictment announced in March 2018 while eight are new. The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of five defendants — an indicator that none are in U.S. custody.
Why It Matters
The conspiracy targeted more than 100,000 professor accounts worldwide, roughly half of them at U.S. schools, and successfully compromised about 8,000, including 3,768 belonging to U.S. professors. One reused password gave outsiders the same library access a tenured faculty member has, which is the same basic failure behind most student loan and financial aid scams that hit borrowers.
The number that should catch a reader’s eye is $3.4 billion. That’s what U.S. universities spent to license and access the academic material prosecutors say was stolen — journals, dissertations, e-books, and database subscriptions. Library and research licensing is a fixed line item that never shrinks, and it feeds directly into why college costs keep climbing even at schools with flat enrollment.
The Details
Spearphishing. According to the indictment, conspirators researched professors’ published work, then emailed them posing as faculty at another university, referencing a recent article and linking to “related” papers. The links led to a look-alike domain with a fake university login page that captured credentials. Password spraying at companies and agencies. For corporate and government targets, the group collected employee email addresses from public sources and tried commonly used and default passwords across them, then exfiltrated entire mailboxes and set up automatic forwarding rules to keep receiving mail. The stolen data was resold. Megapaper sold pilfered academic resources to Iranian universities and institutions. Gigapaper sold customers direct access to compromised professor accounts so they could use U.S. and foreign university library systems themselves. Named victims. The Department of Labor, the Federal Energy Regulatory Commission, the State of Hawaii, the State of Indiana, the Indiana Department of Education, the United Nations, and UNICEF. Private-sector victims included three academic publishers, two defense contractors, and HBO. The HBO connection. Behzad Mesri was charged separately in 2017 with hacking HBO and demanding roughly $6 million in bitcoin. Five additional defendants are now alleged to have taken part in that intrusion. Remediation costs. Private and government victims spent more than $20 million investigating and cleaning up the intrusions.What This Means For Your Own Accounts
Nothing in the alleged playbook required advanced skill, only a convincing email, a domain that looked almost right, and passwords people reuse. Anyone with a .edu account should assume they are a target, since institutional library credentials are worth real money on a resale market.
Use a unique password everywhere, turn on multi-factor authentication or passkeys, and check your email for forwarding rules you didn’t create, which is the step almost nobody takes.
If credentials tied to your identity are exposed, the follow-on risk is financial rather than academic. Knowing how to freeze your credit and what to do if someone takes out loans in your name matters more than the specific breach that caused it.
How This Connects
Research access is one of the least visible expenses in higher education, and its a driver of the same cost increases that families are already facing. Sallie Mae reported families spent $34,019 on college last year, up 10%. Graduate students and postdocs feel it more directly, since library and database access is part of what makes a funded assistantship or fellowship usable at all.
What’s Next
The defendants are believed to be in Iran, which has no extradition treaty with the United States, so the practical outcome is likely travel restriction and sanctions exposure rather than a trial.
Watch for two things: whether the Rewards for Justice offer produces a location on any of the five named individuals, and whether universities respond with hard multi-factor authentication mandates for faculty accounts, a cost that, like everything else in higher education, eventually shows up in the price students pay.
Editor: Colin Graves
The post 8,000 Professor Accounts Hacked: What Every .edu Email Holder Should Do appeared first on The College Investor.

2 hours ago
6

Bengali (Bangladesh) ·
English (United States) ·