Zero Day Room
Live
Threats

Amir Barati Extradited to U.S. For University Hacking

An Iranian-Turkish dual national was extradited from Montenegro to face U.S. Charges for leading a global cyber espionage campaign that stole 31 terabytes of academic data, causing billions in damages.

Threats: An Iranian-Turkish dual national was extradited from Montenegro to face U.S

Amir Barati, a 40-year-old dual citizen of Turkey and Iran, was extradited from Montenegro to the United States on Thursday. A Montenegrin court issued a final extradition decision this week, following his arrest in June by Montenegro’s Interpol office and local police in the coastal municipality of Kotor.

Barati faces multiple counts of conspiracy to commit computer fraud, hacking, and identity theft in the U.S. Southern District of New York. He is expected to face wire and computer fraud charges there.

Barati charged in expansive cyber campaign linked to IRGC

The indictment relates to an expansive campaign prosecutors believe was run through the Mabna Institute. This entity is believed to have operated on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). Barati is accused of being a key figure in an operation that allegedly saw Iranian hackers breach email inboxes at universities and other research institutions worldwide.

In August, the Justice Department named Barati in a 14-count superseding indictment charging 17 people. The hacking scheme began in 2013.

Global scale of data theft and system breaches revealed

The campaign had a staggering global reach. According to the Department of Justice, the group breached email accounts at over 144 U.S. Universities, 42 U.S. Companies, 178 foreign universities, and at least 11 foreign companies. The hackers allegedly stole at least 31 terabytes of information and intellectual property.

The university hacking campaign allegedly involved the successful targeting of about 8,000 email accounts belonging to professors in the U.S., Europe, and elsewhere. The targeting spanned dozens of fields. The stolen data included academic journals, theses, dissertations, and electronic books.

Target TypeNumber Breached
U.S. Universities144
U.S. Companies42
Foreign Universities178
Foreign CompaniesAt least 11

Stolen academic data used to benefit Iranian institutions

Prosecutors allege stolen credentials and data were used to access U.S. University systems and benefit Iranian organizations. Data stolen in the attacks and access to compromised university accounts were allegedly used to benefit Iran’s Islamic Revolutionary Guard Corps and other Iranian universities.

The stolen documents were given to the government of Iran. They were also sold through two websites to universities in Iran. One website allowed customers in Iran to use stolen professor accounts to access online library systems of multiple U.S. Universities.

Barati’s role detailed in phishing, reconnaissance, and targeting

Prosecutors provided specific details on Barati's alleged activities. They said he conducted computer network reconnaissance and crafted phishing messages. He also exchanged login credentials for compromised accounts with co-conspirators and created targeting lists.

Barati allegedly helped track the progress of hacks and create targeting lists for the private sector. He was involved in tracking spearphishing campaign progress.

The alleged damage from these attacks is estimated at more than 3.4 billion US dollars. U.S. Officials claimed Barati’s group was responsible for $3.4 billion in damages. The academic data and intellectual property targeted cost U.S. Universities about $3.4 billion to procure and access. Prosecutors said the universities spent about $20 million to investigate and remediate the breaches.

The scheme breached more than 150 U.S. Universities and companies and targeted data worth over $3 billion. One of the companies allegedly victimized was HBO, a subsidiary of Warner Brothers Discovery. Among breached private U.S. Companies were 11 tech firms and two defense contractors.

Other members of the conspiracy allegedly hacked the Department of Labor, the Federal Energy Regulatory Commission, and the United Nations. Many intrusions were conducted on behalf of Iran’s Islamic Revolutionary Guard Corps, according to prosecutors.

Accounts of Barati's background differ. One outlet reported that Barati has a lengthy history as a hacker in Iran and launched multiple prominent groups like the Iran Black Hats Team and the Digital Boys Underground Team. These groups were accused of attacking Microsoft, MIT and other institutions.

Iran has been a key suspect in cyberattacks on U.S. Water systems, tank readers at gas stations, a major medical device maker, and an FBI director's private email account over seven months of war with the U.S. and Israel. A spokesperson for the U.S. Southern District of New York declined to comment on Thursday about Barati’s extradition. CNN was unable to reach a lawyer for Barati.

Barati is expected to face wire and computer fraud charges in the U.S. Southern District of New York.

Topics

#Threats

Related coverage

More from Threats