Eight years after the Justice Department first charged members of Iran’s Mabna Institute, it went back and charged eight more. I do not think anyone should mistake that for progress against the underlying problem, which is not that the United States lacks the paperwork to name Iranian hackers. It is that naming them changes almost nothing about whether they keep working.

The superseding indictment unsealed this week adds eight defendants to the nine charged in 2018, bringing the total to 17 people the government says built and ran a hacking-for-hire operation on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian government and private clients. The scale, even years later, is still worth sitting with: more than 31 terabytes of academic data and intellectual property stolen from 144 U.S. universities and 178 foreign ones, roughly 8,000 compromised professor email accounts out of about 100,000 targeted, and an estimated $3.4 billion that U.S. universities spent replacing what was taken. Brett Leatherman, assistant director of the FBI’s Cyber Division, put it plainly: “These defendants allegedly built and profited from a sprawling hacking-for-hire operation that targeted the intellectual property of American and allied universities, companies, and government agencies for the benefit of the Iranian government.”

The Strongest Case for the Indictment

Before I make the argument that this accomplishes less than it looks like, I want to state the best case for it, because it is a real one. U.S. Attorney Jamie McDonald said the new charges “reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions.” Naming names is not nothing. It puts five of the defendants under a $10 million Rewards for Justice bounty, restricts their ability to travel outside Iran and a shrinking list of friendly states, and gives allied governments a documented basis for sanctions and asset freezes. It also hands defenders a concrete list of tactics and infrastructure to hunt for, which is more than a vague “Iran is hacking universities” advisory would give them.

Media Partner

Web3 x AI Fusion — Media Partner

Why It Still Does Not Move the Needle

None of that changes the operational reality: not one of these 17 people is likely to ever sit in a U.S. courtroom. Iran does not extradite its nationals for cyber offenses, and the hacking-for-hire model these defendants allegedly ran depends on exactly that shelter. A contractor who can steal $3.4 billion worth of research with functional impunity, then watch the U.S. government spend eight years building a case it cannot enforce, has very little reason to change careers. The 2018 indictment did not stop the campaign from continuing. There is no evidence in this week’s charges that this one will either, and it sits alongside a pattern of other state-linked operators, including the group behind fake job offers paired with a Windows zero-day, who keep working because the legal risk has never outweighed the payoff.

Washington’s own recent moves suggest the government knows indictments alone are not enough. The White House’s decision to deputize private firms for offensive cyber operations is, whatever its other risks, an admission that the prosecute-and-wait model has not kept pace with state-linked hacking-for-hire operations like this one.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The deeper issue is that an indictment treats state-linked hacking-for-hire as an individual-defendant crime, prosecuted defendant by defendant, when the thing actually being sustained is a market: a standing pipeline of contractors the IRGC and other Iranian entities can hire, task, and replace. Charging 17 people in one network does not touch the incentive structure that produced the next Mabna Institute, or the one after that. If deterrence is the goal, deterrence has to raise the cost of operating the market itself, not just the legal risk of any one participant in it, most of whom were already effectively judgment-proof the moment they were named.

What Would Actually Help

Indictments still matter, but they matter as one input to a strategy, not as the strategy. The parts of this announcement most likely to change behavior are the financial ones: the $10 million reward, and any sanctions or asset actions that follow from formally attributing this activity to the IRGC. Those hit the market’s economics in a way that a docket filing alone cannot. For CISOs at research universities and the private companies that hire them, the honest takeaway from this indictment is not “the government is handling it.” It is that the access-broker model Mabna represents keeps operating on a multi-year timescale that outlasts any single case, and that the defense against it has to be built the same way, on standing controls around spearphishing and credential hygiene in exactly the research and IP-heavy institutions this campaign spent a decade proving are underprotected.

Source: U.S. Department of Justice, Office of Public Affairs