31 terabytes. 144 U.S. universities. Thirteen years. And almost none of it involved a zero-day.

On August 20, 2026, the DOJ unsealed a 14-count superseding indictment charging 17 Iranian nationals from the Tehran-based Mabna Institute with running intrusions since at least 2013 for the IRGC.
WHAT ACTUALLY HAPPENED
The scope, per the indictment: 144 U.S. universities and 178 abroad, at least 42 U.S. private companies and 11 foreign ones, at least five U.S. federal and state agencies, and two NGOs.
More than 31 TB of academic journals, theses, dissertations, ebooks and proprietary research taken across dozens of fields.
The stolen material was handed to the Iranian government and resold through two websites to universities inside Iran. Charges include conspiracy to commit computer intrusions, wire fraud, computer fraud and aggravated identity theft.
Thirteen years of collection. Most of it built on credential theft against professors and researchers — identity abuse, not exotic exploitation.
WHY SLOW THEFT BEATS LOUD ATTACKS
Ransomware announces itself. This did not.
An attacker logging in with valid credentials, downloading documents an academic account is entitled to read, generates no malware alert, no lateral movement signature, no encryption event. It looks exactly like work.
That is the profile of intellectual property theft everywhere — research labs, engineering firms, pharma, energy, telecom. The damage does not show up as downtime. It shows up years later as a competitor with your designs, or a state with your research.
Detection built only around disruption will never see it. You need controls that notice a legitimate account behaving abnormally: volume, timing, geography, data class.
An indictment is not a defence. These 17 are unlikely to see a U.S. courtroom, and the model they built is being copied.
WHAT TO DO NOW
DEPLOY PHISHING-RESISTANT MFA ON RESEARCH AND R&D ACCOUNTS — credential phishing was the backbone of this campaign for over a decade.
ALERT ON BULK DATA ACCESS, NOT JUST INTRUSION — a valid account pulling thousands of documents is the signal here.
CLASSIFY IP AND RESTRICT BY NEED — if every account can reach every repository, one phished login equals full archive loss.
REVIEW THIRD-PARTY AND ACADEMIC PARTNER ACCESS — collaboration accounts are the standard entry point into research environments.
Not every breach ends in a ransom note. Some end in someone else publishing your work.
If an attacker logged into your environment with valid credentials tomorrow, what would actually flag it?