The U.S. has charged 17 Iranians alleged to be members of the Mabna Institute, a hacking-for-hire company, over a years-long campaign to steal data from American organizations, according to BleepingComputer. The report, citing U.S. government statements, says the defendants are accused of stealing academic research, intellectual property, emails and other proprietary information. The case expands a March 2018 indictment. BleepingComputer reports that nine of the 17 defendants had already been charged in that earlier case, which involved hacking more than 300 universities and private companies. The latest charges add eight more individuals to what U.S. Attorney Jamie McDonald described as a broader alleged network behind a state-sponsored campaign targeting universities, businesses and government institutions. According to BleepingComputer’s account of the Justice Department announcement, the operation is believed to have begun around 2013. The U.S. government says the campaign targeted the accounts of more than 100,000 professors worldwide and successfully compromised roughly 8,000 of them. The alleged theft was substantial. BleepingComputer reports that the hackers used compromised accounts to take 31.5 terabytes of academic data, including journals, theses, dissertations, ebooks and research across multiple disciplines. The U.S. government valued the stolen material at about $3.4 billion. The reported victim list spans education, business and government. The activity allegedly affected 178 universities, including 144 in the U.S.; at least 53 private firms, including 42 in the U.S.; two nongovernmental organizations; and at least 10 U.S. state agencies. BleepingComputer also reports that HBO was highlighted as one victim and was allegedly extorted for $6 million worth of Bitcoin. The Justice Department says the defendants were involved in cyber operations for Iran’s Islamic Revolutionary Guard Corps, other Iranian government bodies, universities and paying customers, according to BleepingComputer. The charges include conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain and aggravated identity theft. The report says the charges can carry maximum penalties of up to 20 years in prison. The State Department is also offering rewards of up to $10 million for information leading to the whereabouts of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh. BleepingComputer reports that a Tor link was provided for anonymous submissions. All defendants are presumed innocent unless proven guilty in court. With only one report in this cluster, the case should be read as a detailed account of U.S. government allegations rather than an independently corroborated finding of liability. Who benefits: U.S. investigators benefit if the reward program produces location information on the named defendants. Potential victim organizations benefit from clearer attribution and a public account of the tactics and scope alleged by the government. Who's exposed: Universities, private firms, NGOs and state agencies with valuable research or proprietary data remain exposed where compromised accounts can provide broad internal access. The reported targeting of more than 100,000 professors underscores the risk around academic identity systems.