Iranian hacker extradited to US in rare prosecution of state-backed cyber campaign
An Iranian-Turkish national has been handed over to American authorities from Montenegro to face charges related to a sprawling hacking operation that compromised hundreds of institutions and extracted vast quantities of stolen data.

Amir Barati, an Iranian-Turkish individual, arrived in the United States following his extradition from Montenegro on October 1. The move marks an uncommon instance of law enforcement successfully bringing a suspect accused of state-sponsored cyber operations to trial. Montenegrin authorities had detained Barati in June following a request from the FBI.
Barati and 16 other Iranian nationals were charged with wire and computer fraud offenses in August. The group faces prosecution in the U.S. Southern District of New York. All 17 defendants are alleged to be affiliated with Mabna Institute, an organization based in Iran that has been linked to government-directed hacking operations worldwide.
The hacking operation in question spanned from 2013 through several subsequent years. During this period, the defendants are accused of acquiring more than 31 terabytes of academic research and proprietary information. The campaign also involved unauthorized access to approximately 8,000 email accounts belonging to academics in the United States and internationally.
The scope of the breaches extended across numerous institutions and organizations. Targets included 144 universities, 42 corporations, and five government agencies within the United States—specifically the Department of Labor and the Federal Energy Regulatory Commission. Beyond U.S. borders, the attacks reached 178 universities, 11 companies, and at least two nonprofit organizations. Cumulative losses and damages from the campaign totaled over $3.4 billion.
Following the thefts, the defendants allegedly transferred the compromised data and system access credentials to Iranian government authorities. These materials subsequently benefited Iran's Islamic Revolutionary Guard Corps alongside other state organizations and academic institutions. Court documents indicate that Barati's specific role involved "helped track the progress of the hacks of universities and helped create 'targeting lists' for the private sector."
The extradition represents a significant achievement for U.S. law enforcement, as individuals suspected of hacking on behalf of Iran seldom face prosecution in American courts. Iran's cyber capabilities have inflicted substantial harm across the globe. In August, U.S. water infrastructure in 45 municipalities came under suspected Iranian cyberattack. Additionally, a hacking group with Iranian connections claimed responsibility for a March operation that rendered over 200,000 devices inoperable and exfiltrated more than 50 teabytes of data.