US DOJ Charges 17 Iranians for Decade‑Long Hack That Stole 31 TB of Research from Universities, Companies, and Agencies
What Happened — Federal prosecutors unsealed a superseding indictment charging 17 Iranian nationals, linked to the Tehran‑based Mabna Institute, with a hacking campaign that began in 2013 and exfiltrated more than 31 TB of academic and proprietary data from 144 U.S. universities, 42 U.S. companies, multiple federal and state agencies, and hundreds of foreign institutions. The attackers used spear‑phishing to compromise roughly 8,000 professor accounts and then sold the stolen material through Iranian websites.
Why It Matters for Compliance & Audit Readiness —
- The incident illustrates a third‑party risk where a private contractor acted as a conduit for nation‑state espionage, underscoring the need for robust vendor‑management controls required by SOC 2 CC6.1.
- Continuous monitoring of third‑party access and systematic evidence collection are essential to demonstrate due‑diligence and maintain a defensible audit trail.
- Mapping this breach to your vendor‑risk program helps satisfy SOC 2 requirements for monitoring, responding to, and reporting supplier‑originated incidents.
Who Is Affected — Higher‑education and research institutions, technology firms, federal and state agencies, energy regulators, and international NGOs.
Recommended Actions —
- Review and tighten vendor‑risk policies: require SOC 2 attestations, security questionnaires, and continuous monitoring for any third‑party with access to sensitive data.
- Deploy advanced email‑security controls (DMARC, anti‑phishing training) and enforce multi‑factor authentication for privileged academic accounts.
- Collect and retain evidence of vendor assessments and incident‑response activities to support future SOC 2 audits. Source: DataBreachToday
Technical Notes — The attackers leveraged spear‑phishing emails to harvest credentials, then accessed university library systems and corporate repositories, exfiltrating research papers, dissertations, and proprietary documents. No specific CVE was disclosed; the vector was social engineering. Source: DataBreachToday