Dark Mode
Iranian Hacking Suspect Arrested in Montenegro in $3.4 Billion U.S. Cyber Case

Iranian Hacking Suspect Arrested in Montenegro in $3.4 Billion U.S. Cyber Case

Latest news on WhatsApp أجدد الأخبار على واتساب

 

Montenegrin police, working with the U.S. Federal Bureau of Investigation, have arrested a 39-year-old man with dual Iranian and Turkish citizenship in the coastal town of Kotor at the request of U.S. authorities. He is wanted by a New York court on charges that include conspiracy to commit computer fraud, hacking and identity theft.

 

According to Montenegrin authorities, the suspect allegedly carried out large-scale cyberattacks from 2013 onward, targeting U.S. infrastructure and more than 150 American universities. Police said the attacks caused damage estimated at more than $3.4 billion, and extradition proceedings will now be handled by a court in Podgorica, Montenegro’s capital.

 

Police said the illegally obtained data, as well as access to compromised university accounts, was used for the benefit of Iran’s Islamic Revolutionary Guard Corps and other Iranian entities, including universities. Reuters reported that the FBI was not immediately available for comment.

 

The $3.4 billion figure does not mean that this amount was stolen in cash from the U.S. government. It refers to the estimated cost of academic data, research and intellectual property that U.S. universities had spent money to procure and access before it was allegedly compromised in a broader hacking campaign linked by U.S. prosecutors to Iran’s Mabna Institute.

 

The arrest brings renewed attention to the Mabna Institute case, first announced by the U.S. Department of Justice in 2018. At the time, U.S. prosecutors charged nine Iranian nationals described as leaders, contractors, associates or affiliates of the institute in what authorities called a coordinated cyber intrusion campaign against universities, companies, government agencies and international organizations.

 

According to the Justice Department, that campaign targeted 144 U.S.-based universities and 176 universities in 21 other countries, along with 47 private-sector companies and several U.S. government entities. U.S. authorities also said the attackers targeted more than 100,000 academic accounts worldwide, compromised about 8,000 of them, and stole at least 31.5 terabytes of academic data and intellectual property.

 

The case is significant because it is not simply about stolen passwords or hacked accounts. It is about the theft of academic research, scientific resources and intellectual property with potential economic and security value. The Justice Department’s earlier list of affected countries included Canada, making the case relevant to universities and research institutions across North America.

 

The arrest also comes amid growing Western concern that state-linked or organized cyber operations are expanding beyond government targets to universities, companies, hospitals and local authorities. For academic and research institutions, the message is clear: protecting email accounts, enforcing multi-factor authentication and monitoring privileged access are no longer optional security measures, but essential safeguards for data and intellectual property.