Skip to content

Ten Years of Theft From 322 Universities: What Was Taken Is What Universities Had Already Paid 3.4 Billion Dollars For

1 min read
Share
Ten Years of Theft From 322 Universities: What Was Taken Is What Universities Had Already Paid 3.4 Billion Dollars For

Thirty-one and a half terabytes. That, according to the American indictment, is how much data hackers extracted from 322 universities around the world - 144 in the United States and 178 in other countries. Not military secrets, not weapons codes. Scientific journals and doctoral dissertations.

Federal prosecutors in the United States have issued a 14-count indictment against 17 members of the Iranian Mabna Institute for a decade-long cyber espionage campaign. According to the Department of Justice, the group acted primarily at the behest of Iran's Revolutionary Guard.

What was stolen had already been paid for

The most interesting figure in the whole case is neither the 31.5 terabytes nor the 322 universities. It is 3.4 billion dollars - the amount the Department of Justice says American universities spent to acquire the very data that was then stolen and resold through Iranian websites.

Pause there for a moment. The science in those journals is most often paid for by the public through budgets and grants. Then institutions pay for it a second time in order to access it. And now a third player takes it for free and sells it a third time. The theft is a crime and it is the subject of the indictment, but the model that made it so profitable is nobody's count in that indictment.

Not only universities

The targets also included 42 private American companies, 11 foreign firms, several US government agencies and the United Nations. In one of the cases the defendants hacked the media company HBO and tried to extort six million dollars in bitcoin.

Damage to the victims is estimated at more than 20 million dollars for system remediation alone. The State Department has offered a reward of up to 10 million dollars for information leading to the location of the five main fugitives. When a state offers more money to find the perpetrators than the damage itself cost, that is not accounting - it is a message.

„The wider network”

„These charges expose the wider network believed to be behind an extensive state-sponsored campaign. The aim was to steal research and intellectual property from American universities, from companies and government institutions”, said US attorney Jamie McDonald.

Note the phrasing - „believed to be”. An indictment is an allegation, not a verdict, and 17 people outside American jurisdiction will probably never sit in a courtroom in Maryland. That does not make the document meaningless. It means its function is more to name than to punish.

Why this is closer than it looks

A university does not look like a military target, and that is exactly what makes it a good one. It has open networks, thousands of user accounts and a security budget that always loses out to the budget for everything else. Academic networks are open by design, because that is how science works - exchanging papers is the point, not the flaw.

If someone can get into the systems of 322 universities for ten years before anyone drafts an indictment, the question is not how good the attackers are. The question is how long anyone was actually watching.