Iranian hacker accused in 31TB university email theft approved for US extradition
According to Security Affairs, a Montenegrin court has approved the extradition to the United States of Amir Barati, a dual Turkish and Iranian citizen accused of helping run a hacking campaign that stole at least 31 terabytes of data from university email accounts. The allegations are prosecutors’ claims, and the sources do not report a US trial or verdict.
The case matters to defenders because the alleged method was ordinary: spearphishing to steal credentials, then using those credentials to stay inside mailboxes.
What we know
- Barati, 40, was arrested on June 25 in Kotor, Montenegro, while on holiday, after the FBI issued a warrant. Security Affairs reports that a Montenegrin court approved his transfer to the US this week.
- Montenegro’s police said he is accused of conspiracy to commit computer fraud and computer hacking, and of identity theft, in attacks on US infrastructure since 2013, at over 150 US universities. Their estimate of the damage is more than 3.4 billion US dollars.
- In August, the US Justice Department named him in a 14-count indictment against 17 people. Prosecutors allege the group operated through the Iranian Mabna Institute on behalf of the Islamic Revolutionary Guard Corps.
- Prosecutors say the campaign ran between 2013 and 2017, compromised roughly 8,000 professor email accounts, and used stolen credentials to gain and keep access.
- Per the DOJ, as quoted by The Record Media, Barati helped track spearphishing progress, shared stolen credentials with other members, built target lists, carried out network reconnaissance and wrote phishing emails himself.
Who is affected
Prosecutors say the targets were academic and research institutions: 144 American universities and 42 US companies, plus 178 foreign universities and at least 11 foreign companies. The stolen material included academic journals, theses, dissertations and electronic books.
The DOJ says the data was sent to the Iranian government and also sold through two websites to universities in Iran. One of those sites reportedly let users log in to US university library systems with stolen professor credentials. That detail shows stolen credentials being reused to reach systems beyond the mailbox that was first compromised.
What has not been confirmed
- Security Affairs says Barati founded the Iran Black Hats Team and co-founded Digital Boys Underground Team, citing archived records. It describes this as reported rather than proven.
- It also reports that, after a 2010 arrest in Iran, sources said he was recruited as an intelligence asset. The outlet notes this could not be independently confirmed.
- Iran International reports that he left Iran for Turkey in 2021, gained Turkish citizenship and changed his name.
- The indictment is an accusation. Barati’s own response to the charges is not disclosed in the source, and the extradition ruling is not a finding of guilt.
- This story rests on a single outlet’s report. We have not independently verified the figures, which come from prosecutors and Montenegro’s police.
Why this matters
Analysis, not new reporting. University mailboxes hold research, grant material and credentials that can be reused elsewhere, and the case shows how long mailbox access can last when it is gained with valid credentials rather than malware. Phishing-resistant multi-factor authentication is the control most directly aimed at this kind of campaign. Organisations with research staff, in education or in industry partnerships, are realistic targets for the same approach.
What to do
- Require phishing-resistant MFA, such as FIDO2 security keys, for staff email, library and research systems.
- Review mailbox sign-in logs for logins from unfamiliar locations or hosts, and for new forwarding rules or mailbox delegation.
- Check whether library or journal access portals accept single-factor logins from outside your network.
- Reset credentials for any account reported in a phishing incident, and revoke active sessions.
- Brief academic and research staff on credential-phishing lures, and give them an easy way to report suspicious mail.
