Industry News

US Charges 17 Alleged Iranian Hackers in Global Hacking-for-Profit Scheme

Decrypt · 20 Aug 2026
Key Takeaway Even small businesses should maintain strong password practices, multi-factor authentication, and regular backups, since cybercriminal groups target organisations of all sizes for data theft and extortion.

US prosecutors have unsealed charges against 17 alleged members of the Iran-based Mabna Institute, accused of running a large-scale hacking campaign that targeted hundreds of universities, private companies, and government agencies worldwide. The group is also linked to a $6 million bitcoin extortion operation, according to the charges.

While the case centres on Iranian state-linked actors, it highlights a broader trend: cybercriminal groups increasingly target organisations of all sizes to steal data, extort payments, or resell access to stolen credentials. Small and medium businesses are often seen as easier targets than large institutions because they typically have fewer security resources, even though they can hold valuable data or serve as a stepping stone into larger supply chains.

This case is a reminder that cyber extortion and credential theft are global, organised activities—not isolated incidents—and that businesses of any size should assume they could be a target.

Summarised by CISO AI from Decrypt. We link back to every original so you can read it yourself.