Skip to content

Alleged Mabna hacker Amir Barati extradited to US from Montenegro

Amir Barati, named in a 14-count DOJ indictment over the Mabna Institute campaign against 144 US universities, was extradited from Montenegro. He is accused, not convicted.

Published 3 min read

Montenegro has extradited Amir Barati, a 40-year-old dual Turkish-Iranian national, to the United States over his alleged role in the Mabna Institute campaign against academic institutions. Barati was named in a 14-count US indictment unsealed in August 2026; a Montenegrin court issued its final extradition decision in late September. He is accused, not convicted — the charges are the government's allegations.

What he's charged with

The Department of Justice charges Barati with conspiracy to commit computer intrusions, wire fraud, computer fraud, and identity theft, as reported by Recorded Future and CNN. The August indictment names 17 defendants and ties the operation to the Mabna Institute, which US prosecutors say acted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). That attribution is a formal charging document, not a vendor's best guess — which is why we state it as the DOJ's filed allegation rather than hedge it.

Scope of the campaign

Per the indictment as reported, the campaign ran from 2013 to 2017 and compromised roughly 8,000 professor email accounts. Prosecutors put the footprint at:

  • 144 US universities and 42 US companies
  • 178 foreign universities and at least 11 foreign companies
  • 31+ terabytes of stolen intellectual property and data
  • An estimated $3.4 billion in damages, with universities spending about $20 million on investigation and remediation

Arrest and extradition

Barati was arrested on June 25 in Kotor, Montenegro, after the FBI issued a warrant; he was reportedly detained while on vacation. Montenegro's courts cleared the surrender in late September, and he was handed to US custody this week.

What to do today

This is a law-enforcement milestone, not a new vulnerability — there's no patch to apply. But the tradecraft is worth revisiting if you run a research or university network:

  1. Review credential-phishing resistance for faculty and research staff. The Mabna playbook was spear-phishing into library and journal portals, not zero-days.
  2. Enforce phishing-resistant MFA on identity providers and library proxy systems, the exact accounts this campaign harvested.
  3. Watch for bulk journal/library access from unusual geographies — the historical campaign monetized stolen credentials through resale of academic access.

Context

Extraditions in IRGC-linked cases are rare and slow; the 2018 Mabna indictment named nine individuals who stayed out of reach for years. Barati's surrender shows the long tail of these cases — indictments filed against state-nexus operators can still produce an arrest when a defendant travels to a cooperating jurisdiction. For defenders, the enduring lesson is unchanged: the intellectual-property theft that prosecutors value at billions started with ordinary credential phishing against under-defended academic accounts.

Related stories