The news
Amir Barati, an accused member of Iran's Mabna Institute, was extradited from Montenegro to the U.S., The Record reported October 1. The research espionage case came a day after MI5 said over 100 UK-linked academics worked on projects funded by a Chinese intelligence-linked institute.
Barati, 40, a dual Iranian and Turkish citizen, is one of 17 people named in a 14-count superseding indictment that the Justice Department unsealed on August 18 in federal court in New York. Prosecutors allege the Mabna Institute hacked on behalf of Iran's Islamic Revolutionary Guard Corps, targeting 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, 11 foreign companies and five U.S. federal and state agencies.
According to the Justice Department, the group compromised about 8,000 professor accounts and stole at least about 31.5 terabytes of academic data and intellectual property. U.S. universities spent more than about $3.4 billion to procure and access that material, the department said, and the defendants also sold stolen data through two Iranian websites, Megapaper and Gigapaper.
Prosecutors say Barati tracked spearphishing campaigns, swapped stolen login credentials with co-conspirators, built target lists, ran network reconnaissance and wrote phishing messages. The Record reported that he was arrested on June 25 in Kotor, Montenegro, while on vacation. Charges include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft; they are allegations, and SecurityWeek noted such extraditions of Iranian state-linked hackers are extremely rare.
In the UK, MI5 issued a public alert on September 30 naming the China General Technology Research Institute (CGTRI), which it says has very strong ties to China's Ministry of State Security (MSS). CGTRI-funded projects covered AI, cybersecurity, covert communications and steganography, the practice of hiding data inside other files. "This activity supports MSS espionage, which poses a threat to UK national security," MI5 said, according to The Register. Security Minister Dan Jarvis wrote to all university vice-chancellors asking them to end arrangements with CGTRI, Times Higher Education reported.
AI researchers face phishing too. The Record reported on October 1 that Proofpoint tied China-aligned group TA419 to emails sent in July to AI experts at universities, think tanks and law firms, using fake AI policy committee lures. Cisco Talos linked a China-nexus group it tracks as UAT-11587 to a backdoor called Antino that compromised about 350 endpoints in eight countries, including Taiwan, at what Talos counts as 10 confirmed and five probable affected institutions, mostly government and policy organizations, between September 2025 and July 2026.
The numbers
- U.S. universities targeted in the Mabna case (DOJ)
- 144
- Foreign universities targeted (DOJ)
- 178
- Professor accounts compromised (DOJ)
- About 8,000
- Academic data and IP stolen (DOJ)
- At least about 31.5 TB
- What U.S. universities spent to procure and access that data (DOJ)
- More than about $3.4 billion
- UK-linked academics on CGTRI-funded projects (MI5)
- More than 100
- Endpoints compromised in the Antino campaign (Cisco Talos)
- About 350
Why CEOs should care
For CEOs and boards of AI labs and R&D-heavy companies, both cases put research itself at the center of the target list. The Mabna group allegedly worked through ordinary staff logins, not exotic exploits: professor accounts, phishing messages and shared credentials. Treat researcher and lab accounts as privileged, require phishing-resistant multifactor authentication and watch research portals and data repositories for unusual bulk downloads.
For general counsel and anyone who funds or partners with universities, MI5's advice is a due-diligence checklist. It told researchers to establish who ultimately funds their work, and the UK government reminded academics of possible criminal consequences under the National Security Act 2023 for assisting a foreign intelligence service. Ask research partners to disclose co-funders and foreign sponsors, add that duty to contracts, and review any current work in AI, cybersecurity or covert communications.
For CISOs, the phishing side is practical. TA419's lures posed as AI policy advisory committees and well-known figures, so staff should verify unsolicited invitations through a known channel before clicking. Talos says Antino uses Microsoft 365 Outlook and OneDrive for command and control, so security teams should look for endpoints talking to cloud mail and storage in unusual ways.
The bigger picture
The Mabna case shows how long these matters run. Prosecutors say the intrusions began around 2013, the first charges came in 2018, and Barati's arrest came during a 2026 trip to Montenegro. For victims, the legal record arrives years after the data is gone, so prevention and detection matter more than eventual prosecution.
MI5 naming AI among CGTRI's funded fields reflects how governments now rank the technology. Agencies that once issued quiet guidance to universities are naming specific institutions in public, and that raises the stakes for any company whose research partners have not mapped their own funding.
What’s next
Watch for Barati's appearance in federal court in New York and any plea or trial schedule, and for whether other Mabna defendants named in the indictment are detained abroad. In the UK, watch whether universities disclose CGTRI-linked projects after the vice-chancellor letters, and whether other Western agencies issue similar alerts.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





