US charges Iranians for sprawling hacking campaign on government agencies, universities
DOJ indicts 17 Iranians tied to Mabna Institute IRGC hacking-for-hire campaign that stole 31TB from universities, agencies, and UN organizations.
The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 people linked to the Mabna Institute, allegedly operating on behalf of the IRGC, in a campaign running since around 2013. The group breached 144 US universities, 42 US companies, 178 foreign universities, 11 foreign companies, and agencies including the Department of Labor, Federal Energy Regulatory Commission, and Hawaii and Indiana state governments, plus UN organizations such as UNICEF, stealing at least 31 terabytes of academic and proprietary data and about 8,000 professor email accounts. The State Department offered a $10 million reward for five individuals including Behzad Mesri, previously indicted for the $6 million HBO extortion; universities spent roughly $20 million on investigation and remediation.
Investigation of banking hack leads to arrests in Europe, Brazil
German and Brazilian police arrested seven suspects over a 2023 hack that drained an estimated 30 million euros from German bank accounts.
Germany's BKA said three suspects were arrested in Europe and charged with fraud, while Brazil's federal police arrested four others and executed 21 search warrants under Operacao Klonen (Operation Clone). The November 2023 attack exploited a vulnerability at a payment provider and used cloned payment cards to make unauthorized withdrawals from German online banking users, draining an estimated 30 million euros (34.7 million dollars). Funds were laundered through Brazil and four European countries, and courts ordered seizure of assets worth more than 20 million dollars. Brazilian media identified the affected bank as Commerzbank, which said customers suffered no financial loss.
Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts
Ukrainian prosecutors charged three men for stealing session tokens from over 610,000 Roblox accounts and selling them for an estimated $480,000.
Prosecutors in Ukraine's Lviv region said a 19-year-old organizer from Drohobych and two 22-year-old associates operated from May 2025 to April 2026, harvesting Roblox session tokens via infostealer malware disguised as game cheats and bonus software. They used software to validate stolen cookies and inventory virtual currency and rare items, then sold accounts via Russian platforms for as little as $0.80 each, advertising through Telegram channels and receiving crypto payments. All three are in custody facing charges of theft, money laundering, unauthorized computer interference, and illegal sale of restricted information, carrying up to 12 years in prison.
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
Australian police arrested two suspects over TeamPCP cyberattacks targeting Mercor, OpenAI, and other tech companies.
Australian police have arrested two people in connection with the TeamPCP hacks. The arrests follow a wave of cyberattacks earlier in the year that targeted tech companies including Mercor and OpenAI, many of which rely on high-profile, widely used open source software. The article provides no technical details or CVE identifiers.