Amir Barati, an Iranian and Turkish national accused of participating in a widespread cyberattack campaign, has been extradited from Montenegro to the United States. Authorities have linked him to cases of hacking academic data and intellectual property from universities and businesses. Montenegrin police confirmed the extradition.
His extradition to the United States was announced on October 1. Barati was arrested in June in the city of Kotor at the request of American authorities and the FBI. According to The Record, a Montenegrin court approved the extradition earlier this week.
See also: Iranian hacker arrested for $3.4 billion cyberattack on US infrastructure
The Amir Barati case and academic data
His name is included in a 14-count indictmentunsealed in August that involves 17 members of the Mabna Institute, an Iran-based firm. The U.S. Justice Department describes a multi-year operation that the indictment alleges was aimed at gaining access to research materials and email accounts. The charges are not evidence of guilt and there is a presumption of innocence.
The indictment attributes the network to breaches at 144 universities in the United States and 178 abroad, as well as at least 42 American and 11 foreign companies. It also names public sector organizations and non-governmental organizations. The attackers allegedly stole more than 31 terabytes of academic data and intellectual property, covering different scientific fields.

According to US authorities, the network targeted more than 100,000 academic accounts and gained access to about 8,000 professor accounts. The perpetrators allegedly used stolen login credentials to access academic services and copy scientific articles, theses, books and other documents. The US Department of Justice describes the scope of the targets and the data.
The same indictment also describes targets outside of universities: employees of U.S. agencies, government agencies and businesses. Among the organizations named are the U.S. Department of Labor, the Federal Energy Regulatory Commission, state agencies, the United Nations and UNICEF. Prosecutors say the hacks served a variety of clients, including Iranian government agencies and universities.
What is attributed to Amir Barati?
Amir Barati is accused of monitoring the progress of targeted phishing campaigns, exchanging login details from compromised accounts and helping to create target lists. The indictment also charges him with identifying networks and writing misleading messages. These are allegations by prosecutors, not facts established by the courts.
Prosecutors say some of the data was funneled to Iranian entities, while others were sold through two online services. Using the compromised accounts, customers were able to gain access to university libraries. The same chain of events allegedly combined the theft of credentials with the exploitation of legitimate academic services.

The reference to economic impact requires caution: the $3.4 billion is not presented by the indictment as an amount lost in direct transfers or as compensation. It is an estimate of the costs that American universities had paid to obtain and use the research material to which the defendants allegedly gained access.
See also: CHOSEN BRICK: The malware used by Iranian hackers for espionage
The extradition brings the case before a US court
Barati's extradition means he will face U.S. prosecution on charges including conspiracy to commit computer hacking, wire fraud and identity theft. The U.S. Department of Justice has said that all defendants are presumed innocent until proven guilty.
Montenegrin authorities' cooperation with the United States initially led to the arrest and subsequent extradition of a defendant who allegedly played a role in coordinating the attacks. The development does not prejudge the outcome of the trial, but it does bring to court a case involving the interception of university research and the illegal use of accounts.

For universities, the case is a reminder of the value of protecting staff accounts and verifying unexpected login requests. At the same time, prosecutors’ reports show how account attacks can be turned into access to subscription libraries and sensitive research. The outcome of the charges will be decided by the courts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Roundcube: Vulnerabilities exploited by hackers against universities
