IRANIAN HACKERS SPEND YEARS STEALING 31 TERABYTES, DISCOVER MOST PASSWORDS WERE 'SPRING2024!'
DOJ charges 17 Iranian operatives after a years-long breach that college IT departments mostly noticed via the indictment.
The Justice Department unsealed charges Tuesday against 17 members of Iran's Mabna Institute for a sprawling cyber-theft campaign that vacuumed up more than 31 terabytes of data from hundreds of universities, companies, and government agencies, allegedly on behalf of the Islamic Revolutionary Guard Corps. Investigators describe years of methodical, state-sponsored infiltration. IT professionals nationwide describe it as 'Tuesday.'
One flagship university reportedly only learned it had been breached when federal prosecutors requested server logs it turned out it had never kept, a discovery that has apparently been escalated to a help-desk ticket still marked 'awaiting assignment.' 'The persistence was impressive, though several targets were less locked doors than polite suggestions,' said an FBI spokesperson, adding that at least one compromised network's master password was, and remains, 'Spring2024!' with the exclamation point doing all the security work.
The DOJ's reward line for tips has reportedly fielded a steady trickle of calls from anonymous campus sysadmins asking, in a professional capacity, whether self-reporting one's own institution counts toward the bounty. 'We appreciate the transparency,' the spokesperson said, 'though technically confessing you never patched anything since 2019 is not the tip we were fishing for.' Meanwhile, the 17 named defendants remain at large, presumably still logged in.
