A federal indictment unsealed Tuesday charges 17 members of an Iran-based hacking group with a years-long, state-directed campaign against American universities, companies, and government agencies. For the cyber insurance market, the charges bring into sharp focus the type of IRGC-linked commercial intrusion that war exclusion language has struggled to address.
The DoJ said a 14-count superseding indictment names Mabna Institute members for intrusions into 144 US universities, at least 42 private-sector companies, and five government agencies, as BBC News reported. Mabna is an Iran-based firm founded around 2013, and the campaign ran until at least December 2017.
The DoJ said Mabna stole more than 31 terabytes of academic data and intellectual property from universities. Private-sector victims suffered more than $20 million in investigation and remediation costs, the DoJ said. Many of the intrusions were conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC), with stolen academic data also sold through two websites inside Iran.
"Cyber operations have become a central instrument of national power," US Attorney Jamie McDonald for the Southern District of New York told BBC. "Attacks on American and allied institutions carry direct consequences for our security and economic strength."
The indictment lands against a backdrop of escalating Iranian cyber activity. Since US and Israeli forces struck Iran in Operation Epic Fury in February, Iranian-linked actors have intensified operations against US commercial and infrastructure targets. That escalation has pushed brokers and underwriters to take a closer look at the precise language of cyber war exclusions in clients' policies.
The most widely adopted wording in the Lloyd's market is LMA5567, mandated across all standalone cyber policies from March 2023. The clause does not blanket-exclude state-linked incidents. Coverage is excluded only when a cyber operation causes "major detrimental impact" on a state's essential services or security capabilities. Corporate-targeted intrusions generally do not reach that bar.
That matters for how the Mabna case reads from an insurance standpoint. Victims of attacks similar to those the DoJ describes would likely find their cyber policies responding, provided they meet attribution and notification requirements. The $20 million in remediation costs the DoJ cited falls squarely within the type of loss that a responding cyber policy covers.
The Mabna indictment is unusual in the clarity it offers. It names defendants, sets out their organizational ties to the IRGC, and carries the weight of a formal DoJ determination. Most Iran-linked intrusions do not arrive packaged that way.
In the Stryker cyberattack of March, Iran-linked group Handala claimed responsibility, but no formal US government attribution had been issued at the time. Where attribution is absent or delayed, policyholders face the risk that a claim is deferred or disputed while the coverage question works through legal channels. Marsh has flagged non-concurrency as a persistent complication, with some clients carrying five or more different war exclusion wordings across a single coverage tower.
The water utility attacks of early August illustrated the same pattern. Iran-linked actors were suspected but not formally confirmed as responsible at the time of reporting. Coverage disputes would turn on the same variables: state-backed attribution, the detrimental-impact threshold, and whether the specific wording responds to corporate-targeted rather than infrastructure-level damage.
The DoJ charges are a concrete anchor point for brokers placing cyber coverage on clients in the sectors Mabna targeted. The indictment establishes, as a matter of documented legal record, that the IRGC has run commercial hacking operations against US private-sector businesses. That confirmation supports the case for coverage under LMA5567, but also sharpens the attribution questions that can complicate and delay claims.
Brokers renewing cyber coverage in professional services, financial firms, or research-intensive sectors should understand what attribution evidence their policies require. They should also know how war exclusion wordings differ across a stacked program. The $10 million reward the State Department is offering for five defendants is a reminder that several individuals remain at large.