Feds Indict 7 Iranians in Infamous Bank Attacks

The Department of Justice indicted 7 Iranian nationals today (March 24) on charges related to the "Operation Ababil" wave of cyberattacks upon U.S. bank websites that lasted from the fall of 2012 through the spring of 2013.

Credit: mj007/Shutterstock

(Image credit: mj007/Shutterstock)

The attacks "disabled victim bank websites, prevented customers from accessing their accounts online, and collectively cost the banks tens of millions of dollars in remediation costs," a DoJ press release said. It also said that "the attacks did not affect or result in the theft of customer account data."

Each of the seven defendants was charged with one count of conspiracy to commit and aid and abet computer hacking. One man was also charged with obtaining and aiding and abetting unauthorized access to a protected computer, related to a September 2013 network intrusion of the Bowman Avenue Dam in Rye, New York, just north of New York City. No damage was incurred at the dam.

MORE: 7 Scariest Security Threats Headed Your Way

The massive distributed denial-of-service (DDoS) attacks knocked several banking sites offline at once, two or three times per week for extended periods. The affected institutions included Bank of America, Citibank, Wells Fargo, JPMorgan Chase, the New York Stock Exchange, PNC Bank, Capital One, Union Bank, Fifth Third Bank, HSBC, TD Bank, American Express and US Bancorp.

Claiming credit was a previously unknown group calling itself the Izz Ad-Din Al-Qassam Cyber Brigades, which called its attack Operation Ababil and posted manifestoes online in English and Arabic demanding that the notorious "Innocence of Muslims" video be removed from YouTube.

However, U.S. intelligence officials quickly said that the attacks came not from a religiously motivated "hacktivist" group, but instead from Iranian government entities. At the time, the sheer power of the attacks was thought to be out of range for hacktivists, but subsequent, unrelated DDoS attacks proved that wrong.

The indictments allege that the seven men were employed by two Iranian companies, ITSecTeam or ITSEC and Mersad Company. Both companies were seemingly controlled by Iran's Revolutionary Guard Corps, the former street fighters who have become as militarily powerful as Iran's regular armed forces and control large sectors of the Iranian economy.

Three men — Ahmad Fathi, Hamid Firoozi and Amin Shokohi — are alleged to have been ITSec employees. Sadegh Ahmadzadegan, aka "Nitr0jen26," Omid Ghaffarinia, aka "Plus," Sina Keissar and Nader Saedi, aka "Turk Server," all apparently worked at Mersad. Fathi and Firoozi are 37 and 34, respectively; the other five defendants are all in their mid-20s. Each faces up to 10 years in prison for the banking attacks.

Firoozi is alleged to have been the person who penetrated the Bowman Avenue Dam's control systems and gathered "information regarding the status and operation of the dam, including information about the water levels and temperature, and the status of the sluice gate, which is responsible for controlling water levels and flow rates," according to the indictment. He faces an additional five years in prison for that.

The Bowman Avenue Dam intrusion is really not much of a hack, and security researchers snooping online often find similar industrial-control systems left unprotected or lightly protected. The indictment alleges that Firoozi could have opened the dam's sluice gate had it not been manually disabled at the time, but that would have had to take place during heavy rains to cause even localized flooding.

As with the five Chinese military personnel indicted in 2014 for alleged industrial espionage, the U.S. does not expect the Iranian defendants to appear in court any time soon.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Tech
Casetify Bounce Suitcase
I ditched my Away Carry-On for a bright red suitcase made by a phone case brand, and I was shocked by how much I liked it
Columbia Sportswear and Intuitive Machines partnership
Columbia Sportswear’s UV-blocking technology just landed on the moon, and I spoke to the materials scientist who designed it
iPhone 16e review.
What Tom’s Guide tested this week — the iPhone 16e is the most polarizing phone of the year
A split screen photo showing a coffee grinder on one side and a smart watch on the other
What Tom’s Guide tested this week: Sony, OnePlus, Corsair and more
A split screen image showing an instant camera on the left and a Dyson vacuum on the right
What Tom’s Guide tested this week: Expert reviews of Dyson, Insta360 and more
A composite of Soundcore Space One Pro headphones and Sony ZV-1F vlogging camera
What Tom’s Guide tested this week: 5 products that won our expert reviewers’ hearts
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now
  • Ajax__
    The indictment follows a string of provocative acts the Iranian regime has undertaken ranging from illegal launches of new ballistic missiles to appalling human rights crackdowns to continued support of three proxy wars that have generated a massive refugee crisis. The indictment was expected to directly link the hacking campaign to the Iranian government. The banks will not be identified in the indictment due to fear of retaliation. Though a planned indictment for the breach of back-office computer systems at the Bowman Avenue Dam has been reported, it was only part of a hacking campaign that was broader than previously known, as the indictment will show.
    Reply