Montenegro's government said its police sent a 40-year-old man to the US. It gave only his initials, A.B. Police arrested him in Kotor on 25 June, on an FBI request. Montenegro said he faces New York charges of conspiracy to commit computer fraud and identity theft. It said he worked with an Iran-based entity that attacked over 150 US universities from 2013. The damage is put at more than $3.4 billion.
Montenegro said the stolen data, and access to hacked university accounts, served Iran's Revolutionary Guard and other Iranian users. SecurityWeek reported that an August US indictment covers over 31 terabytes of research data and stolen staff email accounts. Neither source says how the intruders got in. Montenegro gave no name and no trial date.
A copied file is a one-time loss. A working account is different, because its holder can log in again, read new mail and pass as the owner. Several users can share that access. So harm can go on after the stolen data is counted. Leaders can ask: which accounts reach research data or email? Would we notice a login from an odd place? How fast can we shut an account off?