Skip to content
Brief Security & Trust ·

Montenegro sends alleged Iran-linked hacker to US in a rare extradition

Montenegro handed a 40-year-old man, known only as A.B., to US authorities over attacks on universities.

In brief
  • Montenegro says stolen data and access to hacked university accounts both served Iran's Revolutionary Guard. A copied file is a one-time loss, but a working account keeps giving access.
  • Neither source says how the intruders got in. Montenegro gave no name and no trial date.

Montenegro's government said its police sent a 40-year-old man to the US. It gave only his initials, A.B. Police arrested him in Kotor on 25 June, on an FBI request. Montenegro said he faces New York charges of conspiracy to commit computer fraud and identity theft. It said he worked with an Iran-based entity that attacked over 150 US universities from 2013. The damage is put at more than $3.4 billion.

Montenegro said the stolen data, and access to hacked university accounts, served Iran's Revolutionary Guard and other Iranian users. SecurityWeek reported that an August US indictment covers over 31 terabytes of research data and stolen staff email accounts. Neither source says how the intruders got in. Montenegro gave no name and no trial date.

A copied file is a one-time loss. A working account is different, because its holder can log in again, read new mail and pass as the owner. Several users can share that access. So harm can go on after the stolen data is counted. Leaders can ask: which accounts reach research data or email? Would we notice a login from an odd place? How fast can we shut an account off?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Government of Montenegro.