- The Washington Times - Wednesday, November 28, 2018

The Justice Department unsealed charges Wednesday against two Iranian nationals who are accused of using sophisticated ransomware to extort more than $6 million from cities, hospitals, universities and government agencies, among others.

More than 200 entities were affected by the ransomware attack, including the cities of Atlanta and Newark, New Jersey; the Colorado Department of Transportation; the Port of San Diego; and the Nebraska Orthopedic Hospital.

Justice Department officials declined to comment on how many or which victims paid the ransom.



Nearly every U.S. state had at least one victim and at least six victims resided on the Eastern Seaboard, according to the indictment.

All told, the defendants allegedly caused more than $30 million in damage through their sophisticated ransomware scheme. They encrypted critical data on affected computers, preventing access and threatening to delete the information unless a ransom was paid, according to the indictment.

“The defendants chose to focus their scheme on public entities, hospitals and municipalities,” Deputy Attorney General Rod Rosenstein said at a press conference announcing the indictment. “They knew that shutting down those computer systems could cause significant harm to innocent victims.”

The hackers schemed for their own personal profit and the attacks were not directed by the Iranian government, according to a 25-page indictment. Authorities said the attacks started in December 2015 and continued through this month.

The defendants Faramarz Shahi Savandi, 34, and Mohammad Mehdi Shah Mansouri, 27, each face six charges related to the hacking, including conspiracy to commit wire fraud.

Advertisement
Advertisement

Mr. Rosenstein said the defendants are believed to be in Iran, but vowed that law enforcement will catch up to the pair.

“As the result of the indictment, the defendants are now fugitives from justice,” he said. “They face arrest and extradition to the United States in many nations that honor the rule of law.”

Brian Benczkowski said this is the first time federal charges have been lodged against hackers using ransomware with Bitcoin exchanges. The exchanges transfer traditional currencies into Bitcoin cryptocurrency.

The defendants used ransomware known as SamSam to launch their attack, according to the indictment. Authorities said SamSam is a more complex form of ransomware because it guesses passwords rather than relying on phishing to infiltrate computer systems.

In Atlanta, which the defendants targeted in March, the ransomware attack shut down computers in its court system, blocked residents from paying their water bills online and forced police offline. The defendants demanded $51,000 in ransom, which the city refused to pay. However, it is estimated the attack cost $9 million in taxpayer funds.

Advertisement
Advertisement

Craig Carpenito, the U.S. attorney for the District of New Jersey — the jurisdiction where the indictment was returned — called the scheme “a dangerous escalation of cybercrime.”

“Money is not their sole objective,” Mr. Carpenito said. “They are trying to impact our way of life. They are trying to maximize the damage they do.”

Contact the author

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Story Topics

Please read our comment policy before commenting.