Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The U.S. Department of Justice announced on September 27, 2024, that an indictment charged three Iranian nationals it identified as employees of Iran’s Islamic Revolutionary Guard Corps (IRGC) with an alleged hacking campaign that included targeting people connected to Donald Trump’s presidential campaign. Prosecutors say the operation stole nonpublic campaign material and tried to get it to media outlets and campaign-associated people. The indictment contains allegations, not findings of guilt; DOJ says the defendants are presumed innocent unless proven guilty.

Who are the three Iranians charged?

DOJ named the defendants as Masoud Jalili, Seyyed Ali Aghamiri, and Yaser Balaghi. The department identified them as Iranian nationals and IRGC employees. The indictment was unsealed on September 27, 2024, in federal court in Washington, D.C. DOJ’s announcement and the indictment describe what prosecutors allege; neither establishes that the defendants committed the charged crimes.

What did prosecutors say the alleged hacking campaign involved?

According to DOJ, the alleged activity began around January 2020 and continued through at least September 2024. Prosecutors say targets included current and former U.S. officials, media members, nongovernmental organizations, and people associated with political campaigns—not only people connected with the 2024 Trump campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The indictment describes alleged tactics including spearphishing, social engineering, fraudulent accounts, and spoofed login pages. Prosecutors say the defendants sought account credentials and multi-factor authentication or recovery codes; some attempts allegedly succeeded and others did not. These are descriptions of the alleged operation in the charging documents, not an independent determination of who carried it out.

#1 Best Overall

What was allegedly taken from the Trump campaign?

DOJ says that in or around May 2024, the alleged operation began targeting personal accounts belonging to people associated with an identified presidential campaign. Prosecutors allege the activity led to the theft of nonpublic campaign documents and emails, followed by an effort to distribute the material in a hack-and-leak operation.

DOJ says the alleged effort to reach campaign-associated people and news media took place from late June through August 2024. Its account describes attempts to pass along the stolen material; it does not establish that every intended recipient received or acted on it.

Did the Biden campaign receive the stolen Trump files?

A September 18, 2024, joint statement from the Office of the Director of National Intelligence, FBI, and Cybersecurity and Infrastructure Security Agency said actors sent excerpts from stolen, nonpublic Trump campaign material to individuals then associated with President Joe Biden’s campaign. The agencies said, “There is currently no information indicating those recipients replied.” Read the joint statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That agency statement reports that excerpts were emailed and says officials had no information indicating a reply. Separately, DOJ’s indictment alleges broader attempts to send stolen material to campaign-associated people and news media. The two descriptions should not be conflated: an unsolicited email containing an excerpt is not evidence that the recipients solicited, accepted, or used the material.

What charges did the Justice Department file?

The indictment includes conspiracy and substantive charges involving identity theft, access-device fraud, unauthorized computer access, wire fraud, and providing material support to a designated foreign terrorist organization. DOJ’s release lists statutory maximum penalties for the charges, but those maximums are not predicted sentences. If a defendant is convicted, sentencing would be determined by a federal judge.

What is known about the case’s status?

The FBI’s wanted page says arrest warrants for each of the three men were issued in the District of Columbia on September 27, 2024. The official pages cited here establish the indictment and warrants, but do not establish a later arrest, plea, trial, or judgment. Do not treat the charges as a conviction or infer a later case outcome from the 2024 announcement. FBI wanted notice.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the risk of a similar phishing attack

A September 27, 2024, joint advisory from the FBI, U.S. Cyber Command Cyber National Mission Force, Treasury, and the UK National Cyber Security Centre describes impersonation and rapport-building tactics: an attacker may pose as a professional contact or email provider, build trust, then send a link to a fake login page or ask for credentials or two-factor codes. The advisory recommends practical safeguards for individuals and organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Verify links and requests independently. Be cautious with unsolicited messages, links, and requests for passwords or authentication codes. If an account alert arrives, open the service through its known app or by entering its address yourself rather than following the message link.
  • Use multi-factor authentication. Where available, choose a phishing-resistant authenticator such as a passkey or FIDO authenticator. Organizations can consider advanced account-protection services and FIDO2-compatible hardware security keys, while planning secure recovery for lost or replaced devices.
  • Harden organizational email. The advisory recommends email anti-spoofing controls to make it harder for attackers to impersonate legitimate senders.

The advisory addresses protective measures; it does not establish that any single product would have prevented the alleged intrusion, and it does not endorse commercial products.

Rewards for information

The U.S. State Department’s Rewards for Justice program lists a reward of up to $10 million for information about the defendants, election interference, or associated people and entities. “Up to” is the program’s stated ceiling, not a guaranteed payment; eligibility and terms depend on the information and program rules. See the Rewards for Justice page for current details.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.