CrimeOwl AI logoCrimeOwl AI
CasesBlogPricingAboutLaw Enforcement
  1. Home
  2. /
  3. Cases
  4. /
  5. AMIN SHOKOHI
Back to CasesMore Cases
Amin Shokohi (suspect)

The person at the center of this case

Amin Shokohi (suspect)

Case
#626
SourceFBI WantedUpdated Mar 15, 2026
Iran
Federal Bureau of Investigation (FBI) / U.S. District Court, Southern District of New York
Cold Case · Open
10 years waiting · since 2016

AMIN SHOKOHI

Justice for Amin Shokohi (suspect) — the trail went cold in 2016, but the truth hasn't.

Start here

Key leads to think about

🎯
suspect
Lead #1

What is Shokohi's current location and status in Iran, and does he maintain contact with ITSecTeam or other hacking networks?

🔍
evidence
Lead #2

What specific U.S. financial institutions and companies were targeted, and what was the total financial impact of the DDoS attacks?

💡
clue
Lead #3

Are there identifiable associates or co-conspirators within ITSecTeam who may assist in locating Shokohi or provide additional evidence?

Amin Shokohi, an Iranian computer hacker employed by ITSecTeam, is wanted for his alleged role in coordinating distributed denial of service (DDoS) attacks against U.S. financial institutions and companies between 2011 and 2013. He allegedly designed botnets, authored attack scripts, and created malware used in the campaign. Shokohi was indicted on January 21, 2016, by a federal grand jury in the Southern District of New York, and is believed to be residing in Iran.

Case
#626
SourceFBI WantedUpdated Mar 15, 2026
Iran
Federal Bureau of Investigation (FBI) / U.S. District Court, Southern District of New York

Try asking

Claim this imported case

A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.

10 uploads25 AI questions/day

This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.

More leads to consider

Beyond the top three above — each detail below could be the thread that pulls this case open.

🚗
vehicle
Lead #4

What technical infrastructure, servers, or communication channels did Shokohi use to coordinate and execute the attacks?

Have information about any of these leads?

Even the smallest detail could be the key to solving this case.

Official wording

Source Narrative

Conspiracy to Commit, and Aid and Abet, Computer Intrusion Caution: Amin Shokohi is wanted for his alleged involvement in a conspiracy to conduct a coordinated campaign of distributed denial of service ("DDoS") attacks against the United States financial sector and other United States companies from 2011 through 2013. Shokohi was a computer hacker who worked for ITSecTeam, an Iranian information technology company.

He allegedly helped build the botnet that was used to direct the DDoS attacks, and authored attack scripts and created malware that were used to engage in the attacks. Shokohi also allegedly obtained bot shells that were used in the DDoS attacks.

On January 21, 2016, a grand jury in the United States District Court, Southern District of New York, indicted Shokohi for his alleged involvement in the scheme and a federal warrant was issued for his arrest after he was charged with conspiracy to commit, and aid and abet, computer intrusion. Remarks: Shokohi is known to speak Farsi and is thought to be living in Iran.

Timeline of Events

🕵️
2011-01-01

DDoS Campaign Period Begins

Coordinated distributed denial of service attacks against U.S. financial sector and companies commence

🕵️
2013-12-31

DDoS Campaign Period Ends

Coordinated distributed denial of service attacks against U.S. financial sector and companies conclude

🕵️
2016-01-21

Federal Indictment

Grand jury in U.S. District Court, Southern District of New York, indicts Shokohi for conspiracy to commit and aid and abet computer intrusion; federal warrant issued for arrest

Case Information

Incident:January 1, 2011
Last Updated:July 12, 2026

Leave a comment

Comments

Case Information

Incident:January 1, 2011
Last Updated:July 12, 2026