The U.S. Department of State is dangling a reward of up to $10 million for anyone who can provide information leading to the capture or location of Amir Yaryab, a high-ranking commander in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The announcement falls under the Rewards for Justice program, and accuses Yaryab of orchestrating cyberattacks targeting critical infrastructure across the U.S., Europe, and the Middle East.
Scope of Alleged Attacks
U.S. officials contend that Yaryab oversees the Cyber Operations Command of IRGC-CEC, which includes two divisions known as Shahid Hemmat and Shahid Shushtari. These entities are reportedly tied to both cyber warfare and disinformation operations that have struck sectors such as defense, energy, telecommunications, and finance.
Yaryab is alleged to be linked with groups like CyberAv3ngers and Dadeh Afzar Arman (DAA), blamed for deploying malware and launching assaults on civilian infrastructure. Among the more detailed U.S. findings: CyberAv3ngers has been targeting industrial control systems—specifically Israeli-made Unitronics Vision PLCs—since late 2023. At least 75 of these PLCs were breached (34 in the U.S.), particularly in water and wastewater facilities. Attackers have compromised devices that were exposed on the internet with weak or default passwords, and have even modified ladder logic—the programming that controls physical operations like pumps and valves.
Vulnerabilities Exposed and Urgent Recommendations
The intrusions didn’t stop at logic manipulation. Attackers changed firmware version details, device names, and hijacked remote access credentials. They also replaced human-machine interface (HMI) displays with threatening messages targeting Israeli equipment, complicating both detection and recovery. U.S. cybersecurity agencies stress that vulnerable operational technology (OT) exposed to the public internet poses serious risk.
CISA’s guidance to affected organizations includes removing internet-exposed PLCs, enforcing strong password practices, enabling multifactor authentication, keeping firmware and engineering workstations up to date, and using VPNs and firewalls for remote access. Maintaining thorough asset inventories and monitoring anomalous behaviors are also core defenses urged for safeguarding critical services.
The reward brings renewed scrutiny on how IRGC-aligned cyber forces operate. It underscores how increasingly hybrid threats—combining cyberattacks with malign information campaigns—are aimed at not just stealing data but disrupting physical systems. For industries that depend on PLCs and HMIs, the stakes are much higher as access to infrastructure becomes more interconnected to broader networks.
What to watch: whether this reward yields actionable intelligence, whether IRGC-CEC adjusts its tactics in response, and how quickly sectors like water and energy globally move to harden their OT environments before the next breach.