Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS
September 8, 2026
US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
September 8, 2026
Best Managed XDR Services for 2026
September 8, 2026
Home/CyberSecurity News/US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
CyberSecurity News

US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks

Key Takeaways The U.S. State Department is offering a $10 million reward for information on Amir Yaryab, a top cyber official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic...

Jennifer sherman
Jennifer sherman
September 8, 2026 3 Min Read
2 0

Key Takeaways

  • The U.S. State Department is offering a $10 million reward for information on Amir Yaryab, a top cyber official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).
  • Yaryab is accused of directing cyber operations that have targeted critical infrastructure across the U.S., Europe, and the Middle East.
  • The IRGC-CEC, through groups like CyberAv3ngers, has been linked to attacks on industrial control systems, including at least 75 Unitronics PLCs, with 34 in the U.S. water and wastewater sector.
  • These attacks involved defacement, alteration of PLC ladder logic, and manipulation of operational data, highlighting severe vulnerabilities in critical infrastructure.

U.S. Targets Iranian Cyber Chief with $10 Million Bounty

The United States Department of State’s Rewards for Justice program has announced a substantial reward of up to $10 million. This bounty is for intelligence that leads to the identification or location of Amir Yaryab, a high-ranking officer within Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).

Table Of Content

  • Key Takeaways
  • U.S. Targets Iranian Cyber Chief with $10 Million Bounty
  • Yaryab’s Alleged Role in IRGC Cyber Operations
  • Critical Infrastructure Under Attack: The Unitronics PLC Incidents
  • What You Should Do

According to U.S. officials, Yaryab is responsible for overseeing the IRGC-CEC’s Cyber Operations Command. This command manages various cyber units implicated in malicious activities against critical infrastructure in the United States, Europe, and the Middle East.

This initiative underscores a broader strategy by the U.S. government to counter aggressive cyber operations that threaten American critical infrastructure, aligning with provisions under the Computer Fraud and Abuse Act.

Yaryab’s Alleged Role in IRGC Cyber Operations

Yaryab is reportedly at the helm of several IRGC-CEC components, specifically Shahid Hemmat and Shahid Shushtari. These units are known for executing cyber and cyber-enabled information campaigns against a diverse array of sectors, including defense, telecommunications, energy, and finance.

U.S. authorities have further connected Yaryab to various IRGC-affiliated cyber groups, such as CyberAv3ngers and Dadeh Afzar Arman (DAA). These groups have been implicated in deploying malware and launching assaults on civilian infrastructure globally.

This recent announcement intensifies the focus on Iran’s cyber command, particularly as operational technology (OT) systems continue to face significant internet-borne threats. The alert reinforces earlier warnings concerning CyberAv3ngers’ activities targeting industrial control systems (ICS).

Critical Infrastructure Under Attack: The Unitronics PLC Incidents

A collaborative advisory from CISA, the FBI, NSA, EPA, and international partners revealed that actors linked to the IRGC began compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) in late 2023. These devices are integral to the functioning of various critical sectors, including water treatment, energy, transportation, and healthcare.

Reports indicate that between November 2023 and January 2024, CyberAv3ngers launched multiple waves of attacks against Unitronics PLCs based in the U.S. At least 75 devices were compromised, with 34 of these located within the U.S. water and wastewater sector.

The attackers predominantly targeted internet-exposed devices that either utilized default passwords or lacked any password protection. The cyber offensive extended beyond mere defacement; it involved altering the ladder logic within the PLCs, which directly controls physical processes like pumps and valves. Such unauthorized modifications could severely disrupt essential services. Furthermore, attackers tampered with device names, software versions, and remote access credentials, complicating recovery efforts for affected organizations.

In several incidents, the perpetrators replaced human-machine interface (HMI) displays with messages claiming responsibility and issuing threats against Israeli-manufactured equipment. This interference can prevent plant operators from accessing vital operational data, posing a direct threat to system stability and safety.

The activities attributed to CyberAv3ngers underscore the substantial risks to critical infrastructure stemming from inadequate operational technology security. When PLCs are compromised, attackers gain the ability to manipulate crucial industrial processes, potentially leading to catastrophic outcomes.

What You Should Do

  • Identify and isolate any OT devices, especially PLCs and HMIs, that are directly exposed to the public internet.
  • Implement and enforce robust password policies for all OT systems, ensuring complex, unique passwords are used.
  • Deploy multifactor authentication (MFA) for remote access to OT environments.
  • For Unitronics Vision Series PLCs, CISA recommends updating engineering workstations and firmware to the latest available versions.
  • Secure all remote access to OT systems through VPNs and properly configured firewalls.
  • Maintain comprehensive and up-to-date asset inventories of all industrial control systems.
  • Continuously monitor OT networks for unusual activity or unauthorized changes to configurations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Best Managed XDR Services for 2026

Next Post

Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaw in HashiCorp Terraform Registry Lets Attackers Steal Cloud Credentials
September 8, 2026
Top 10 Web Application Firewall Solutions for 2026
September 8, 2026
Top Firewall-as-a-Service (FWaaS) Providers in 2026
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us