$10M bounty, one Iranian cyber commander, and a lesson every OT engineer should already know.
On September 3, 2026, the U.S. State Department's Rewards for Justice program put a $10 million reward on Amir Yaryab, a senior official in Iran's IRGC Cyber-Electronic Command (IRGC-CEC). He's accused of directing cyber units — Shahid Hemmat and Shahid Shushtari — and overseeing the hacking group CyberAv3ngers, which is responsible for one of the more consequential ICS/SCADA incidents of the past few years.
Here's the technical breakdown, dev-to-dev:
Between November 2023 and January 2024, CyberAv3ngers compromised 75+ Unitronics Vision Series PLCs in the U.S., 34 of them inside water and wastewater utilities. The attack chain looked like this:
- Recon: scanning the internet for exposed Unitronics PLCs/HMIs
- Initial access: default or missing credentials — no exploit chain needed
- Impact: ladder logic altered to affect pumps and valves
- Obfuscation: device names, firmware versions, and remote access creds changed; HMI screens defaced
No zero-day. No custom malware. Just internet-facing industrial hardware with factory-default passwords. That's the real story behind the headline bounty.
The joint CISA/FBI/NSA/EPA advisory (AA23-335A) lays out the fix, and it's not complicated:
- Remove PLCs/HMIs from direct internet exposure — VPN + MFA for remote access
- Rotate default credentials on any OT/ICS device
- Keep firmware and engineering workstations patched on a separate OT cycle
- Maintain a live asset inventory (you can't protect what you don't know exists)
- Monitor for configuration drift on ladder logic and device metadata
If you build or maintain anything touching industrial control systems, SCADA, or OT networks, this case is worth 10 minutes of your time — not for the bounty drama, but for the exposure-audit checklist buried in it.
Full technical writeup with IOCs and detection steps here:
https://www.xpert4cyber.com/2026/09/us-offers-10-million-reward-iranian-irgc-cyber-chief.html
Top comments (0)