Security1 distinct publisher2 min readPublished
Amir Yaryab is named as head of the IRGC's Cyber-Electronic Command and the officer directing five hacking crews, which tells water and energy operators who is at the other end of the intrusions without telling them what to hunt.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A chain of command is what the notice adds. Washington puts five groups under one officer: CyberAv3ngers, Dadeh Afzar Arman and Mehrsam Andisheh Saz Nik as IRGC-CEC affiliates, plus Shahid Hemmat and Shahid Shushtari, which the State Department says conduct attacks on US organizations [4][5][1]. The sector list is wide: defense, news, shipping, hotels and airlines, energy, finance and telecommunications, in the United States, Europe and the Middle East [3]. No malware families, CVEs or indicators accompany it [13]. Anyone building detection from the announcement is back to the CyberAv3ngers water utility casework from 2023 and 2024 [7].
The operational number is in the water sector. US officials have said since late July that Iran resumed attacks there, breaching more than 100 entities across at least 12 states [8], which averages out above eight per state [3]. That is a victim count. The reporting does not separate intrusions that reached control systems from those that stopped at business networks [14].
Credential and mailbox access against government bodies is where the Justice Department landed last week, with employee email accounts at the Labor Department, the Federal Energy Regulatory Commission and multiple United Nations organizations [11]. Volume intrusion into small utility networks is happening in the same month [8]. The first produces documents. The second produces reach into physical process control, and it is the one that matters for anyone with a PLC in a pump house.
The State Department posted $10 million last year for the people behind CyberAv3ngers [9] and $10 million now for the officer it says controls them [1], so $20 million is on one command chain [2]. Treasury has sanctioned many of the same Iranian nationals for critical infrastructure attacks [12]. The water breaches reported from late July onward ran alongside that [8]. Designations and rewards have not interrupted the tempo.
The chain of command, the group names and the sector list are State Department allegations [3][4]. The claimed compromises of a medical device company and of the FBI director's personal email account come from Iranian hackers taking credit for their own work [10], which is a weaker grade of evidence than an indictment and should be scored that way.
For an asset owner in the named sectors, the usable part of this is the group list, because it collapses several loosely tracked crews into one attributed set and points detection engineering at the water intrusion tradecraft already documented. The reward changes nothing about exposure. The 12-state figure is the item to work from.
Ranked by verification strength, evidence, and original report placement.
The State Department posted a $10 million reward for information on the whereabouts of senior Iranian official Amir Yaryab.
Yaryab allegedly leads the Islamic Revolutionary Guard Corps' Cyber-Electronic Command (CEC).
US officials accused Yaryab of directing multiple Iranian hacking groups that have targeted critical infrastructure sectors including defense, news, shipping, travel (hotels and airlines), energy, and financial and telecommunications systems in the United States, Europe and the Middle East.
The State Department said on Thursday that Yaryab oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN), and that these groups have used malware to target civilian infrastructure worldwide.
Yaryab also allegedly directs Shahid Hemmat and Shahid Shushtari, two groups conducting cyberattacks on US organizations.
CyberAv3ngers was previously accused of launching cyberattacks on water utilities in 2023 and 2024.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
U.S. Bank's answer to LockBit: the breach happened two tiers out2 distinct publishers
invest
Treasury puts the tax exemption of up to 18,000 schools on a nine-month clock1 distinct publisher
security
The aim point was a peripheral: how US operators blinded Iran's air defenses1 distinct publisher
product
Insurers war-gamed 5,000 water utilities going down at once. That is a correlation problem.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Sourced to a single State Department statement
Every name, sector and dollar figure here traces to a State Department statement relayed by Recorded Future News. The command claim about Yaryab, the five affiliated crews and the sector list are the department's own wording; no indictment, advisory or second outlet corroborates them, and the water sector count is attributed only to unnamed officials.
Twelve states, no breakdown of severity
Real-world effect is visible only as scale: 100-plus water entities in at least a dozen states since late July, plus federal and UN mailboxes in the Justice Department case. What is missing is the boundary that changes an operator's response, since nothing distinguishes a compromised business inbox from access to a treatment plant's controls.
Attribution running ahead of indicators
A $10 million price and the phrase "civilian infrastructure worldwide" carry weight that malware names and observables would carry better. Recorded Future News relays the notice rather than amplifying it, but a defender finishes the piece knowing who Washington blames and what it will pay, with nothing to search logs for.
The accuser also sets the bounty
The State Department makes the accusation, prices the information it wants, and did the same thing for CyberAv3ngers a year ago; Treasury designations and a Justice Department case against overlapping people belong to the same campaign of pressure. Recorded Future News is owned by a threat intelligence firm and covers this beat closely. None of that makes the attribution wrong, but the frame of a legible Iranian chain of command comes from a party with reason to draw it.
Announcement details confirmed, real-world effects unclear
What was announced, by whom and on which day is not in doubt. Which crew did what inside the 100-plus water intrusions, how deep they got, and whether the named medical device victim confirms anything are all unanswered here, and with a single outlet on the story there is no way to close those gaps from this reporting.