U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Water and Wastewater Systems, Energy.
- Documented Financial Loss: $15.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.
Operational & Financial Fallout
Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.
Adversary Kill Chain Flow
2 Documented PhasesDefendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.
Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.
Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.
Procedural & Incident Timeline
CISA publishes alert on exploitation of Unitronics PLCs used in water systems.
Treasury OFAC sanctions officials of the IRGC Cyber-Electronic Command.
Unsealing of criminal indictment against six Iranian military cyber actors.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'." | CISA Advisory AA23-335A ¶ 4 | reviewed |
| T1485 | Data Destruction Impact | "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation." | Indictment ¶ 18, Page 9 | reviewed |