CASE DOSSIER fugitive

U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Docket: 2:24-cr-00185 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2024-09-24 Sector: Water and Wastewater Systems, Energy

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$15.0 million
Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Water and Wastewater Systems, Energy.
  • Documented Financial Loss: $15.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.

Operational & Financial Fallout

Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.

Artifacts & Tooling: T1078 Valid Accounts
2
Phase 2: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1485 →

Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.

Artifacts & Tooling: T1485 Data Destruction
Real-World Blast Radius & Operational Fallout

Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2023-11-28 advisory

CISA publishes alert on exploitation of Unitronics PLCs used in water systems.

2024-02-02 sanction

Treasury OFAC sanctions officials of the IRGC Cyber-Electronic Command.

2024-09-24 indictment

Unsealing of criminal indictment against six Iranian military cyber actors.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'." CISA Advisory AA23-335A ¶ 4 reviewed
T1485 Data Destruction
Impact
"Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation." Indictment ¶ 18, Page 9 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks), No. 2:24-cr-00185 (U.S. District Court for the Western District of Pennsylvania 2024), https://cybercaselibrary.com/cases/us-v-irgc-cyberav3ngers-water/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-irgc-cyberav3ngers-water" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>