{
  "id": "case-irgc-water-cyberav3ngers",
  "slug": "us-v-irgc-cyberav3ngers-water",
  "title": "U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)",
  "summary": "Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
  "case_number": "2:24-cr-00185",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2024-09-24",
  "status": "fugitive",
  "victim_sector": "Water and Wastewater Systems, Energy",
  "victim_country": "United States, Israel",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey.",
  "first_seen_at": "2023-11-25T00:00:00Z",
  "last_updated_at": "2026-09-21T18:00:00Z",
  "actor_slug": "irgc-cyber-electronic-command",
  "defendant_slugs": [
    "hamid-reza-lashgarian",
    "mahdi-lashgarian"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.",
      "evidence_locator": "CISA Advisory AA23-335A \u00b6 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-335A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1485",
      "evidence_excerpt": "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.",
      "evidence_locator": "Indictment \u00b6 18, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment Press Release",
      "source_url": "https://www.justice.gov/opa/pr/justice-department-charges-six-iranian-nationals-cyberattacks-us-critical-infrastructure",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2023-11-28",
      "description": "CISA publishes alert on exploitation of Unitronics PLCs used in water systems."
    },
    {
      "event_type": "sanction",
      "event_date": "2024-02-02",
      "description": "Treasury OFAC sanctions officials of the IRGC Cyber-Electronic Command."
    },
    {
      "event_type": "indictment",
      "event_date": "2024-09-24",
      "description": "Unsealing of criminal indictment against six Iranian military cyber actors."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Water and Wastewater Systems, Energy networks. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
    "blast_radius": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey. Impacted Water and Wastewater Systems, Energy infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 2: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.",
        "technical_artifacts": [
          "T1485",
          "Data Destruction"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}