VYPR
advisoryPublished Sep 4, 2026· 1 source

US Offers $10 Million Reward for Information on Iranian Official Allegedly Behind Critical Infrastructure Cyberattacks

The U.S. State Department has placed a $10 million bounty on Amir Yaryab, a senior Iranian official accused of leading the IRGC's cyber operations and directing multiple hacking groups targeting critical infrastructure globally.

The United States is escalating its efforts to counter state-sponsored cyber threats by offering a substantial $10 million reward for information leading to the whereabouts of Amir Yaryab, a key figure within Iran's Islamic Revolutionary Guard Corps (IRGC).

U.S. officials have identified Yaryab as the alleged leader of the IRGC's Cyber-Electronic Command (CEC). In this capacity, he is accused of orchestrating and overseeing a network of Iranian hacking groups that have systematically targeted critical infrastructure sectors across the United States, Europe, and the Middle East. The affected sectors include vital areas such as defense, news media, shipping, travel, energy, finance, and telecommunications.

According to the State Department, Yaryab's alleged responsibilities extend to directing the operations of several IRGC-CEC-affiliated groups. These include CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These groups are known to employ malware to attack civilian infrastructure worldwide, posing a direct threat to public safety and essential services.

Furthermore, Yaryab is reportedly in command of Shahid Hemmat and Shahid Shushtari, two other groups implicated in cyberattacks against U.S. organizations. The CyberAv3ngers group, in particular, has a documented history of targeting water utilities, with alleged attacks occurring in 2023 and 2024. This specific threat to water infrastructure has been a recurring concern, with U.S. officials noting a resumption of such attacks in late July, impacting over 100 entities across at least 12 states.

The U.S. government has been increasingly vocal about Iran's cyber activities, especially following periods of heightened geopolitical tension. Since the onset of recent conflicts involving Iran, Tehran's alleged cyber actors have claimed responsibility for attacks on significant targets, including a prominent medical device company and even the personal email account of the FBI director.

This reward announcement follows recent actions by the Justice Department, which accused hackers linked to Iran's military of breaching employee email accounts at the Department of Labor, the Federal Energy Regulatory Commission, and various United Nations organizations. The Treasury Department has also previously sanctioned many of the same Iranian nationals for their involvement in cyberattacks against critical infrastructure, underscoring a coordinated multi-agency approach.

The State Department's action highlights a strategic shift towards directly targeting individuals believed to be orchestrating significant cyber campaigns. By offering a substantial financial incentive, the U.S. aims to disrupt these operations, gather intelligence, and hold perpetrators accountable for their actions against global critical infrastructure.

Synthesized by Vypr AI