Cyber Threat Intelligence, Entrepreneur, Presentation Virtuoso

America Named the Man Attacking Its Water Plants and Can Do Nothing About It

The US put a $10 million bounty on the IRGC officer it says is attacking American water systems. He is a serving Iranian official, sitting inside Iran, and the money will never be paid. After three years of sanctions and indictments that did not work, this is what is left. It patches nothing.
America Named the Man Attacking Its Water Plants and Can Do Nothing About It

the us just put a US$10 million bounty on a man it will never catch, and everyone involved in this "national security theater" knows it. the real question is not whether anyone collects it, but wtf is this even being done?

the state department is offering up to US$10 million for information leading to amir yaryab, a senior commander in iran's revolutionary guard cyber command. he allegedly directs the cyber operations hitting critical infrastructure across the us, europe, and the middle east. energy, finance, telecom, and water.

yaryab's people include cyberav3ngers, the group behind multiple attacks on water-utility control systems. they hit small, underfunded water systems in at least 12 us states, because those utilities are high-value targets with almost no budget to defend themselves. i wrote about this previously.

the us named the man it believes is running the campaign, and put a price on his proverbial head. sounds like a tough stance, right?

now look at what the bounty can actually accomplish. yaryab is a serving officer of the iranian state. he is sitting inside iran, protected by the regime he works for. nobody is walking him across a border for a reward. this money is never getting paid, and the state department knows that better than anyone.

so what is this theatrical reward on an untouchable man actually for? it is what a government reaches for when it has run out of ideas, but also feels this peculiar desire to pound its fists on its chest.

to be fair, there is a potential intelligence angle to these shenanigans. somebody inside his orbit might trade an alias, infrastructure, travel information, or details about the people working underneath him for a life-changing amount of money. doubtful, but possible.

none of that changes the absurd asymmetry here. washington is offering eight figures for information about the man attacking us critical infrastructure while many of the systems he is allegedly targeting remain embarrassingly easy to compromise.

the us has spent three years on this. sanctions on iranian cyber personnel. indictments. treasury designations. public advisories. and through all of it, the attacks on the water systems kept coming. the operators kept operating.

this bounty is not the next escalation. it is what is left after the escalations did not work. the us government is opting to get loud rather than be diplomatic. this is wholly on-brand for this administration.

this is a superpower announcing, with a dollar figure and a press release, that it has identified exactly who is attacking its water supply, and can do almost nothing to stop him. naming him is not the same as reaching him. and putting a number on his head does not lower the risk to a single water treatment plant in a single one of those 12 states.

there is a real argument to be made this bounty and public naming makes things worse. think about the incentives the us just created. yaryab is a career officer whose entire standing inside the irgc rests on being effective and being feared. washington just told the world he is effective enough to warrant a US$10 million bounty, and feared enough to name personally.

that is not a deterrent to a man like yaryab. it is a credential. it is motivation.

the worst thing that can happen to an operator who was just publicly branded america's most wanted cyber commander is to go quiet and look deterred. the pressure now runs the other way, prove the bounty was justified. do not be surprised if the response to naming him is not less activity against us critical infrastructure, but more. its not like iran has shown any penchant for wanting to back down in the recent kinetic clashes with the us. surely this nonsense will not decrease their offensive cyber operations.

here is what the US$10 million does not buy. it does not patch a vulnerable programmable logic controller at a rural utility. it does not fund the one overworked ot or it person defending a town's water system. it does not do the boring, unglamorous, actually-effective work of hardening the infrastructure that keeps getting hit. a bounty is loud and cheap. defending the utilities is quiet and expensive. the us apparently prefers to opt for the loud, cheap one.

this is not a warning shot, and not a strategy. it is a substitute for one.

the threat is against a person the us cannot touch. his teams have been attacking systems the us has not bothered to properly defend. the response is a lame attempt at a reward nobody will ever claim.

the bounty will expire uncollected. the water systems will remain exposed. and the guy with the US$10 million price on his head will most likely read about it, shrug, and go back to work terrifying the us utility sector.