Free tools Windows power users keep installed
One-click scans. No signup required.
The U.S. Treasury sanctioned two members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR) on July 19, 2024, over cyberattacks targeting critical infrastructure. Treasury said the group manipulated water-facility controls in Texas and accessed an energy company’s industrial-control system. The incidents show why even technically unsophisticated access to systems that operate pumps and alarms can pose a real risk.
Who did the U.S. sanction?
The Treasury Department’s Office of Foreign Assets Control (OFAC) designated Yuliya Vladimirovna Pankratova, known online as YUliYA, and Denis Olegovich Degtyarenko, known as Dena, on July 19, 2024. Treasury identified Pankratova as CARR’s leader and spokesperson and Degtyarenko as one of its primary hackers.
The action named two individuals, not Russians generally. Treasury designated them under Executive Order 13694, as amended, which addresses cyber-enabled activity reasonably likely to threaten U.S. national security, foreign policy, or economic health and to harm or significantly compromise critical-infrastructure services.
What did Cyber Army of Russia Reborn target?
Treasury said CARR, also called Cyber Army of Russia, began claiming attacks on industrial-control systems in late 2023. Its reported targets included water, hydroelectric, wastewater, and energy facilities in the United States and Europe. These are operational technology (OT) environments: systems that monitor or control physical equipment and processes, rather than ordinary office computers alone.
#1 Best Overall
Texas water-facility controls
In January 2024, CARR claimed responsibility for manipulating human-machine interfaces (HMIs) at water facilities in Abernathy and Muleshoe, Texas. An HMI is the interface operators use to monitor and interact with industrial equipment. Treasury said the incidents caused the loss of tens of thousands of gallons of water.
Treasury’s release gives that water loss as the concrete quantified impact. It does not provide a dollar-loss total or an independent impact study, so the reported volume should not be treated as a comprehensive accounting of damage.
Rank #2
An energy company’s SCADA system
Treasury also said CARR compromised the supervisory control and data acquisition (SCADA) system of a U.S. energy company and gained control of alarms and pumps. SCADA systems collect data from industrial equipment and can let operators monitor or control it remotely. Treasury said major damage had so far been avoided because of the group’s limited technical sophistication.
Were the Texas water attacks actually dangerous?
Treasury described the techniques as unsophisticated, but simplicity does not make access to operational controls harmless. Manipulating an HMI or gaining control of pumps and alarms can affect how a facility operates; the possible consequences depend on the equipment, safeguards, and actions taken. In the Texas cases, Treasury reported water loss, but its release does not establish that the incidents caused broader public-health effects or other physical damage.
Treasury Under Secretary for Terrorism and Financial Intelligence Brian E. Nelson called CARR’s efforts “an unacceptable threat to our citizens and our communities, with potentially dangerous consequences.” That statement describes the risk officials attributed to targeting critical infrastructure; it is not a claim that every CARR operation caused severe damage.
What does the sanction mean?
The designation is an OFAC financial and legal measure under an existing cyber-sanctions executive order. It is distinct from a criminal conviction, and the Treasury announcement does not itself prove that every public claim made by CARR was independently verified. It identifies the two people Treasury held responsible and the basis for the designation.
Rank #4
The practical significance is that the U.S. government formally targeted named individuals for cyber-enabled activity tied to critical-infrastructure services. The action did not name an undifferentiated Russian population, and the Treasury release does not quantify financial losses from the incidents.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the case shows about hacktivist attacks on infrastructure
This case involved a hacktivist group and operational-technology targets, with reported manipulation of controls and access to pumps and alarms. Treasury’s account describes service and safety risks alongside limited technical sophistication; it does not report a dollar-loss figure or establish that all CARR claims were independently verified. Those distinctions matter when assessing both the severity of an incident and the government’s response.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

