CyberX labs raised interest at the 2017 Black Hat Europe Conference by describing a method to use compromised industrial programmable logic controllers (PLCs) to exfiltrate data from an industrial control system (ICS) network, using encoded radio signals generated from within the supposedly air-gapped target.
View all the details here: https://cyberx-labs.com/en/blog/cyberx-security-researchers-demonstrate-reconnaissance-data-exfiltration-air-gapped-ics-scada-networks/