PRIMARY SOURCE REPOSITORY • ATT&CK v15.1
Cyberattack Case Library
A public, structured record of real cyberattacks built exclusively from primary sources: grand jury indictments, sworn complaints, court dockets, CISA technical advisories, SEC Form 8-K Item 1.05 disclosures, and OFAC sanctions notices.
Cases
46
Primary dockets
ATT&CK Techs
64
With case proof
Threat Actors
16
Attributed groups
Defendants
54
Named in charges
Statutes
12
Title 18 offenses
SEC Filings
6
Item 1.05 reports
Key Facts
- 46 major cyberattack prosecutions, state campaigns, and corporate breaches cataloged.
- 64 MITRE ATT&CK techniques substantiated with verbatim primary source excerpts.
- 24 defendants sentenced with average federal prison terms of 142.3 months.
- Zero secondary reporting: built exclusively from sworn court records, CISA alerts, and SEC disclosures.
Target Sectors
View all →| Target Sector | Case Count |
|---|---|
| Financial Services | 11 cases |
| Banking | 8 cases |
| Healthcare | 6 cases |
| Retail | 6 cases |
| E-Commerce | 5 cases |
| Energy | 4 cases |
| Education | 4 cases |
| Telecommunications | 4 cases |
Sentencing Distribution
View outcomes →| Prison Term | Defendants |
|---|---|
| 1-3 Years | 5 defendants |
| 3-5 Years | 0 defendants |
| 5-10 Years | 8 defendants |
| 10-20 Years | 5 defendants |
| 20+ Years | 4 defendants |
| Life Imprisonment | 2 defendants |
Recent Case Filings & Dockets
Chronological record of federal indictments and disclosures
| Case Title | Legal Status | Sector | Jurisdiction | Techniques | Reported Loss |
|---|---|---|---|---|---|
| U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks) 2:24-cr-00185 | fugitive | Water and Wastewater Systems, Energy | U.S. District Court for the Western District of Pennsylvania | 2 | $15.0 million |
| Snowflake Customer Multi-Tenant Credential Stuffing Campaign SEC CIK 0001640147 | alleged | Telecommunications, Entertainment, Banking, Cloud Services | U.S. District Court for the Northern District of California | 2 | $150.0 million |
| U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion) 1:24-cr-00305 | charged | Consumer Privacy, Cryptocurrency | U.S. District Court for the Southern District of New York | 1 | $100.0 million |
| U.S. v. Khoroshev et al. (LockBit Ransomware Operation) 2:24-cr-00330 | charged | Healthcare, Education, Manufacturing, Government, Financial Services | U.S. District Court for the District of New Jersey | 9 | $500.0 million |
| U.S. v. Daniel Rhyne (Industrial Insider Extortion) 3:24-cr-00122 | charged | Industrial Manufacturing, Critical Infrastructure | U.S. District Court for the Western District of Missouri | 1 | $750,000 |
| ALPHV / BlackCat Ransomware Attack on Change Healthcare SEC CIK 0000731766 | alleged | Healthcare and Public Health | U.S. District Court for the District of Minnesota | 6 | $2.5 billion |
| Volt Typhoon Critical Infrastructure Pre-Positioning CISA-AA24-038A | alleged | Communications, Energy, Transportation, Water, Defense Industrial Base | Federal Law Enforcement Action / FISA Court Authorized Operations | 9 | $150.0 million |
| U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service) 1:23-cr-00171 | fugitive | Financial Services, Payment Networks | U.S. District Court for the Eastern District of New York | 1 | $18.0 million |
| Operation Cookie Monster (Genesis Market Takedown) Operation Cookie Monster | alleged | Consumer Accounts, Banking, E-Commerce | U.S. District Court for the Eastern District of Wisconsin | 2 | $50.0 million |
| U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer) 2:23-mj-00122 | fugitive | Financial Services, Blockchain Infrastructure | U.S. District Court for the Eastern District of Pennsylvania | 2 | $3.0 billion |
Frequently Substantiated Techniques
Techniques with the largest number of primary source court citations
T1078 19 cases
Valid Accounts
T1190 11 cases
Exploit Public-Facing Application
T1486 10 cases
Data Encrypted for Impact
T1041 8 cases
Exfiltration Over C2 Channel
T1566.001 6 cases
Spearphishing Attachment
T1090 6 cases
Proxy
T1566.002 5 cases
Spearphishing Link
T1555 4 cases
Credentials from Password Stores
T1003 3 cases
OS Credential Dumping
T1485 3 cases
Data Destruction
T1584 3 cases
Compromise Infrastructure
T1059.001 2 cases
PowerShell