CASE DOSSIER
sentenced
U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
Docket: 3:16-cr-00440 Court: U.S. District Court for the Northern District of California Opened: 2016-10-05 Sector: Internet Services, Social Media, Cloud Storage
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$15.0 million
LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.
Techniques
2
Verified mappings
Defendants
1
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Internet Services, Social Media, Cloud Storage.
- Documented Financial Loss: $15.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.
Procedural & Incident Timeline
2016-10-05 arrest
Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice.
2018-03-30 extradition
Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied.
2020-07-10 verdict
Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft.
2020-09-29 sentencing
Sentenced to 88 months (7 years and 4 months) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yevgeniy Aleksandrovich Nikulin | Russian Federation | sentenced | 88 mo | None | Perpetrator of LinkedIn and Dropbox data thefts. Sentenced to 88 months in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.002 | Spearphishing Link Initial Access | "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials." | Trial Transcript Day 4, Page 61 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes." | Indictment ¶ 14, Page 7 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches), No. 3:16-cr-00440 (U.S. District Court for the Northern District of California 2016), https://cyberattackcaselibrary.pages.dev/cases/us-v-nikulin-linkedin-dropbox/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-nikulin-linkedin-dropbox" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>