CASE DOSSIER
sentenced
U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)
Docket: 1:15-cr-00393 Court: U.S. District Court for the Southern District of New York Opened: 2015-11-10 Sector: Financial Services, Banking, Publishing
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$19.0 million
Court ordered $19,952,861 in restitution to victim financial institutions.
Techniques
2
Verified mappings
Defendants
1
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the Southern District of New York.
- Primary Target Sector: Financial Services, Banking, Publishing.
- Documented Financial Loss: $19.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.
Procedural & Incident Timeline
2018-09-07 extradition
Extradited from the Republic of Georgia to the Southern District of New York.
2019-09-23 plea
Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies.
2021-01-07 sentencing
Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Andrei Tyurin | Russian Federation | sentenced | 144 mo | None | Perpetrator of JPMorgan Chase 83-million-customer data intrusion. Sentenced to 144 months in prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication." | Indictment ¶ 12, Page 6 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time." | Indictment ¶ 15, Page 8 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach), No. 1:15-cr-00393 (U.S. District Court for the Southern District of New York 2015), https://cyberattackcaselibrary.pages.dev/cases/us-v-tyurin-jpmorgan-chase/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-tyurin-jpmorgan-chase" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>