CASE DOSSIER sentenced

U.S. v. Vachon-Desjardins (Netwalker Ransomware)

Docket: 8:20-cr-00366 Court: U.S. District Court for the Middle District of Florida Opened: 2020-12-16 Sector: Healthcare, Education, Municipal Government

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$21.5 million
Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.
Techniques
6
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Middle District of Florida.
  • Primary Target Sector: Healthcare, Education, Municipal Government.
  • Documented Financial Loss: $21.5 million.
  • 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.

Procedural & Incident Timeline

2020-12-16 indictment

Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage.

2022-03-09 extradition

Vachon-Desjardins extradited from Canada to the United States.

2022-06-29 plea

Defendant pleads guilty to all counts in the indictment.

2022-10-04 sentencing

Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Sebastien Vachon-Desjardins Canada sentenced 240 mo $21.5 million Netwalker ransomware affiliate sentenced to 20 years in federal prison with $21.5 million forfeiture.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals." Plea Agreement ¶ 4, Page 12 reviewed
T1078 Valid Accounts
Defense Evasion
"Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials." Plea Agreement ¶ 4, Page 13 reviewed
T1490 Inhibit System Recovery
Impact
"Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery." Indictment ¶ 8 reviewed
T1112 Modify Registry
Defense Evasion
"Netwalker modified registry keys under HKLM\SYSTEM\CurrentControlSet\Control\Lsa to weaken local security authority validation." Plea Agreement ¶ 6, Page 14 reviewed
T1548.002 Bypass User Account Control
Privilege Escalation
"The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting." Indictment ¶ 11, Page 6 reviewed
T1007 System Service Discovery
Discovery
"Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware." Plea Agreement ¶ 5, Page 13 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Vachon-Desjardins (Netwalker Ransomware), No. 8:20-cr-00366 (U.S. District Court for the Middle District of Florida 2020), https://cyberattackcaselibrary.pages.dev/cases/us-v-vachon-desjardins-netwalker/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-vachon-desjardins-netwalker" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>