Jurisdiction: United States
Court filings and enforcement actions documenting cyber intrusions within or targeting entities in United States.
Key Facts
- 22 documented prosecution matters involving United States.
- Cumulative identified losses exceed $8.4 billion.
- Includes federal court filings, international extraditions, and sanctions designations.
Documented Incidents
ALPHV / BlackCat Ransomware Attack on Change Healthcare
Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.
Colonial Pipeline DarkSide Ransomware Attack
DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.
U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.
U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)
Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.
U.S. v. Joshua Schulte (CIA Vault 7 Leak)
Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.
U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)
Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.
U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)
Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.
U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)
Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.
U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)
Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.
U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.
U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)
Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.
U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)
Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.
U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)
Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.
U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)
Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.
U.S. v. Max Ray Vision (Iceman / CardersMarket)
Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.
U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)
Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.
U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)
Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.
U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)
Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.
U.S. v. Daniel Rhyne (Industrial Insider Extortion)
Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.
U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)
Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Road darknet market in 2012 by triggering race conditions in the withdrawal logic.
U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)
International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.