[
  {
    "id": "case-sandworm-notpetya",
    "slug": "sandworm-notpetya-olympic-destroyer",
    "title": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)",
    "summary": "Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.",
    "case_number": "2:20-cr-00316",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-10-15",
    "status": "fugitive",
    "victim_sector": "Energy, Healthcare, Government, Transportation",
    "victim_country": "Ukraine, United States, France, South Korea",
    "loss_amount_usd": 10000000000,
    "loss_amount_note": "Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.",
    "first_seen_at": "2015-12-23T15:00:00Z",
    "last_updated_at": "2026-09-20T12:00:00Z",
    "actor_slug": "sandworm-team",
    "defendant_slugs": [
      "yuriy-andrienko",
      "sergey-detistov",
      "pavel-frolov",
      "anatoliy-kovalev",
      "artem-ochichenko",
      "petr-pliskin"
    ],
    "cves": [
      "CVE-2017-0144"
    ],
    "techniques": [
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware.",
        "evidence_locator": "Indictment \u00b6 44, Page 22",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary.",
        "evidence_locator": "Indictment \u00b6 38, Page 19",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1021.002",
        "evidence_excerpt": "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention.",
        "evidence_locator": "Indictment \u00b6 47, Page 24",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA17-181A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
        "technique_name": "SMB / Windows Admin Shares",
        "tactic": "Lateral Movement"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators.",
        "evidence_locator": "Indictment \u00b6 46, Page 23",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators.",
        "evidence_locator": "Indictment \u00b6 15, Page 7",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1055.012",
        "evidence_excerpt": "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity.",
        "evidence_locator": "Indictment \u00b6 52, Page 27",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Process Hollowing",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1036.005",
        "evidence_excerpt": "NotPetya named its primary payload dllhost.dat inside C:\\Windows\\ to blend in with legitimate host process binaries.",
        "evidence_locator": "Indictment \u00b6 45, Page 23",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Andrienko et al.",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Match Legitimate Name or Location",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1543.003",
        "evidence_excerpt": "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type.",
        "evidence_locator": "CISA Advisory ICS-ALERT-14-281-01B",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA ICS Advisory",
        "source_url": "https://www.cisa.gov/news-events/ics-advisories",
        "technique_name": "Windows Service",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1499",
        "evidence_excerpt": "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops.",
        "evidence_locator": "Indictment \u00b6 54, Page 28",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
        "technique_name": "Endpoint Denial of Service",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1124",
        "evidence_excerpt": "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps.",
        "evidence_locator": "CISA Advisory AA17-181A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA17-181A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
        "technique_name": "System Time Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2020-10-15",
        "description": "Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage."
      },
      {
        "event_type": "sanction",
        "event_date": "2021-04-15",
        "description": "U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities."
      },
      {
        "event_type": "advisory",
        "event_date": "2022-02-23",
        "description": "CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A)."
      }
    ]
  },
  {
    "id": "case-lockbit-takedown",
    "slug": "lockbit-ransomware-takedown",
    "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
    "summary": "Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.",
    "case_number": "2:24-cr-00330",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2024-05-07",
    "status": "charged",
    "victim_sector": "Healthcare, Education, Manufacturing, Government, Financial Services",
    "victim_country": "United States, United Kingdom, France, Germany, Japan",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.",
    "first_seen_at": "2019-09-01T00:00:00Z",
    "last_updated_at": "2026-09-18T10:00:00Z",
    "actor_slug": "lockbit-group",
    "defendant_slugs": [
      "dmitry-khoroshev",
      "mikhail-vasiliev",
      "ruslan-astamirov",
      "artur-sungatov"
    ],
    "cves": [
      "CVE-2023-4966",
      "CVE-2023-38831"
    ],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts.",
        "evidence_locator": "Indictment \u00b6 18, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1490",
        "evidence_excerpt": "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-165A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Inhibit System Recovery",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances.",
        "evidence_locator": "CISA Advisory AA23-325A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-325A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals.",
        "evidence_locator": "Complaint \u00b6 22",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "U.S. v. Astamirov Complaint",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-arrested-connection-lockbit-ransomware-attacks",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1047",
        "evidence_excerpt": "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets.",
        "evidence_locator": "CISA Advisory AA23-165A \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-165A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Windows Management Instrumentation",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1562.001",
        "evidence_excerpt": "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption.",
        "evidence_locator": "Indictment \u00b6 21, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Disable or Modify Tools",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1558.003",
        "evidence_excerpt": "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking.",
        "evidence_locator": "CISA Advisory AA23-165A Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Joint Technical Report",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "technique_name": "Kerberoasting",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1573",
        "evidence_excerpt": "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Khoroshev",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "technique_name": "Encrypted Channel",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2022-11-10",
        "description": "Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request."
      },
      {
        "event_type": "arrest",
        "event_date": "2023-06-14",
        "description": "Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks."
      },
      {
        "event_type": "indictment",
        "event_date": "2024-05-07",
        "description": "Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp)."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-05-07",
        "description": "U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev."
      }
    ]
  },
  {
    "id": "case-volt-typhoon",
    "slug": "volt-typhoon-critical-infrastructure",
    "title": "Volt Typhoon Critical Infrastructure Pre-Positioning",
    "summary": "State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.",
    "case_number": "CISA-AA24-038A",
    "court": "Federal Law Enforcement Action / FISA Court Authorized Operations",
    "district": "S.D. Tex. & Multiple",
    "country": "United States",
    "opened_at": "2023-05-24",
    "status": "alleged",
    "victim_sector": "Communications, Energy, Transportation, Water, Defense Industrial Base",
    "victim_country": "United States, Guam",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.",
    "first_seen_at": "2021-06-01T00:00:00Z",
    "last_updated_at": "2026-09-15T14:00:00Z",
    "actor_slug": "volt-typhoon",
    "defendant_slugs": [],
    "cves": [
      "CVE-2023-27997",
      "CVE-2023-46805"
    ],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States.",
        "evidence_locator": "DOJ Press Release 24-118",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Takedown of KV Botnet",
        "source_url": "https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      },
      {
        "technique_id": "T1059.003",
        "evidence_excerpt": "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware.",
        "evidence_locator": "Advisory Technical Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Joint Guidance",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Windows Command Shell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1016",
        "evidence_excerpt": "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 18",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "System Network Configuration Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1018",
        "evidence_excerpt": "Adversaries executed ping sweeps and 'net group \"Domain Computers\" /domain' to identify neighboring workstation hostnames.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 22",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Remote System Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1033",
        "evidence_excerpt": "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope.",
        "evidence_locator": "CISA Technical Appendix",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "System Owner/User Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1057",
        "evidence_excerpt": "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 19",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Process Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1570",
        "evidence_excerpt": "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels.",
        "evidence_locator": "CISA Advisory AA24-038A \u00b6 25",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA24-038A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
        "technique_name": "Lateral Tool Transfer",
        "tactic": "Lateral Movement"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2023-05-24",
        "description": "CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns."
      },
      {
        "event_type": "court_order",
        "event_date": "2023-12-14",
        "description": "Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-01-31",
        "description": "FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure."
      }
    ]
  },
  {
    "id": "case-alphv-change-healthcare",
    "slug": "alphv-blackcat-change-healthcare",
    "title": "ALPHV / BlackCat Ransomware Attack on Change Healthcare",
    "summary": "Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.",
    "case_number": "SEC CIK 0000731766",
    "court": "U.S. District Court for the District of Minnesota",
    "district": "D. Minn.",
    "country": "United States",
    "opened_at": "2024-02-21",
    "status": "alleged",
    "victim_sector": "Healthcare and Public Health",
    "victim_country": "United States",
    "loss_amount_usd": 2450000000,
    "loss_amount_note": "UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.",
    "first_seen_at": "2024-02-12T00:00:00Z",
    "last_updated_at": "2026-09-19T16:00:00Z",
    "actor_slug": "alphv-blackcat",
    "defendant_slugs": [],
    "cves": [
      "CVE-2024-1709"
    ],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication.",
        "evidence_locator": "Senate Finance Committee Testimony \u00b6 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Congressional Testimony by UnitedHealth CEO",
        "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways.",
        "evidence_locator": "SEC Form 8-K Item 1.05",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "UnitedHealth Group Form 8-K Item 1.05",
        "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1567",
        "evidence_excerpt": "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom.",
        "evidence_locator": "SEC Form 8-K Disclosure",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "UnitedHealth Group SEC Filing",
        "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
        "technique_name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery.",
        "evidence_locator": "HHS OCR Notice",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "HHS Office for Civil Rights Breach Notice",
        "source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1133",
        "evidence_excerpt": "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls.",
        "evidence_locator": "UnitedHealth Senate Testimony \u00b6 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Senate Testimony",
        "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
        "technique_name": "External Remote Services",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1087",
        "evidence_excerpt": "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts.",
        "evidence_locator": "CISA Advisory AA23-353A \u00b6 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-353A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a",
        "technique_name": "Account Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "disclosure",
        "event_date": "2024-02-21",
        "description": "UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems."
      },
      {
        "event_type": "advisory",
        "event_date": "2024-02-27",
        "description": "CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion."
      },
      {
        "event_type": "disclosure",
        "event_date": "2024-04-22",
        "description": "UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data."
      }
    ]
  },
  {
    "id": "case-colonial-pipeline",
    "slug": "colonial-pipeline-ransomware",
    "title": "Colonial Pipeline DarkSide Ransomware Attack",
    "summary": "DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.",
    "case_number": "1:21-mj-00454",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2021-05-07",
    "status": "pleaded",
    "victim_sector": "Energy, Oil and Gas",
    "victim_country": "United States",
    "loss_amount_usd": 4400000,
    "loss_amount_note": "Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.",
    "first_seen_at": "2021-05-06T00:00:00Z",
    "last_updated_at": "2026-09-17T11:00:00Z",
    "actor_slug": "darkside",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "The initial entry vector was a legacy Virtual Private Network account that was active without multifactor authentication using a password discovered in a dark web leak.",
        "evidence_locator": "Senate Homeland Security Committee Testimony",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Senate Testimony of Colonial Pipeline CEO",
        "source_url": "https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution.",
        "evidence_locator": "CISA Alert AA21-131A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-131A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines.",
        "evidence_locator": "FBI Alert Flash",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "FBI Cyber Division Alert",
        "source_url": "https://www.fbi.gov/investigate/cyber",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1021.001",
        "evidence_excerpt": "The DarkSide affiliate logged in via single-factor VPN and established an interactive Remote Desktop session to lateral servers.",
        "evidence_locator": "House Homeland Security Committee Testimony",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Congressional Hearing Transcript",
        "source_url": "https://homeland.house.gov/hearing/cyber-threats-in-the-pipeline-lessons-from-the-colonial-pipeline-attack/",
        "technique_name": "Remote Desktop Protocol",
        "tactic": "Lateral Movement"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2021-05-11",
        "description": "CISA and FBI publish joint advisory AA21-131A on DarkSide ransomware tactics."
      },
      {
        "event_type": "court_order",
        "event_date": "2021-06-07",
        "description": "DOJ unseals seizure warrant recovering 63.7 Bitcoins ($2.3 million) paid by Colonial Pipeline."
      }
    ]
  },
  {
    "id": "case-solarwinds-apt29",
    "slug": "solarwinds-orion-supply-chain-compromise",
    "title": "SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)",
    "summary": "Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.",
    "case_number": "SEC CIK 0001739942",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2020-12-13",
    "status": "alleged",
    "victim_sector": "Information Technology, Defense, Federal Government, Telecommunications",
    "victim_country": "United States, United Kingdom, Canada, European Union",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.",
    "first_seen_at": "2019-09-04T00:00:00Z",
    "last_updated_at": "2026-09-18T18:00:00Z",
    "actor_slug": "apt29",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1071.001",
        "evidence_excerpt": "The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Technical Analysis",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Web Protocols",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments.",
        "evidence_locator": "CISA Emergency Directive 21-01",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Emergency Directive 21-01",
        "source_url": "https://www.cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1132",
        "evidence_excerpt": "SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Data Encoding",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1036",
        "evidence_excerpt": "The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence.",
        "evidence_locator": "CISA Advisory AA20-352A \u00b6 21",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-352A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
        "technique_name": "Masquerading",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "disclosure",
        "event_date": "2020-12-14",
        "description": "SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise."
      },
      {
        "event_type": "advisory",
        "event_date": "2020-12-17",
        "description": "CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies."
      },
      {
        "event_type": "sanction",
        "event_date": "2021-04-15",
        "description": "White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors."
      }
    ]
  },
  {
    "id": "case-fin7-carbanak",
    "slug": "us-v-hladyr-fin7-carbanak",
    "title": "U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)",
    "summary": "Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.",
    "case_number": "2:18-cr-00067",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2018-03-27",
    "status": "sentenced",
    "victim_sector": "Hospitality, Food Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli.",
    "first_seen_at": "2015-08-01T00:00:00Z",
    "last_updated_at": "2026-09-12T14:00:00Z",
    "actor_slug": "fin7",
    "defendant_slugs": [
      "fedir-hladyr",
      "andrii-kolpakov",
      "denys-iarmak"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1059.001",
        "evidence_excerpt": "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.",
        "evidence_locator": "Indictment \u00b6 16, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "PowerShell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.",
        "evidence_locator": "Plea Agreement \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "U.S. v. Hladyr Plea Agreement",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1056.001",
        "evidence_excerpt": "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.",
        "evidence_locator": "Indictment \u00b6 22, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Keylogging",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1113",
        "evidence_excerpt": "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.",
        "evidence_locator": "Indictment \u00b6 25, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hladyr",
        "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
        "technique_name": "Screen Capture",
        "tactic": "Collection"
      },
      {
        "technique_id": "T1074.001",
        "evidence_excerpt": "Stolen credit card tracks were staged in hidden directories under AppData\\Local\\Temp prior to scheduled exfiltration batches.",
        "evidence_locator": "Trial Exhibit 8-C",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Local Data Staging",
        "tactic": "Collection"
      },
      {
        "technique_id": "T1020",
        "evidence_excerpt": "Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops.",
        "evidence_locator": "Plea Agreement \u00b6 9, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
        "technique_name": "Automated Exfiltration",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2018-01-20",
        "description": "Fedir Hladyr arrested in Dresden, Germany, and extradited to the Western District of Washington."
      },
      {
        "event_type": "plea",
        "event_date": "2019-09-11",
        "description": "Hladyr pleads guilty to conspiracy to commit wire fraud and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-04-16",
        "description": "Hladyr sentenced to 120 months (10 years) in federal prison and ordered to pay $2.5 million in restitution."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-06-24",
        "description": "Kolpakov sentenced to 84 months (7 years) in federal prison and ordered to pay $2.5 million in restitution."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-04-07",
        "description": "Iarmak sentenced to 60 months (5 years) in federal prison after pleading guilty."
      }
    ]
  },
  {
    "id": "case-evil-corp-yakubets",
    "slug": "us-v-yakubets-evil-corp-dridex",
    "title": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)",
    "summary": "Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.",
    "case_number": "2:19-cr-00336",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2019-11-14",
    "status": "fugitive",
    "victim_sector": "Banking, Financial Services, Municipalities, Education",
    "victim_country": "United States, United Kingdom",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.",
    "first_seen_at": "2011-05-01T00:00:00Z",
    "last_updated_at": "2026-09-10T12:00:00Z",
    "actor_slug": "evil-corp",
    "defendant_slugs": [
      "maksim-yakubets",
      "igor-turashev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
        "evidence_locator": "Indictment \u00b6 19, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
        "evidence_locator": "Indictment \u00b6 24, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
        "evidence_locator": "Treasury Designation Announcement",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "OFAC Sanctions Action",
        "source_url": "https://home.treasury.gov/news/press-releases/sm845",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1055",
        "evidence_excerpt": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
        "evidence_locator": "Indictment \u00b6 23, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Process Injection",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1547.001",
        "evidence_excerpt": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
        "evidence_locator": "Indictment \u00b6 26, Page 15",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Yakubets",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
        "technique_name": "Registry Run Keys / Startup Folder",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1053.005",
        "evidence_excerpt": "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads.",
        "evidence_locator": "CISA Advisory AA19-339A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA19-339A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
        "technique_name": "Scheduled Task",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1102",
        "evidence_excerpt": "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses.",
        "evidence_locator": "CISA Technical Analysis Report",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Technical Report",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
        "technique_name": "Web Service: Dead Drop Resolver",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2019-11-14",
        "description": "Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud."
      },
      {
        "event_type": "sanction",
        "event_date": "2019-12-05",
        "description": "OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-10-01",
        "description": "Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration."
      }
    ]
  },
  {
    "id": "case-lazarus-park-jin-hyok",
    "slug": "us-v-park-jin-hyok-lazarus",
    "title": "U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)",
    "summary": "Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.",
    "case_number": "2:18-mj-01479",
    "court": "U.S. District Court for the Central District of California",
    "district": "C.D. Cal.",
    "country": "United States",
    "opened_at": "2018-06-08",
    "status": "fugitive",
    "victim_sector": "Media and Entertainment, Financial Services, Healthcare",
    "victim_country": "United States, United Kingdom, Bangladesh, Philippines",
    "loss_amount_usd": 1300000000,
    "loss_amount_note": "Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.",
    "first_seen_at": "2014-11-01T00:00:00Z",
    "last_updated_at": "2026-09-14T09:00:00Z",
    "actor_slug": "lazarus-group",
    "defendant_slugs": [
      "park-jin-hyok"
    ],
    "cves": [
      "CVE-2017-0144"
    ],
    "techniques": [
      {
        "technique_id": "T1485",
        "evidence_excerpt": "The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable.",
        "evidence_locator": "Criminal Complaint \u00b6 42, Page 27",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days.",
        "evidence_locator": "Criminal Complaint \u00b6 88, Page 61",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1021.002",
        "evidence_excerpt": "WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers.",
        "evidence_locator": "Criminal Complaint \u00b6 92, Page 64",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "SMB / Windows Admin Shares",
        "tactic": "Lateral Movement"
      },
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Spearphishing emails were sent to bank officials at Bangladesh Bank directing them to fake SWIFT messaging updates.",
        "evidence_locator": "Complaint \u00b6 55",
        "mapping_status": "proposed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1027",
        "evidence_excerpt": "Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers.",
        "evidence_locator": "Criminal Complaint \u00b6 63, Page 42",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Obfuscated Files or Information",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1001.002",
        "evidence_excerpt": "Lazarus malware disguised executable payloads inside benign PNG image files using steganographic pixel modification algorithms.",
        "evidence_locator": "Criminal Complaint \u00b6 74, Page 51",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Steganography",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1068",
        "evidence_excerpt": "WannaCry automated exploitation of kernel pool memory corruption via EternalBlue to execute ring 0 shellcode.",
        "evidence_locator": "Criminal Complaint \u00b6 94, Page 66",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Criminal Complaint",
        "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
        "technique_name": "Exploitation for Privilege Escalation",
        "tactic": "Privilege Escalation"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-06-08",
        "description": "Criminal complaint filed charging Park Jin Hyok with computer fraud and wire fraud conspiracies."
      },
      {
        "event_type": "sanction",
        "event_date": "2018-09-06",
        "description": "Treasury sanctions Park Jin Hyok and front company Chosun Expo Joint Venture."
      },
      {
        "event_type": "indictment",
        "event_date": "2021-02-17",
        "description": "Unsealing of superseding indictment adding co-conspirators Jon Chang Hyok and Kim Il."
      }
    ]
  },
  {
    "id": "case-netwalker-vachon",
    "slug": "us-v-vachon-desjardins-netwalker",
    "title": "U.S. v. Vachon-Desjardins (Netwalker Ransomware)",
    "summary": "Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
    "case_number": "8:20-cr-00366",
    "court": "U.S. District Court for the Middle District of Florida",
    "district": "M.D. Fla.",
    "country": "United States",
    "opened_at": "2020-12-16",
    "status": "sentenced",
    "victim_sector": "Healthcare, Education, Municipal Government",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 21500000,
    "loss_amount_note": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.",
    "first_seen_at": "2020-04-01T00:00:00Z",
    "last_updated_at": "2026-09-11T16:00:00Z",
    "actor_slug": "netwalker",
    "defendant_slugs": [
      "sebastien-vachon-desjardins"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Vachon-Desjardins",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1490",
        "evidence_excerpt": "Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery.",
        "evidence_locator": "Indictment \u00b6 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vachon-Desjardins",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Inhibit System Recovery",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1112",
        "evidence_excerpt": "Netwalker modified registry keys under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa to weaken local security authority validation.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Modify Registry",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1548.002",
        "evidence_excerpt": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
        "evidence_locator": "Indictment \u00b6 11, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "Bypass User Account Control",
        "tactic": "Privilege Escalation"
      },
      {
        "technique_id": "T1007",
        "evidence_excerpt": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
        "evidence_locator": "Plea Agreement \u00b6 5, Page 13",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
        "technique_name": "System Service Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2020-12-16",
        "description": "Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage."
      },
      {
        "event_type": "extradition",
        "event_date": "2022-03-09",
        "description": "Vachon-Desjardins extradited from Canada to the United States."
      },
      {
        "event_type": "plea",
        "event_date": "2022-06-29",
        "description": "Defendant pleads guilty to all counts in the indictment."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-10-04",
        "description": "Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million."
      }
    ]
  },
  {
    "id": "case-seleznev-point-of-sale",
    "slug": "us-v-seleznev-track2",
    "title": "U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)",
    "summary": "Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
    "case_number": "2:11-cr-00070",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2011-03-03",
    "status": "sentenced",
    "victim_sector": "Retail, Hospitality, Small Business",
    "victim_country": "United States",
    "loss_amount_usd": 169000000,
    "loss_amount_note": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions.",
    "first_seen_at": "2009-10-01T00:00:00Z",
    "last_updated_at": "2026-09-08T15:00:00Z",
    "actor_slug": "track2",
    "defendant_slugs": [
      "roman-seleznev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1046",
        "evidence_excerpt": "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.",
        "evidence_locator": "Trial Transcript Day 4, Page 82",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record: U.S. v. Seleznev",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Network Service Discovery",
        "tactic": "Discovery"
      },
      {
        "technique_id": "T1110",
        "evidence_excerpt": "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.",
        "evidence_locator": "Trial Transcript Day 5, Page 112",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Brute Force",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.",
        "evidence_locator": "Trial Exhibit 14-A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Government Trial Exhibit",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      },
      {
        "technique_id": "T1588.002",
        "evidence_excerpt": "Seleznev purchased specialized memory scraping tools and POS card harvesting scripts from Russian underground forums.",
        "evidence_locator": "Trial Transcript Day 6, Page 140",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
        "technique_name": "Obtain Tool",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2014-07-05",
        "description": "Seleznev arrested by U.S. Secret Service in the Maldives with a laptop containing 1.7 million stolen credit cards."
      },
      {
        "event_type": "verdict",
        "event_date": "2016-08-25",
        "description": "Jury finds Seleznev guilty of 38 federal felony counts including wire fraud and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2017-04-21",
        "description": "Sentenced to 324 months (27 years) in federal prison, the longest computer hacking sentence in U.S. history at the time, and ordered to pay $169,879,276 restitution."
      }
    ]
  },
  {
    "id": "case-kaseya-revil",
    "slug": "us-v-vasinskyi-kaseya-revil",
    "title": "U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)",
    "summary": "Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.",
    "case_number": "3:21-cr-00314",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-08-11",
    "status": "sentenced",
    "victim_sector": "Managed Service Providers, Information Technology, Retail, Education",
    "victim_country": "United States, Sweden, New Zealand",
    "loss_amount_usd": 70000000,
    "loss_amount_note": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.",
    "first_seen_at": "2021-07-02T00:00:00Z",
    "last_updated_at": "2026-09-14T11:00:00Z",
    "actor_slug": "revil-sodinokibi",
    "defendant_slugs": [
      "yaroslav-vasinskyi",
      "yevgeniy-polyanin"
    ],
    "cves": [
      "CVE-2021-30116",
      "CVE-2021-30117",
      "CVE-2021-30118"
    ],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vasinskyi",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1574.002",
        "evidence_excerpt": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
        "evidence_locator": "CISA Advisory AA21-189A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-189A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
        "technique_name": "DLL Side-Loading",
        "tactic": "Persistence"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
        "evidence_locator": "Indictment \u00b6 16, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vasinskyi",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1569.002",
        "evidence_excerpt": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
        "technique_name": "Service Execution",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1082",
        "evidence_excerpt": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
        "evidence_locator": "CISA Advisory AA21-189A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA21-189A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
        "technique_name": "System Information Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2021-10-08",
        "description": "Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border."
      },
      {
        "event_type": "extradition",
        "event_date": "2022-03-03",
        "description": "Extradited from Poland to the Northern District of Texas."
      },
      {
        "event_type": "plea",
        "event_date": "2022-11-01",
        "description": "Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-05-01",
        "description": "Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution."
      }
    ]
  },
  {
    "id": "case-baratov-yahoo",
    "slug": "us-v-baratov-yahoo-breach",
    "title": "U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)",
    "summary": "Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.",
    "case_number": "3:17-cr-00103",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2017-02-28",
    "status": "sentenced",
    "victim_sector": "Internet Services, Telecommunications",
    "victim_country": "United States",
    "loss_amount_usd": 350000000,
    "loss_amount_note": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds.",
    "first_seen_at": "2014-01-01T00:00:00Z",
    "last_updated_at": "2026-09-09T18:00:00Z",
    "actor_slug": "fsb-center-18",
    "defendant_slugs": [
      "karim-baratov",
      "dmitry-dokuchaev",
      "igor-sushchin",
      "alexsey-belan"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
        "evidence_locator": "Indictment \u00b6 22, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Dokuchaev et al.",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.",
        "evidence_locator": "Indictment \u00b6 31, Page 18",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.",
        "evidence_locator": "Indictment \u00b6 27, Page 15",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2017-02-28",
        "description": "Indictment unsealed charging two FSB officers (Dokuchaev, Sushchin) and hackers Alexsey Belan and Karim Baratov."
      },
      {
        "event_type": "arrest",
        "event_date": "2017-03-14",
        "description": "Baratov arrested by Canadian authorities in Hamilton, Ontario."
      },
      {
        "event_type": "plea",
        "event_date": "2017-11-28",
        "description": "Baratov pleads guilty to nine counts of computer hacking and wire fraud conspiracies."
      },
      {
        "event_type": "sentencing",
        "event_date": "2018-05-29",
        "description": "Baratov sentenced to 60 months (5 years) in prison and fined $250,000."
      }
    ]
  },
  {
    "id": "case-schulte-vault7",
    "slug": "us-v-schulte-cia-vault-7",
    "title": "U.S. v. Joshua Schulte (CIA Vault 7 Leak)",
    "summary": "Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
    "case_number": "1:17-cr-00548",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2017-08-24",
    "status": "sentenced",
    "victim_sector": "Intelligence, National Defense, Federal Government",
    "victim_country": "United States",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities.",
    "first_seen_at": "2016-04-20T00:00:00Z",
    "last_updated_at": "2026-09-10T11:00:00Z",
    "actor_slug": "insider-threat",
    "defendant_slugs": [
      "joshua-schulte"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Schulte abused his administrative credentials as a CIA Center for Cyber Intelligence software engineer to grant himself backdoor access to secure development servers.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Schulte",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1070",
        "evidence_excerpt": "Defendant deleted server log files and altered system configuration timestamps to conceal his exfiltration of the CIA development branch.",
        "evidence_locator": "Indictment \u00b6 18, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Indicator Removal",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1560.001",
        "evidence_excerpt": "He compressed the entire CCI codebase into encrypted archives before transferring the files offsite.",
        "evidence_locator": "Trial Transcript Day 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-sdny/pr/former-cia-software-engineer-joshua-adam-schulte-sentenced-40-years-prison-espionage-and",
        "technique_name": "Archive via Utility",
        "tactic": "Collection"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-06-18",
        "description": "Grand jury indicts Schulte for illegal transmission of national defense information and computer hacking under the Espionage Act."
      },
      {
        "event_type": "verdict",
        "event_date": "2022-07-13",
        "description": "Jury convicts Schulte on all counts of espionage, computer hacking, and obstruction of justice."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-02-01",
        "description": "Sentenced to 480 months (40 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-pla-unit-61398",
    "slug": "us-v-sun-kailiang-pla-unit-61398",
    "title": "U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)",
    "summary": "Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.",
    "case_number": "2:14-cr-00118",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2014-05-01",
    "status": "fugitive",
    "victim_sector": "Nuclear Energy, Metals, Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies.",
    "first_seen_at": "2006-01-01T00:00:00Z",
    "last_updated_at": "2026-09-07T12:00:00Z",
    "actor_slug": "pla-unit-61398",
    "defendant_slugs": [
      "sun-kailiang",
      "huang-zhenyu",
      "wen-xinyu",
      "wang-dong",
      "gu-chunhui"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.",
        "evidence_locator": "Indictment \u00b6 15, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Sun Kailiang",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.",
        "evidence_locator": "Indictment \u00b6 29, Page 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2014-05-01",
        "description": "Grand jury unseals 31-count indictment against five PLA Unit 61398 military officers."
      },
      {
        "event_type": "sanction",
        "event_date": "2015-09-25",
        "description": "Cyber espionage agreement signed between U.S. and PRC following sustained enforcement pressure."
      }
    ]
  },
  {
    "id": "case-gonzalez-carding",
    "slug": "us-v-albert-gonzalez-tjx-heartland",
    "title": "U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)",
    "summary": "Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.",
    "case_number": "1:08-cr-10223",
    "court": "U.S. District Court for the District of Massachusetts",
    "district": "D. Mass.",
    "country": "United States",
    "opened_at": "2008-08-05",
    "status": "sentenced",
    "victim_sector": "Retail, Financial Payment Processors",
    "victim_country": "United States",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Direct merchant and bank losses in excess of $200 million across TJX and Heartland.",
    "first_seen_at": "2005-07-01T00:00:00Z",
    "last_updated_at": "2026-09-06T10:00:00Z",
    "actor_slug": "shadowcrew",
    "defendant_slugs": [
      "albert-gonzalez"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks.",
        "evidence_locator": "Indictment \u00b6 14, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Gonzalez",
        "source_url": "https://www.justice.gov/opa/pr/former-secret-service-informant-sentenced-20-years-prison-massive-credit-card-theft",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Installed packet sniffer utilities inside Heartland's payment processing network that captured unencrypted credit card magnetic stripe data during authorization.",
        "evidence_locator": "Indictment \u00b6 22, Page 10",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/former-secret-service-informant-sentenced-20-years-prison-massive-credit-card-theft",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2008-05-07",
        "description": "Gonzalez arrested in a Miami Beach hotel room by U.S. Secret Service agents."
      },
      {
        "event_type": "plea",
        "event_date": "2009-08-28",
        "description": "Pleads guilty to 19 counts of conspiracy, computer fraud, wire fraud, and aggravated identity theft."
      },
      {
        "event_type": "sentencing",
        "event_date": "2010-03-25",
        "description": "Sentenced to 240 months (20 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-tyurin-jpmorgan",
    "slug": "us-v-tyurin-jpmorgan-chase",
    "title": "U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)",
    "summary": "Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.",
    "case_number": "1:15-cr-00393",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2015-11-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Banking, Publishing",
    "victim_country": "United States",
    "loss_amount_usd": 19000000,
    "loss_amount_note": "Court ordered $19,952,861 in restitution to victim financial institutions.",
    "first_seen_at": "2012-01-01T00:00:00Z",
    "last_updated_at": "2026-09-05T14:00:00Z",
    "actor_slug": "shalon-cyber-syndicate",
    "defendant_slugs": [
      "andrei-tyurin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Tyurin",
        "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.",
        "evidence_locator": "Indictment \u00b6 15, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "extradition",
        "event_date": "2018-09-07",
        "description": "Extradited from the Republic of Georgia to the Southern District of New York."
      },
      {
        "event_type": "plea",
        "event_date": "2019-09-23",
        "description": "Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-01-07",
        "description": "Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956."
      }
    ]
  },
  {
    "id": "case-paige-thompson-capitalone",
    "slug": "us-v-thompson-capital-one-breach",
    "title": "U.S. v. Paige Thompson (Capital One Cloud Breach)",
    "summary": "Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.",
    "case_number": "2:19-cr-00159",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2019-07-29",
    "status": "convicted",
    "victim_sector": "Financial Services, Cloud Computing",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 270000000,
    "loss_amount_note": "Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines.",
    "first_seen_at": "2019-03-01T00:00:00Z",
    "last_updated_at": "2026-09-04T11:00:00Z",
    "actor_slug": "erratic",
    "defendant_slugs": [
      "paige-thompson"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.",
        "evidence_locator": "Indictment \u00b6 9, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Thompson",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets.",
        "evidence_locator": "Trial Transcript Day 3, Page 54",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1083",
        "evidence_excerpt": "Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories.",
        "evidence_locator": "Indictment \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Thompson",
        "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
        "technique_name": "File and Directory Discovery",
        "tactic": "Discovery"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2019-07-29",
        "description": "FBI agents arrest Thompson at her residence in Seattle."
      },
      {
        "event_type": "verdict",
        "event_date": "2022-06-17",
        "description": "Jury finds Thompson guilty of wire fraud and six counts of unauthorized access to a protected computer."
      },
      {
        "event_type": "sentencing",
        "event_date": "2022-10-04",
        "description": "Sentenced to time served and five years of supervised release with restitution ordered."
      }
    ]
  },
  {
    "id": "case-bitzlato-hydra",
    "slug": "us-v-legkodymov-bitzlato",
    "title": "U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)",
    "summary": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
    "case_number": "1:23-cr-00021",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-01-17",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Financial Services",
    "victim_country": "United States, Russia, France",
    "loss_amount_usd": 700000000,
    "loss_amount_note": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds.",
    "first_seen_at": "2018-05-01T00:00:00Z",
    "last_updated_at": "2026-09-03T16:00:00Z",
    "actor_slug": "bitzlato",
    "defendant_slugs": [
      "anatoly-legkodymov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Bitzlato operated with negligible anti-money laundering controls, advertising that users could open accounts with no identity verification via Tor.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Legkodymov",
        "source_url": "https://www.justice.gov/opa/pr/founder-and-majority-owner-bitzlato-pleads-guilty-unlicensed-money-transmitting",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2023-01-17",
        "description": "Legkodymov arrested in Miami by FBI agents in coordinated international operation."
      },
      {
        "event_type": "plea",
        "event_date": "2023-12-06",
        "description": "Defendant pleads guilty to operating an unlicensed money transmitting business."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-07-18",
        "description": "Sentenced to time served (18 months) and ordered to forfeit all interest in Bitzlato ($23 million)."
      }
    ]
  },
  {
    "id": "case-genesis-market",
    "slug": "genesis-market-takedown-cookie-monster",
    "title": "Operation Cookie Monster (Genesis Market Takedown)",
    "summary": "Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
    "case_number": "Operation Cookie Monster",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2023-04-04",
    "status": "alleged",
    "victim_sector": "Consumer Accounts, Banking, E-Commerce",
    "victim_country": "United States, United Kingdom, European Union, Australia",
    "loss_amount_usd": 50000000,
    "loss_amount_note": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide.",
    "first_seen_at": "2018-01-01T00:00:00Z",
    "last_updated_at": "2026-09-02T13:00:00Z",
    "actor_slug": "genesis-market",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware.",
        "evidence_locator": "DOJ Seizure Affidavit \u00b6 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Press Release 23-388",
        "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Purchasers loaded stolen fingerprints into custom browser plugins to perfectly impersonate victim machines and bypass fraud detection.",
        "evidence_locator": "DOJ Seizure Affidavit \u00b6 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Seizure Notice",
        "source_url": "https://www.justice.gov/opa/pr/genesis-market-seized-multinational-operation",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "court_order",
        "event_date": "2023-04-04",
        "description": "FBI and 17 international partner agencies seize 11 domains hosting the Genesis Market infrastructure."
      },
      {
        "event_type": "arrest",
        "event_date": "2023-04-05",
        "description": "Over 120 arrests executed globally against Genesis Market high-volume purchasers."
      }
    ]
  },
  {
    "id": "case-chipmixer-nguyen",
    "slug": "us-v-nguyen-chipmixer",
    "title": "U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)",
    "summary": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
    "case_number": "2:23-mj-00122",
    "court": "U.S. District Court for the Eastern District of Pennsylvania",
    "district": "E.D. Pa.",
    "country": "United States",
    "opened_at": "2023-03-15",
    "status": "fugitive",
    "victim_sector": "Financial Services, Blockchain Infrastructure",
    "victim_country": "United States, Germany",
    "loss_amount_usd": 3000000000,
    "loss_amount_note": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware.",
    "first_seen_at": "2017-08-01T00:00:00Z",
    "last_updated_at": "2026-09-01T15:00:00Z",
    "actor_slug": "chipmixer",
    "defendant_slugs": [
      "minh-quoc-nguyen"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "ChipMixer chopped up Bitcoin deposits into fixed small denomination chips and redistributed them through multiple dummy wallets to defeat blockchain tracing.",
        "evidence_locator": "Criminal Complaint \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Nguyen",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1571",
        "evidence_excerpt": "ChipMixer communicated with relay nodes over non-standard high ports to evade firewall packet categorization.",
        "evidence_locator": "Affidavit \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Affidavit",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-investigation-leads-shutdown-darknet-cryptocurrency-mixer-processed-over-3",
        "technique_name": "Non-Standard Port",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2023-03-15",
        "description": "Criminal complaint filed in the Eastern District of Pennsylvania charging Nguyen with money laundering and identity theft."
      },
      {
        "event_type": "court_order",
        "event_date": "2023-03-15",
        "description": "Federal court order and German BKA operation seize ChipMixer servers and $46 million in cryptocurrency."
      }
    ]
  },
  {
    "id": "case-trickbot-witte",
    "slug": "us-v-witte-dunaev-trickbot",
    "title": "U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)",
    "summary": "Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.",
    "case_number": "1:20-cr-00384",
    "court": "U.S. District Court for the Northern District of Ohio",
    "district": "N.D. Ohio",
    "country": "United States",
    "opened_at": "2021-02-18",
    "status": "sentenced",
    "victim_sector": "Healthcare, Banking, Local Government",
    "victim_country": "United States, United Kingdom, Australia",
    "loss_amount_usd": 180000000,
    "loss_amount_note": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.",
    "first_seen_at": "2016-10-01T00:00:00Z",
    "last_updated_at": "2026-08-30T10:00:00Z",
    "actor_slug": "wizard-spider",
    "defendant_slugs": [
      "alla-witte",
      "vladimir-dunaev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Witte et al.",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1003",
        "evidence_excerpt": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
        "evidence_locator": "Indictment \u00b6 19, Page 11",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
        "technique_name": "OS Credential Dumping",
        "tactic": "Credential Access"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
        "evidence_locator": "CISA Advisory AA20-302A",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA20-302A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "extradition",
        "event_date": "2021-06-04",
        "description": "Alla Witte extradited from Suriname to the Northern District of Ohio."
      },
      {
        "event_type": "extradition",
        "event_date": "2021-10-20",
        "description": "Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio."
      },
      {
        "event_type": "sentencing",
        "event_date": "2023-06-20",
        "description": "Alla Witte sentenced to 32 months in prison after pleading guilty."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-01-24",
        "description": "Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison."
      }
    ]
  },
  {
    "id": "case-kriuchkov-tesla",
    "slug": "us-v-kriuchkov-tesla-ransomware",
    "title": "U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)",
    "summary": "Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
    "case_number": "3:20-cr-00032",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2020-08-25",
    "status": "sentenced",
    "victim_sector": "Automotive, Advanced Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Intended extortion demand was $4 million; operation was intercepted before malware execution.",
    "first_seen_at": "2020-07-16T00:00:00Z",
    "last_updated_at": "2026-08-28T14:00:00Z",
    "actor_slug": "kriuchkov-group",
    "defendant_slugs": [
      "egor-kriuchkov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Defendant recruited an insider with legitimate administrator privileges to connect an infected USB drive and execute custom malware within the company's intranet.",
        "evidence_locator": "Criminal Complaint \u00b6 12, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Kriuchkov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1486",
        "evidence_excerpt": "The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers.",
        "evidence_locator": "Plea Agreement \u00b6 6, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "technique_id": "T1498",
        "evidence_excerpt": "The plan included launching a distributed network denial of service flood against Tesla's external gateways to distract security staff during malware deployment.",
        "evidence_locator": "Complaint \u00b6 15, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Kriuchkov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-conspiracy-cause-damage-protected-computer",
        "technique_name": "Network Denial of Service",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-08-22",
        "description": "Kriuchkov arrested in Los Angeles while attempting to flee the United States."
      },
      {
        "event_type": "plea",
        "event_date": "2021-03-18",
        "description": "Pleads guilty to conspiracy to intentionally cause damage to a protected computer."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-05-25",
        "description": "Sentenced to time served (10 months) and ordered to pay $14,825 in restitution before deportation."
      }
    ]
  },
  {
    "id": "case-marcus-hutchins-kronos",
    "slug": "us-v-hutchins-kronos-malware",
    "title": "U.S. v. Marcus Hutchins (Kronos Banking Malware)",
    "summary": "British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
    "case_number": "2:17-cr-00124",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2017-07-12",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Finance",
    "victim_country": "United States, Germany, United Kingdom",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Stole banking credentials and redirected bank transactions in criminal markets.",
    "first_seen_at": "2014-06-01T00:00:00Z",
    "last_updated_at": "2026-08-25T11:00:00Z",
    "actor_slug": "malwaretech",
    "defendant_slugs": [
      "marcus-hutchins"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.",
        "evidence_locator": "Superseding Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Hutchins",
        "source_url": "https://www.justice.gov/usao-edwi/pr/british-national-pleads-guilty-developing-and-distributing-malicious-computer-code",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-08-02",
        "description": "Hutchins arrested at Las Vegas airport following the DEF CON security conference."
      },
      {
        "event_type": "plea",
        "event_date": "2019-04-19",
        "description": "Pleads guilty to two counts of conspiracy to distribute malicious software."
      },
      {
        "event_type": "sentencing",
        "event_date": "2019-07-26",
        "description": "Sentenced to time served and one year of supervised release with no prison time or fines, recognizing his positive contributions in halting WannaCry."
      }
    ]
  },
  {
    "id": "case-nikulin-linkedin",
    "slug": "us-v-nikulin-linkedin-dropbox",
    "title": "U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)",
    "summary": "Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.",
    "case_number": "3:16-cr-00440",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2016-10-05",
    "status": "sentenced",
    "victim_sector": "Internet Services, Social Media, Cloud Storage",
    "victim_country": "United States",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.",
    "first_seen_at": "2012-03-01T00:00:00Z",
    "last_updated_at": "2026-08-20T16:00:00Z",
    "actor_slug": "chinik",
    "defendant_slugs": [
      "yevgeniy-nikulin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
        "evidence_locator": "Trial Transcript Day 4, Page 61",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Trial Record: U.S. v. Nikulin",
        "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1078",
        "evidence_excerpt": "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2016-10-05",
        "description": "Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice."
      },
      {
        "event_type": "extradition",
        "event_date": "2018-03-30",
        "description": "Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied."
      },
      {
        "event_type": "verdict",
        "event_date": "2020-07-10",
        "description": "Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft."
      },
      {
        "event_type": "sentencing",
        "event_date": "2020-09-29",
        "description": "Sentenced to 88 months (7 years and 4 months) in federal prison."
      }
    ]
  },
  {
    "id": "case-levashov-kelihos",
    "slug": "us-v-levashov-kelihos-botnet",
    "title": "U.S. v. Peter Levashov (Kelihos Botnet)",
    "summary": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
    "case_number": "3:17-cr-00083",
    "court": "U.S. District Court for the District of Connecticut",
    "district": "D. Conn.",
    "country": "United States",
    "opened_at": "2017-04-07",
    "status": "pleaded",
    "victim_sector": "E-Commerce, Consumer Services, Telecommunications",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 25000000,
    "loss_amount_note": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees.",
    "first_seen_at": "2010-01-01T00:00:00Z",
    "last_updated_at": "2026-08-15T12:00:00Z",
    "actor_slug": "kelihos-crew",
    "defendant_slugs": [
      "peter-levashov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure.",
        "evidence_locator": "Indictment \u00b6 11, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Levashov",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-pleads-guilty-operating-notorious-kelihos-botnet",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-04-07",
        "description": "Levashov arrested while vacationing in Barcelona, Spain, by Spanish National Police."
      },
      {
        "event_type": "extradition",
        "event_date": "2018-02-02",
        "description": "Extradited from Spain to the District of Connecticut."
      },
      {
        "event_type": "plea",
        "event_date": "2018-09-12",
        "description": "Pleads guilty to wire fraud, computer fraud, and identity theft charges."
      }
    ]
  },
  {
    "id": "case-irgc-water-cyberav3ngers",
    "slug": "us-v-irgc-cyberav3ngers-water",
    "title": "U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)",
    "summary": "Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
    "case_number": "2:24-cr-00185",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2024-09-24",
    "status": "fugitive",
    "victim_sector": "Water and Wastewater Systems, Energy",
    "victim_country": "United States, Israel",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey.",
    "first_seen_at": "2023-11-25T00:00:00Z",
    "last_updated_at": "2026-09-21T18:00:00Z",
    "actor_slug": "irgc-cyber-electronic-command",
    "defendant_slugs": [
      "hamid-reza-lashgarian",
      "mahdi-lashgarian"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Defendants gained access to internet-connected Unitronics Vision PLCs because the industrial devices remained configured with the default manufacturer password '1111'.",
        "evidence_locator": "CISA Advisory AA23-335A \u00b6 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Advisory AA23-335A",
        "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1485",
        "evidence_excerpt": "Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation.",
        "evidence_locator": "Indictment \u00b6 18, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "DOJ Indictment Press Release",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-charges-six-iranian-nationals-cyberattacks-us-critical-infrastructure",
        "technique_name": "Data Destruction",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2023-11-28",
        "description": "CISA publishes alert on exploitation of Unitronics PLCs used in water systems."
      },
      {
        "event_type": "sanction",
        "event_date": "2024-02-02",
        "description": "Treasury OFAC sanctions officials of the IRGC Cyber-Electronic Command."
      },
      {
        "event_type": "indictment",
        "event_date": "2024-09-24",
        "description": "Unsealing of criminal indictment against six Iranian military cyber actors."
      }
    ]
  },
  {
    "id": "case-netyksho-apt28",
    "slug": "us-v-netyksho-apt28-dnc",
    "title": "U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)",
    "summary": "Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.",
    "case_number": "1:18-cr-00215",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2018-07-13",
    "status": "fugitive",
    "victim_sector": "Political Organizations, Government",
    "victim_country": "United States",
    "loss_amount_usd": 10000000,
    "loss_amount_note": "Extensive campaign disruption and federal investigative expenditure.",
    "first_seen_at": "2016-03-15T00:00:00Z",
    "last_updated_at": "2026-09-02T10:00:00Z",
    "actor_slug": "apt28",
    "defendant_slugs": [
      "viktor-netyksho",
      "boris-antonov",
      "dmitriy-badin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.",
        "evidence_locator": "Indictment \u00b6 21, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Netyksho",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      },
      {
        "technique_id": "T1059.001",
        "evidence_excerpt": "Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.",
        "evidence_locator": "Indictment \u00b6 33, Page 14",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "PowerShell",
        "tactic": "Execution"
      },
      {
        "technique_id": "T1583.001",
        "evidence_excerpt": "GRU officers registered misleading domain names such as dcleaks.com and actblues.com using cryptocurrency to stage leaks.",
        "evidence_locator": "Indictment \u00b6 28, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Netyksho",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Domains",
        "tactic": "Resource Development"
      },
      {
        "technique_id": "T1071.004",
        "evidence_excerpt": "X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls.",
        "evidence_locator": "Indictment \u00b6 35, Page 16",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "DNS Tunneling",
        "tactic": "Command and Control"
      },
      {
        "technique_id": "T1546.003",
        "evidence_excerpt": "Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.",
        "evidence_locator": "Indictment \u00b6 38, Page 17",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment",
        "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
        "technique_name": "Windows Management Instrumentation Event Subscription",
        "tactic": "Persistence"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-07-13",
        "description": "Special Counsel Robert Mueller unseals 11-count indictment against 12 GRU military officers."
      }
    ]
  },
  {
    "id": "case-brovko-botnet",
    "slug": "us-v-brovko-botnet-logs",
    "title": "U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)",
    "summary": "Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
    "case_number": "1:20-cr-00037",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2020-02-12",
    "status": "sentenced",
    "victim_sector": "Consumer Finance, Banking",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses.",
    "first_seen_at": "2007-01-01T00:00:00Z",
    "last_updated_at": "2026-08-18T14:00:00Z",
    "actor_slug": "brovko-network",
    "defendant_slugs": [
      "aleksandr-brovko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1555",
        "evidence_excerpt": "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.",
        "evidence_locator": "Plea Agreement \u00b6 4, Page 5",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Brovko",
        "source_url": "https://www.justice.gov/usao-edva/pr/russian-national-sentenced-conspiracy-commit-wire-fraud",
        "technique_name": "Credentials from Password Stores",
        "tactic": "Credential Access"
      }
    ],
    "events": [
      {
        "event_type": "plea",
        "event_date": "2020-02-14",
        "description": "Pleads guilty to conspiracy to commit wire fraud and computer intrusion."
      },
      {
        "event_type": "sentencing",
        "event_date": "2020-10-30",
        "description": "Sentenced to 96 months (8 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-firsov-deerio",
    "slug": "us-v-firsov-deer-io",
    "title": "U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)",
    "summary": "Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
    "case_number": "3:20-cr-01053",
    "court": "U.S. District Court for the Southern District of California",
    "district": "S.D. Cal.",
    "country": "United States",
    "opened_at": "2020-03-04",
    "status": "sentenced",
    "victim_sector": "Consumer Services, E-Commerce, Identity Providers",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 17000000,
    "loss_amount_note": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts.",
    "first_seen_at": "2013-10-01T00:00:00Z",
    "last_updated_at": "2026-08-14T11:00:00Z",
    "actor_slug": "deer-io",
    "defendant_slugs": [
      "kirill-firsov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.",
        "evidence_locator": "Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Firsov",
        "source_url": "https://www.justice.gov/usao-sdca/pr/russian-national-sentenced-operating-cybercrime-storefront-trafficked-stolen-credentials",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-03-04",
        "description": "Firsov arrested by FBI agents at New York's John F. Kennedy International Airport."
      },
      {
        "event_type": "plea",
        "event_date": "2021-01-22",
        "description": "Pleads guilty to trafficking in unauthorized access devices."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-04-26",
        "description": "Sentenced to 30 months in federal prison."
      }
    ]
  },
  {
    "id": "case-medvedev-infraud",
    "slug": "us-v-medvedev-infraud-organization",
    "title": "U.S. v. Sergey Medvedev et al. (Infraud Organization)",
    "summary": "Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
    "case_number": "2:17-cr-00360",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2018-01-26",
    "status": "sentenced",
    "victim_sector": "Financial Services, Consumer Credit, Retail",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 568000000,
    "loss_amount_note": "Caused actual financial losses of over $568 million to financial institutions and cardholders.",
    "first_seen_at": "2010-10-01T00:00:00Z",
    "last_updated_at": "2026-08-10T15:00:00Z",
    "actor_slug": "infraud-organization",
    "defendant_slugs": [
      "sergey-medvedev"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Medvedev",
        "source_url": "https://www.justice.gov/opa/pr/co-founder-infraud-organization-sentenced-10-years-prison-role-568-million-cyberfraud-enterprise",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2018-02-02",
        "description": "Medvedev arrested in Bangkok, Thailand, with over 100,000 Bitcoins in digital wallets."
      },
      {
        "event_type": "plea",
        "event_date": "2020-06-26",
        "description": "Pleads guilty to RICO conspiracy in federal court in Las Vegas."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-03-19",
        "description": "Sentenced to 120 months (10 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-barriss-swatting",
    "slug": "us-v-barriss-serial-swatting",
    "title": "U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)",
    "summary": "Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.",
    "case_number": "6:18-cr-10028",
    "court": "U.S. District Court for the District of Kansas",
    "district": "D. Kan.",
    "country": "United States",
    "opened_at": "2018-03-20",
    "status": "sentenced",
    "victim_sector": "Emergency Services, Municipalities, Schools",
    "victim_country": "United States",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Caused tragic loss of innocent human life, massive municipal emergency response mobilization, and $1.5 million in damages.",
    "first_seen_at": "2017-01-01T00:00:00Z",
    "last_updated_at": "2026-08-05T12:00:00Z",
    "actor_slug": "swatting-group",
    "defendant_slugs": [
      "tyler-barriss"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Barriss routed VoIP phone communications through anonymous proxies and spoofing apps to simulate local caller ID numbers during emergency calls.",
        "evidence_locator": "Plea Agreement \u00b6 5, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Plea Agreement: U.S. v. Barriss",
        "source_url": "https://www.justice.gov/opa/pr/serial-swatter-sentenced-20-years-prison-fatal-wichita-kansas-swatting",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2017-12-29",
        "description": "Barriss arrested by Los Angeles police following the fatal Wichita swatting call."
      },
      {
        "event_type": "plea",
        "event_date": "2018-11-13",
        "description": "Pleads guilty to 51 federal charges including cyberstalking, false emergency reporting, and wire fraud."
      },
      {
        "event_type": "sentencing",
        "event_date": "2019-03-29",
        "description": "Sentenced to 240 months (20 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-brett-johnson-shadowcrew",
    "slug": "us-v-johnson-shadowcrew",
    "title": "U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)",
    "summary": "Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.",
    "case_number": "2:04-cr-00725",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2004-10-26",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Identity, E-Commerce",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Facilitated millions in fraudulent debit card cloning transactions.",
    "first_seen_at": "2002-05-01T00:00:00Z",
    "last_updated_at": "2026-08-01T10:00:00Z",
    "actor_slug": "shadowcrew",
    "defendant_slugs": [
      "brett-johnson"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.002",
        "evidence_excerpt": "Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
        "evidence_locator": "Indictment \u00b6 11, Page 6",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Johnson",
        "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2004/shadowcrewIndict.htm",
        "technique_name": "Spearphishing Link",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2005-02-08",
        "description": "Johnson arrested by U.S. Secret Service in Operation Open Market."
      },
      {
        "event_type": "sentencing",
        "event_date": "2007-06-20",
        "description": "Sentenced to 90 months (7.5 years) in federal prison."
      }
    ]
  },
  {
    "id": "case-max-vision-cardersmarket",
    "slug": "us-v-vision-cardersmarket",
    "title": "U.S. v. Max Ray Vision (Iceman / CardersMarket)",
    "summary": "Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.",
    "case_number": "3:07-cr-00624",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2007-09-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 86000000,
    "loss_amount_note": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges.",
    "first_seen_at": "2004-01-01T00:00:00Z",
    "last_updated_at": "2026-07-28T14:00:00Z",
    "actor_slug": "cardersmarket",
    "defendant_slugs": [
      "max-vision"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Vision",
        "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2010/visionSent.pdf",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2007-09-08",
        "description": "Vision arrested at his San Francisco apartment by federal agents."
      },
      {
        "event_type": "plea",
        "event_date": "2009-06-29",
        "description": "Pleads guilty to two counts of wire fraud conspiracy."
      },
      {
        "event_type": "sentencing",
        "event_date": "2010-02-12",
        "description": "Sentenced to 168 months (14 years) in federal prison and ordered to pay $27.5 million in restitution."
      }
    ]
  },
  {
    "id": "case-khusyaynova-lakhta",
    "slug": "us-v-khusyaynova-project-lakhta",
    "title": "U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)",
    "summary": "Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.",
    "case_number": "1:18-mj-00464",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2018-09-28",
    "status": "fugitive",
    "victim_sector": "Electoral Systems, Social Media, Public Institutions",
    "victim_country": "United States",
    "loss_amount_usd": 35000000,
    "loss_amount_note": "Managed an operating budget exceeding $35 million for covert information warfare activities.",
    "first_seen_at": "2014-04-01T00:00:00Z",
    "last_updated_at": "2026-07-25T11:00:00Z",
    "actor_slug": "project-lakhta",
    "defendant_slugs": [
      "elena-khusyaynova"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1584",
        "evidence_excerpt": "Operatives purchased thousands of virtual private servers and compromised proxy networks in the United States to disguise Russian origins.",
        "evidence_locator": "Criminal Complaint \u00b6 24, Page 12",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Khusyaynova",
        "source_url": "https://www.justice.gov/opa/pr/russian-national-charged-interfering-us-political-system",
        "technique_name": "Compromise Infrastructure",
        "tactic": "Resource Development"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2018-09-28",
        "description": "Criminal complaint filed charging Khusyaynova with conspiracy to defraud the United States."
      }
    ]
  },
  {
    "id": "case-kulkov-try2check",
    "slug": "us-v-kulkov-try2check",
    "title": "U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)",
    "summary": "Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.",
    "case_number": "1:23-cr-00171",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-04-18",
    "status": "fugitive",
    "victim_sector": "Financial Services, Payment Networks",
    "victim_country": "United States",
    "loss_amount_usd": 18000000,
    "loss_amount_note": "Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service.",
    "first_seen_at": "2005-01-01T00:00:00Z",
    "last_updated_at": "2026-07-20T16:00:00Z",
    "actor_slug": "try2check",
    "defendant_slugs": [
      "denis-kulkov"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Kulkov",
        "source_url": "https://www.justice.gov/usao-edny/pr/justice-and-state-departments-announce-action-against-russian-national-operating-major",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2023-04-18",
        "description": "Federal indictment unsealed charging Kulkov with access device fraud, computer intrusion, and money laundering; Try2Check domains seized in coordination with Austrian and German authorities."
      }
    ]
  },
  {
    "id": "case-incognito-siew",
    "slug": "us-v-siew-incognito-market",
    "title": "U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)",
    "summary": "Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.",
    "case_number": "1:24-cr-00305",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2024-05-20",
    "status": "charged",
    "victim_sector": "Consumer Privacy, Cryptocurrency",
    "victim_country": "United States, Taiwan",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Processed over $100 million in illicit crypto sales and demanded extortion fees up to $20,000 per vendor.",
    "first_seen_at": "2020-10-01T00:00:00Z",
    "last_updated_at": "2026-07-15T12:00:00Z",
    "actor_slug": "incognito-market",
    "defendant_slugs": [
      "rui-siang-siew"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Operated hidden onion services over the Tor network equipped with automated cryptocurrency escrow mechanisms.",
        "evidence_locator": "Criminal Complaint \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Siew",
        "source_url": "https://www.justice.gov/usao-sdny/pr/owner-and-operator-incognito-market-dark-web-narcotics-marketplace-arrested-and-charged",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2024-05-18",
        "description": "Siew arrested at JFK International Airport in New York upon arrival from Taiwan."
      }
    ]
  },
  {
    "id": "case-boiko-qqaazz",
    "slug": "us-v-boiko-qqaazz-laundering",
    "title": "U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)",
    "summary": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
    "case_number": "2:20-cr-00227",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-09-15",
    "status": "sentenced",
    "victim_sector": "Financial Institutions, Ransomware Victims",
    "victim_country": "United States, United Kingdom, Latvia, Georgia",
    "loss_amount_usd": 20000000,
    "loss_amount_note": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe.",
    "first_seen_at": "2016-01-01T00:00:00Z",
    "last_updated_at": "2026-07-10T14:00:00Z",
    "actor_slug": "qqaazz",
    "defendant_slugs": [
      "maksim-boiko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "QQAAZZ used hundreds of bank accounts opened in the names of fake shell companies to rapidly layer stolen wire funds before converting them into Bitcoin.",
        "evidence_locator": "Indictment \u00b6 16, Page 9",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Boiko",
        "source_url": "https://www.justice.gov/opa/pr/fourteen-alleged-members-qqaazz-cybercrime-network-charged-laundering-millions-stolen-cyber",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2020-03-28",
        "description": "Boiko arrested in Miami, Florida, with $3.8 million in seized cryptocurrency."
      },
      {
        "event_type": "plea",
        "event_date": "2021-04-12",
        "description": "Pleads guilty to conspiracy to commit money laundering in federal court in Pittsburgh."
      },
      {
        "event_type": "sentencing",
        "event_date": "2021-07-16",
        "description": "Sentenced to time served and ordered to forfeit over $3.8 million in illicit cryptocurrency."
      }
    ]
  },
  {
    "id": "case-radchenko-sec-edgar-hack",
    "slug": "us-v-radchenko-sec-edgar-intrusion",
    "title": "U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)",
    "summary": "Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.",
    "case_number": "2:19-cr-00040",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2019-01-15",
    "status": "fugitive",
    "victim_sector": "Regulatory Agencies, Securities Markets, Public Corporations",
    "victim_country": "United States",
    "loss_amount_usd": 4100000,
    "loss_amount_note": "Generated $4.1 million in illegal trading profits using stolen corporate filings.",
    "first_seen_at": "2016-05-01T00:00:00Z",
    "last_updated_at": "2026-07-05T11:00:00Z",
    "actor_slug": "edgar-hack-syndicate",
    "defendant_slugs": [
      "artem-radchenko"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
        "evidence_locator": "Indictment \u00b6 14, Page 8",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Radchenko",
        "source_url": "https://www.justice.gov/opa/pr/two-ukrainian-nationals-indicted-computer-hacking-and-securities-fraud-scheme",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2019-01-15",
        "description": "Grand jury in Newark, New Jersey, indicts Radchenko and Oleksandr Ieremenko for computer fraud and wire fraud."
      }
    ]
  },
  {
    "id": "case-daniel-rhyne-ransomware",
    "slug": "us-v-rhyne-insider-ransomware-extortion",
    "title": "U.S. v. Daniel Rhyne (Industrial Insider Extortion)",
    "summary": "Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
    "case_number": "3:24-cr-00122",
    "court": "U.S. District Court for the Western District of Missouri",
    "district": "W.D. Mo.",
    "country": "United States",
    "opened_at": "2024-04-16",
    "status": "charged",
    "victim_sector": "Industrial Manufacturing, Critical Infrastructure",
    "victim_country": "United States",
    "loss_amount_usd": 750000,
    "loss_amount_note": "Demanded $750,000 ransom and caused significant corporate operational stoppage.",
    "first_seen_at": "2023-11-20T00:00:00Z",
    "last_updated_at": "2026-07-01T15:00:00Z",
    "actor_slug": "insider-threat",
    "defendant_slugs": [
      "daniel-rhyne"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Rhyne accessed domain controllers using an unauthorized administrative service account that he covertly provisioned weeks earlier.",
        "evidence_locator": "Criminal Complaint \u00b6 9, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Complaint: U.S. v. Rhyne",
        "source_url": "https://www.justice.gov/usao-wdmo/pr/former-systems-administrator-charged-extortion-and-intentionally-damaging-protected",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2024-04-18",
        "description": "Rhyne arrested in Kansas City by FBI agents."
      }
    ]
  },
  {
    "id": "case-snowflake-credential-stuffing",
    "slug": "snowflake-multi-tenant-credential-attacks",
    "title": "Snowflake Customer Multi-Tenant Credential Stuffing Campaign",
    "summary": "Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
    "case_number": "SEC CIK 0001640147",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2024-05-31",
    "status": "alleged",
    "victim_sector": "Telecommunications, Entertainment, Banking, Cloud Services",
    "victim_country": "United States, Spain, Worldwide",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.",
    "first_seen_at": "2024-04-14T00:00:00Z",
    "last_updated_at": "2026-06-25T14:00:00Z",
    "actor_slug": "unc5537",
    "defendant_slugs": [],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Threat actors authenticated to victim Snowflake tenants using valid usernames and passwords that had been stolen by info-stealers (Lumma, RedLine) months earlier.",
        "evidence_locator": "Mandiant Joint Advisory \u00b6 2",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Mandiant & Snowflake Joint Security Bulletin",
        "source_url": "https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      },
      {
        "technique_id": "T1041",
        "evidence_excerpt": "Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables.",
        "evidence_locator": "CISA Advisory Alert",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "CISA Alert",
        "source_url": "https://www.cisa.gov/news-events/alerts",
        "technique_name": "Exfiltration Over C2 Channel",
        "tactic": "Exfiltration"
      }
    ],
    "events": [
      {
        "event_type": "advisory",
        "event_date": "2024-06-05",
        "description": "CISA issues alert warning organizations with Snowflake tenants to enforce multi-factor authentication and review network allowlists."
      }
    ]
  },
  {
    "id": "case-james-zhong-silkroad-theft",
    "slug": "us-v-zhong-silk-road-bitcoin-seizure",
    "title": "U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)",
    "summary": "Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Road darknet market in 2012 by triggering race conditions in the withdrawal logic.",
    "case_number": "1:22-cr-00594",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2022-11-04",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Darknet Markets",
    "victim_country": "United States",
    "loss_amount_usd": 3360000000,
    "loss_amount_note": "Largest cryptocurrency seizure in DOJ history at the time: 50,676 Bitcoins valued at $3.36 billion.",
    "first_seen_at": "2012-09-01T00:00:00Z",
    "last_updated_at": "2026-06-20T10:00:00Z",
    "actor_slug": "zhong-silkroad",
    "defendant_slugs": [
      "james-zhong"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1190",
        "evidence_excerpt": "Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances.",
        "evidence_locator": "Information \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Information: U.S. v. Zhong",
        "source_url": "https://www.justice.gov/usao-sdny/pr/us-attorney-announces-historic-336-billion-cryptocurrency-seizure-and-conviction-connection",
        "technique_name": "Exploit Public-Facing Application",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "court_order",
        "event_date": "2021-11-09",
        "description": "IRS Criminal Investigation and federal agents execute search warrant at Zhong's Gainesville residence, seizing 50,491 Bitcoins."
      },
      {
        "event_type": "plea",
        "event_date": "2022-11-04",
        "description": "Zhong pleads guilty to wire fraud in Manhattan federal court."
      },
      {
        "event_type": "sentencing",
        "event_date": "2023-04-14",
        "description": "Sentenced to 12 months and one day in prison."
      }
    ]
  },
  {
    "id": "case-lichtenstein-bitfinex",
    "slug": "us-v-lichtenstein-bitfinex-heist-laundering",
    "title": "U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)",
    "summary": "Conviction of Ilya Lichtenstein and Heather Morgan for executing the 2016 hack of the Bitfinex virtual currency exchange, stealing 119,754 Bitcoins (valued at $4.5 billion at arrest), and laundering the funds through complex cryptocurrency mixers and darknet markets.",
    "case_number": "1:23-cr-00239",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2022-02-07",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency Exchanges, Financial Services",
    "victim_country": "United States, Hong Kong",
    "loss_amount_usd": 4500000000,
    "loss_amount_note": "Stole 119,754 Bitcoins from Bitfinex; DOJ recovered 94,000 Bitcoins valued at $3.6 billion in the largest single financial seizure in U.S. history.",
    "first_seen_at": "2016-08-02T00:00:00Z",
    "last_updated_at": "2026-06-15T16:00:00Z",
    "actor_slug": "bitfinex-heist",
    "defendant_slugs": [
      "ilya-lichtenstein",
      "heather-morgan"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1078",
        "evidence_excerpt": "Lichtenstein gained access to Bitfinex's internal systems and authorized over 2,000 fraudulent cryptocurrency withdrawal transactions to private wallets.",
        "evidence_locator": "Statement of Offense \u00b6 6, Page 3",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Statement of Offense: U.S. v. Lichtenstein",
        "source_url": "https://www.justice.gov/opa/pr/two-individuals-plead-guilty-money-laundering-conspiracies-connection-bitfinex-hack",
        "technique_name": "Valid Accounts",
        "tactic": "Defense Evasion"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2022-02-08",
        "description": "Lichtenstein and Morgan arrested in Manhattan by federal agents with recovery of 94,000 Bitcoins."
      },
      {
        "event_type": "plea",
        "event_date": "2023-08-03",
        "description": "Defendants plead guilty to conspiracy to commit money laundering in D.D.C."
      },
      {
        "event_type": "sentencing",
        "event_date": "2024-11-14",
        "description": "Lichtenstein sentenced to 60 months (5 years) in federal prison; Morgan sentenced to 18 months."
      }
    ]
  },
  {
    "id": "case-ross-ulbricht-silkroad",
    "slug": "us-v-ross-ulbricht-silk-road",
    "title": "U.S. v. Ross Ulbricht (Dread Pirate Roberts / Silk Road)",
    "summary": "Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and Bitcoin.",
    "case_number": "1:14-cr-00068",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2014-02-04",
    "status": "sentenced",
    "victim_sector": "Public Safety, E-Commerce, Controlled Substances",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 213000000,
    "loss_amount_note": "Generated $213 million in total sales and $13 million in commissions across 1.5 million transactions.",
    "first_seen_at": "2011-01-01T00:00:00Z",
    "last_updated_at": "2026-06-10T12:00:00Z",
    "actor_slug": "silk-road",
    "defendant_slugs": [
      "ross-ulbricht"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1090",
        "evidence_excerpt": "Ulbricht built Silk Road as a hidden service on the Tor network to conceal server IP addresses and protect buyer and seller anonymity.",
        "evidence_locator": "Indictment \u00b6 8, Page 4",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Ulbricht",
        "source_url": "https://www.justice.gov/usao-sdny/pr/ross-ulbricht-creator-and-operator-silk-road-website-sentenced-manhattan-federal-court",
        "technique_name": "Proxy",
        "tactic": "Command and Control"
      }
    ],
    "events": [
      {
        "event_type": "arrest",
        "event_date": "2013-10-01",
        "description": "Ulbricht arrested in the Glen Park branch of the San Francisco Public Library by FBI agents while logged into the Silk Road admin panel."
      },
      {
        "event_type": "verdict",
        "event_date": "2015-02-04",
        "description": "Jury finds Ulbricht guilty on all seven felony counts including narcotics conspiracy and computer hacking."
      },
      {
        "event_type": "sentencing",
        "event_date": "2015-05-29",
        "description": "Sentenced to two life terms of imprisonment plus 40 years without parole and ordered to forfeit $183 million."
      }
    ]
  },
  {
    "id": "case-dmitry-badin-bundestag",
    "slug": "us-v-badin-german-bundestag-apt28",
    "title": "U.S. & International Action: Dmitry Badin (German Bundestag Hack)",
    "summary": "Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.",
    "case_number": "German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215",
    "court": "Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia",
    "district": "D.D.C. & BGH Karlsruhe",
    "country": "Germany & United States",
    "opened_at": "2020-05-05",
    "status": "fugitive",
    "victim_sector": "Legislative Bodies, National Government",
    "victim_country": "Germany",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced the total decommissioning and complete rebuild of the Bundestag computer network.",
    "first_seen_at": "2015-04-30T00:00:00Z",
    "last_updated_at": "2026-06-05T14:00:00Z",
    "actor_slug": "apt28",
    "defendant_slugs": [
      "dmitriy-badin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1566.001",
        "evidence_excerpt": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
        "evidence_locator": "BKA Investigation Summary",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "EU Sanctions Notice",
        "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32020D1537",
        "technique_name": "Spearphishing Attachment",
        "tactic": "Initial Access"
      }
    ],
    "events": [
      {
        "event_type": "sanction",
        "event_date": "2020-10-22",
        "description": "European Union imposes sanctions against Dmitry Badin and GRU Unit 26165."
      }
    ]
  },
  {
    "id": "case-sikerin-polyanin-revil",
    "slug": "us-v-sikerin-polyanin-revil-affiliates",
    "title": "U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)",
    "summary": "International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
    "case_number": "3:21-cr-00315",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-11-08",
    "status": "fugitive",
    "victim_sector": "Local Government, Healthcare, Manufacturing",
    "victim_country": "United States",
    "loss_amount_usd": 13000000,
    "loss_amount_note": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets.",
    "first_seen_at": "2019-08-01T00:00:00Z",
    "last_updated_at": "2026-05-30T11:00:00Z",
    "actor_slug": "revil-sodinokibi",
    "defendant_slugs": [
      "yevgeniy-polyanin"
    ],
    "cves": [],
    "techniques": [
      {
        "technique_id": "T1486",
        "evidence_excerpt": "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.",
        "evidence_locator": "Indictment \u00b6 14, Page 7",
        "mapping_status": "reviewed",
        "mapped_by": "rule",
        "source_title": "Indictment: U.S. v. Polyanin",
        "source_url": "https://www.justice.gov/opa/pr/justice-department-announces-first-extradition-revil-ransomware-attacks-seizure-61-million",
        "technique_name": "Data Encrypted for Impact",
        "tactic": "Impact"
      }
    ],
    "events": [
      {
        "event_type": "indictment",
        "event_date": "2021-11-08",
        "description": "DOJ unseals indictment against Polyanin and announces recovery of $6.1 million in extorted funds."
      }
    ]
  }
]