[
  {
    "id": "case-sandworm-notpetya",
    "slug": "sandworm-notpetya-olympic-destroyer",
    "title": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)",
    "summary": "Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.",
    "case_number": "2:20-cr-00316",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-10-15",
    "status": "fugitive",
    "victim_sector": "Energy, Healthcare, Government, Transportation",
    "victim_country": "Ukraine, United States, France, South Korea",
    "loss_amount_usd": 10000000000,
    "loss_amount_note": "Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.",
    "first_seen_at": "2015-12-23T15:00:00Z",
    "last_updated_at": "2026-09-20T12:00:00Z",
    "technique_count": 10,
    "defendant_count": 6,
    "actor_name": "Sandworm Team",
    "actor_slug": "sandworm-team"
  },
  {
    "id": "case-lockbit-takedown",
    "slug": "lockbit-ransomware-takedown",
    "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
    "summary": "Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.",
    "case_number": "2:24-cr-00330",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2024-05-07",
    "status": "charged",
    "victim_sector": "Healthcare, Education, Manufacturing, Government, Financial Services",
    "victim_country": "United States, United Kingdom, France, Germany, Japan",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.",
    "first_seen_at": "2019-09-01T00:00:00Z",
    "last_updated_at": "2026-09-18T10:00:00Z",
    "technique_count": 9,
    "defendant_count": 4,
    "actor_name": "LockBit Ransomware Group",
    "actor_slug": "lockbit-group"
  },
  {
    "id": "case-volt-typhoon",
    "slug": "volt-typhoon-critical-infrastructure",
    "title": "Volt Typhoon Critical Infrastructure Pre-Positioning",
    "summary": "State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.",
    "case_number": "CISA-AA24-038A",
    "court": "Federal Law Enforcement Action / FISA Court Authorized Operations",
    "district": "S.D. Tex. & Multiple",
    "country": "United States",
    "opened_at": "2023-05-24",
    "status": "alleged",
    "victim_sector": "Communications, Energy, Transportation, Water, Defense Industrial Base",
    "victim_country": "United States, Guam",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.",
    "first_seen_at": "2021-06-01T00:00:00Z",
    "last_updated_at": "2026-09-15T14:00:00Z",
    "technique_count": 9,
    "defendant_count": 0,
    "actor_name": "Volt Typhoon",
    "actor_slug": "volt-typhoon"
  },
  {
    "id": "case-alphv-change-healthcare",
    "slug": "alphv-blackcat-change-healthcare",
    "title": "ALPHV / BlackCat Ransomware Attack on Change Healthcare",
    "summary": "Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.",
    "case_number": "SEC CIK 0000731766",
    "court": "U.S. District Court for the District of Minnesota",
    "district": "D. Minn.",
    "country": "United States",
    "opened_at": "2024-02-21",
    "status": "alleged",
    "victim_sector": "Healthcare and Public Health",
    "victim_country": "United States",
    "loss_amount_usd": 2450000000,
    "loss_amount_note": "UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.",
    "first_seen_at": "2024-02-12T00:00:00Z",
    "last_updated_at": "2026-09-19T16:00:00Z",
    "technique_count": 6,
    "defendant_count": 0,
    "actor_name": "ALPHV / BlackCat",
    "actor_slug": "alphv-blackcat"
  },
  {
    "id": "case-colonial-pipeline",
    "slug": "colonial-pipeline-ransomware",
    "title": "Colonial Pipeline DarkSide Ransomware Attack",
    "summary": "DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.",
    "case_number": "1:21-mj-00454",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2021-05-07",
    "status": "pleaded",
    "victim_sector": "Energy, Oil and Gas",
    "victim_country": "United States",
    "loss_amount_usd": 4400000,
    "loss_amount_note": "Colonial Pipeline paid 75 Bitcoin ($4.4 million) ransom; DOJ seized and recovered 63.7 Bitcoin ($2.3 million) from the affiliate's wallet.",
    "first_seen_at": "2021-05-06T00:00:00Z",
    "last_updated_at": "2026-09-17T11:00:00Z",
    "technique_count": 4,
    "defendant_count": 0,
    "actor_name": "DarkSide",
    "actor_slug": "darkside"
  },
  {
    "id": "case-solarwinds-apt29",
    "slug": "solarwinds-orion-supply-chain-compromise",
    "title": "SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)",
    "summary": "Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.",
    "case_number": "SEC CIK 0001739942",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2020-12-13",
    "status": "alleged",
    "victim_sector": "Information Technology, Defense, Federal Government, Telecommunications",
    "victim_country": "United States, United Kingdom, Canada, European Union",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.",
    "first_seen_at": "2019-09-04T00:00:00Z",
    "last_updated_at": "2026-09-18T18:00:00Z",
    "technique_count": 5,
    "defendant_count": 0,
    "actor_name": "APT29",
    "actor_slug": "apt29"
  },
  {
    "id": "case-fin7-carbanak",
    "slug": "us-v-hladyr-fin7-carbanak",
    "title": "U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)",
    "summary": "Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.",
    "case_number": "2:18-cr-00067",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2018-03-27",
    "status": "sentenced",
    "victim_sector": "Hospitality, Food Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 1000000000,
    "loss_amount_note": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli.",
    "first_seen_at": "2015-08-01T00:00:00Z",
    "last_updated_at": "2026-09-12T14:00:00Z",
    "technique_count": 7,
    "defendant_count": 3,
    "actor_name": "FIN7",
    "actor_slug": "fin7"
  },
  {
    "id": "case-evil-corp-yakubets",
    "slug": "us-v-yakubets-evil-corp-dridex",
    "title": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)",
    "summary": "Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.",
    "case_number": "2:19-cr-00336",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2019-11-14",
    "status": "fugitive",
    "victim_sector": "Banking, Financial Services, Municipalities, Education",
    "victim_country": "United States, United Kingdom",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.",
    "first_seen_at": "2011-05-01T00:00:00Z",
    "last_updated_at": "2026-09-10T12:00:00Z",
    "technique_count": 7,
    "defendant_count": 2,
    "actor_name": "Evil Corp",
    "actor_slug": "evil-corp"
  },
  {
    "id": "case-lazarus-park-jin-hyok",
    "slug": "us-v-park-jin-hyok-lazarus",
    "title": "U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)",
    "summary": "Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.",
    "case_number": "2:18-mj-01479",
    "court": "U.S. District Court for the Central District of California",
    "district": "C.D. Cal.",
    "country": "United States",
    "opened_at": "2018-06-08",
    "status": "fugitive",
    "victim_sector": "Media and Entertainment, Financial Services, Healthcare",
    "victim_country": "United States, United Kingdom, Bangladesh, Philippines",
    "loss_amount_usd": 1300000000,
    "loss_amount_note": "Attempted to steal over $1.3 billion in cash and cryptocurrency, including the $81 million Bangladesh Bank heist and extensive WannaCry disruptions across NHS hospitals.",
    "first_seen_at": "2014-11-01T00:00:00Z",
    "last_updated_at": "2026-09-14T09:00:00Z",
    "technique_count": 7,
    "defendant_count": 1,
    "actor_name": "Lazarus Group",
    "actor_slug": "lazarus-group"
  },
  {
    "id": "case-netwalker-vachon",
    "slug": "us-v-vachon-desjardins-netwalker",
    "title": "U.S. v. Vachon-Desjardins (Netwalker Ransomware)",
    "summary": "Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
    "case_number": "8:20-cr-00366",
    "court": "U.S. District Court for the Middle District of Florida",
    "district": "M.D. Fla.",
    "country": "United States",
    "opened_at": "2020-12-16",
    "status": "sentenced",
    "victim_sector": "Healthcare, Education, Municipal Government",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 21500000,
    "loss_amount_note": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.",
    "first_seen_at": "2020-04-01T00:00:00Z",
    "last_updated_at": "2026-09-11T16:00:00Z",
    "technique_count": 6,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "netwalker"
  },
  {
    "id": "case-seleznev-point-of-sale",
    "slug": "us-v-seleznev-track2",
    "title": "U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)",
    "summary": "Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
    "case_number": "2:11-cr-00070",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2011-03-03",
    "status": "sentenced",
    "victim_sector": "Retail, Hospitality, Small Business",
    "victim_country": "United States",
    "loss_amount_usd": 169000000,
    "loss_amount_note": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions.",
    "first_seen_at": "2009-10-01T00:00:00Z",
    "last_updated_at": "2026-09-08T15:00:00Z",
    "technique_count": 4,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "track2"
  },
  {
    "id": "case-kaseya-revil",
    "slug": "us-v-vasinskyi-kaseya-revil",
    "title": "U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)",
    "summary": "Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.",
    "case_number": "3:21-cr-00314",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-08-11",
    "status": "sentenced",
    "victim_sector": "Managed Service Providers, Information Technology, Retail, Education",
    "victim_country": "United States, Sweden, New Zealand",
    "loss_amount_usd": 70000000,
    "loss_amount_note": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.",
    "first_seen_at": "2021-07-02T00:00:00Z",
    "last_updated_at": "2026-09-14T11:00:00Z",
    "technique_count": 5,
    "defendant_count": 2,
    "actor_name": "REvil / Sodinokibi",
    "actor_slug": "revil-sodinokibi"
  },
  {
    "id": "case-baratov-yahoo",
    "slug": "us-v-baratov-yahoo-breach",
    "title": "U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)",
    "summary": "Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.",
    "case_number": "3:17-cr-00103",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2017-02-28",
    "status": "sentenced",
    "victim_sector": "Internet Services, Telecommunications",
    "victim_country": "United States",
    "loss_amount_usd": 350000000,
    "loss_amount_note": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds.",
    "first_seen_at": "2014-01-01T00:00:00Z",
    "last_updated_at": "2026-09-09T18:00:00Z",
    "technique_count": 3,
    "defendant_count": 4,
    "actor_name": null,
    "actor_slug": "fsb-center-18"
  },
  {
    "id": "case-schulte-vault7",
    "slug": "us-v-schulte-cia-vault-7",
    "title": "U.S. v. Joshua Schulte (CIA Vault 7 Leak)",
    "summary": "Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.",
    "case_number": "1:17-cr-00548",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2017-08-24",
    "status": "sentenced",
    "victim_sector": "Intelligence, National Defense, Federal Government",
    "victim_country": "United States",
    "loss_amount_usd": 500000000,
    "loss_amount_note": "Government loss estimated in hundreds of millions in operational capability destruction across global intelligence activities.",
    "first_seen_at": "2016-04-20T00:00:00Z",
    "last_updated_at": "2026-09-10T11:00:00Z",
    "technique_count": 3,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "insider-threat"
  },
  {
    "id": "case-pla-unit-61398",
    "slug": "us-v-sun-kailiang-pla-unit-61398",
    "title": "U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)",
    "summary": "Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.",
    "case_number": "2:14-cr-00118",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2014-05-01",
    "status": "fugitive",
    "victim_sector": "Nuclear Energy, Metals, Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies.",
    "first_seen_at": "2006-01-01T00:00:00Z",
    "last_updated_at": "2026-09-07T12:00:00Z",
    "technique_count": 2,
    "defendant_count": 5,
    "actor_name": "PLA Unit 61398",
    "actor_slug": "pla-unit-61398"
  },
  {
    "id": "case-gonzalez-carding",
    "slug": "us-v-albert-gonzalez-tjx-heartland",
    "title": "U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)",
    "summary": "Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.",
    "case_number": "1:08-cr-10223",
    "court": "U.S. District Court for the District of Massachusetts",
    "district": "D. Mass.",
    "country": "United States",
    "opened_at": "2008-08-05",
    "status": "sentenced",
    "victim_sector": "Retail, Financial Payment Processors",
    "victim_country": "United States",
    "loss_amount_usd": 200000000,
    "loss_amount_note": "Direct merchant and bank losses in excess of $200 million across TJX and Heartland.",
    "first_seen_at": "2005-07-01T00:00:00Z",
    "last_updated_at": "2026-09-06T10:00:00Z",
    "technique_count": 2,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "shadowcrew"
  },
  {
    "id": "case-tyurin-jpmorgan",
    "slug": "us-v-tyurin-jpmorgan-chase",
    "title": "U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)",
    "summary": "Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.",
    "case_number": "1:15-cr-00393",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2015-11-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Banking, Publishing",
    "victim_country": "United States",
    "loss_amount_usd": 19000000,
    "loss_amount_note": "Court ordered $19,952,861 in restitution to victim financial institutions.",
    "first_seen_at": "2012-01-01T00:00:00Z",
    "last_updated_at": "2026-09-05T14:00:00Z",
    "technique_count": 2,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "shalon-cyber-syndicate"
  },
  {
    "id": "case-paige-thompson-capitalone",
    "slug": "us-v-thompson-capital-one-breach",
    "title": "U.S. v. Paige Thompson (Capital One Cloud Breach)",
    "summary": "Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.",
    "case_number": "2:19-cr-00159",
    "court": "U.S. District Court for the Western District of Washington",
    "district": "W.D. Wash.",
    "country": "United States",
    "opened_at": "2019-07-29",
    "status": "convicted",
    "victim_sector": "Financial Services, Cloud Computing",
    "victim_country": "United States, Canada",
    "loss_amount_usd": 270000000,
    "loss_amount_note": "Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines.",
    "first_seen_at": "2019-03-01T00:00:00Z",
    "last_updated_at": "2026-09-04T11:00:00Z",
    "technique_count": 3,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "erratic"
  },
  {
    "id": "case-bitzlato-hydra",
    "slug": "us-v-legkodymov-bitzlato",
    "title": "U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)",
    "summary": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
    "case_number": "1:23-cr-00021",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-01-17",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Financial Services",
    "victim_country": "United States, Russia, France",
    "loss_amount_usd": 700000000,
    "loss_amount_note": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds.",
    "first_seen_at": "2018-05-01T00:00:00Z",
    "last_updated_at": "2026-09-03T16:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "bitzlato"
  },
  {
    "id": "case-genesis-market",
    "slug": "genesis-market-takedown-cookie-monster",
    "title": "Operation Cookie Monster (Genesis Market Takedown)",
    "summary": "Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised account credentials.",
    "case_number": "Operation Cookie Monster",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2023-04-04",
    "status": "alleged",
    "victim_sector": "Consumer Accounts, Banking, E-Commerce",
    "victim_country": "United States, United Kingdom, European Union, Australia",
    "loss_amount_usd": 50000000,
    "loss_amount_note": "Facilitated millions of unauthorized account takeover transactions across 1.5 million infected computers worldwide.",
    "first_seen_at": "2018-01-01T00:00:00Z",
    "last_updated_at": "2026-09-02T13:00:00Z",
    "technique_count": 2,
    "defendant_count": 0,
    "actor_name": null,
    "actor_slug": "genesis-market"
  },
  {
    "id": "case-chipmixer-nguyen",
    "slug": "us-v-nguyen-chipmixer",
    "title": "U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)",
    "summary": "Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.",
    "case_number": "2:23-mj-00122",
    "court": "U.S. District Court for the Eastern District of Pennsylvania",
    "district": "E.D. Pa.",
    "country": "United States",
    "opened_at": "2023-03-15",
    "status": "fugitive",
    "victim_sector": "Financial Services, Blockchain Infrastructure",
    "victim_country": "United States, Germany",
    "loss_amount_usd": 3000000000,
    "loss_amount_note": "Laundered over $3 billion in Bitcoin, including $700 million tied to Hydra Market and $200 million tied to LockBit and Zeppelin ransomware.",
    "first_seen_at": "2017-08-01T00:00:00Z",
    "last_updated_at": "2026-09-01T15:00:00Z",
    "technique_count": 2,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "chipmixer"
  },
  {
    "id": "case-trickbot-witte",
    "slug": "us-v-witte-dunaev-trickbot",
    "title": "U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)",
    "summary": "Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.",
    "case_number": "1:20-cr-00384",
    "court": "U.S. District Court for the Northern District of Ohio",
    "district": "N.D. Ohio",
    "country": "United States",
    "opened_at": "2021-02-18",
    "status": "sentenced",
    "victim_sector": "Healthcare, Banking, Local Government",
    "victim_country": "United States, United Kingdom, Australia",
    "loss_amount_usd": 180000000,
    "loss_amount_note": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.",
    "first_seen_at": "2016-10-01T00:00:00Z",
    "last_updated_at": "2026-08-30T10:00:00Z",
    "technique_count": 3,
    "defendant_count": 2,
    "actor_name": "Wizard Spider",
    "actor_slug": "wizard-spider"
  },
  {
    "id": "case-kriuchkov-tesla",
    "slug": "us-v-kriuchkov-tesla-ransomware",
    "title": "U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)",
    "summary": "Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.",
    "case_number": "3:20-cr-00032",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2020-08-25",
    "status": "sentenced",
    "victim_sector": "Automotive, Advanced Manufacturing, Clean Energy",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Intended extortion demand was $4 million; operation was intercepted before malware execution.",
    "first_seen_at": "2020-07-16T00:00:00Z",
    "last_updated_at": "2026-08-28T14:00:00Z",
    "technique_count": 3,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "kriuchkov-group"
  },
  {
    "id": "case-marcus-hutchins-kronos",
    "slug": "us-v-hutchins-kronos-malware",
    "title": "U.S. v. Marcus Hutchins (Kronos Banking Malware)",
    "summary": "British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
    "case_number": "2:17-cr-00124",
    "court": "U.S. District Court for the Eastern District of Wisconsin",
    "district": "E.D. Wis.",
    "country": "United States",
    "opened_at": "2017-07-12",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Finance",
    "victim_country": "United States, Germany, United Kingdom",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Stole banking credentials and redirected bank transactions in criminal markets.",
    "first_seen_at": "2014-06-01T00:00:00Z",
    "last_updated_at": "2026-08-25T11:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "malwaretech"
  },
  {
    "id": "case-nikulin-linkedin",
    "slug": "us-v-nikulin-linkedin-dropbox",
    "title": "U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)",
    "summary": "Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.",
    "case_number": "3:16-cr-00440",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2016-10-05",
    "status": "sentenced",
    "victim_sector": "Internet Services, Social Media, Cloud Storage",
    "victim_country": "United States",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.",
    "first_seen_at": "2012-03-01T00:00:00Z",
    "last_updated_at": "2026-08-20T16:00:00Z",
    "technique_count": 2,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "chinik"
  },
  {
    "id": "case-levashov-kelihos",
    "slug": "us-v-levashov-kelihos-botnet",
    "title": "U.S. v. Peter Levashov (Kelihos Botnet)",
    "summary": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
    "case_number": "3:17-cr-00083",
    "court": "U.S. District Court for the District of Connecticut",
    "district": "D. Conn.",
    "country": "United States",
    "opened_at": "2017-04-07",
    "status": "pleaded",
    "victim_sector": "E-Commerce, Consumer Services, Telecommunications",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 25000000,
    "loss_amount_note": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees.",
    "first_seen_at": "2010-01-01T00:00:00Z",
    "last_updated_at": "2026-08-15T12:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "kelihos-crew"
  },
  {
    "id": "case-irgc-water-cyberav3ngers",
    "slug": "us-v-irgc-cyberav3ngers-water",
    "title": "U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)",
    "summary": "Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.",
    "case_number": "2:24-cr-00185",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2024-09-24",
    "status": "fugitive",
    "victim_sector": "Water and Wastewater Systems, Energy",
    "victim_country": "United States, Israel",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced manual pump operations at multiple municipal water authorities across Pennsylvania and New Jersey.",
    "first_seen_at": "2023-11-25T00:00:00Z",
    "last_updated_at": "2026-09-21T18:00:00Z",
    "technique_count": 2,
    "defendant_count": 2,
    "actor_name": "IRGC Cyber-Electronic Command",
    "actor_slug": "irgc-cyber-electronic-command"
  },
  {
    "id": "case-netyksho-apt28",
    "slug": "us-v-netyksho-apt28-dnc",
    "title": "U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)",
    "summary": "Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.",
    "case_number": "1:18-cr-00215",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2018-07-13",
    "status": "fugitive",
    "victim_sector": "Political Organizations, Government",
    "victim_country": "United States",
    "loss_amount_usd": 10000000,
    "loss_amount_note": "Extensive campaign disruption and federal investigative expenditure.",
    "first_seen_at": "2016-03-15T00:00:00Z",
    "last_updated_at": "2026-09-02T10:00:00Z",
    "technique_count": 5,
    "defendant_count": 3,
    "actor_name": "APT28",
    "actor_slug": "apt28"
  },
  {
    "id": "case-brovko-botnet",
    "slug": "us-v-brovko-botnet-logs",
    "title": "U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)",
    "summary": "Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
    "case_number": "1:20-cr-00037",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2020-02-12",
    "status": "sentenced",
    "victim_sector": "Consumer Finance, Banking",
    "victim_country": "United States",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses.",
    "first_seen_at": "2007-01-01T00:00:00Z",
    "last_updated_at": "2026-08-18T14:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "brovko-network"
  },
  {
    "id": "case-firsov-deerio",
    "slug": "us-v-firsov-deer-io",
    "title": "U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)",
    "summary": "Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
    "case_number": "3:20-cr-01053",
    "court": "U.S. District Court for the Southern District of California",
    "district": "S.D. Cal.",
    "country": "United States",
    "opened_at": "2020-03-04",
    "status": "sentenced",
    "victim_sector": "Consumer Services, E-Commerce, Identity Providers",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 17000000,
    "loss_amount_note": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts.",
    "first_seen_at": "2013-10-01T00:00:00Z",
    "last_updated_at": "2026-08-14T11:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "deer-io"
  },
  {
    "id": "case-medvedev-infraud",
    "slug": "us-v-medvedev-infraud-organization",
    "title": "U.S. v. Sergey Medvedev et al. (Infraud Organization)",
    "summary": "Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
    "case_number": "2:17-cr-00360",
    "court": "U.S. District Court for the District of Nevada",
    "district": "D. Nev.",
    "country": "United States",
    "opened_at": "2018-01-26",
    "status": "sentenced",
    "victim_sector": "Financial Services, Consumer Credit, Retail",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 568000000,
    "loss_amount_note": "Caused actual financial losses of over $568 million to financial institutions and cardholders.",
    "first_seen_at": "2010-10-01T00:00:00Z",
    "last_updated_at": "2026-08-10T15:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "infraud-organization"
  },
  {
    "id": "case-barriss-swatting",
    "slug": "us-v-barriss-serial-swatting",
    "title": "U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)",
    "summary": "Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.",
    "case_number": "6:18-cr-10028",
    "court": "U.S. District Court for the District of Kansas",
    "district": "D. Kan.",
    "country": "United States",
    "opened_at": "2018-03-20",
    "status": "sentenced",
    "victim_sector": "Emergency Services, Municipalities, Schools",
    "victim_country": "United States",
    "loss_amount_usd": 1500000,
    "loss_amount_note": "Caused tragic loss of innocent human life, massive municipal emergency response mobilization, and $1.5 million in damages.",
    "first_seen_at": "2017-01-01T00:00:00Z",
    "last_updated_at": "2026-08-05T12:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "swatting-group"
  },
  {
    "id": "case-brett-johnson-shadowcrew",
    "slug": "us-v-johnson-shadowcrew",
    "title": "U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)",
    "summary": "Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.",
    "case_number": "2:04-cr-00725",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2004-10-26",
    "status": "sentenced",
    "victim_sector": "Banking, Consumer Identity, E-Commerce",
    "victim_country": "United States",
    "loss_amount_usd": 4000000,
    "loss_amount_note": "Facilitated millions in fraudulent debit card cloning transactions.",
    "first_seen_at": "2002-05-01T00:00:00Z",
    "last_updated_at": "2026-08-01T10:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "shadowcrew"
  },
  {
    "id": "case-max-vision-cardersmarket",
    "slug": "us-v-vision-cardersmarket",
    "title": "U.S. v. Max Ray Vision (Iceman / CardersMarket)",
    "summary": "Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.",
    "case_number": "3:07-cr-00624",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2007-09-10",
    "status": "sentenced",
    "victim_sector": "Financial Services, Retail",
    "victim_country": "United States",
    "loss_amount_usd": 86000000,
    "loss_amount_note": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges.",
    "first_seen_at": "2004-01-01T00:00:00Z",
    "last_updated_at": "2026-07-28T14:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "cardersmarket"
  },
  {
    "id": "case-khusyaynova-lakhta",
    "slug": "us-v-khusyaynova-project-lakhta",
    "title": "U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)",
    "summary": "Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.",
    "case_number": "1:18-mj-00464",
    "court": "U.S. District Court for the Eastern District of Virginia",
    "district": "E.D. Va.",
    "country": "United States",
    "opened_at": "2018-09-28",
    "status": "fugitive",
    "victim_sector": "Electoral Systems, Social Media, Public Institutions",
    "victim_country": "United States",
    "loss_amount_usd": 35000000,
    "loss_amount_note": "Managed an operating budget exceeding $35 million for covert information warfare activities.",
    "first_seen_at": "2014-04-01T00:00:00Z",
    "last_updated_at": "2026-07-25T11:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "project-lakhta"
  },
  {
    "id": "case-kulkov-try2check",
    "slug": "us-v-kulkov-try2check",
    "title": "U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)",
    "summary": "Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.",
    "case_number": "1:23-cr-00171",
    "court": "U.S. District Court for the Eastern District of New York",
    "district": "E.D.N.Y.",
    "country": "United States",
    "opened_at": "2023-04-18",
    "status": "fugitive",
    "victim_sector": "Financial Services, Payment Networks",
    "victim_country": "United States",
    "loss_amount_usd": 18000000,
    "loss_amount_note": "Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service.",
    "first_seen_at": "2005-01-01T00:00:00Z",
    "last_updated_at": "2026-07-20T16:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "try2check"
  },
  {
    "id": "case-incognito-siew",
    "slug": "us-v-siew-incognito-market",
    "title": "U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)",
    "summary": "Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.",
    "case_number": "1:24-cr-00305",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2024-05-20",
    "status": "charged",
    "victim_sector": "Consumer Privacy, Cryptocurrency",
    "victim_country": "United States, Taiwan",
    "loss_amount_usd": 100000000,
    "loss_amount_note": "Processed over $100 million in illicit crypto sales and demanded extortion fees up to $20,000 per vendor.",
    "first_seen_at": "2020-10-01T00:00:00Z",
    "last_updated_at": "2026-07-15T12:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "incognito-market"
  },
  {
    "id": "case-boiko-qqaazz",
    "slug": "us-v-boiko-qqaazz-laundering",
    "title": "U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)",
    "summary": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
    "case_number": "2:20-cr-00227",
    "court": "U.S. District Court for the Western District of Pennsylvania",
    "district": "W.D. Pa.",
    "country": "United States",
    "opened_at": "2020-09-15",
    "status": "sentenced",
    "victim_sector": "Financial Institutions, Ransomware Victims",
    "victim_country": "United States, United Kingdom, Latvia, Georgia",
    "loss_amount_usd": 20000000,
    "loss_amount_note": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe.",
    "first_seen_at": "2016-01-01T00:00:00Z",
    "last_updated_at": "2026-07-10T14:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "qqaazz"
  },
  {
    "id": "case-radchenko-sec-edgar-hack",
    "slug": "us-v-radchenko-sec-edgar-intrusion",
    "title": "U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)",
    "summary": "Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.",
    "case_number": "2:19-cr-00040",
    "court": "U.S. District Court for the District of New Jersey",
    "district": "D.N.J.",
    "country": "United States",
    "opened_at": "2019-01-15",
    "status": "fugitive",
    "victim_sector": "Regulatory Agencies, Securities Markets, Public Corporations",
    "victim_country": "United States",
    "loss_amount_usd": 4100000,
    "loss_amount_note": "Generated $4.1 million in illegal trading profits using stolen corporate filings.",
    "first_seen_at": "2016-05-01T00:00:00Z",
    "last_updated_at": "2026-07-05T11:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "edgar-hack-syndicate"
  },
  {
    "id": "case-daniel-rhyne-ransomware",
    "slug": "us-v-rhyne-insider-ransomware-extortion",
    "title": "U.S. v. Daniel Rhyne (Industrial Insider Extortion)",
    "summary": "Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.",
    "case_number": "3:24-cr-00122",
    "court": "U.S. District Court for the Western District of Missouri",
    "district": "W.D. Mo.",
    "country": "United States",
    "opened_at": "2024-04-16",
    "status": "charged",
    "victim_sector": "Industrial Manufacturing, Critical Infrastructure",
    "victim_country": "United States",
    "loss_amount_usd": 750000,
    "loss_amount_note": "Demanded $750,000 ransom and caused significant corporate operational stoppage.",
    "first_seen_at": "2023-11-20T00:00:00Z",
    "last_updated_at": "2026-07-01T15:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "insider-threat"
  },
  {
    "id": "case-snowflake-credential-stuffing",
    "slug": "snowflake-multi-tenant-credential-attacks",
    "title": "Snowflake Customer Multi-Tenant Credential Stuffing Campaign",
    "summary": "Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.",
    "case_number": "SEC CIK 0001640147",
    "court": "U.S. District Court for the Northern District of California",
    "district": "N.D. Cal.",
    "country": "United States",
    "opened_at": "2024-05-31",
    "status": "alleged",
    "victim_sector": "Telecommunications, Entertainment, Banking, Cloud Services",
    "victim_country": "United States, Spain, Worldwide",
    "loss_amount_usd": 150000000,
    "loss_amount_note": "Stole records of 110 million AT&T phone accounts and 560 million Ticketmaster users, leading to extensive class-action lawsuits and regulatory filings.",
    "first_seen_at": "2024-04-14T00:00:00Z",
    "last_updated_at": "2026-06-25T14:00:00Z",
    "technique_count": 2,
    "defendant_count": 0,
    "actor_name": null,
    "actor_slug": "unc5537"
  },
  {
    "id": "case-james-zhong-silkroad-theft",
    "slug": "us-v-zhong-silk-road-bitcoin-seizure",
    "title": "U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)",
    "summary": "Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Road darknet market in 2012 by triggering race conditions in the withdrawal logic.",
    "case_number": "1:22-cr-00594",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2022-11-04",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency, Darknet Markets",
    "victim_country": "United States",
    "loss_amount_usd": 3360000000,
    "loss_amount_note": "Largest cryptocurrency seizure in DOJ history at the time: 50,676 Bitcoins valued at $3.36 billion.",
    "first_seen_at": "2012-09-01T00:00:00Z",
    "last_updated_at": "2026-06-20T10:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "zhong-silkroad"
  },
  {
    "id": "case-lichtenstein-bitfinex",
    "slug": "us-v-lichtenstein-bitfinex-heist-laundering",
    "title": "U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)",
    "summary": "Conviction of Ilya Lichtenstein and Heather Morgan for executing the 2016 hack of the Bitfinex virtual currency exchange, stealing 119,754 Bitcoins (valued at $4.5 billion at arrest), and laundering the funds through complex cryptocurrency mixers and darknet markets.",
    "case_number": "1:23-cr-00239",
    "court": "U.S. District Court for the District of Columbia",
    "district": "D.D.C.",
    "country": "United States",
    "opened_at": "2022-02-07",
    "status": "sentenced",
    "victim_sector": "Cryptocurrency Exchanges, Financial Services",
    "victim_country": "United States, Hong Kong",
    "loss_amount_usd": 4500000000,
    "loss_amount_note": "Stole 119,754 Bitcoins from Bitfinex; DOJ recovered 94,000 Bitcoins valued at $3.6 billion in the largest single financial seizure in U.S. history.",
    "first_seen_at": "2016-08-02T00:00:00Z",
    "last_updated_at": "2026-06-15T16:00:00Z",
    "technique_count": 1,
    "defendant_count": 2,
    "actor_name": null,
    "actor_slug": "bitfinex-heist"
  },
  {
    "id": "case-ross-ulbricht-silkroad",
    "slug": "us-v-ross-ulbricht-silk-road",
    "title": "U.S. v. Ross Ulbricht (Dread Pirate Roberts / Silk Road)",
    "summary": "Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and Bitcoin.",
    "case_number": "1:14-cr-00068",
    "court": "U.S. District Court for the Southern District of New York",
    "district": "S.D.N.Y.",
    "country": "United States",
    "opened_at": "2014-02-04",
    "status": "sentenced",
    "victim_sector": "Public Safety, E-Commerce, Controlled Substances",
    "victim_country": "United States, Worldwide",
    "loss_amount_usd": 213000000,
    "loss_amount_note": "Generated $213 million in total sales and $13 million in commissions across 1.5 million transactions.",
    "first_seen_at": "2011-01-01T00:00:00Z",
    "last_updated_at": "2026-06-10T12:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": null,
    "actor_slug": "silk-road"
  },
  {
    "id": "case-dmitry-badin-bundestag",
    "slug": "us-v-badin-german-bundestag-apt28",
    "title": "U.S. & International Action: Dmitry Badin (German Bundestag Hack)",
    "summary": "Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.",
    "case_number": "German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215",
    "court": "Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia",
    "district": "D.D.C. & BGH Karlsruhe",
    "country": "Germany & United States",
    "opened_at": "2020-05-05",
    "status": "fugitive",
    "victim_sector": "Legislative Bodies, National Government",
    "victim_country": "Germany",
    "loss_amount_usd": 15000000,
    "loss_amount_note": "Forced the total decommissioning and complete rebuild of the Bundestag computer network.",
    "first_seen_at": "2015-04-30T00:00:00Z",
    "last_updated_at": "2026-06-05T14:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": "APT28",
    "actor_slug": "apt28"
  },
  {
    "id": "case-sikerin-polyanin-revil",
    "slug": "us-v-sikerin-polyanin-revil-affiliates",
    "title": "U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)",
    "summary": "International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
    "case_number": "3:21-cr-00315",
    "court": "U.S. District Court for the Northern District of Texas",
    "district": "N.D. Tex.",
    "country": "United States",
    "opened_at": "2021-11-08",
    "status": "fugitive",
    "victim_sector": "Local Government, Healthcare, Manufacturing",
    "victim_country": "United States",
    "loss_amount_usd": 13000000,
    "loss_amount_note": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets.",
    "first_seen_at": "2019-08-01T00:00:00Z",
    "last_updated_at": "2026-05-30T11:00:00Z",
    "technique_count": 1,
    "defendant_count": 1,
    "actor_name": "REvil / Sodinokibi",
    "actor_slug": "revil-sodinokibi"
  }
]