{
  "id": "case-dmitry-badin-bundestag",
  "slug": "us-v-badin-german-bundestag-apt28",
  "title": "U.S. & International Action: Dmitry Badin (German Bundestag Hack)",
  "summary": "Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.",
  "case_number": "German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215",
  "court": "Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia",
  "district": "D.D.C. & BGH Karlsruhe",
  "country": "Germany & United States",
  "opened_at": "2020-05-05",
  "status": "fugitive",
  "victim_sector": "Legislative Bodies, National Government",
  "victim_country": "Germany",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "Forced the total decommissioning and complete rebuild of the Bundestag computer network.",
  "first_seen_at": "2015-04-30T00:00:00Z",
  "last_updated_at": "2026-06-05T14:00:00Z",
  "actor_slug": "apt28",
  "defendant_slugs": [
    "dmitriy-badin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
      "evidence_locator": "BKA Investigation Summary",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "EU Sanctions Notice",
      "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32020D1537",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "sanction",
      "event_date": "2020-10-22",
      "description": "European Union imposes sanctions against Dmitry Badin and GRU Unit 26165."
    }
  ]
}