TACTIC: IMPACT
Data Encrypted for Impact (T1486): real cases
MITRE Definition ↗ Adversaries encrypt victim files and databases to disrupt business operations and demand financial extortion.
Key Facts
Technique ID
T1486
Impact
Mapped Cases
10
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1486.
- Tactical Phase: Impact.
- Substantiated in 10 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
charged 2024-05-07
Primary Source Evidence Excerpt: Indictment ¶ 12, Page 6
"LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal."
U.S. District Court for the District of New Jersey
View full case dossier →
ALPHV / BlackCat Ransomware Attack on Change Healthcare
alleged 2024-02-21
Primary Source Evidence Excerpt: SEC Form 8-K Item 1.05
"ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways."
U.S. District Court for the District of Minnesota
View full case dossier →
Colonial Pipeline DarkSide Ransomware Attack
pleaded 2021-05-07
Primary Source Evidence Excerpt: CISA Alert AA21-131A
"DarkSide ransomware encrypted billing and corporate IT systems within hours, prompting pipeline operators to halt physical fuel transmission as a precaution."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
fugitive 2019-11-14
Primary Source Evidence Excerpt: Treasury Designation Announcement
"In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
fugitive 2018-06-08
Primary Source Evidence Excerpt: Criminal Complaint ¶ 88, Page 61
"Park and his co-conspirators developed and distributed the WannaCry ransomware worm that infected over 230,000 computers across 150 nations within days."
U.S. District Court for the Central District of California
View full case dossier →
U.S. v. Vachon-Desjardins (Netwalker Ransomware)
sentenced 2020-12-16
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 12
"Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals."
U.S. District Court for the Middle District of Florida
View full case dossier →
U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)
sentenced 2021-08-11
Primary Source Evidence Excerpt: Indictment ¶ 16, Page 8
"Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021."
U.S. District Court for the Northern District of Texas
View full case dossier →
U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)
sentenced 2021-02-18
Primary Source Evidence Excerpt: CISA Advisory AA20-302A
"Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities."
U.S. District Court for the Northern District of Ohio
View full case dossier →
U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)
sentenced 2020-08-25
Primary Source Evidence Excerpt: Plea Agreement ¶ 6, Page 5
"The plan called for staging a diversionary distributed denial of service attack while simultaneously exfiltrating trade secrets and encrypting production servers."
U.S. District Court for the District of Nevada
View full case dossier →
U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)
fugitive 2021-11-08
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero."
U.S. District Court for the Northern District of Texas
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.