JUDICIAL & THREAT CHRONOLOGY

Historical Cyberattack Legal Timeline

Chronological tracking of state-sponsored intrusions, ransomware campaigns, and federal enforcement actions documented in official court records from 2004 to the present day.

Total Milestones: 92
Timespan: 2004 - 2026
Jurisdictions: 6 Attributed Regions
Showing all 92 milestones
2024-09-24 Legal Indictment
Islamic Republic of Iran

Court Action: U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Pennsylvania. Case: 2:24-cr-00185.

Group: IRGC Cyber-Electronic Command View Case Docket →
2024-05-31 Legal Indictment
United States

Court Action: Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Federal indictment or judicial action filed in U.S. District Court for the Northern District of California. Case: SEC CIK 0001640147.

Group: Unknown Threat Actor View Case Docket →
2024-05-20 Legal Indictment
United States

Court Action: U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: 1:24-cr-00305.

Group: Unknown Threat Actor View Case Docket →
2024-05-07 Legal Indictment
Russian Federation

Court Action: U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Federal indictment or judicial action filed in U.S. District Court for the District of New Jersey. Case: 2:24-cr-00330.

Group: LockBit Ransomware Group View Case Docket →
2024-04-16 Legal Indictment
United States

Court Action: U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Missouri. Case: 3:24-cr-00122.

Group: Unknown Threat Actor View Case Docket →
2024-04-14 Threat Activity
United States

Intrusions Detected: Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Initial intrusion activity documented in legal record. Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer ma...

Group: Unknown Threat Actor View Case Docket →
2024-02-21 Legal Indictment
Russian Federation

Court Action: ALPHV / BlackCat Ransomware Attack on Change Healthcare

Federal indictment or judicial action filed in U.S. District Court for the District of Minnesota. Case: SEC CIK 0000731766.

Group: ALPHV / BlackCat View Case Docket →
2024-02-12 Threat Activity
Russian Federation

Intrusions Detected: ALPHV / BlackCat Ransomware Attack on Change Healthcare

Initial intrusion activity documented in legal record. Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthca...

Group: ALPHV / BlackCat View Case Docket →
2023-11-25 Threat Activity
Islamic Republic of Iran

Intrusions Detected: U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Initial intrusion activity documented in legal record. Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic contr...

Group: IRGC Cyber-Electronic Command View Case Docket →
2023-11-20 Threat Activity
United States

Intrusions Detected: U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Initial intrusion activity documented in legal record. Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain contro...

Group: Unknown Threat Actor View Case Docket →
2023-05-24 Legal Indictment
People's Republic of China

Court Action: Volt Typhoon Critical Infrastructure Pre-Positioning

Federal indictment or judicial action filed in Federal Law Enforcement Action / FISA Court Authorized Operations. Case: CISA-AA24-038A.

Group: Volt Typhoon View Case Docket →
2023-04-18 Legal Indictment
United States

Court Action: U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of New York. Case: 1:23-cr-00171.

Group: Unknown Threat Actor View Case Docket →
2023-04-04 Legal Indictment
United States

Court Action: Operation Cookie Monster (Genesis Market Takedown)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of Wisconsin. Case: Operation Cookie Monster.

Group: Unknown Threat Actor View Case Docket →
2023-03-15 Legal Indictment
United States

Court Action: U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of Pennsylvania. Case: 2:23-mj-00122.

Group: Unknown Threat Actor View Case Docket →
2023-01-17 Legal Indictment
United States

Court Action: U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of New York. Case: 1:23-cr-00021.

Group: Unknown Threat Actor View Case Docket →
2022-11-04 Legal Indictment
United States

Court Action: U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: 1:22-cr-00594.

Group: Unknown Threat Actor View Case Docket →
2022-02-07 Legal Indictment
United States

Court Action: U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)

Federal indictment or judicial action filed in U.S. District Court for the District of Columbia. Case: 1:23-cr-00239.

Group: Unknown Threat Actor View Case Docket →
2021-11-08 Legal Indictment
Russian Federation

Court Action: U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of Texas. Case: 3:21-cr-00315.

Group: REvil / Sodinokibi View Case Docket →
2021-08-11 Legal Indictment
Russian Federation

Court Action: U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of Texas. Case: 3:21-cr-00314.

Group: REvil / Sodinokibi View Case Docket →
2021-07-02 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)

Initial intrusion activity documented in legal record. Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encryp...

Group: REvil / Sodinokibi View Case Docket →
2021-06-01 Threat Activity
People's Republic of China

Intrusions Detected: Volt Typhoon Critical Infrastructure Pre-Positioning

Initial intrusion activity documented in legal record. State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, tra...

Group: Volt Typhoon View Case Docket →
2021-05-07 Legal Indictment
Russian Federation

Court Action: Colonial Pipeline DarkSide Ransomware Attack

Federal indictment or judicial action filed in U.S. District Court for the Northern District of California. Case: 1:21-mj-00454.

Group: DarkSide View Case Docket →
2021-05-06 Threat Activity
Russian Federation

Intrusions Detected: Colonial Pipeline DarkSide Ransomware Attack

Initial intrusion activity documented in legal record. DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines ...

Group: DarkSide View Case Docket →
2021-02-18 Legal Indictment
Russian Federation

Court Action: U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of Ohio. Case: 1:20-cr-00384.

Group: Wizard Spider View Case Docket →
2020-12-16 Legal Indictment
United States

Court Action: U.S. v. Vachon-Desjardins (Netwalker Ransomware)

Federal indictment or judicial action filed in U.S. District Court for the Middle District of Florida. Case: 8:20-cr-00366.

Group: Unknown Threat Actor View Case Docket →
2020-12-13 Legal Indictment
Russian Federation

Court Action: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: SEC CIK 0001739942.

2020-10-15 Legal Indictment
Russian Federation

Court Action: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Pennsylvania. Case: 2:20-cr-00316.

Group: Sandworm Team View Case Docket →
2020-10-01 Threat Activity
United States

Intrusions Detected: U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)

Initial intrusion activity documented in legal record. Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registe...

Group: Unknown Threat Actor View Case Docket →
2020-09-15 Legal Indictment
United States

Court Action: U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Pennsylvania. Case: 2:20-cr-00227.

Group: Unknown Threat Actor View Case Docket →
2020-08-25 Legal Indictment
United States

Court Action: U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)

Federal indictment or judicial action filed in U.S. District Court for the District of Nevada. Case: 3:20-cr-00032.

Group: Unknown Threat Actor View Case Docket →
2020-07-16 Threat Activity
United States

Intrusions Detected: U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)

Initial intrusion activity documented in legal record. Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware o...

Group: Unknown Threat Actor View Case Docket →
2020-05-05 Legal Indictment
Russian Federation

Court Action: U.S. & International Action: Dmitry Badin (German Bundestag Hack)

Federal indictment or judicial action filed in Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia. Case: German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215.

2020-04-01 Threat Activity
United States

Intrusions Detected: U.S. v. Vachon-Desjardins (Netwalker Ransomware)

Initial intrusion activity documented in legal record. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting t...

Group: Unknown Threat Actor View Case Docket →
2020-03-04 Legal Indictment
United States

Court Action: U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of California. Case: 3:20-cr-01053.

Group: Unknown Threat Actor View Case Docket →
2020-02-12 Legal Indictment
United States

Court Action: U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of Virginia. Case: 1:20-cr-00037.

Group: Unknown Threat Actor View Case Docket →
2019-11-14 Legal Indictment
Russian Federation

Court Action: U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Pennsylvania. Case: 2:19-cr-00336.

Group: Evil Corp View Case Docket →
2019-09-04 Threat Activity
Russian Federation

Intrusions Detected: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Initial intrusion activity documented in legal record. Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Ori...

2019-09-01 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Initial intrusion activity documented in legal record. Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and mult...

Group: LockBit Ransomware Group View Case Docket →
2019-08-01 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)

Initial intrusion activity documented in legal record. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesse...

Group: REvil / Sodinokibi View Case Docket →
2019-07-29 Legal Indictment
United States

Court Action: U.S. v. Paige Thompson (Capital One Cloud Breach)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Washington. Case: 2:19-cr-00159.

Group: Unknown Threat Actor View Case Docket →
2019-03-01 Threat Activity
United States

Intrusions Detected: U.S. v. Paige Thompson (Capital One Cloud Breach)

Initial intrusion activity documented in legal record. Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage bu...

Group: Unknown Threat Actor View Case Docket →
2019-01-15 Legal Indictment
United States

Court Action: U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)

Federal indictment or judicial action filed in U.S. District Court for the District of New Jersey. Case: 2:19-cr-00040.

Group: Unknown Threat Actor View Case Docket →
2018-09-28 Legal Indictment
United States

Court Action: U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of Virginia. Case: 1:18-mj-00464.

Group: Unknown Threat Actor View Case Docket →
2018-07-13 Legal Indictment
Russian Federation

Court Action: U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)

Federal indictment or judicial action filed in U.S. District Court for the District of Columbia. Case: 1:18-cr-00215.

2018-06-08 Legal Indictment
Democratic People's Republic of Korea

Court Action: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)

Federal indictment or judicial action filed in U.S. District Court for the Central District of California. Case: 2:18-mj-01479.

Group: Lazarus Group View Case Docket →
2018-05-01 Threat Activity
United States

Intrusions Detected: U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)

Initial intrusion activity documented in legal record. Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, se...

Group: Unknown Threat Actor View Case Docket →
2018-03-27 Legal Indictment
Transnational / Eastern Europe

Court Action: U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Washington. Case: 2:18-cr-00067.

2018-03-20 Legal Indictment
United States

Court Action: U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)

Federal indictment or judicial action filed in U.S. District Court for the District of Kansas. Case: 6:18-cr-10028.

Group: Unknown Threat Actor View Case Docket →
2018-01-26 Legal Indictment
United States

Court Action: U.S. v. Sergey Medvedev et al. (Infraud Organization)

Federal indictment or judicial action filed in U.S. District Court for the District of Nevada. Case: 2:17-cr-00360.

Group: Unknown Threat Actor View Case Docket →
2018-01-01 Threat Activity
United States

Intrusions Detected: Operation Cookie Monster (Genesis Market Takedown)

Initial intrusion activity documented in legal record. Coordinated multinational takedown of Genesis Market, the world's most prominent illicit broker of stolen digital browser fingerprints, cookies, and compromised...

Group: Unknown Threat Actor View Case Docket →
2017-08-24 Legal Indictment
United States

Court Action: U.S. v. Joshua Schulte (CIA Vault 7 Leak)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: 1:17-cr-00548.

Group: Unknown Threat Actor View Case Docket →
2017-08-01 Threat Activity
United States

Intrusions Detected: U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)

Initial intrusion activity documented in legal record. Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associat...

Group: Unknown Threat Actor View Case Docket →
2017-07-12 Legal Indictment
United States

Court Action: U.S. v. Marcus Hutchins (Kronos Banking Malware)

Federal indictment or judicial action filed in U.S. District Court for the Eastern District of Wisconsin. Case: 2:17-cr-00124.

Group: Unknown Threat Actor View Case Docket →
2017-04-07 Legal Indictment
United States

Court Action: U.S. v. Peter Levashov (Kelihos Botnet)

Federal indictment or judicial action filed in U.S. District Court for the District of Connecticut. Case: 3:17-cr-00083.

Group: Unknown Threat Actor View Case Docket →
2017-02-28 Legal Indictment
United States

Court Action: U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of California. Case: 3:17-cr-00103.

Group: Unknown Threat Actor View Case Docket →
2017-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)

Initial intrusion activity documented in legal record. Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, K...

Group: Unknown Threat Actor View Case Docket →
2016-10-05 Legal Indictment
United States

Court Action: U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of California. Case: 3:16-cr-00440.

Group: Unknown Threat Actor View Case Docket →
2016-10-01 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)

Initial intrusion activity documented in legal record. Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and f...

Group: Wizard Spider View Case Docket →
2016-08-02 Threat Activity
United States

Intrusions Detected: U.S. v. Ilya Lichtenstein & Heather Morgan (Bitfinex Hack & Laundering)

Initial intrusion activity documented in legal record. Conviction of Ilya Lichtenstein and Heather Morgan for executing the 2016 hack of the Bitfinex virtual currency exchange, stealing 119,754 Bitcoins (valued at $...

Group: Unknown Threat Actor View Case Docket →
2016-05-01 Threat Activity
United States

Intrusions Detected: U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)

Initial intrusion activity documented in legal record. Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly...

Group: Unknown Threat Actor View Case Docket →
2016-04-20 Threat Activity
United States

Intrusions Detected: U.S. v. Joshua Schulte (CIA Vault 7 Leak)

Initial intrusion activity documented in legal record. Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day ex...

Group: Unknown Threat Actor View Case Docket →
2016-03-15 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)

Initial intrusion activity documented in legal record. Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers,...

2016-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)

Initial intrusion activity documented in legal record. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, ...

Group: Unknown Threat Actor View Case Docket →
2015-12-23 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Initial intrusion activity documented in legal record. Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against...

Group: Sandworm Team View Case Docket →
2015-11-10 Legal Indictment
United States

Court Action: U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: 1:15-cr-00393.

Group: Unknown Threat Actor View Case Docket →
2015-08-01 Threat Activity
Transnational / Eastern Europe

Intrusions Detected: U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)

Initial intrusion activity documented in legal record. Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing mo...

2015-04-30 Threat Activity
Russian Federation

Intrusions Detected: U.S. & International Action: Dmitry Badin (German Bundestag Hack)

Initial intrusion activity documented in legal record. Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastruc...

2014-11-01 Threat Activity
Democratic People's Republic of Korea

Intrusions Detected: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)

Initial intrusion activity documented in legal record. Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $8...

Group: Lazarus Group View Case Docket →
2014-06-01 Threat Activity
United States

Intrusions Detected: U.S. v. Marcus Hutchins (Kronos Banking Malware)

Initial intrusion activity documented in legal record. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years ear...

Group: Unknown Threat Actor View Case Docket →
2014-05-01 Legal Indictment
People's Republic of China

Court Action: U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Pennsylvania. Case: 2:14-cr-00118.

Group: PLA Unit 61398 View Case Docket →
2014-04-01 Threat Activity
United States

Intrusions Detected: U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)

Initial intrusion activity documented in legal record. Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation desig...

Group: Unknown Threat Actor View Case Docket →
2014-02-04 Legal Indictment
United States

Court Action: U.S. v. Ross Ulbricht (Dread Pirate Roberts / Silk Road)

Federal indictment or judicial action filed in U.S. District Court for the Southern District of New York. Case: 1:14-cr-00068.

Group: Unknown Threat Actor View Case Docket →
2014-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)

Initial intrusion activity documented in legal record. Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to con...

Group: Unknown Threat Actor View Case Docket →
2013-10-01 Threat Activity
United States

Intrusions Detected: U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)

Initial intrusion activity documented in legal record. Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate creden...

Group: Unknown Threat Actor View Case Docket →
2012-09-01 Threat Activity
United States

Intrusions Detected: U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)

Initial intrusion activity documented in legal record. Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Roa...

Group: Unknown Threat Actor View Case Docket →
2012-03-01 Threat Activity
United States

Intrusions Detected: U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)

Initial intrusion activity documented in legal record. Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling t...

Group: Unknown Threat Actor View Case Docket →
2012-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)

Initial intrusion activity documented in legal record. Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 10...

Group: Unknown Threat Actor View Case Docket →
2011-05-01 Threat Activity
Russian Federation

Intrusions Detected: U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)

Initial intrusion activity documented in legal record. Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank ...

Group: Evil Corp View Case Docket →
2011-03-03 Legal Indictment
United States

Court Action: U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)

Federal indictment or judicial action filed in U.S. District Court for the Western District of Washington. Case: 2:11-cr-00070.

Group: Unknown Threat Actor View Case Docket →
2011-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Ross Ulbricht (Dread Pirate Roberts / Silk Road)

Initial intrusion activity documented in legal record. Historic trial and life sentencing of Ross William Ulbricht, creator and operator of Silk Road, the internet's first comprehensive darknet market using Tor and ...

Group: Unknown Threat Actor View Case Docket →
2010-10-01 Threat Activity
United States

Intrusions Detected: U.S. v. Sergey Medvedev et al. (Infraud Organization)

Initial intrusion activity documented in legal record. Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, c...

Group: Unknown Threat Actor View Case Docket →
2010-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Peter Levashov (Kelihos Botnet)

Initial intrusion activity documented in legal record. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomw...

Group: Unknown Threat Actor View Case Docket →
2009-10-01 Threat Activity
United States

Intrusions Detected: U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)

Initial intrusion activity documented in legal record. Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card number...

Group: Unknown Threat Actor View Case Docket →
2008-08-05 Legal Indictment
United States

Court Action: U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)

Federal indictment or judicial action filed in U.S. District Court for the District of Massachusetts. Case: 1:08-cr-10223.

Group: Unknown Threat Actor View Case Docket →
2007-09-10 Legal Indictment
United States

Court Action: U.S. v. Max Ray Vision (Iceman / CardersMarket)

Federal indictment or judicial action filed in U.S. District Court for the Northern District of California. Case: 3:07-cr-00624.

Group: Unknown Threat Actor View Case Docket →
2007-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)

Initial intrusion activity documented in legal record. Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim compute...

Group: Unknown Threat Actor View Case Docket →
2006-01-01 Threat Activity
People's Republic of China

Intrusions Detected: U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)

Initial intrusion activity documented in legal record. Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber ...

Group: PLA Unit 61398 View Case Docket →
2005-07-01 Threat Activity
United States

Intrusions Detected: U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)

Initial intrusion activity documented in legal record. Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Syste...

Group: Unknown Threat Actor View Case Docket →
2005-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)

Initial intrusion activity documented in legal record. Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals b...

Group: Unknown Threat Actor View Case Docket →
2004-10-26 Legal Indictment
United States

Court Action: U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)

Federal indictment or judicial action filed in U.S. District Court for the District of New Jersey. Case: 2:04-cr-00725.

Group: Unknown Threat Actor View Case Docket →
2004-01-01 Threat Activity
United States

Intrusions Detected: U.S. v. Max Ray Vision (Iceman / CardersMarket)

Initial intrusion activity documented in legal record. Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases a...

Group: Unknown Threat Actor View Case Docket →
2002-05-01 Threat Activity
United States

Intrusions Detected: U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)

Initial intrusion activity documented in legal record. Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in ...

Group: Unknown Threat Actor View Case Docket →