YEAR IN REVIEW

Year: 2020

Court filings and enforcement actions initiated or unsealed during calendar year 2020.

Key Facts

Cases Opened
8
Prosecution dockets
Identified Losses
$10.4 billion
Reported damages
  • 8 major cases opened or unsealed in 2020.
  • Cumulative losses identified for 2020 matters exceed $10.4 billion.
  • Documented from federal indictments and official government disclosures.

Documented Matters for 2020

fugitive 2020-10-15

U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.

alleged 2020-12-13

SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.

sentenced 2020-12-16

U.S. v. Vachon-Desjardins (Netwalker Ransomware)

Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.

sentenced 2020-08-25

U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)

Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.

sentenced 2020-02-12

U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)

Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.

sentenced 2020-03-04

U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)

Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.

sentenced 2020-09-15

U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)

Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.

fugitive 2020-05-05

U.S. & International Action: Dmitry Badin (German Bundestag Hack)

Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.