YEAR IN REVIEW

Year: 2024

Court filings and enforcement actions initiated or unsealed during calendar year 2024.

Key Facts

Cases Opened
6
Prosecution dockets
Identified Losses
$3.2 billion
Reported damages
  • 6 major cases opened or unsealed in 2024.
  • Cumulative losses identified for 2024 matters exceed $3.2 billion.
  • Documented from federal indictments and official government disclosures.

Documented Matters for 2024

charged 2024-05-07

U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.

alleged 2024-02-21

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

fugitive 2024-09-24

U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.

charged 2024-05-20

U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)

Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.

charged 2024-04-16

U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.

alleged 2024-05-31

Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.