CASE DOSSIER sentenced

U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)

Docket: 3:17-cr-00103 Court: U.S. District Court for the Northern District of California Opened: 2017-02-28 Sector: Internet Services, Telecommunications

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$350.0 million
Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds.
Techniques
3
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Internet Services, Telecommunications.
  • Documented Financial Loss: $350.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Link. Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.

Operational & Financial Fallout

Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds. Impacted Internet Services, Telecommunications infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Link. Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.

Adversary Kill Chain Flow

3 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.002 →

Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.

Artifacts & Tooling: T1566.002 Spearphishing Link
2
Phase 2: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.

Artifacts & Tooling: T1078 Valid Accounts
3
Phase 3: Credential Access Credential Harvesting & Memory Dumping
MITRE ATT&CK T1003 →

Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.

Artifacts & Tooling: T1003 OS Credential Dumping
Real-World Blast Radius & Operational Fallout

Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds. Impacted Internet Services, Telecommunications infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2017-02-28 indictment

Indictment unsealed charging two FSB officers (Dokuchaev, Sushchin) and hackers Alexsey Belan and Karim Baratov.

2017-03-14 arrest

Baratov arrested by Canadian authorities in Hamilton, Ontario.

2017-11-28 plea

Baratov pleads guilty to nine counts of computer hacking and wire fraud conspiracies.

2018-05-29 sentencing

Baratov sentenced to 60 months (5 years) in prison and fined $250,000.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Karim Baratov Canadian and Kazakh sentenced 60 mo None Hacker-for-hire who worked with Russian FSB agents in the Yahoo breach. Sentenced to 60 months in prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.002 Spearphishing Link
Initial Access
"Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials." Indictment ¶ 22, Page 12 reviewed
T1078 Valid Accounts
Defense Evasion
"Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords." Indictment ¶ 31, Page 18 reviewed
T1003 OS Credential Dumping
Credential Access
"Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords." Indictment ¶ 27, Page 15 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers), No. 3:17-cr-00103 (U.S. District Court for the Northern District of California 2017), https://cybercaselibrary.com/cases/us-v-baratov-yahoo-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-baratov-yahoo-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>