U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Internet Services, Social Media, Cloud Storage.
- Documented Financial Loss: $15.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.
Operational & Financial Fallout
LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.
Adversary Kill Chain Flow
2 Documented PhasesNikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.
He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.
LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.
Procedural & Incident Timeline
Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice.
Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied.
Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft.
Sentenced to 88 months (7 years and 4 months) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yevgeniy Aleksandrovich Nikulin | Russian Federation | sentenced | 88 mo | None | Perpetrator of LinkedIn and Dropbox data thefts. Sentenced to 88 months in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.002 | Spearphishing Link Initial Access | "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials." | Trial Transcript Day 4, Page 61 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes." | Indictment ¶ 14, Page 7 | reviewed |