CASE DOSSIER sentenced

U.S. v. Vachon-Desjardins (Netwalker Ransomware)

Docket: 8:20-cr-00366 Court: U.S. District Court for the Middle District of Florida Opened: 2020-12-16 Sector: Healthcare, Education, Municipal Government

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$21.5 million
Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.
Techniques
6
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Middle District of Florida.
  • Primary Target Sector: Healthcare, Education, Municipal Government.
  • Documented Financial Loss: $21.5 million.
  • 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.

Operational & Financial Fallout

Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.

Adversary Kill Chain Flow

4 Documented Phases
1
Phase 1: Privilege Escalation Privilege Escalation & Account Takeover
MITRE ATT&CK T1548.002 →

The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.

Artifacts & Tooling: T1548.002 Bypass User Account Control
2
Phase 2: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.

Artifacts & Tooling: T1078 Valid Accounts
3
Phase 3: Discovery Internal Subnet & Trust Reconnaissance
MITRE ATT&CK T1007 →

Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.

Artifacts & Tooling: T1007 System Service Discovery
4
Phase 4: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.

Artifacts & Tooling: T1486 Data Encrypted for Impact
Real-World Blast Radius & Operational Fallout

Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2020-12-16 indictment

Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage.

2022-03-09 extradition

Vachon-Desjardins extradited from Canada to the United States.

2022-06-29 plea

Defendant pleads guilty to all counts in the indictment.

2022-10-04 sentencing

Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Sebastien Vachon-Desjardins Canada sentenced 240 mo $21.5 million Netwalker ransomware affiliate sentenced to 20 years in federal prison with $21.5 million forfeiture.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals." Plea Agreement ¶ 4, Page 12 reviewed
T1078 Valid Accounts
Defense Evasion
"Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials." Plea Agreement ¶ 4, Page 13 reviewed
T1490 Inhibit System Recovery
Impact
"Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery." Indictment ¶ 8 reviewed
T1112 Modify Registry
Defense Evasion
"Netwalker modified registry keys under HKLM\SYSTEM\CurrentControlSet\Control\Lsa to weaken local security authority validation." Plea Agreement ¶ 6, Page 14 reviewed
T1548.002 Bypass User Account Control
Privilege Escalation
"The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting." Indictment ¶ 11, Page 6 reviewed
T1007 System Service Discovery
Discovery
"Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware." Plea Agreement ¶ 5, Page 13 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Vachon-Desjardins (Netwalker Ransomware), No. 8:20-cr-00366 (U.S. District Court for the Middle District of Florida 2020), https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-vachon-desjardins-netwalker" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>