JURISDICTION PROFILE

Jurisdiction: United States

Court filings and enforcement actions documenting cyber intrusions within or targeting entities in United States.

Key Facts

Total Cases
33
Prosecution matters
Identified Losses
$18.6 billion
Court & SEC records
  • 33 documented prosecution matters involving United States.
  • Cumulative identified losses exceed $18.6 billion.
  • Includes federal court filings, international extraditions, and sanctions designations.

Documented Incidents

alleged 2024-02-21

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

pleaded 2021-05-07

Colonial Pipeline DarkSide Ransomware Attack

DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.

sentenced 2018-03-27

U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)

Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.

sentenced 2011-03-03

U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)

Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.

sentenced 2017-02-28

U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)

Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.

sentenced 2017-08-24

U.S. v. Joshua Schulte (CIA Vault 7 Leak)

Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.

fugitive 2014-05-01

U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)

Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.

sentenced 2008-08-05

U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)

Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.

sentenced 2015-11-10

U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)

Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.

sentenced 2020-08-25

U.S. v. Egor Igorevich Kriuchkov (Tesla Insider Threat Attempt)

Russian national who traveled to Nevada and offered a $1 million Bitcoin bribe to an employee at the Tesla Gigafactory in Sparks, Nevada, to introduce malware onto the company's internal network.

sentenced 2016-10-05

U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)

Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.

fugitive 2018-07-13

U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)

Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.

sentenced 2020-02-12

U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)

Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.

sentenced 2018-03-20

U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)

Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.

sentenced 2004-10-26

U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)

Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.

sentenced 2007-09-10

U.S. v. Max Ray Vision (Iceman / CardersMarket)

Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.

fugitive 2018-09-28

U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)

Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.

fugitive 2023-04-18

U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)

Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.

fugitive 2019-01-15

U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)

Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.

charged 2024-04-16

U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.

sentenced 2022-11-04

U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)

Historic seizure of over 50,676 Bitcoins ($3.36 billion at seizure) hidden in an underground floor safe and popcorn tin, stolen by James Zhong from the Silk Road darknet market in 2012 by triggering race conditions in the withdrawal logic.

fugitive 2021-11-08

U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)

International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.

fugitive 2020-01-28

U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)

Four military officers with the Chinese People's Liberation Army (PLA) 54th Research Institute charged with hacking into Equifax networks, stealing trade secrets, and exfiltrating personally identifiable information (PII) of roughly 147 million American citizens.

settled 2014-04-02

Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)

Landmark retail cyberattack where attackers penetrated Target internal corporate networks using stolen billing portal credentials from a third-party refrigeration and HVAC vendor, subsequently deploying BlackPOS memory scraping malware to steal 40 million credit card numbers and 70 million customer records.

alleged 2023-10-05

MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)

Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.

sentenced 2019-08-28

U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)

Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.

sentenced 2020-07-31

State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)

17-year-old hacker orchestrated a spearphishing and social engineering scheme targeting Twitter employees, gaining access to internal administrative customer service tools and hijacking 130 high-profile verified accounts (including Joe Biden, Barack Obama, Elon Musk, and Apple) to promote a fraudulent Bitcoin giveaway.

sentenced 2014-02-04

U.S. v. Ross Ulbricht (Silk Road Darknet Marketplace)

Landmark prosecution of Ross Ulbricht, creator and operator of the Silk Road dark web marketplace, which processed hundreds of millions in anonymous Bitcoin transactions for illicit narcotics, computer hacking tools, and money laundering services. Federal agents seized over $3.3 billion in Bitcoin.

convicted 2024-02-21

Change Healthcare Ransomware Outage (ALPHV / BlackCat)

Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.

alleged 2024-05-23

Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts

Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.

alleged 2024-06-19

CDK Global BlackSuit Ransomware Incident

Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.

investigation 2024-07-12

AT&T Cloud Telecom Call and Text Metadata Exfiltration

Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.

investigation 2024-01-19

Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)

Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.