{
  "id": "case-dmitry-badin-bundestag",
  "slug": "us-v-badin-german-bundestag-apt28",
  "title": "U.S. & International Action: Dmitry Badin (German Bundestag Hack)",
  "summary": "Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.",
  "case_number": "German Federal Prosecutor Warrant / U.S. D.D.C. 1:18-cr-00215",
  "court": "Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia",
  "district": "D.D.C. & BGH Karlsruhe",
  "country": "Germany & United States",
  "opened_at": "2020-05-05",
  "status": "fugitive",
  "victim_sector": "Legislative Bodies, National Government",
  "victim_country": "Germany",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "Forced the total decommissioning and complete rebuild of the Bundestag computer network.",
  "first_seen_at": "2015-04-30T00:00:00Z",
  "last_updated_at": "2026-06-05T14:00:00Z",
  "actor_slug": "apt28",
  "defendant_slugs": [
    "dmitriy-badin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
      "evidence_locator": "BKA Investigation Summary",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "EU Sanctions Notice",
      "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32020D1537",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "sanction",
      "event_date": "2020-10-22",
      "description": "European Union imposes sanctions against Dmitry Badin and GRU Unit 26165."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
    "blast_radius": "Forced the total decommissioning and complete rebuild of the Bundestag computer network. Impacted Legislative Bodies, National Government infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament.",
        "technical_artifacts": [
          "T1566.001",
          "Spearphishing Attachment"
        ],
        "mitre_technique_id": "T1566.001"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}