{
  "id": "case-brett-johnson-shadowcrew",
  "slug": "us-v-johnson-shadowcrew",
  "title": "U.S. v. Brett Johnson (ShadowCrew Cybercrime Syndicate)",
  "summary": "Pioneering cybercriminal known as 'The Original Internet Godfather' who built and operated ShadowCrew, the prototypical dark web marketplace for trafficking in stolen identities and credit card data.",
  "case_number": "2:04-cr-00725",
  "court": "U.S. District Court for the District of New Jersey",
  "district": "D.N.J.",
  "country": "United States",
  "opened_at": "2004-10-26",
  "status": "sentenced",
  "victim_sector": "Banking, Consumer Identity, E-Commerce",
  "victim_country": "United States",
  "loss_amount_usd": 4000000,
  "loss_amount_note": "Facilitated millions in fraudulent debit card cloning transactions.",
  "first_seen_at": "2002-05-01T00:00:00Z",
  "last_updated_at": "2026-08-01T10:00:00Z",
  "actor_slug": "shadowcrew",
  "defendant_slugs": [
    "brett-johnson"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
      "evidence_locator": "Indictment \u00b6 11, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Johnson",
      "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2004/shadowcrewIndict.htm",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2005-02-08",
      "description": "Johnson arrested by U.S. Secret Service in Operation Open Market."
    },
    {
      "event_type": "sentencing",
      "event_date": "2007-06-20",
      "description": "Sentenced to 90 months (7.5 years) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Link. Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
    "blast_radius": "Facilitated millions in fraudulent debit card cloning transactions. Impacted Banking, Consumer Identity, E-Commerce infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Johnson established early phishing operations that cloned PayPal and eBay authentication web pages to steal account credentials.",
        "technical_artifacts": [
          "T1566.002",
          "Spearphishing Link"
        ],
        "mitre_technique_id": "T1566.002"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}