{
  "id": "case-nikulin-linkedin",
  "slug": "us-v-nikulin-linkedin-dropbox",
  "title": "U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)",
  "summary": "Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.",
  "case_number": "3:16-cr-00440",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2016-10-05",
  "status": "sentenced",
  "victim_sector": "Internet Services, Social Media, Cloud Storage",
  "victim_country": "United States",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.",
  "first_seen_at": "2012-03-01T00:00:00Z",
  "last_updated_at": "2026-08-20T16:00:00Z",
  "actor_slug": "chinik",
  "defendant_slugs": [
    "yevgeniy-nikulin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
      "evidence_locator": "Trial Transcript Day 4, Page 61",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record: U.S. v. Nikulin",
      "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/usao-ndca/pr/russian-national-sentenced-88-months-prison-massive-cyberattacks-linkedin-and-dropbox",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2016-10-05",
      "description": "Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice."
    },
    {
      "event_type": "extradition",
      "event_date": "2018-03-30",
      "description": "Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied."
    },
    {
      "event_type": "verdict",
      "event_date": "2020-07-10",
      "description": "Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft."
    },
    {
      "event_type": "sentencing",
      "event_date": "2020-09-29",
      "description": "Sentenced to 88 months (7 years and 4 months) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
    "blast_radius": "LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.",
        "technical_artifacts": [
          "T1566.002",
          "Spearphishing Link"
        ],
        "mitre_technique_id": "T1566.002"
      },
      {
        "phase": "Phase 2: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}