{
  "id": "case-tyurin-jpmorgan",
  "slug": "us-v-tyurin-jpmorgan-chase",
  "title": "U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)",
  "summary": "Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.",
  "case_number": "1:15-cr-00393",
  "court": "U.S. District Court for the Southern District of New York",
  "district": "S.D.N.Y.",
  "country": "United States",
  "opened_at": "2015-11-10",
  "status": "sentenced",
  "victim_sector": "Financial Services, Banking, Publishing",
  "victim_country": "United States",
  "loss_amount_usd": 19000000,
  "loss_amount_note": "Court ordered $19,952,861 in restitution to victim financial institutions.",
  "first_seen_at": "2012-01-01T00:00:00Z",
  "last_updated_at": "2026-09-05T14:00:00Z",
  "actor_slug": "shalon-cyber-syndicate",
  "defendant_slugs": [
    "andrei-tyurin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
      "evidence_locator": "Indictment \u00b6 12, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Tyurin",
      "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.",
      "evidence_locator": "Indictment \u00b6 15, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/usao-sdny/pr/russian-hacker-andrei-tyurin-sentenced-12-years-prison-massive-cyber-attacks-us-financial",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "extradition",
      "event_date": "2018-09-07",
      "description": "Extradited from the Republic of Georgia to the Southern District of New York."
    },
    {
      "event_type": "plea",
      "event_date": "2019-09-23",
      "description": "Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-01-07",
      "description": "Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
    "blast_radius": "Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.",
        "technical_artifacts": [
          "T1190",
          "Exploit Public-Facing Application"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Exfiltration",
        "title": "Encrypted Cloud Data Exfiltration",
        "description": "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.",
        "technical_artifacts": [
          "T1041",
          "Exfiltration Over C2 Channel"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}