<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Daily Intelligence &amp; Case Feeds</title>
    <link>https://cybercaselibrary.com/</link>
    <description>Daily primary-sourced cyber facts, federal court indictments, and technical attack anatomies.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2026 03:58:54 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/rss.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Cyber Fact: A Single Power Outage in Ghana Saved the World's Largest Shipping Line]]></title>
      <link>https://cybercaselibrary.com/facts/#notpetya-ghana-power-outage-saved-maersk</link>
      <guid>https://cybercaselibrary.com/facts/#notpetya-ghana-power-outage-saved-maersk</guid>
      <description><![CDATA[When the NotPetya wiper obliterated all 150 Active Directory domain controllers across A.P. Moller-Maersk's global headquarters in minutes, the entire company was saved by a single offline domain controller in Ghana that survived solely because of a local blackout. Technicians physically flew the hard drive to London in a passenger seat to restore worldwide operations. (Source: Wired Forensic Investigation & Maersk Disclosures)]]></description>
      <category><![CDATA[Malware Forensics]]></category>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A 10-Minute Phone Call Brought Down the Las Vegas Strip]]></title>
      <link>https://cybercaselibrary.com/facts/#mgm-resorts-10-minute-phone-call</link>
      <guid>https://cybercaselibrary.com/facts/#mgm-resorts-10-minute-phone-call</guid>
      <description><![CDATA[The catastrophic September 2023 breach that shut down MGM Resorts slot machines, digital room keys, and ATMs was not initiated by zero-day malware. Operatives from Scattered Spider looked up an employee on LinkedIn, called the Okta IT helpdesk pretending to be that employee, and convinced technicians to reset their MFA credentials in under 10 minutes. (Source: CISA & FBI Advisory AA23-320A)]]></description>
      <category><![CDATA[Social Engineering]]></category>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A Jammed Printer Saved $870 Million from North Korean Hackers]]></title>
      <link>https://cybercaselibrary.com/facts/#bangladesh-bank-printer-jam-saved-millions</link>
      <guid>https://cybercaselibrary.com/facts/#bangladesh-bank-printer-jam-saved-millions</guid>
      <description><![CDATA[When North Korean Lazarus Group operatives issued 35 fraudulent SWIFT wire transfer orders totaling $951 million against the Bangladesh Central Bank, they were stopped from stealing the remaining $870 million because a local automated receipt printer on the 10th floor jammed and ran out of paper, alerting staff to anomalous transactions. (Source: DOJ Indictment 2:18-mj-02222)]]></description>
      <category><![CDATA[Heists & Extortion]]></category>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A Leaked Dark-Web Password Shut Down 45% of East Coast Fuel]]></title>
      <link>https://cybercaselibrary.com/facts/#colonial-pipeline-single-password-leak</link>
      <guid>https://cybercaselibrary.com/facts/#colonial-pipeline-single-password-leak</guid>
      <description><![CDATA[The DarkSide ransomware attack that paralyzed the 5,500-mile Colonial Pipeline and triggered emergency declarations across 17 states was traced back to a single inactive employee password leaked on a dark-web paste. The legacy VPN portal lacked multifactor authentication, letting attackers walk straight into the billing network. (Source: Senate HSGAC Testimony & CISA Alert)]]></description>
      <category><![CDATA[Infrastructure]]></category>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A $10.69 Domain Registration Stopped the Worst Ransomware Outbreak in History]]></title>
      <link>https://cybercaselibrary.com/facts/#wannacry-stopped-by-10-dollar-domain</link>
      <guid>https://cybercaselibrary.com/facts/#wannacry-stopped-by-10-dollar-domain</guid>
      <description><![CDATA[In May 2017, the global WannaCry ransomware outbreak infected 300,000 computers in 150 countries within hours, paralyzing the UK National Health Service. 22-year-old researcher Marcus Hutchins discovered a bizarre hardcoded web address in the code and registered it for $10.69, accidentally activating an internal kill-switch that halted global propagation. (Source: DOJ Indictment & UK NCSC Incident Report)]]></description>
      <category><![CDATA[Malware Forensics]]></category>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: Stuxnet Physically Tore Centrifuges Apart While Showing Normal Displays]]></title>
      <link>https://cybercaselibrary.com/facts/#stuxnet-acoustic-frequency-sabotage</link>
      <guid>https://cybercaselibrary.com/facts/#stuxnet-acoustic-frequency-sabotage</guid>
      <description><![CDATA[Stuxnet did not just shut down Iranian uranium centrifuges at Natanz; it secretly sped them up from their safe 1,064 Hz frequency to 1,410 Hz (causing physical rotor deformation and explosion) while recording normal operational sensor telemetry and playing it back on a loop to control room monitors so scientists thought everything was normal. (Source: Symantec Security Response Technical Dossier)]]></description>
      <category><![CDATA[Espionage]]></category>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A Staged Lovers' Quarrel Prevented Full-Disk Encryption]]></title>
      <link>https://cybercaselibrary.com/facts/#ross-ulbricht-library-laptop-distraction</link>
      <guid>https://cybercaselibrary.com/facts/#ross-ulbricht-library-laptop-distraction</guid>
      <description><![CDATA[When the FBI arrested Silk Road mastermind Ross Ulbricht at the Glen Park Public Library in San Francisco, two undercover agents staged a loud, dramatic domestic argument right behind him. When Ulbricht turned around in shock, an agent snatched his unencrypted Samsung laptop from his hands before he could press a hotkey to encrypt his disk. (Source: Trial Testimony: U.S. v. Ulbricht (S.D.N.Y.))]]></description>
      <category><![CDATA[Law & Precedent]]></category>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: Saudi Aramco Had to Buy Up the Global Supply of Hard Drives]]></title>
      <link>https://cybercaselibrary.com/facts/#shamoon-burning-flag-hard-drive-shortage</link>
      <guid>https://cybercaselibrary.com/facts/#shamoon-burning-flag-hard-drive-shortage</guid>
      <description><![CDATA[In August 2012, Iranian state hackers deployed the Shamoon wiper against Saudi Aramco, wiping 35,000 computers simultaneously and replacing their boot screens with a burning American flag. To rebuild operations, Saudi Aramco executives flew to Taiwan and Southeast Asian factories to purchase every computer hard drive coming off production lines. (Source: CISA Alert TA12-240A)]]></description>
      <category><![CDATA[Malware Forensics]]></category>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: 40 Million Credit Cards Compromised via an Air Conditioning Vendor]]></title>
      <link>https://cybercaselibrary.com/facts/#target-breach-refrigeration-vendor</link>
      <guid>https://cybercaselibrary.com/facts/#target-breach-refrigeration-vendor</guid>
      <description><![CDATA[The historic 2013 Target data breach that exposed 40 million debit and credit cards was not launched by hacking Target's servers directly. Hackers sent a phishing email to Fazio Mechanical Services, a small heating, ventilation, and air conditioning (HVAC) contractor in Pennsylvania, and used their electronic billing credentials to jump onto Target's corporate network. (Source: U.S. Senate Commerce Committee Investigation)]]></description>
      <category><![CDATA[Social Engineering]]></category>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A 17-Year-Old Used 'God Mode' to Hijack the President and Elon Musk]]></title>
      <link>https://cybercaselibrary.com/facts/#twitter-17-year-old-godmode-portal</link>
      <guid>https://cybercaselibrary.com/facts/#twitter-17-year-old-godmode-portal</guid>
      <description><![CDATA[In July 2020, 17-year-old Graham Ivan Clark phoned Twitter employees claiming to be from corporate IT support, convincing them to enter their credentials on a phishing page. With access to Twitter's internal customer service tool (known internally as 'God Mode'), he hijacked verified accounts for Joe Biden, Barack Obama, and Elon Musk to promote a Bitcoin giveaway. (Source: Florida State Attorney Criminal Information)]]></description>
      <category><![CDATA[Social Engineering]]></category>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: Russian Spies Used 'Golden SAML' to Read Federal Emails Undetected for 9 Months]]></title>
      <link>https://cybercaselibrary.com/facts/#solarwinds-golden-saml-nine-months</link>
      <guid>https://cybercaselibrary.com/facts/#solarwinds-golden-saml-nine-months</guid>
      <description><![CDATA[Russian SVR operatives behind the SolarWinds breach did not just infiltrate networks; they stole Active Directory Federation Services (AD FS) private token-signing certificates to execute 'Golden SAML' attacks. This allowed them to mint their own cryptographic identity tokens and access federal Microsoft 365 cloud email without knowing any passwords or triggering MFA. (Source: CISA Advisory AA20-352A)]]></description>
      <category><![CDATA[Espionage]]></category>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A 66-Day Delay on a Free Security Patch Exposed 147 Million Americans]]></title>
      <link>https://cybercaselibrary.com/facts/#equifax-struts-patch-ignored-66-days</link>
      <guid>https://cybercaselibrary.com/facts/#equifax-struts-patch-ignored-66-days</guid>
      <description><![CDATA[The Equifax breach that compromised the Social Security numbers of 147 million Americans occurred because a free security patch for Apache Struts (CVE-2017-5638) was released in March 2017, but Equifax's internal security scanner failed to flag vulnerable dispute portal servers. The servers remained unpatched for 66 days until Chinese PLA hackers extracted 265 separate databases. (Source: DOJ Indictment 1:20-cr-00071 & House Oversight Report)]]></description>
      <category><![CDATA[Infrastructure]]></category>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A Cloud Hacker Was Caught Because She Posted Her Exploits on Public GitHub]]></title>
      <link>https://cybercaselibrary.com/facts/#capital-one-paige-thompson-github-slack</link>
      <guid>https://cybercaselibrary.com/facts/#capital-one-paige-thompson-github-slack</guid>
      <description><![CDATA[Former AWS engineer Paige Thompson exploited an SSRF flaw on Capital One's cloud firewall to download 100 million credit card applications from 700 Amazon S3 buckets. Despite the sophisticated cloud exploit, she was apprehended within days because she boasted about the hack in a private Slack channel and published the exact extraction script on her public GitHub profile. (Source: DOJ Criminal Complaint 2:19-cr-00159)]]></description>
      <category><![CDATA[Law & Precedent]]></category>
      <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: A Ransomware Boss Took a $22M Payout and Cheated His Own Hacker]]></title>
      <link>https://cybercaselibrary.com/facts/#alphv-blackcat-exit-scam-change-healthcare</link>
      <guid>https://cybercaselibrary.com/facts/#alphv-blackcat-exit-scam-change-healthcare</guid>
      <description><![CDATA[When Change Healthcare paid a record 350 Bitcoin ($22 million) ransom in March 2024 to restore healthcare billing systems, the mastermind behind ALPHV/BlackCat kept the entire sum, locked out the affiliate operative who actually executed the intrusion, and posted a fake law enforcement takedown notice to fake his own disappearance. (Source: Blockchain Intelligence & Public Forum Disclosures)]]></description>
      <category><![CDATA[Heists & Extortion]]></category>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Cyber Fact: LockBit Promised to Delete Stolen Files, But Secretly Kept Them All]]></title>
      <link>https://cybercaselibrary.com/facts/#lockbit-cronos-secret-file-copies</link>
      <guid>https://cybercaselibrary.com/facts/#lockbit-cronos-secret-file-copies</guid>
      <description><![CDATA[Operation Cronos, the international police operation that took down LockBit in February 2024, seized backend servers revealing that despite charging victims millions of dollars for 'proof of destruction', LockBit never deleted the exfiltrated data. Law enforcement recovered petabytes of files that victims had paid ransoms to have destroyed. (Source: UK National Crime Agency Operation Cronos Release)]]></description>
      <category><![CDATA[Heists & Extortion]]></category>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  
    
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)]]></title>
      <link>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</link>
      <guid>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</guid>
      <description><![CDATA[Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.]]></description>
      <category><![CDATA[Energy, Healthcare, Government, Transportation]]></category>
      <pubDate>Thu, 15 Oct 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Khoroshev et al. (LockBit Ransomware Operation)]]></title>
      <link>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</link>
      <guid>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</guid>
      <description><![CDATA[Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.]]></description>
      <category><![CDATA[Healthcare, Education, Manufacturing, Government, Financial Services]]></category>
      <pubDate>Tue, 07 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: Volt Typhoon Critical Infrastructure Pre-Positioning]]></title>
      <link>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</link>
      <guid>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</guid>
      <description><![CDATA[State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.]]></description>
      <category><![CDATA[Communications, Energy, Transportation, Water, Defense Industrial Base]]></category>
      <pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: ALPHV / BlackCat Ransomware Attack on Change Healthcare]]></title>
      <link>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</link>
      <guid>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</guid>
      <description><![CDATA[Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.]]></description>
      <category><![CDATA[Healthcare and Public Health]]></category>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: Colonial Pipeline DarkSide Ransomware Attack]]></title>
      <link>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</guid>
      <description><![CDATA[DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.]]></description>
      <category><![CDATA[Energy, Oil and Gas]]></category>
      <pubDate>Fri, 07 May 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</link>
      <guid>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</guid>
      <description><![CDATA[Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.]]></description>
      <category><![CDATA[Information Technology, Defense, Federal Government, Telecommunications]]></category>
      <pubDate>Sun, 13 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</guid>
      <description><![CDATA[Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.]]></description>
      <category><![CDATA[Hospitality, Food Services, Retail]]></category>
      <pubDate>Tue, 27 Mar 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-yakubets-evil-corp-dridex/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-yakubets-evil-corp-dridex/</guid>
      <description><![CDATA[Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.]]></description>
      <category><![CDATA[Banking, Financial Services, Municipalities, Education]]></category>
      <pubDate>Thu, 14 Nov 2019 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</guid>
      <description><![CDATA[Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.]]></description>
      <category><![CDATA[Media and Entertainment, Financial Services, Healthcare]]></category>
      <pubDate>Fri, 08 Jun 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Vachon-Desjardins (Netwalker Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</guid>
      <description><![CDATA[Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.]]></description>
      <category><![CDATA[Healthcare, Education, Municipal Government]]></category>
      <pubDate>Wed, 16 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</guid>
      <description><![CDATA[Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.]]></description>
      <category><![CDATA[Retail, Hospitality, Small Business]]></category>
      <pubDate>Thu, 03 Mar 2011 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</guid>
      <description><![CDATA[Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.]]></description>
      <category><![CDATA[Managed Service Providers, Information Technology, Retail, Education]]></category>
      <pubDate>Wed, 11 Aug 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-baratov-yahoo-breach/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-baratov-yahoo-breach/</guid>
      <description><![CDATA[Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.]]></description>
      <category><![CDATA[Internet Services, Telecommunications]]></category>
      <pubDate>Tue, 28 Feb 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Joshua Schulte (CIA Vault 7 Leak)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-schulte-cia-vault-7/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-schulte-cia-vault-7/</guid>
      <description><![CDATA[Former Central Intelligence Agency software developer convicted of the historic transmission of classified CIA cyber warfare tools, source code, and zero-day exploits (Vault 7) to WikiLeaks, causing catastrophic national security damage.]]></description>
      <category><![CDATA[Intelligence, National Defense, Federal Government]]></category>
      <pubDate>Thu, 24 Aug 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Landmark Case: U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</guid>
      <description><![CDATA[Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.]]></description>
      <category><![CDATA[Nuclear Energy, Metals, Manufacturing, Clean Energy]]></category>
      <pubDate>Thu, 01 May 2014 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>