YEAR IN REVIEW

Year: 2024

Court filings and enforcement actions initiated or unsealed during calendar year 2024.

Key Facts

Cases Opened
11
Prosecution dockets
Identified Losses
$8.0 billion
Reported damages
  • 11 major cases opened or unsealed in 2024.
  • Cumulative losses identified for 2024 matters exceed $8.0 billion.
  • Documented from federal indictments and official government disclosures.

Documented Matters for 2024

charged 2024-05-07

U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.

alleged 2024-02-21

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

fugitive 2024-09-24

U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.

charged 2024-05-20

U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)

Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.

charged 2024-04-16

U.S. v. Daniel Rhyne (Industrial Insider Extortion)

Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.

alleged 2024-05-31

Snowflake Customer Multi-Tenant Credential Stuffing Campaign

Coordinated cybercrime campaign targeting over 165 corporate customer tenants of cloud database provider Snowflake using credentials harvested by infostealer malware, exfiltrating billions of consumer records from Ticketmaster, Santander, and AT&T.

convicted 2024-02-21

Change Healthcare Ransomware Outage (ALPHV / BlackCat)

Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.

alleged 2024-05-23

Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts

Financially motivated threat actor collective UNC5537 systematically infiltrated over 165 corporate customer tenants hosted on Snowflake (including Ticketmaster, Santander Bank, Advance Auto Parts, and LendingTree). Attackers leveraged infostealer malware logs dating back years against enterprise user accounts that lacked multi-factor authentication and IP network allowlists, exfiltrating billions of consumer records.

alleged 2024-06-19

CDK Global BlackSuit Ransomware Incident

Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.

investigation 2024-07-12

AT&T Cloud Telecom Call and Text Metadata Exfiltration

Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.

investigation 2024-01-19

Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)

Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.