CASE DOSSIER sentenced

U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)

Docket: 3:20-cr-01053 Court: U.S. District Court for the Southern District of California Opened: 2020-03-04 Sector: Consumer Services, E-Commerce, Identity Providers

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$17.0 million
Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Southern District of California.
  • Primary Target Sector: Consumer Services, E-Commerce, Identity Providers.
  • Documented Financial Loss: $17.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Consumer Services, E-Commerce, Identity Providers networks. Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.

Operational & Financial Fallout

Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts. Impacted Consumer Services, E-Commerce, Identity Providers infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Consumer Services, E-Commerce, Identity Providers networks. Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts. Impacted Consumer Services, E-Commerce, Identity Providers infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2020-03-04 arrest

Firsov arrested by FBI agents at New York's John F. Kennedy International Airport.

2021-01-22 plea

Pleads guilty to trafficking in unauthorized access devices.

2021-04-26 sentencing

Sentenced to 30 months in federal prison.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Kirill Victorovich Firsov Russian Federation sentenced 30 mo None Administrator of Deer.io cybercrime marketplace; sentenced to 30 months.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk." Indictment ¶ 8, Page 4 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop), No. 3:20-cr-01053 (U.S. District Court for the Southern District of California 2020), https://cybercaselibrary.com/cases/us-v-firsov-deer-io/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-firsov-deer-io" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>