CASE DOSSIER sentenced

U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches)

Docket: 3:16-cr-00440 Court: U.S. District Court for the Northern District of California Opened: 2016-10-05 Sector: Internet Services, Social Media, Cloud Storage

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$15.0 million
LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls.
Techniques
2
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Internet Services, Social Media, Cloud Storage.
  • Documented Financial Loss: $15.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian national who hacked into the corporate networks of LinkedIn, Dropbox, and Formspring, stealing login credentials of over 100 million users and selling the stolen database dumps on darknet forums.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.

Operational & Financial Fallout

LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Link. Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.002 →

Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials.

Artifacts & Tooling: T1566.002 Spearphishing Link
2
Phase 2: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

LinkedIn and Dropbox incurred millions in incident response and mandatory security overhauls. Impacted Internet Services, Social Media, Cloud Storage infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2016-10-05 arrest

Nikulin arrested in Prague, Czech Republic, by Czech police pursuant to Interpol red notice.

2018-03-30 extradition

Extradited from the Czech Republic to the United States after competing extradition requests from Russia were denied.

2020-07-10 verdict

Jury finds Nikulin guilty of nine counts of computer intrusion, damage, and aggravated identity theft.

2020-09-29 sentencing

Sentenced to 88 months (7 years and 4 months) in federal prison.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yevgeniy Aleksandrovich Nikulin Russian Federation sentenced 88 mo None Perpetrator of LinkedIn and Dropbox data thefts. Sentenced to 88 months in federal prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.002 Spearphishing Link
Initial Access
"Nikulin infected a LinkedIn employee's personal computer with malware via spearphishing to obtain corporate VPN credentials." Trial Transcript Day 4, Page 61 reviewed
T1078 Valid Accounts
Defense Evasion
"He pivoted through the employee's authenticated corporate session into internal databases containing user password hashes." Indictment ¶ 14, Page 7 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yevgeniy Nikulin (LinkedIn & Dropbox Breaches), No. 3:16-cr-00440 (U.S. District Court for the Northern District of California 2016), https://cybercaselibrary.com/cases/us-v-nikulin-linkedin-dropbox/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-nikulin-linkedin-dropbox" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>