CASE DOSSIER sentenced

U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)

Docket: 1:15-cr-00393 Court: U.S. District Court for the Southern District of New York Opened: 2015-11-10 Sector: Financial Services, Banking, Publishing

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$19.0 million
Court ordered $19,952,861 in restitution to victim financial institutions.
Techniques
2
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Southern District of New York.
  • Primary Target Sector: Financial Services, Banking, Publishing.
  • Documented Financial Loss: $19.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian hacker who penetrated JPMorgan Chase and eleven other major U.S. financial institutions and media companies, stealing personal data belonging to over 100 million customers to fuel securities pump-and-dump schemes.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.

Operational & Financial Fallout

Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1190 →

Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.

Artifacts & Tooling: T1190 Exploit Public-Facing Application
2
Phase 2: Exfiltration Encrypted Cloud Data Exfiltration
MITRE ATT&CK T1041 →

Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.

Artifacts & Tooling: T1041 Exfiltration Over C2 Channel
Real-World Blast Radius & Operational Fallout

Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2018-09-07 extradition

Extradited from the Republic of Georgia to the Southern District of New York.

2019-09-23 plea

Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies.

2021-01-07 sentencing

Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Andrei Tyurin Russian Federation sentenced 144 mo None Perpetrator of JPMorgan Chase 83-million-customer data intrusion. Sentenced to 144 months in prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication." Indictment ¶ 12, Page 6 reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time." Indictment ¶ 15, Page 8 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach), No. 1:15-cr-00393 (U.S. District Court for the Southern District of New York 2015), https://cybercaselibrary.com/cases/us-v-tyurin-jpmorgan-chase/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-tyurin-jpmorgan-chase" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>