U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Southern District of New York.
- Primary Target Sector: Financial Services, Banking, Publishing.
- Documented Financial Loss: $19.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.
Operational & Financial Fallout
Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Exploit Public-Facing Application. Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.
Adversary Kill Chain Flow
2 Documented PhasesTyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication.
Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time.
Court ordered $19,952,861 in restitution to victim financial institutions. Impacted Financial Services, Banking, Publishing infrastructure and associated victim operations.
Procedural & Incident Timeline
Extradited from the Republic of Georgia to the Southern District of New York.
Pleads guilty to computer intrusion, wire fraud, bank fraud, and illegal gambling conspiracies.
Sentenced to 144 months (12 years) in federal prison and ordered to forfeit $19,214,956.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Andrei Tyurin | Russian Federation | sentenced | 144 mo | None | Perpetrator of JPMorgan Chase 83-million-customer data intrusion. Sentenced to 144 months in prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication." | Indictment ¶ 12, Page 6 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time." | Indictment ¶ 15, Page 8 | reviewed |