{
  "id": "case-baratov-yahoo",
  "slug": "us-v-baratov-yahoo-breach",
  "title": "U.S. v. Baratov et al. (Yahoo 2014 Breach / FSB Officers)",
  "summary": "Conspiracy between Russian Federal Security Service (FSB) officers and criminal hackers to breach Yahoo's network, compromising 500 million user accounts to conduct espionage against journalists, government officials, and commercial executives.",
  "case_number": "3:17-cr-00103",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2017-02-28",
  "status": "sentenced",
  "victim_sector": "Internet Services, Telecommunications",
  "victim_country": "United States",
  "loss_amount_usd": 350000000,
  "loss_amount_note": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds.",
  "first_seen_at": "2014-01-01T00:00:00Z",
  "last_updated_at": "2026-09-09T18:00:00Z",
  "actor_slug": "fsb-center-18",
  "defendant_slugs": [
    "karim-baratov",
    "dmitry-dokuchaev",
    "igor-sushchin",
    "alexsey-belan"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
      "evidence_locator": "Indictment \u00b6 22, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Dokuchaev et al.",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.",
      "evidence_locator": "Indictment \u00b6 31, Page 18",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.",
      "evidence_locator": "Indictment \u00b6 27, Page 15",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-using-stolen",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2017-02-28",
      "description": "Indictment unsealed charging two FSB officers (Dokuchaev, Sushchin) and hackers Alexsey Belan and Karim Baratov."
    },
    {
      "event_type": "arrest",
      "event_date": "2017-03-14",
      "description": "Baratov arrested by Canadian authorities in Hamilton, Ontario."
    },
    {
      "event_type": "plea",
      "event_date": "2017-11-28",
      "description": "Baratov pleads guilty to nine counts of computer hacking and wire fraud conspiracies."
    },
    {
      "event_type": "sentencing",
      "event_date": "2018-05-29",
      "description": "Baratov sentenced to 60 months (5 years) in prison and fined $250,000."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Link. Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
    "blast_radius": "Breach reduced Verizon's acquisition price of Yahoo by $350 million and required $117 million in class action settlement funds. Impacted Internet Services, Telecommunications infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Spearphishing emails with malicious web links were sent to Yahoo employees to steal privileged system access credentials.",
        "technical_artifacts": [
          "T1566.002",
          "Spearphishing Link"
        ],
        "mitre_technique_id": "T1566.002"
      },
      {
        "phase": "Phase 2: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Adversaries created forged cryptographic authentication cookies to access Yahoo webmail accounts of targeted individuals without passwords.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 3: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Adversaries stole Yahoo's proprietary user database containing names, email addresses, cryptographic salts, and hashed passwords.",
        "technical_artifacts": [
          "T1003",
          "OS Credential Dumping"
        ],
        "mitre_technique_id": "T1003"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}