{
  "id": "case-firsov-deerio",
  "slug": "us-v-firsov-deer-io",
  "title": "U.S. v. Kirill Victorovich Firsov (Deer.io Dark Web Shop)",
  "summary": "Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
  "case_number": "3:20-cr-01053",
  "court": "U.S. District Court for the Southern District of California",
  "district": "S.D. Cal.",
  "country": "United States",
  "opened_at": "2020-03-04",
  "status": "sentenced",
  "victim_sector": "Consumer Services, E-Commerce, Identity Providers",
  "victim_country": "United States, Worldwide",
  "loss_amount_usd": 17000000,
  "loss_amount_note": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts.",
  "first_seen_at": "2013-10-01T00:00:00Z",
  "last_updated_at": "2026-08-14T11:00:00Z",
  "actor_slug": "deer-io",
  "defendant_slugs": [
    "kirill-firsov"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.",
      "evidence_locator": "Indictment \u00b6 8, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Firsov",
      "source_url": "https://www.justice.gov/usao-sdca/pr/russian-national-sentenced-operating-cybercrime-storefront-trafficked-stolen-credentials",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2020-03-04",
      "description": "Firsov arrested by FBI agents at New York's John F. Kennedy International Airport."
    },
    {
      "event_type": "plea",
      "event_date": "2021-01-22",
      "description": "Pleads guilty to trafficking in unauthorized access devices."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-04-26",
      "description": "Sentenced to 30 months in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Services, E-Commerce, Identity Providers networks. Russian administrator of Deer.io, a decentralized cyber storefront platform hosting over 24,000 active automated shops selling hacked accounts, corporate credentials, and identity documents.",
    "blast_radius": "Deer.io stores generated at least $17 million in cryptocurrency sales of stolen accounts. Impacted Consumer Services, E-Commerce, Identity Providers infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Deer.io functioned as an automated turn-key storefront allowing hackers to upload and sell stolen user account databases in bulk.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}