{
  "id": "case-medvedev-infraud",
  "slug": "us-v-medvedev-infraud-organization",
  "title": "U.S. v. Sergey Medvedev et al. (Infraud Organization)",
  "summary": "Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
  "case_number": "2:17-cr-00360",
  "court": "U.S. District Court for the District of Nevada",
  "district": "D. Nev.",
  "country": "United States",
  "opened_at": "2018-01-26",
  "status": "sentenced",
  "victim_sector": "Financial Services, Consumer Credit, Retail",
  "victim_country": "United States, Worldwide",
  "loss_amount_usd": 568000000,
  "loss_amount_note": "Caused actual financial losses of over $568 million to financial institutions and cardholders.",
  "first_seen_at": "2010-10-01T00:00:00Z",
  "last_updated_at": "2026-08-10T15:00:00Z",
  "actor_slug": "infraud-organization",
  "defendant_slugs": [
    "sergey-medvedev"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Medvedev",
      "source_url": "https://www.justice.gov/opa/pr/co-founder-infraud-organization-sentenced-10-years-prison-role-568-million-cyberfraud-enterprise",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2018-02-02",
      "description": "Medvedev arrested in Bangkok, Thailand, with over 100,000 Bitcoins in digital wallets."
    },
    {
      "event_type": "plea",
      "event_date": "2020-06-26",
      "description": "Pleads guilty to RICO conspiracy in federal court in Las Vegas."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-03-19",
      "description": "Sentenced to 120 months (10 years) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Consumer Credit, Retail networks. Global cybercrime enterprise operating under the slogan 'In Fraud We Trust' with over 10,000 members, trafficking in stolen identities, counterfeit documents, compromised credit cards, and banking trojans.",
    "blast_radius": "Caused actual financial losses of over $568 million to financial institutions and cardholders. Impacted Financial Services, Consumer Credit, Retail infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Infraud operated escrow systems enabling cybercriminals to buy and sell verified high-balance administrative account credentials.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}