LinkedIn says a Russian man arrested in the Czech Republic is believed to be involved in the 2012 breach, which saw the release of 117M passwords
Russian man drove luxury car, then collapsed after being apprehended, police say. — An alleged Russian hacker arrested in the Czech Republic following …
Context & Ripple Effects
This arrest is the first custody event in a case that has been building since the 2012 dump of 117M LinkedIn passwords surfaced alongside breaches at Dropbox and Formspring. The US indictment of Yevgeniy Nikulin followed within days of the Czech apprehension, turning an anonymous breach into a named defendant.
First-order effects
- Nikulin now faces competing claims: a US indictment covering LinkedIn, Dropbox, and Formspring, with his extradition contested while he sits in Czech custody.
- LinkedIn's 2012 breach moves from a closed incident to active litigation, with the company positioned as a victim-witness in a federal case.
Second-order effects
- Dropbox and Formspring are pulled into the same prosecution's orbit, since the single indictment bundles all three 2012 intrusions — evidence in one case becomes discovery in another.
- The case validates the tracking work behind large-scale credential theft investigations, following the pattern of Alex Holden's pursuit of hackers behind a 1.2B-credential haul.
Third-order effects
- The timeline itself is the structural lesson: from 2012 breach to extradition to the US in 2018 to a guilty verdict by a San Francisco federal jury in 2020, mega-breach prosecutions run on near-decade horizons — meaning credential dumps keep generating legal exposure long after the passwords rotate.
The trend: Mega-breaches from the early-2010s credential-dump era are being converted, one extradition at a time, into criminal convictions that outlast the incidents themselves.