Yevgeniy Nikulin, a Russian indicted for allegedly hacking LinkedIn, Dropbox in 2012 resulting in ~117M stolen credentials, is found guilty by SF federal jury
> + He's guilty of the most serious charges, hacking LinkedIn and Formspring, but not guilty of doing it for financial gain . + This after a DOJ investigation tied Nikulin to a who's who of Russian scammers & FSB assets. https://www.cyberscoop.com/...
Context & Ripple Effects
This verdict closes an eight-year loop that began with Nikulin's arrest in the Czech Republic in 2016 and ran through his extradition to the US in 2018 — a transfer notable because Moscow had contested it. The San Francisco jury split the indictment: guilty on the most serious hacking counts for LinkedIn and Formspring, not guilty on the charge that he did it for financial gain.
What makes the case bigger than one defendant is the DOJ finding underneath it — an investigation tying Nikulin to a network of Russian scammers and FSB assets, which reframes the 2012 LinkedIn/Dropbox breach (~117M credentials) as state-adjacent work rather than lone-wolf crime. The conviction also set up his sentencing to more than seven years three months later.
First-order effects
- Nikulin now faces sentencing on the LinkedIn and Formspring hacking counts, while the not-guilty verdict on financial-gain charges narrows what prosecutors can claim about his motive.
- LinkedIn and Dropbox get a legal record attributing the 2012 breach — and its roughly 117 million stolen credentials — to a named actor, years after the incident itself.
Second-order effects
- The DOJ's FSB linkage gives US prosecutors a template for arguing that credential-harvesting cases against Russian nationals carry state ties, raising the stakes of extradition fights like the one fought in Prague.
- The conviction feeds the broader US pattern of trying Russian hackers in federal court — the same playbook later used in the Klyushin insider-trading conviction — reinforcing the message that US indictments of Russian cyber operators end in US courtrooms.
Third-order effects
- Breaches from the 2012 credential-harvesting era are now producing convictions nearly a decade later, meaning attribution and prosecution — not the breach itself — set the timeline for accountability.
- If the DOJ keeps winning cases where defendants are tied to FSB assets, hacking indictments become a standing friction point in US-Russia relations, with extradition custody as the contested ground.
The trend: US prosecutors are steadily converting years-old Russian credential-harvesting breaches into convictions, increasingly framed around defendants' ties to Russian intelligence.