Yevgeniy Nikulin, a Russian national convicted by a San Francisco federal jury in July for hacking LinkedIn and Dropbox in 2012, sentenced to 7+ years in prison
More than two years after he was extradited from Czechoslovakia where he was arrested in 2016 for hacking LinkedIn, Dropbox …
Context & Ripple Effects
This sentence closes a four-year arc that began with Nikulin's 2016 arrest in Prague and his contentious extradition to the US in 2018, a transfer that pitted Washington against Moscow's own claim on him. Two years of trial followed, ending in the San Francisco jury's guilty verdict this July on charges tied to the 2012 breaches at LinkedIn, Dropbox, and Formspring.
The stakes were always the scale: roughly 117 million stolen credentials from two of the biggest consumer platforms of the era. The sentencing converts that indictment into an actual penalty, and it lands alongside other US prosecutions treating stolen-credential troves as serious federal crimes.
First-order effects
- Nikulin begins serving a term of more than seven years, resolving the final open question left by the July conviction.
- LinkedIn and Dropbox, whose 2012 breaches produced the ~117M stolen credentials, get formal legal closure on the intrusion case more than eight years after the fact.
Second-order effects
- The sentence sets a benchmark against comparable cases: a Toronto man got five years plus a $250K fine for exploiting Yahoo breach data, so prosecutors and defendants now have a clearer price range for large-scale credential theft.
- For Russian nationals facing US cyber indictments, the outcome shows the extradition route through willing European states remains viable even where Moscow contests custody.
Third-order effects
- If the pattern holds, decade-old mega-breaches keep generating convictions long after the incidents fade from headlines, extending the enforcement tail for credential theft.
- The case reinforces a structural norm: major consumer-platform breaches are prosecuted as multi-year federal matters rather than settled privately or diplomatically, regardless of the hacker's nationality.
The trend: US prosecution of foreign nationals for mass credential theft is lengthening the enforcement horizon on old mega-breaches, with European extraditions supplying the jurisdiction that direct arrest cannot.