Cyber Resilience
← All news
Confirmed

Federal docket: United States v. Thomson (3:26-cr-00426, District Court, N.D.

Our takeNew federal case, US v. Thomson, filed Aug 25 in N.D. California. The docket exists — that much is confirmed — but the filing itself is all we have: no charge details yet. An indictment is an allegation, not a verdict. Nothing to act on until the charging document lands.
Sources (1)
What this means for you — Security leader:Review the unsealed indictment for any indicators tied to your environment or third-party relationships; update threat models if Thomson’s methods overlap with your exposure.
What this means for you — Lean IT orgs:If you see any mention of your company, vendors, or data in the court documents, treat it as a confirmed breach and begin your incident response steps immediately.
What this means for you — MSP:Scan client environments for any overlap with the TTPs or compromised assets named in the indictment; notify affected clients and document your review.
What this means for you — Researcher:The full indictment and supporting exhibits are now public on CourtListener; pull them for primary-source analysis of the alleged activity.