US v. Obrezko · 1:26-cr-10194

DENIS OBREZKO · FSB 2012–2017 · YUTEK-NN

He worked for the FSB. An AI allegedly read more than 13,000 stolen parliamentary emails.

The indictment says Denis Obrezko worked for the FSB from 2012 to 2017 in an unknown capacity and was a deputy director at Yutek-NN from 2024. The company allegedly conducted Void Blizzard/Laundry Bear operations at the Russian government's behest. A file stored on Obrezko's phone allegedly contained summaries and keyword digests covering the stolen parliamentary archive.

STOLEN PARLIAMENTARY ARCHIVE

The parliament, country and AI provider are unnamed. The document describes the victim only as the parliament of an Eastern European democracy.

2012–17WORKED FOR THE FSB
2024DEPUTY DIRECTOR AT YUTEK-NN
13K+PARLIAMENTARY EMAILS IN THE FILE
2023–25ALLEGED CONSPIRACY

The same system, read in two directions

Forward, the trail shows the exploitation of stolen data. In reverse, the same traces show how investigators may reconstruct the operation's intelligence interests.

ALLEGED EXPLOITATION TRAIL
01

Session token

Account access without a new authentication step.

02

Email access

Compromised accounts and cloud spaces.

03

13,000+ messages

An archive too large for rapid manual reading.

04

LLM

Summaries and keyword digests.

05

Intelligence leads

Decisions, meetings, contracts and agreements.

View: from stolen access to the information being sought.

AI appears as a processing layer

The value of a breach also depends on how quickly stolen material can be searched, triaged and converted into usable leads.

An archive of 13,000 messages contains noise, repetitive conversations and administrative detail. Automated summaries reduce the cost of a first reading and enable thematic searches at a scale that is difficult to sustain manually.

The filing describes the output as LLM-created summaries and keyword digests. The operators were allegedly seeking political activity, strategic decisions, and government or business information about meetings, international contracts, deals and other agreements.

This use places AI in the information-exploitation stage: after access and collection, the model helps reduce volume and direct attention.

INPUT · 13,000+ MESSAGESOUTPUT · CATEGORIES
DECISIONS MEETINGS CONTRACTS AGREEMENTS

The stored file may document two things

The indictment describes the material and lists the categories being sought. Their counterintelligence significance remains an interpretation.

FACT IN THE FILING

A record of exploitation

The file allegedly contained summaries and digests covering more than 13,000 emails. The generated text indicated the subjects sought by Obrezko and his alleged co-conspirators.

EXPLICIT TARGETS + INTERPRETATION

What the operators were seeking

The generated text pointed to four categories of interest listed in the indictment:

  • Political activity
  • Strategic decisions
  • Government or business information about meetings
  • International contracts, deals and other agreements

Together, these categories outline a collection agenda: decisions under preparation, institutional relationships that mattered, and political or commercial commitments of interest to the operation. Their presence in the generated text may help investigators reconstruct the questions asked of the archive and the order of priorities.

The published filing does not identify the specific people, meetings, contracts or agreements found, or say whether any lead was used later.

The traces described in the indictment

The document connects the FSB period, the Yutek role, Void Blizzard infrastructure, data theft and the file containing model-generated results.

2012–17

He worked for the FSB

The indictment says Obrezko worked in an unknown capacity for Russia's domestic intelligence and security service.

17 AUG 2023

Access to the internal system

Obrezko allegedly sent credentials for a data-visualization tool hosted on an internal Void Blizzard subdomain.

DIN 2024

Deputy director at Yutek-NN

The technology company allegedly conducted cyberespionage operations at the Russian government's behest.

12 IUN 2024

At least 1,207 emails

Operators allegedly accessed employee accounts at a social network and removed the messages.

11–19 NOV 2024

At least 51,000 files

Two employee accounts at a US development company allegedly opened access to a SharePoint server.

4 APR 2025

The file on the phone

A file stored on Obrezko's phone allegedly contained the summaries and digests of the parliamentary archive.

27 MAI 2025

The Microsoft report circulates internally

On the day the Void Blizzard analysis was published, Obrezko allegedly sent it to an alleged co-conspirator and arranged a meeting.

What remains unknown

The filing gives a compact description of the file without the material needed to assess the model, prompts or output quality.

01

The parliament

The country is described only as an Eastern European democracy. The document does not identify Romania.

02

The AI provider

The indictment uses the generic term LLM and names neither the company nor the model.

03

The prompts

The instructions given to the model and the sequence of queries have not been published.

04

The complete outputs

The published filing does not include the summaries, errors, omissions or any fabricated responses.

05

The chain of custody

The document says the file was on the phone. This passage does not describe the device's seizure or examination.

06

The operational effect

The filing does not say which leads were used later or whether the summaries influenced other operations.

The phrase “chain-of-thought text” comes from the indictment. It may describe reasoning-like text visible in the saved file and does not establish access to a provider's hidden internal reasoning.

Documents and sources

The figures and sequence of events come from the court document. Secondary sources provide procedural status and attribution context.

TECHNICAL CONTEXT · 27 MAY 2025

Microsoft Threat Intelligence, Void Blizzard

Microsoft describes the actor as Russia-affiliated, targeting NATO states and Ukraine, using stolen credentials and collecting email and files in bulk.

PROCEDURAL STATUS · 9 JULY 2026

Reuters, Obrezko pleads not guilty

Reuters reports the not-guilty plea, extradition from Thailand and the defense position that the charge will be contested.

The indictment contains allegations, not findings of guilt. Obrezko faces one count of conspiracy to commit computer fraud and abuse, has pleaded not guilty and is presumed innocent. Victims anonymized in the filing remain anonymized here.