U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Western District of Washington.
- Primary Target Sector: Hospitality, Food Services, Retail.
- Documented Financial Loss: $1.0 billion.
- 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.
Operational & Financial Fallout
Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.
Adversary Kill Chain Flow
5 Documented PhasesFIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.
Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.
Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.
Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.
Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.
Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.
Procedural & Incident Timeline
Fedir Hladyr arrested in Dresden, Germany, and extradited to the Western District of Washington.
Hladyr pleads guilty to conspiracy to commit wire fraud and computer hacking.
Hladyr sentenced to 120 months (10 years) in federal prison and ordered to pay $2.5 million in restitution.
Kolpakov sentenced to 84 months (7 years) in federal prison and ordered to pay $2.5 million in restitution.
Iarmak sentenced to 60 months (5 years) in federal prison after pleading guilty.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Fedir Hladyr | Ukraine | sentenced | 120 mo | None | FIN7 systems administrator sentenced to 10 years in federal prison. |
| Andrii Kolpakov | Ukraine | sentenced | 84 mo | None | FIN7 pen-testing manager sentenced to 7 years in federal prison. |
| Denys Iarmak | Ukraine | sentenced | 60 mo | None | FIN7 penetration tester sentenced to 5 years in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints." | Indictment ¶ 14, Page 8 | reviewed |
| T1059.001 | PowerShell Execution | "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite." | Indictment ¶ 16, Page 9 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers." | Plea Agreement ¶ 8 | reviewed |
| T1056.001 | Keylogging Credential Access | "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions." | Indictment ¶ 22, Page 12 | reviewed |
| T1113 | Screen Capture Collection | "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time." | Indictment ¶ 25, Page 14 | reviewed |
| T1074.001 | Local Data Staging Collection | "Stolen credit card tracks were staged in hidden directories under AppData\Local\Temp prior to scheduled exfiltration batches." | Trial Exhibit 8-C | reviewed |
| T1020 | Automated Exfiltration Exfiltration | "Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops." | Plea Agreement ¶ 9, Page 6 | reviewed |