U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Western District of Washington.
- Primary Target Sector: Retail, Hospitality, Small Business.
- Documented Financial Loss: $169.0 million.
- 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Retail, Hospitality, Small Business networks. Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.
Operational & Financial Fallout
Caused verified financial fraud losses of $169 million to 3,700 financial institutions. Impacted Retail, Hospitality, Small Business infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Retail, Hospitality, Small Business networks. Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.
Adversary Kill Chain Flow
3 Documented PhasesHe used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.
Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.
Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.
Caused verified financial fraud losses of $169 million to 3,700 financial institutions. Impacted Retail, Hospitality, Small Business infrastructure and associated victim operations.
Procedural & Incident Timeline
Seleznev arrested by U.S. Secret Service in the Maldives with a laptop containing 1.7 million stolen credit cards.
Jury finds Seleznev guilty of 38 federal felony counts including wire fraud and computer hacking.
Sentenced to 324 months (27 years) in federal prison, the longest computer hacking sentence in U.S. history at the time, and ordered to pay $169,879,276 restitution.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Roman Valerevich Seleznev | Russian Federation | sentenced | 324 mo | None | Mastermind behind POS point-of-sale malware operations. Sentenced to 27 years in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1046 | Network Service Discovery Discovery | "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389." | Trial Transcript Day 4, Page 82 | reviewed |
| T1110 | Brute Force Credential Access | "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems." | Trial Transcript Day 5, Page 112 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops." | Trial Exhibit 14-A | reviewed |
| T1588.002 | Obtain Tool Resource Development | "Seleznev purchased specialized memory scraping tools and POS card harvesting scripts from Russian underground forums." | Trial Transcript Day 6, Page 140 | reviewed |