{
  "id": "case-fin7-carbanak",
  "slug": "us-v-hladyr-fin7-carbanak",
  "title": "U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)",
  "summary": "Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.",
  "case_number": "2:18-cr-00067",
  "court": "U.S. District Court for the Western District of Washington",
  "district": "W.D. Wash.",
  "country": "United States",
  "opened_at": "2018-03-27",
  "status": "sentenced",
  "victim_sector": "Hospitality, Food Services, Retail",
  "victim_country": "United States",
  "loss_amount_usd": 1000000000,
  "loss_amount_note": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli.",
  "first_seen_at": "2015-08-01T00:00:00Z",
  "last_updated_at": "2026-09-12T14:00:00Z",
  "actor_slug": "fin7",
  "defendant_slugs": [
    "fedir-hladyr",
    "andrii-kolpakov",
    "denys-iarmak"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
      "evidence_locator": "Indictment \u00b6 14, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Hladyr",
      "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1059.001",
      "evidence_excerpt": "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.",
      "evidence_locator": "Indictment \u00b6 16, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Hladyr",
      "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
      "technique_name": "PowerShell",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.",
      "evidence_locator": "Plea Agreement \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "U.S. v. Hladyr Plea Agreement",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1056.001",
      "evidence_excerpt": "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.",
      "evidence_locator": "Indictment \u00b6 22, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Hladyr",
      "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
      "technique_name": "Keylogging",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1113",
      "evidence_excerpt": "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.",
      "evidence_locator": "Indictment \u00b6 25, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Hladyr",
      "source_url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacks-over-100",
      "technique_name": "Screen Capture",
      "tactic": "Collection"
    },
    {
      "technique_id": "T1074.001",
      "evidence_excerpt": "Stolen credit card tracks were staged in hidden directories under AppData\\Local\\Temp prior to scheduled exfiltration batches.",
      "evidence_locator": "Trial Exhibit 8-C",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
      "technique_name": "Local Data Staging",
      "tactic": "Collection"
    },
    {
      "technique_id": "T1020",
      "evidence_excerpt": "Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops.",
      "evidence_locator": "Plea Agreement \u00b6 9, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/high-ranking-fin7-member-sentenced-10-years-prison-role-massive-cyber-scheme",
      "technique_name": "Automated Exfiltration",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2018-01-20",
      "description": "Fedir Hladyr arrested in Dresden, Germany, and extradited to the Western District of Washington."
    },
    {
      "event_type": "plea",
      "event_date": "2019-09-11",
      "description": "Hladyr pleads guilty to conspiracy to commit wire fraud and computer hacking."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-04-16",
      "description": "Hladyr sentenced to 120 months (10 years) in federal prison and ordered to pay $2.5 million in restitution."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-06-24",
      "description": "Kolpakov sentenced to 84 months (7 years) in federal prison and ordered to pay $2.5 million in restitution."
    },
    {
      "event_type": "sentencing",
      "event_date": "2022-04-07",
      "description": "Iarmak sentenced to 60 months (5 years) in federal prison after pleading guilty."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
    "blast_radius": "Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.",
        "technical_artifacts": [
          "T1566.001",
          "Spearphishing Attachment"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Host Execution & Payload Staging",
        "description": "Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.",
        "technical_artifacts": [
          "T1059.001",
          "PowerShell"
        ],
        "mitre_technique_id": "T1059.001"
      },
      {
        "phase": "Phase 3: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.",
        "technical_artifacts": [
          "T1056.001",
          "Keylogging"
        ],
        "mitre_technique_id": "T1056.001"
      },
      {
        "phase": "Phase 4: Collection",
        "title": "Target Data Harvesting & Archiving",
        "description": "Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.",
        "technical_artifacts": [
          "T1113",
          "Screen Capture"
        ],
        "mitre_technique_id": "T1113"
      },
      {
        "phase": "Phase 5: Exfiltration",
        "title": "Encrypted Cloud Data Exfiltration",
        "description": "Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.",
        "technical_artifacts": [
          "T1041",
          "Exfiltration Over C2 Channel"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}