POST Online Media Lite Edition



 

Ukrainian member of FIN7 hacking group sentenced for compromising tens of millions of debit and credit cards

Christian Fernsby |
A Ukrainian man was sentenced in the Western District of Washington to 5 years in prison for his criminal work in the hacking group FIN7.

Article continues below




Denys Iarmak served as a high-level hacker, whom the group referred to as a “pen tester,” for FIN7. He was arrested in Bangkok, Thailand in November 2019 at the request of U.S. law enforcement.

At the sentencing hearing Chief U.S. District Judge Ricardo S. Martinez noted that Iarmak had been in custody during both the COVID pandemic and now the war in Ukraine.

“There is some irony, that the nation you were plundering is now leading an international effort to protect your country, your people, your family.”

Iarmak is the third FIN7 member of the group to be sentenced in the United States. On April 16, 2021, FIN7 member Fedir Hladyr was sentenced to 10 years in prison. On June 24, 2021, FIN7 member Andrii Kolpakov was sentenced to seven years in custody.

In the United States alone, FIN7 successfully breached the computer networks of businesses in all 50 states and the District of Columbia, stealing more than 20 million customer card records from over 6,500 individual point-of-sale terminals at more than 3,600 separate business locations.

According to court documents, victims incurred enormous costs that, according to some estimates, exceeded $1 billion dollars. Additional intrusions occurred abroad, including in the United Kingdom, Australia, and France. Companies that have publicly disclosed hacks attributable to FIN7 include such chains as Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin, and Jason’s Deli.

“Iarmak and his conspirators compromised millions of financial accounts, causing over a billion dollars in losses to Americans and costs to America’s economy,” said Assistant Attorney General Kenneth A. Polite, Jr. of the Justice Department’s Criminal Division.

“Protecting businesses – both large and small – online is a top priority for the Department of Justice. We are committed to working with our international partners to hold such cyber criminals accountable, no matter where they live or how anonymous they think they are.”

“Mr. Iarmak was directly involved in designing phishing emails embedded with malware, intruding on victim networks, and extracting data such as payment card information,” said U.S. Attorney Nicholas W. Brown of the Western District of Washington.

“To make matters worse, he continued his work with the FIN7 criminal enterprise even after the arrests and prosecution of co-conspirators. He and others in this cybercrime group used hacking techniques to essentially rob thousands of locations of multiple restaurant chains at once, from the comfort and safety of their keyboards in distant countries.”

“This cyber-criminal probed and mapped victims’ networks searching for data to exploit,” said Special Agent in Charge Donald M. Voiret of the FBI’s Seattle Field Office.

“Masquerading as a legitimate business, the hacking group he belonged to recruited other members to assist with their criminal activities. Thanks to the hard work of law enforcement, this defendant, who is responsible for an enormous loss amount, will be spending the next few years in prison.”

According to court documents, since at least 2015, members of FIN7 (also referred to as Carbanak Group and the Navigator Group, among other names) engaged in a highly sophisticated malware campaign to attack hundreds of U.S. companies, predominantly in the restaurant, gambling, and hospitality industries.

FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers that were then used or sold for profit. FIN7, through its dozens of members, launched waves of malicious cyberattacks on numerous businesses operating in the United States and abroad.

To execute its scheme, FIN7 carefully crafted email messages that would appear legitimate to a business’ employees and accompanied emails with telephone calls intended to further legitimize the emails. Once a file attached to a fraudulent email was opened and activated, FIN7 would use an adapted version of the Carbanak malware, in addition to an arsenal of other tools, to access and steal payment card data for the business’s customers.

Since 2015, many of the stolen payment card numbers have been offered for sale through online underground marketplaces.

Iarmak was involved with FIN7 from approximately November 2016 through November 2018. Iarmak frequently used project management software such as JIRA, hosted on private virtual servers in various countries, to coordinate FIN7 malicious activity and to manage the assorted network intrusions. JIRA is a project management and issue-tracking program used by software development teams. JIRA allows team members to create “projects” containing posted “issues” under which other team members can make comments and share data.

Under each issue, FIN7 members tracked their progress breaching a victim’s security, uploaded data stolen from the victim, and provided guidance to each other.

As one example, Iarmak created a JIRA issue, to which he and other members of the cybergroup had access, for a specific victim company, and, on or about March 3, 2017, Iarmak updated that JIRA and uploaded data he had stolen from that company.

During the course of the scheme, Iarmak received compensation for his participation in FIN7, which far exceeded comparable legitimate employment in Ukraine. Moreover, FIN7 members, including Iarmak, were aware of reported arrests of other FIN7 members, but nevertheless continued to attack U.S. businesses.

Iarmak initially fought extradition but in February 2020 he consented to extradition in a Thai court. In May 2020 he was transferred to U.S. custody. In November 2021, Iarmak pleaded guilty to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking.

This case is the result of an investigation conducted by the FBI’s Seattle Cyber Task Force. The Justice Department’s Office of International Affairs, the National Cyber-Forensics and Training Alliance, numerous computer security firms and financial institutions, FBI offices across the nation and globe, as well as a number of international agencies provided significant assistance.

Thailand law enforcement authorities provided significant assistance by arresting Iarmak.

This case was prosecuted by Assistant U.S. Attorney Steven Masada of the Western District of Washington and Trial Attorney Anthony Teelucksingh of the Criminal Division’s Computer Crime and Intellectual Property Section.


What to read next

Chinese intelligence conspired to steal sensitive aviation and technological data for years
Trinity Mirror says 80% of phone-hacking claims settled
Three North Korean military hackers indicted in cyberattacks, financial crimes

U.S.: Areas of severe thunderstorms and heavy rain through the weekend

 
Upper-level ridging weakens from the Ohio Valley to the Southeast on Friday, resulting in a reduced area of Heat Advisories over the east.
 
 

Latest

Baker Hughes: U.S. oil rig count down by 6 to 432
Malaysia introduces new rules prohibiting all plastic waste imports from U.S.
Kazakh-German JV Skyhansa to build $500 mln airport near Chinese border
Ukrainian poultry products gained access to Oman market

NEWS

EPPO targets criminal organisation suspected of VAT fraud involving sales of diesel

U.S.: Severe thunderstorms in the Northern Plains and Upper Midwest
Former U.S. senator Bob Menendez begins serving 11-year bribery sentence
Russian-linked tanker crew accused in Finland-Estonia undersea cable sabotage probe
Croatia: Former minister sentenced to two years of imprisonment for abuse of office and authority
U.S.: Widespread showers across the eastern half, severe thunderstorms in Montana into the Plains
 

BUSINESS

Peru's mining exports jump 23 pct

Vietnam encourages private businesses to invest in railway sector
Baker Hughes: U.S. oil rig count down by 1 to 438
AfDB to provide $184.1 million for Africa’s largest solar energy and battery storage project
EIB supports Bay of Biscay electricity interconnection between Spain and France
U.S., UK, and Congolese officials inaugurate Kiswishi City Special Economic Zone
 

Trending Now

Peru's mining exports jump 23 pct

Fire in Egyptian hospital kills at least seven coronavirus patients

Egyptians start paying taxes on imported mobiles

Micron plans to invest $200 billion in semiconductor manufacturing and R&D


POLITICS

New York Power Authority directed to develop nuclear power plant

Cuban President begins official visit to Belarus
EU adopts new tariffs on Russian and Belarusian agricultural goods and fertilisers
EU proposes banning LNG gas imports from Russia by end of 2027
New York Governor announces Sullivan County broadband project
Zimbabwe to ban lithium concentrate exports
 

Today We Recommend

New York Power Authority directed to develop nuclear power plant


Highlights 

Micron plans to invest $200 billion in semiconductor manufacturing and R&D

750 new jobs coming to Michigan

WFS to open new multi-purpose terminal at Lyon Airport


COMPANIES

Micron plans to invest $200 billion in semiconductor manufacturing and R&D

750 new jobs coming to Michigan
LS Cable and unit join Korea-Japan submarine cable project
WFS to open new multi-purpose terminal at Lyon Airport
CEVA Logistics renews contract to transport aeronautics parts between France, Morocco, Tunisia
Malian government takes over Canadian-owned Barrick Gold mine
 

CAREERS

Bluecrux appoints four new partners

Isomorphic Labs appoints Ben Wolf as chief medical officer
Vodacom names new international markets CEO
David Andreadakis joins Loyalty Juggernaut as chief commercial officer
Tom Montali joins CSL as business development director
Concirrus appoints Steve O'Reilly as product manager
 

ECONOMY

EU-Mercosur trade up substantially in last decade

Russia's trade surplus falls 18.3% to $42.4 bln in January-April
U.S. economy in Q1 revised up to 0.2-pct contraction
Japan loses top creditor position for first time in 34 years
NZ exports to EU jump 28% in first year of trade deal
EU generated €39.2 billion surplus in trade in agricultural products
 

EARNINGS

Ericsson Q2 sales down but North America up

Lockton revenue $3.55 billion
Motorcar Parts of America Q4 sales $189.5 million
Limoneira Q2 revenue $44.6 million
Lululemon athletica Q1 revenue increased 10% to $2.2 billion
PVH Q1 GAAP EBIT $205 million
 

OP-ED

Micromanaging is the worst enemy of efficiency and teamwork

Niger set to monetize massive gas reserves through Saharan natural gas pipeline
Putting the brakes on EV folly that choked the market
Oil discovery in Kavango Basin may mean huge benefits for Namibians
Cape Town and Dubai battle over Africa's energy future
Is America going to lose its superpower status?
 

AGRIFISH

Ireland: Minister Donohoe removes broiler poultry farmers from VAT Flat Rate Addition scheme

FLI tests mobile One Health laboratory for diagnosing highly pathogenic pathogens
First vaccine against swine dysentery disease recommended for approval
USDA expands fruit pest quarantines in New York and California
Peru records 23.6% growth in agricultural export sales compared to 2024
China allows imports of rapeseed meal, soybean meal from Uruguay
 

LEADERSHIP

Study: Missing a deadline has a bigger impact than you might think

Employers prefer younger job candidates for AI roles although experienced workers perform same or better
Study finds workers misjudge wage markets
Some organizations may need to expand their hierarchical structures earlier than others
Study finds there's right way and wrong way to deliver negative feedback in workplace
Allyship is critical and its needs appreciation
 

CRIME

German court convicts four ex-Volkswagen managers of fraud in emissions scandal

EU fines carmakers €458 million for anti-recycling cartel
Commission fines Pierre Cardin and its licensee Ahlers €5.7 million for restricting cross-border sales of clothing
BHP, Vale agree to pay $30B damages for Brazil dam disaster
Commission fines České dráhy and Österreichische Bundesbahnen €48.7 million over collusion to exclude common compe
SEC charges Keurig with making inaccurate statements regarding recyclability of K-Cup beverage pod
 

Magazine

TRAVEL

Radisson Hotel Group debuts in the heart of Tunisia’s capital city, Tunis

Morocco’s first Radisson branded hotel opens in Casablanca
Buna channels, an unreal and beautiful part of Bosnia and Herzegovina
JW Marriott unveils Mindful Haven with opening of JW Marriott Hotel Nairobi
Sotheby's Sports Week returns with fantastic artifacts
Red Roof properties open in Michigan
 

SEA, LAND, AIR

Citroën C3 Aircross, the most affordable compact SUV with 7 seats

2025 Chevrolet Equinox stands apart with fresh looks and capability
Hill Helicopters HX50, luxury in the sky
Opel Movano becomes fully equipped camper van
Porsche Panamera, new hybrid variants
Dodge Charger, 670 horsepower of electric
 

DESIGN

Cold night, hot fire pit, cool entertainment

Embellish your home with PVC panels
You'll have to hurry if you want one of 20 new Louis Vuitton watches
Luxury duvet looks good, fells good and keeps you healthy
Vacheron Constantin, watches for life and more
Schüller kitchens, where functionality marries design
 

GADGETS

MESA/Boogie Celebrates 40-year partnership with John Petrucci

reMarkable 2, monochrome tablet for your thoughts and your eyes
OnePlus Ace 3V, first with Snapdragon 7 Plus Gen 3
ASUS Zenfone 11 Ultra, flagship with a reason
Samsung Galaxy S24 is photography powerhouse
Casette tapes are making a big comeback, and so are portable players
 

HEALTH

Bolivia declares national health emergency due to measles outbreak

Hong Kong researchers develop needle-free flu vaccine with broad protection
World's first vaccines that don't need refrigeration entered trials
First patient enrolled in Phase 1 clinical trial of Akiram’s cancer drug candidate
FDA grants marketing authorization of first home test for chlamydia, gonorrhea and trichomoniasis
Human cases of anthrax reported in western Mongolia
 

MEANTIME

Cost of keeping wind turbines out of sight

Mission to "weigh" all of Earth's forests from space launched
NASA's SPHEREx space telescope begins mapping entire sky
Russian academics, gas industry experts see undersea LNG transportation as feasible
India launches space docking experiment mission
World-first carbon-14 diamond battery made