DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.
Reviewed by the Social Engineering Examples team.
Between 2015 and 2021, FIN7 (also tracked as the Carbanak Group and Navigator Group) breached the computer networks of more than 100 U.S. companies, concentrated in the restaurant, gaming, and hospitality sectors, across 49 states and D.C., stealing more than 15 million customer payment-card records from over 6,500 point-of-sale terminals at more than 3,600 business locations. The U.S. Department of Justice, Western District of Washington, unsealed superseding indictments on August 1, 2018 against three alleged high-level members, Dmytro Fedorov, Fedir Hladyr, and Andrii Kolpakov, charging conspiracy to commit wire fraud and computer hacking; a fourth member, Denys Iarmak, was indicted separately after his 2019 arrest. The group's tradecraft blended remote cyber-intrusion (spear-phishing with malicious Word attachments, sometimes reinforced with pretext phone calls) with physical and in-person social engineering: a fake front company, "Combi Security," used to recruit hackers under the pretense of legitimate cybersecurity work, and, in a later, related campaign publicly attributed to FIN7 by the FBI, mailed BadUSB keystroke-injection devices disguised as gift cards, teddy-bear gifts, or (from 2021) fake government/Amazon mailings sent to HR, IT, and executive staff at target companies. This record treats the DOJ's criminal cases against Fedorov, Hladyr, Kolpakov, and Iarmak as the authoritative government-documented anchor for FIN7's identity and its physical baiting/USB tactics.
FIN7 combined remote cyber intrusion with physical and in-person social-engineering tradecraft. (1) Recruitment cover: the group operated a fake cybersecurity company, "Combi Security," complete with a phony website, to publicly advertise legitimate-sounding jobs (penetration tester, developer) and recruit hackers who believed they were doing lawful security work; defendants Hladyr and Kolpakov were both recruited this way, giving the organization plausible deniability and giving lower-level members cover to deny knowingly committing crimes. (2) Core intrusion vector: spear-phishing emails to employees at target restaurant/hotel/casino chains carrying malicious Microsoft Word attachments (sometimes using pretexts like a fabricated food-poisoning complaint to a restaurant manager), frequently reinforced by a follow-up phone call from a FIN7 member posing as the sender to talk the employee into opening the attachment; once inside, operators moved laterally to point-of-sale systems to harvest card data. (3) Physical baiting/USB campaign (documented in FBI FLASH alerts starting March 2020, attributed to FIN7 by FBI and independently corroborated by Kaspersky and FireEye/Mandiant researchers via malware/infrastructure overlap): FIN7 mailed BadUSB/"Bad Beetle" USB keystroke-injection devices via USPS/UPS to employees in HR, IT, and executive roles at retail, restaurant, and hotel companies, disguised as a $50 Best Buy gift card with a USB "product list," sometimes bundled with a teddy bear; the campaign later (from August 2021) expanded to transportation, insurance, and defense-sector targets using a fake U.S. Department of Health and Human Services COVID-19 guidance letter or a decorative "thank you" gift box impersonating Amazon with a counterfeit gift card. When plugged in, the device registered as a keyboard (HID) and auto-typed a PowerShell command that downloaded the GRIFFON backdoor, leading in later intrusions to ransomware deployment (BlackMatter, REvil).
Lures: (1) a fabricated angry-customer/food-poisoning complaint email to a restaurant manager urging them to open an attached "report"; (2) an unsolicited package appearing to be from Best Buy containing a $50 loyalty gift card and a USB drive claimed to list eligible products; (3) a "gift" package with a teddy bear or gift card mailed to HR/IT/executive staff; (4) a fake U.S. Department of Health and Human Services letter with COVID-19 "guidance" and an enclosed USB; (5) a decorative gift box impersonating Amazon with a counterfeit thank-you gift card and USB; (6) a legitimate-looking classified job ad for "Combi Security," a real-seeming cybersecurity firm with its own website, used to recruit hackers. Tells that gave it away when caught: recipients with security training who did not plug in unsolicited USB devices and instead submitted them for analysis; the USB devices were commercially available "BadUSB"/"Bad Beetle"/LilyGO hardware (cheap, $5-$14) rather than custom silicon; devices registered anomalously as HID keyboards even when storage media was policy-restricted; and Combi Security, on inspection, had no legitimate clients and a phony web presence.
Superseding indictments against Fedorov, Hladyr, and Kolpakov were filed July 27, 2018 and unsealed August 1, 2018 in the Western District of Washington; a fourth defendant, Denys Iarmak, was indicted separately (CR19-257RSM). Hladyr, arrested in Germany in January 2018 and extradited, pleaded guilty September 11, 2019 to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking (24 other counts were dropped), and was sentenced April 16, 2021 to 10 years in prison (including time already served) plus $2.5 million restitution. Kolpakov, arrested on vacation in Lepe, Spain on June 28, 2018 and extradited in June 2019, pleaded guilty November 16, 2020 to conspiracy to commit wire fraud and computer hacking, and was sentenced to 84 months (7 years) plus $2.5 million restitution around June 2021 (his lawyer argued he was unwittingly "backed into a corner" after answering the Combi Security job ad and was paid only about $75,000). Iarmak, arrested in Bangkok, Thailand in November 2019 at the request of U.S. investigators and extradited to U.S. custody in 2020, pleaded guilty November 22, 2021 to conspiracy to commit wire fraud and conspiracy to commit computer hacking (having originally faced 27 counts and a potential life sentence); he was sentenced April 7, 2022 in Seattle by U.S. District Judge Ricardo S. Martinez to 5 years in federal prison, becoming the third FIN7 member sentenced in the U.S. after Hladyr (10 years) and Kolpakov (7 years); his defense cited time served in a Thailand prison and a COVID-19 infection while in BOP custody. Fedorov, arrested in Bielsko-Biala, Poland in early 2018, had a far longer public docket showing trial continuances into 2022, but no plea agreement or sentencing announcement specific to Fedorov was located during this review; the November 22, 2021 change-of-plea and February/April 2022 sentencing entries that had previously been associated with his case in this record actually belong to the separate Iarmak docket (CR19-257RSM), not Fedorov's (CR18-004RSM). Fedorov's case outcome should therefore be treated as unconfirmed/open pending direct review of the WDWA docket or a DOJ press release naming him specifically. Separately, FBI FLASH alerts (from March 2020, updated through 2021-2022) formally attributed the mailed-USB "BadUSB" baiting campaign to FIN7, based on malware (GRIFFON) and infrastructure overlap independently corroborated by Kaspersky and FireEye/Mandiant researchers.
This is one of the few social-engineering threat clusters where physical baiting tactics (mailed malicious USB devices disguised as gifts, and a fraudulent employer used to recruit unwitting or semi-complicit insiders) are tied to a fully adjudicated, government-documented criminal case rather than just vendor threat-intel writeups. It shows that "drop a USB in the parking lot" is not a hypothetical red-team exercise: a real, prolific criminal group ran it at scale via postal mail against real companies, evolving the pretext (gift card, teddy bear, COVID-19 guidance, Amazon "thank you") as awareness grew. It also shows that fraudulent "cybersecurity company" job postings can be used to recruit people into criminal hacking operations under a veneer of legitimacy, which is a durable lesson for vetting unsolicited remote-work/contracting offers. Finally, the DOJ outcomes (extradition, decade-long prison terms, multimillion-dollar restitution) provide a concrete, citable deterrence data point for a threat actor otherwise known mostly through private-sector attribution, with three of the four charged members now sentenced and one (Fedorov) still unresolved in public reporting.
DOJ/FBI and researcher guidance arising from this case: never plug in unsolicited/unknown USB devices received by mail, regardless of accompanying "gift" (gift card, teddy bear, COVID-guidance letter); treat unsolicited packages addressed to HR/IT/executive staff as suspicious and route to security before opening; disable USB autorun/HID-injection risk via endpoint controls and monitor for known malicious device VID/PID signatures (FBI published FIN7's 0x2341/0x8037 IDs); train employees to verify unexpected "vendor" emails and pretext follow-up calls out-of-band before opening attachments; vet unsolicited job/recruiting offers (like FIN7's fake "Combi Security" cybersecurity firm) through independent verification before providing skills, network access, or going to work for an unverified employer; report suspicious packages/USB devices to the FBI (evidence-preservation guidance was published in the FLASH alert). The case itself demonstrates that criminal prosecution (indictment, extradition, guilty pleas, prison sentences, restitution) is a viable, if slow, deterrent and remediation path for organized cyber-enabled fraud crews, with three of the four charged members (Hladyr, Kolpakov, Iarmak) now sentenced.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support…