Case Library / Vishing (Voice Phishing) / FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)

DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr, Andrii Kolpakov, and Denys Iarmak: the authoritative government case documenting the group's fake "Combi Security" recruitment front and its later mailed-USB (BadUSB) baiting campaigns against 100+ U.S. companies.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between 2015 and 2021, FIN7 (also tracked as the Carbanak Group and Navigator Group) breached the computer networks of more than 100 U.S. companies, concentrated in the restaurant, gaming, and hospitality sectors, across 49 states and D.C., stealing more than 15 million customer payment-card records from over 6,500 point-of-sale terminals at more than 3,600 business locations. The U.S. Department of Justice, Western District of Washington, unsealed superseding indictments on August 1, 2018 against three alleged high-level members, Dmytro Fedorov, Fedir Hladyr, and Andrii Kolpakov, charging conspiracy to commit wire fraud and computer hacking; a fourth member, Denys Iarmak, was indicted separately after his 2019 arrest. The group's tradecraft blended remote cyber-intrusion (spear-phishing with malicious Word attachments, sometimes reinforced with pretext phone calls) with physical and in-person social engineering: a fake front company, "Combi Security," used to recruit hackers under the pretense of legitimate cybersecurity work, and, in a later, related campaign publicly attributed to FIN7 by the FBI, mailed BadUSB keystroke-injection devices disguised as gift cards, teddy-bear gifts, or (from 2021) fake government/Amazon mailings sent to HR, IT, and executive staff at target companies. This record treats the DOJ's criminal cases against Fedorov, Hladyr, Kolpakov, and Iarmak as the authoritative government-documented anchor for FIN7's identity and its physical baiting/USB tactics.

How the Attack Worked

FIN7 combined remote cyber intrusion with physical and in-person social-engineering tradecraft. (1) Recruitment cover: the group operated a fake cybersecurity company, "Combi Security," complete with a phony website, to publicly advertise legitimate-sounding jobs (penetration tester, developer) and recruit hackers who believed they were doing lawful security work; defendants Hladyr and Kolpakov were both recruited this way, giving the organization plausible deniability and giving lower-level members cover to deny knowingly committing crimes. (2) Core intrusion vector: spear-phishing emails to employees at target restaurant/hotel/casino chains carrying malicious Microsoft Word attachments (sometimes using pretexts like a fabricated food-poisoning complaint to a restaurant manager), frequently reinforced by a follow-up phone call from a FIN7 member posing as the sender to talk the employee into opening the attachment; once inside, operators moved laterally to point-of-sale systems to harvest card data. (3) Physical baiting/USB campaign (documented in FBI FLASH alerts starting March 2020, attributed to FIN7 by FBI and independently corroborated by Kaspersky and FireEye/Mandiant researchers via malware/infrastructure overlap): FIN7 mailed BadUSB/"Bad Beetle" USB keystroke-injection devices via USPS/UPS to employees in HR, IT, and executive roles at retail, restaurant, and hotel companies, disguised as a $50 Best Buy gift card with a USB "product list," sometimes bundled with a teddy bear; the campaign later (from August 2021) expanded to transportation, insurance, and defense-sector targets using a fake U.S. Department of Health and Human Services COVID-19 guidance letter or a decorative "thank you" gift box impersonating Amazon with a counterfeit gift card. When plugged in, the device registered as a keyboard (HID) and auto-typed a PowerShell command that downloaded the GRIFFON backdoor, leading in later intrusions to ransomware deployment (BlackMatter, REvil).

The Lure & the Tell

Lures: (1) a fabricated angry-customer/food-poisoning complaint email to a restaurant manager urging them to open an attached "report"; (2) an unsolicited package appearing to be from Best Buy containing a $50 loyalty gift card and a USB drive claimed to list eligible products; (3) a "gift" package with a teddy bear or gift card mailed to HR/IT/executive staff; (4) a fake U.S. Department of Health and Human Services letter with COVID-19 "guidance" and an enclosed USB; (5) a decorative gift box impersonating Amazon with a counterfeit thank-you gift card and USB; (6) a legitimate-looking classified job ad for "Combi Security," a real-seeming cybersecurity firm with its own website, used to recruit hackers. Tells that gave it away when caught: recipients with security training who did not plug in unsolicited USB devices and instead submitted them for analysis; the USB devices were commercially available "BadUSB"/"Bad Beetle"/LilyGO hardware (cheap, $5-$14) rather than custom silicon; devices registered anomalously as HID keyboards even when storage media was policy-restricted; and Combi Security, on inspection, had no legitimate clients and a phony web presence.

Outcome

Superseding indictments against Fedorov, Hladyr, and Kolpakov were filed July 27, 2018 and unsealed August 1, 2018 in the Western District of Washington; a fourth defendant, Denys Iarmak, was indicted separately (CR19-257RSM). Hladyr, arrested in Germany in January 2018 and extradited, pleaded guilty September 11, 2019 to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking (24 other counts were dropped), and was sentenced April 16, 2021 to 10 years in prison (including time already served) plus $2.5 million restitution. Kolpakov, arrested on vacation in Lepe, Spain on June 28, 2018 and extradited in June 2019, pleaded guilty November 16, 2020 to conspiracy to commit wire fraud and computer hacking, and was sentenced to 84 months (7 years) plus $2.5 million restitution around June 2021 (his lawyer argued he was unwittingly "backed into a corner" after answering the Combi Security job ad and was paid only about $75,000). Iarmak, arrested in Bangkok, Thailand in November 2019 at the request of U.S. investigators and extradited to U.S. custody in 2020, pleaded guilty November 22, 2021 to conspiracy to commit wire fraud and conspiracy to commit computer hacking (having originally faced 27 counts and a potential life sentence); he was sentenced April 7, 2022 in Seattle by U.S. District Judge Ricardo S. Martinez to 5 years in federal prison, becoming the third FIN7 member sentenced in the U.S. after Hladyr (10 years) and Kolpakov (7 years); his defense cited time served in a Thailand prison and a COVID-19 infection while in BOP custody. Fedorov, arrested in Bielsko-Biala, Poland in early 2018, had a far longer public docket showing trial continuances into 2022, but no plea agreement or sentencing announcement specific to Fedorov was located during this review; the November 22, 2021 change-of-plea and February/April 2022 sentencing entries that had previously been associated with his case in this record actually belong to the separate Iarmak docket (CR19-257RSM), not Fedorov's (CR18-004RSM). Fedorov's case outcome should therefore be treated as unconfirmed/open pending direct review of the WDWA docket or a DOJ press release naming him specifically. Separately, FBI FLASH alerts (from March 2020, updated through 2021-2022) formally attributed the mailed-USB "BadUSB" baiting campaign to FIN7, based on malware (GRIFFON) and infrastructure overlap independently corroborated by Kaspersky and FireEye/Mandiant researchers.

Why It Matters

This is one of the few social-engineering threat clusters where physical baiting tactics (mailed malicious USB devices disguised as gifts, and a fraudulent employer used to recruit unwitting or semi-complicit insiders) are tied to a fully adjudicated, government-documented criminal case rather than just vendor threat-intel writeups. It shows that "drop a USB in the parking lot" is not a hypothetical red-team exercise: a real, prolific criminal group ran it at scale via postal mail against real companies, evolving the pretext (gift card, teddy bear, COVID-19 guidance, Amazon "thank you") as awareness grew. It also shows that fraudulent "cybersecurity company" job postings can be used to recruit people into criminal hacking operations under a veneer of legitimacy, which is a durable lesson for vetting unsolicited remote-work/contracting offers. Finally, the DOJ outcomes (extradition, decade-long prison terms, multimillion-dollar restitution) provide a concrete, citable deterrence data point for a threat actor otherwise known mostly through private-sector attribution, with three of the four charged members now sentenced and one (Fedorov) still unresolved in public reporting.

Defenses

DOJ/FBI and researcher guidance arising from this case: never plug in unsolicited/unknown USB devices received by mail, regardless of accompanying "gift" (gift card, teddy bear, COVID-guidance letter); treat unsolicited packages addressed to HR/IT/executive staff as suspicious and route to security before opening; disable USB autorun/HID-injection risk via endpoint controls and monitor for known malicious device VID/PID signatures (FBI published FIN7's 0x2341/0x8037 IDs); train employees to verify unexpected "vendor" emails and pretext follow-up calls out-of-band before opening attachments; vet unsolicited job/recruiting offers (like FIN7's fake "Combi Security" cybersecurity firm) through independent verification before providing skills, network access, or going to work for an unverified employer; report suspicious packages/USB devices to the FBI (evidence-preservation guidance was published in the FLASH alert). The case itself demonstrates that criminal prosecution (indictment, extradition, guilty pleas, prison sentences, restitution) is a viable, if slow, deterrent and remediation path for organized cyber-enabled fraud crews, with three of the four charged members (Hladyr, Kolpakov, Iarmak) now sentenced.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: FIN7 members, per DOJ court filings, identified restaurant, hotel, and casino chains as targets, likely researching corporate structure and staff roles (front-desk, HR, IT, executive) well enough to craft plausible, industry-specific pretexts, such as a hotel reservation inquiry or a restaurant complaint.
Countering Stage 1: Public information about which companies operate large point-of-sale fleets and staff directories is broadly available and hard to suppress; the realistic control is downstream, hardening the point-of-sale and email environment against the pretexts this reconnaissance enables, rather than trying to hide business structure.
2
Front-company cover for recruitment: the group registered and operated a fake cybersecurity firm, "Combi Security," with its own website and job postings, to recruit hackers and administrators (including Hladyr and Kolpakov) who believed they were taking legitimate penetration-testing or IT jobs, giving the organization a layer of plausible deniability.
Countering Stage 2: Vetting unsolicited job or contracting offers (verifying a company's legitimate clients, business registration, and independent reputation before doing technical work for it, especially remote security/IT work) is the direct countermeasure to a fraudulent front-company recruiter like Combi Security.
3
Spear-phishing weaponization: operators crafted Microsoft Word attachments carrying malware (an adapted Carbanak backdoor and later GRIFFON), embedded in emails tailored to the target's industry, such as a fabricated food-poisoning complaint to a restaurant manager or a reservation request to a hotel.
Countering Stage 3: Email attachment sandboxing, macro-disabling by default for Word documents from external senders, and endpoint detection tuned to known Carbanak/GRIFFON indicators reduce the odds a weaponized attachment executes even if opened.
4
Pretext delivery and vishing follow-up: phishing emails were sent to targeted employees, frequently followed by a phone call from a FIN7 member posing as the sender to legitimize the email and pressure the recipient into opening the attachment.
Countering Stage 4: Training staff to verify unexpected "vendor," reservation, or complaint emails through an out-of-band channel (calling the company's listed number rather than one provided in the email or the follow-up call) breaks the phishing-plus-vishing combination FIN7 relied on.
5
Initial access and lateral movement: once the malicious attachment was opened, the malware gave FIN7 remote access to the victim network; operators then moved laterally, per DOJ and FBI accounts, seeking administrative privileges and point-of-sale systems.
Countering Stage 5: Network segmentation isolating point-of-sale systems from general corporate IT, plus least-privilege access controls and monitoring for lateral movement, limits how far an initial foothold can spread even after a successful phish.
6
Physical baiting/USB campaign as a parallel access vector: in a later, related campaign the FBI attributed to FIN7, the group mailed BadUSB/"Bad Beetle" keystroke-injection devices via USPS/UPS, packaged as Best Buy or Amazon gift cards, teddy-bear gifts, or a fake HHS COVID-19 guidance letter, targeted at HR, IT, and executive staff who were plausibly seen as likely to open unsolicited mail and plug in an included device.
Countering Stage 6: A blanket policy of never plugging in unsolicited or mailed USB devices, regardless of an accompanying gift card or official-looking letter, and instead routing suspicious packages to security for inspection, directly defeats the BadUSB baiting vector.
7
Payload execution and payment-card data exfiltration: whether via phishing malware or a plugged-in BadUSB device (which registered as a keyboard and auto-typed a PowerShell command), the payload gave FIN7 a foothold from which it harvested payment-card data from point-of-sale terminals, and in later intrusions escalated to deploying ransomware (BlackMatter, REvil) for extortion.
Countering Stage 7: Endpoint controls that block or alert on USB devices registering as unexpected HID keyboards, combined with monitoring for the specific VID/PID signatures the FBI published (0x2341/0x8037), catch the keystroke-injection payload at the moment of execution.
8
Monetization and payout: stolen card data was aggregated (per Hladyr's role managing shared FIN7 file repositories) and sold on underground marketplaces such as Joker's Stash, completing the objective of financial gain from over 15 million stolen card records.
Countering Stage 8: Payment-card tokenization/point-to-point encryption at the point-of-sale layer limits the value of any data FIN7 manages to exfiltrate, and, as this case shows, sustained law-enforcement investigation, extradition, and prosecution provide a slower but real deterrent and disruption path against the monetization network itself.
Quick Facts
Victim
100+ U.S. companies, predominantly restaurant, gaming/casino, and hospitality chains; publicly named victims include Chipotle Mexican Grill, Chili's, Arby's, Jason's Deli, Red Robin, and Emerald Queen Casino; a later, related mailed-USB campaign attributed to FIN7 targeted retail, restaurant, and hotel companies (2020) and expanded to transportation, insurance, and defense-sector companies (2021)
Location
United States (nationwide breach footprint across 49 states plus D.C.); defendants apprehended abroad, Hladyr in Dresden, Germany, Fedorov in Bielsko-Biala, Poland, Kolpakov in Lepe, Spain, Iarmak in Bangkok, Thailand, and prosecuted in U.S. District Court for the Western District of Washington, Seattle
Date
2015-2021 (intrusion campaign); superseding indictments filed July 27, 2018, unsealed August 1, 2018; Hladyr arrested Jan. 2018 (Germany), pleaded guilty Sept. 11, 2019, sentenced April 16, 2021; Kolpakov arrested June 28, 2018 (Spain), pleaded guilty Nov. 16, 2020, sentenced ~June 24-25, 2021; Fedorov arrested early 2018 (Poland) and, per the last clear reporting located for this record, remained in Polish custody pending extradition with no confirmed plea or sentencing outcome identified; his case status is unconfirmed, not scheduled dates as previously stated; Iarmak (indicted separately as a fourth defendant, CR19-257RSM) arrested Nov. 2019 in Bangkok, Thailand, extradited to U.S. custody in 2020, pleaded guilty Nov. 22, 2021 to conspiracy to commit wire fraud and conspiracy to commit computer hacking, sentenced April 7, 2022 in Seattle to 5 years in federal prison; related FBI USB-campaign advisories issued March 2020 and updated through late 2021/2022
Impact
DOJ plea agreements (e.g., Hladyr's, Sept. 2019) stipulate FIN7 activity caused "more than $100 million in losses" tied to theft of roughly 15 million payment card records; prosecutors and security researchers have cited broader cumulative damage estimates as high as $1 billion when combined with the group's earlier Carbanak bank-targeting operations (AP News reported over 20 million card records and an estimated $1 billion in losses in its coverage of Iarmak's April 2022 sentencing). Courts ordered $2.5 million in restitution against both Hladyr and Kolpakov (each ordered jointly/severally liable up to that amount, distributed to victims). These are DOJ/plea-agreement and press figures, not a single independently audited total loss for the entire 100+-victim campaign.
Status
Confirmed
Case Type
Real-World Incident
Sector
Defense & Aerospace, Financial Services & Insurance, Hospitality, Gaming & Travel, Retail & E-commerce, Transportation & Logistics
Threat Actor
Organized Crime
Related

Related Cases

UIUC USB Drive Drop Field Experiment (2015)

Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…

Incident 2015Read →

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…

Incident 2016Read →

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support…

Incident 2014Read →