DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Social Engineering Examples·16 sources
Between 2015 and 2021, FIN7 (also tracked as the Carbanak Group and Navigator Group) breached the computer networks of more than 100 U.S. companies, concentrated in the restaurant, gaming, and hospitality sectors, across 49 states and D.C., stealing more than 15 million customer payment-card records from over 6,500 point-of-sale terminals at more than 3,600 business locations.
The U.S. Department of Justice, Western District of Washington, unsealed superseding indictments on August 1, 2018 against three alleged high-level members, Dmytro Fedorov, Fedir Hladyr, and Andrii Kolpakov, charging conspiracy to commit wire fraud and computer hacking; a fourth member, Denys Iarmak, was indicted separately after his 2019 arrest. The group's tradecraft blended remote cyber-intrusion (spear-phishing with malicious Word attachments, sometimes reinforced with pretext phone calls) with physical and in-person social engineering: a fake front company, "Combi Security," used to recruit hackers under the pretense of legitimate cybersecurity work, and, in a later, related campaign publicly attributed to FIN7 by the FBI, mailed BadUSB keystroke-injection devices disguised as gift cards, teddy-bear gifts, or (from 2021) fake government/Amazon mailings sent to HR, IT, and executive staff at target companies.
This record treats the DOJ's criminal cases against Fedorov, Hladyr, Kolpakov, and Iarmak as the authoritative government-documented anchor for FIN7's identity and its physical baiting/USB tactics.
FIN7 combined remote cyber intrusion with physical and in-person social-engineering tradecraft. (1) Recruitment cover: the group operated a fake cybersecurity company, "Combi Security," complete with a phony website, to publicly advertise legitimate-sounding jobs (penetration tester, developer) and recruit hackers who believed they were doing lawful security work; defendants Hladyr and Kolpakov were both recruited this way, giving the organization plausible deniability and giving lower-level members cover to deny knowingly committing crimes. (2) Core intrusion vector: spear-phishing emails to employees at target restaurant/hotel/casino chains carrying malicious Microsoft Word attachments (sometimes using pretexts like a fabricated food-poisoning complaint to a restaurant manager), frequently reinforced by a follow-up phone call from a FIN7 member posing as the sender to talk the employee into opening the attachment; once inside, operators moved laterally to point-of-sale systems to harvest card data. (3) Physical baiting/USB campaign (documented in FBI FLASH alerts starting March 2020, attributed to FIN7 by FBI and independently corroborated by Kaspersky and FireEye/Mandiant researchers via malware/infrastructure overlap): FIN7 mailed BadUSB/"Bad Beetle" USB keystroke-injection devices via USPS/UPS to employees in HR, IT, and executive roles at retail, restaurant, and hotel companies, disguised as a $50 Best Buy gift card with a USB "product list," sometimes bundled with a teddy bear; the campaign later (from August 2021) expanded to transportation, insurance, and defense-sector targets using a fake U.S. Department of Health and Human Services COVID-19 guidance letter or a decorative "thank you" gift box impersonating Amazon with a counterfeit gift card.
When plugged in, the device registered as a keyboard (HID) and auto-typed a PowerShell command that downloaded the GRIFFON backdoor, leading in later intrusions to ransomware deployment (BlackMatter, REvil).
Lures: (1) a fabricated angry-customer/food-poisoning complaint email to a restaurant manager urging them to open an attached "report"; (2) an unsolicited package appearing to be from Best Buy containing a $50 loyalty gift card and a USB drive claimed to list eligible products; (3) a "gift" package with a teddy bear or gift card mailed to HR/IT/executive staff; (4) a fake U.S. Department of Health and Human Services letter with COVID-19 "guidance" and an enclosed USB; (5) a decorative gift box impersonating Amazon with a counterfeit thank-you gift card and USB; (6) a legitimate-looking classified job ad for "Combi Security," a real-seeming cybersecurity firm with its own website, used to recruit hackers.
Tells that gave it away when caught: recipients with security training who did not plug in unsolicited USB devices and instead submitted them for analysis; the USB devices were commercially available "BadUSB"/"Bad Beetle"/LilyGO hardware (cheap, $5-$14) rather than custom silicon; devices registered anomalously as HID keyboards even when storage media was policy-restricted; and Combi Security, on inspection, had no legitimate clients and a phony web presence.
Superseding indictments against Fedorov, Hladyr, and Kolpakov were filed July 27, 2018 and unsealed August 1, 2018 in the Western District of Washington; a fourth defendant, Denys Iarmak, was indicted separately (CR19-257RSM). Hladyr, arrested in Germany in January 2018 and extradited, pleaded guilty September 11, 2019 to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking (24 other counts were dropped), and was sentenced April 16, 2021 to 10 years in prison (including time already served) plus $2.5 million restitution.
Kolpakov, arrested on vacation in Lepe, Spain on June 28, 2018 and extradited in June 2019, pleaded guilty November 16, 2020 to conspiracy to commit wire fraud and computer hacking, and was sentenced to 84 months (7 years) plus $2.5 million restitution around June 2021 (his lawyer argued he was unwittingly "backed into a corner" after answering the Combi Security job ad and was paid only about $75,000).
Iarmak, arrested in Bangkok, Thailand in November 2019 at the request of U.S. investigators and extradited to U.S. custody in 2020, pleaded guilty November 22, 2021 to conspiracy to commit wire fraud and conspiracy to commit computer hacking (having originally faced 27 counts and a potential life sentence); he was sentenced April 7, 2022 in Seattle by U.S. District Judge Ricardo S. Martinez to 5 years in federal prison, becoming the third FIN7 member sentenced in the U.S. after Hladyr (10 years) and Kolpakov (7 years); his defense cited time served in a Thailand prison and a COVID-19 infection while in BOP custody.
Fedorov, arrested in Bielsko-Biala, Poland in early 2018, had a far longer public docket showing trial continuances into 2022, but no plea agreement or sentencing announcement specific to Fedorov was located during this review; the November 22, 2021 change-of-plea and February/April 2022 sentencing entries that had previously been associated with his case in this record actually belong to the separate Iarmak docket (CR19-257RSM), not Fedorov's (CR18-004RSM).
Fedorov's case outcome should therefore be treated as unconfirmed/open pending direct review of the WDWA docket or a DOJ press release naming him specifically. Separately, FBI FLASH alerts (from March 2020, updated through 2021-2022) formally attributed the mailed-USB "BadUSB" baiting campaign to FIN7, based on malware (GRIFFON) and infrastructure overlap independently corroborated by Kaspersky and FireEye/Mandiant researchers.
This is one of the few social-engineering threat clusters where physical baiting tactics (mailed malicious USB devices disguised as gifts, and a fraudulent employer used to recruit unwitting or semi-complicit insiders) are tied to a fully adjudicated, government-documented criminal case rather than just vendor threat-intel writeups. It shows that "drop a USB in the parking lot" is not a hypothetical red-team exercise: a real, prolific criminal group ran it at scale via postal mail against real companies, evolving the pretext (gift card, teddy bear, COVID-19 guidance, Amazon "thank you") as awareness grew.
It also shows that fraudulent "cybersecurity company" job postings can be used to recruit people into criminal hacking operations under a veneer of legitimacy, which is a durable lesson for vetting unsolicited remote-work/contracting offers. Finally, the DOJ outcomes (extradition, decade-long prison terms, multimillion-dollar restitution) provide a concrete, citable deterrence data point for a threat actor otherwise known mostly through private-sector attribution, with three of the four charged members now sentenced and one (Fedorov) still unresolved in public reporting.
DOJ/FBI and researcher guidance arising from this case: never plug in unsolicited/unknown USB devices received by mail, regardless of accompanying "gift" (gift card, teddy bear, COVID-guidance letter); treat unsolicited packages addressed to HR/IT/executive staff as suspicious and route to security before opening; disable USB autorun/HID-injection risk via endpoint controls and monitor for known malicious device VID/PID signatures (FBI published FIN7's 0x2341/0x8037 IDs); train employees to verify unexpected "vendor" emails and pretext follow-up calls out-of-band before opening attachments; vet unsolicited job/recruiting offers (like FIN7's fake "Combi Security" cybersecurity firm) through independent verification before providing skills, network access, or going to work for an unverified employer; report suspicious packages/USB devices to the FBI (evidence-preservation guidance was published in the FLASH alert).
The case itself demonstrates that criminal prosecution (indictment, extradition, guilty pleas, prison sentences, restitution) is a viable, if slow, deterrent and remediation path for organized cyber-enabled fraud crews, with three of the four charged members (Hladyr, Kolpakov, Iarmak) now sentenced.
Social Engineering Examples. “FIN7 (Carbanak Group) DOJ Prosecutions: Fedorov, Hladyr, Kolpakov, and Iarmak (2018-2022)”. Accessed 19 September 2026. https://socialengineeringexamples.com/fin7-carbanak-doj-prosecution-2018-2021
FIN7 members, per DOJ court filings, identified restaurant, hotel, and casino chains as targets, likely researching corporate structure and staff roles (front-desk, HR, IT, executive) well enough to craft plausible, industry-specific pretexts, such as a hotel reservation inquiry or a restaurant complaint.
Public information about which companies operate large point-of-sale fleets and staff directories is broadly available and hard to suppress; the realistic control is downstream, hardening the point-of-sale and email environment against the pretexts this reconnaissance enables, rather than trying to hide business structure.
the group registered and operated a fake cybersecurity firm, "Combi Security," with its own website and job postings, to recruit hackers and administrators (including Hladyr and Kolpakov) who believed they were taking legitimate penetration-testing or IT jobs, giving the organization a layer of plausible deniability.
Vetting unsolicited job or contracting offers (verifying a company's legitimate clients, business registration, and independent reputation before doing technical work for it, especially remote security/IT work) is the direct countermeasure to a fraudulent front-company recruiter like Combi Security.
operators crafted Microsoft Word attachments carrying malware (an adapted Carbanak backdoor and later GRIFFON), embedded in emails tailored to the target's industry, such as a fabricated food-poisoning complaint to a restaurant manager or a reservation request to a hotel.
Email attachment sandboxing, macro-disabling by default for Word documents from external senders, and endpoint detection tuned to known Carbanak/GRIFFON indicators reduce the odds a weaponized attachment executes even if opened.
phishing emails were sent to targeted employees, frequently followed by a phone call from a FIN7 member posing as the sender to legitimize the email and pressure the recipient into opening the attachment.
Training staff to verify unexpected "vendor," reservation, or complaint emails through an out-of-band channel (calling the company's listed number rather than one provided in the email or the follow-up call) breaks the phishing-plus-vishing combination FIN7 relied on.
once the malicious attachment was opened, the malware gave FIN7 remote access to the victim network; operators then moved laterally, per DOJ and FBI accounts, seeking administrative privileges and point-of-sale systems.
Network segmentation isolating point-of-sale systems from general corporate IT, plus least-privilege access controls and monitoring for lateral movement, limits how far an initial foothold can spread even after a successful phish.
in a later, related campaign the FBI attributed to FIN7, the group mailed BadUSB/"Bad Beetle" keystroke-injection devices via USPS/UPS, packaged as Best Buy or Amazon gift cards, teddy-bear gifts, or a fake HHS COVID-19 guidance letter, targeted at HR, IT, and executive staff who were plausibly seen as likely to open unsolicited mail and plug in an included device.
A blanket policy of never plugging in unsolicited or mailed USB devices, regardless of an accompanying gift card or official-looking letter, and instead routing suspicious packages to security for inspection, directly defeats the BadUSB baiting vector.
whether via phishing malware or a plugged-in BadUSB device (which registered as a keyboard and auto-typed a PowerShell command), the payload gave FIN7 a foothold from which it harvested payment-card data from point-of-sale terminals, and in later intrusions escalated to deploying ransomware (BlackMatter, REvil) for extortion.
Endpoint controls that block or alert on USB devices registering as unexpected HID keyboards, combined with monitoring for the specific VID/PID signatures the FBI published (0x2341/0x8037), catch the keystroke-injection payload at the moment of execution.
stolen card data was aggregated (per Hladyr's role managing shared FIN7 file repositories) and sold on underground marketplaces such as Joker's Stash, completing the objective of financial gain from over 15 million stolen card records.
Payment-card tokenization/point-to-point encryption at the point-of-sale layer limits the value of any data FIN7 manages to exfiltrate, and, as this case shows, sustained law-enforcement investigation, extradition, and prosecution provide a slower but real deterrent and disruption path against the monetization network itself.
Browse by what this case has in common with others in the library.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A Mattel finance executive wired $3M to China on a forged email from her brand-new CEO.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.