CASE DOSSIER sentenced

U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)

Docket: 2:18-cr-00067 Court: U.S. District Court for the Western District of Washington Opened: 2018-03-27 Sector: Hospitality, Food Services, Retail

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$1.0 billion
Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli.
Techniques
7
Verified mappings
Defendants
3
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Western District of Washington.
  • Primary Target Sector: Hospitality, Food Services, Retail.
  • Documented Financial Loss: $1.0 billion.
  • 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.

Operational & Financial Fallout

Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Attachment. FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.

Adversary Kill Chain Flow

5 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.001 →

FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints.

Artifacts & Tooling: T1566.001 Spearphishing Attachment
2
Phase 2: Execution Host Execution & Payload Staging
MITRE ATT&CK T1059.001 →

Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite.

Artifacts & Tooling: T1059.001 PowerShell
3
Phase 3: Credential Access Credential Harvesting & Memory Dumping
MITRE ATT&CK T1056.001 →

Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions.

Artifacts & Tooling: T1056.001 Keylogging
4
Phase 4: Collection Target Data Harvesting & Archiving
MITRE ATT&CK T1113 →

Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time.

Artifacts & Tooling: T1113 Screen Capture
5
Phase 5: Exfiltration Encrypted Cloud Data Exfiltration
MITRE ATT&CK T1041 →

Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers.

Artifacts & Tooling: T1041 Exfiltration Over C2 Channel
Real-World Blast Radius & Operational Fallout

Stole over 20 million credit and debit card records, causing financial losses estimated between $1 billion and $3 billion across Chipotle, Red Robin, Arby's, and Jason's Deli. Impacted Hospitality, Food Services, Retail infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2018-01-20 arrest

Fedir Hladyr arrested in Dresden, Germany, and extradited to the Western District of Washington.

2019-09-11 plea

Hladyr pleads guilty to conspiracy to commit wire fraud and computer hacking.

2021-04-16 sentencing

Hladyr sentenced to 120 months (10 years) in federal prison and ordered to pay $2.5 million in restitution.

2021-06-24 sentencing

Kolpakov sentenced to 84 months (7 years) in federal prison and ordered to pay $2.5 million in restitution.

2022-04-07 sentencing

Iarmak sentenced to 60 months (5 years) in federal prison after pleading guilty.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Fedir Hladyr Ukraine sentenced 120 mo None FIN7 systems administrator sentenced to 10 years in federal prison.
Andrii Kolpakov Ukraine sentenced 84 mo None FIN7 pen-testing manager sentenced to 7 years in federal prison.
Denys Iarmak Ukraine sentenced 60 mo None FIN7 penetration tester sentenced to 5 years in federal prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints." Indictment ¶ 14, Page 8 reviewed
T1059.001 PowerShell
Execution
"Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite." Indictment ¶ 16, Page 9 reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers." Plea Agreement ¶ 8 reviewed
T1056.001 Keylogging
Credential Access
"Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions." Indictment ¶ 22, Page 12 reviewed
T1113 Screen Capture
Collection
"Defendants configured video screen-recording modules to capture point-of-sale terminal transactions in real time." Indictment ¶ 25, Page 14 reviewed
T1074.001 Local Data Staging
Collection
"Stolen credit card tracks were staged in hidden directories under AppData\Local\Temp prior to scheduled exfiltration batches." Trial Exhibit 8-C reviewed
T1020 Automated Exfiltration
Exfiltration
"Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops." Plea Agreement ¶ 9, Page 6 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate), No. 2:18-cr-00067 (U.S. District Court for the Western District of Washington 2018), https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-hladyr-fin7-carbanak" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>