U.S. v. Denis Gennadievich Kulkov (Try2Check Card Checking Service)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Eastern District of New York.
- Primary Target Sector: Financial Services, Payment Networks.
- Documented Financial Loss: $18.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Payment Networks networks. Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.
Operational & Financial Fallout
Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service. Impacted Financial Services, Payment Networks infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Financial Services, Payment Networks networks. Creator of Try2Check, the preeminent criminal card-checking platform that processed tens of millions of card verification requests annually for cybercriminals buying stolen credit cards.
Adversary Kill Chain Flow
1 Documented PhasesTry2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins.
Earned over $18 million in Bitcoin fees running the unauthorized credit card verification service. Impacted Financial Services, Payment Networks infrastructure and associated victim operations.
Procedural & Incident Timeline
Federal indictment unsealed charging Kulkov with access device fraud, computer intrusion, and money laundering; Try2Check domains seized in coordination with Austrian and German authorities.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Denis Gennadievich Kulkov | Russian Federation | fugitive | Pending | None | Creator of Try2Check stolen card verification service; indicted in E.D.N.Y. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Try2Check executed automated test transactions against merchant payment gateway APIs using stolen account logins." | Indictment ¶ 14, Page 7 | reviewed |