{
  "id": "case-seleznev-point-of-sale",
  "slug": "us-v-seleznev-track2",
  "title": "U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)",
  "summary": "Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
  "case_number": "2:11-cr-00070",
  "court": "U.S. District Court for the Western District of Washington",
  "district": "W.D. Wash.",
  "country": "United States",
  "opened_at": "2011-03-03",
  "status": "sentenced",
  "victim_sector": "Retail, Hospitality, Small Business",
  "victim_country": "United States",
  "loss_amount_usd": 169000000,
  "loss_amount_note": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions.",
  "first_seen_at": "2009-10-01T00:00:00Z",
  "last_updated_at": "2026-09-08T15:00:00Z",
  "actor_slug": "track2",
  "defendant_slugs": [
    "roman-seleznev"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1046",
      "evidence_excerpt": "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.",
      "evidence_locator": "Trial Transcript Day 4, Page 82",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record: U.S. v. Seleznev",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
      "technique_name": "Network Service Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1110",
      "evidence_excerpt": "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.",
      "evidence_locator": "Trial Transcript Day 5, Page 112",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
      "technique_name": "Brute Force",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.",
      "evidence_locator": "Trial Exhibit 14-A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Government Trial Exhibit",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1588.002",
      "evidence_excerpt": "Seleznev purchased specialized memory scraping tools and POS card harvesting scripts from Russian underground forums.",
      "evidence_locator": "Trial Transcript Day 6, Page 140",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Trial Record",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/prolific-russian-cyber-criminal-sentenced-27-years-prison-massive-scheme-hack-and-steal",
      "technique_name": "Obtain Tool",
      "tactic": "Resource Development"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2014-07-05",
      "description": "Seleznev arrested by U.S. Secret Service in the Maldives with a laptop containing 1.7 million stolen credit cards."
    },
    {
      "event_type": "verdict",
      "event_date": "2016-08-25",
      "description": "Jury finds Seleznev guilty of 38 federal felony counts including wire fraud and computer hacking."
    },
    {
      "event_type": "sentencing",
      "event_date": "2017-04-21",
      "description": "Sentenced to 324 months (27 years) in federal prison, the longest computer hacking sentence in U.S. history at the time, and ordered to pay $169,879,276 restitution."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Retail, Hospitality, Small Business networks. Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.",
    "blast_radius": "Caused verified financial fraud losses of $169 million to 3,700 financial institutions. Impacted Retail, Hospitality, Small Business infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems.",
        "technical_artifacts": [
          "T1110",
          "Brute Force"
        ],
        "mitre_technique_id": "T1110"
      },
      {
        "phase": "Phase 2: Discovery",
        "title": "Internal Subnet & Trust Reconnaissance",
        "description": "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389.",
        "technical_artifacts": [
          "T1046",
          "Network Service Discovery"
        ],
        "mitre_technique_id": "T1046"
      },
      {
        "phase": "Phase 3: Exfiltration",
        "title": "Encrypted Cloud Data Exfiltration",
        "description": "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops.",
        "technical_artifacts": [
          "T1041",
          "Exfiltration Over C2 Channel"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}