Threat Intelligence

9/11/2017
03:30 PM
50%
50%

Credit Card Hacker Roman Seleznev Enters More Guilty Pleas

The Russian hacker already hit with a 27-year prison sentence for credit card hacking pleads guilty to two more charges.

Russian hacker Roman Seleznev, in two separate cases, pleaded guilty Friday to one count of participating in a racketeering enterprise and also one count of conspiracy to commit bank fraud, the Department of Justice (DOJ) announced.

The 33-year-old Seleznev, who also goes by aliases Track2, Bulba, and Ncux, is scheduled to be sentenced Dec. 11. The DOJ was not immediately available to comment on the sentence it will seek.

It could add more time to the unprecedented 27-year prison sentence he received in April for credit card hacking. In the April case, Seleznev was convicted of 38 counts of hacking into point-of-sale computers to steal credit card data.

In the two most recent cases, a federal court in Georgia is overseeing his bank fraud conspiracy case and a Nevada federal court is handling the racketeering case.

In November 2008, Seleznev worked as a "casher" when he and other hackers attacked a Georgia company, which processed credit and debit card transactions. After infiltrating the company's computer system, the group made off with 45.5 million debit card numbers and stole $9.4 million from 2,100 ATMs across the globe, the DOJ says, noting the heist job was performed in less than 12 hours.

In the second case, Seleznev pleaded guilty to one count of "participation in a racketeering enterprise." As with the earlier April case, he was found to have teamed up with the international credit card and identification theft ring Carder.su in 2009. Carder.su provides a platform for members to sell compromised credit card data and counterfeit IDs on the dark web.

Seleznev joined Carder.su just as federal authorities had become aware of his identity and had begun to track his movements on the Carder.su marketplace.

The April case hit Seleznev for hacking point-of-sale computers at more than 500 US businesses and stealing more than $169 million from their customers by posting their credit card data on dark web sites. But in the recent Nevada case, federal agents went after his relationship with Carder.su.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Seleznev engaged in high-volume sales of compromised credit card data and personal ID information to Carder.su members. He created an automated sales site that allowed Carder.su members to log in and purchase pilfered credit card data and advertised this site on Carder.su websites, according to the DOJ. Seleznev sold the compromised card account data for approximately $20 per account and the DOJ estimates victims lost at least $51 million as a result of the Carder.su ring's activities.

Seleznev shared information about Carder.su's processes and internal policies, noting the credit card crime ring required a recommendation from two members in good standing before a new member was allowed into the group. He also revealed that members communicated via email, chatrooms, private messaging systems, and virtual networks, all of which were encrypted, according to the DOJ report.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: In Russia, application hangs YOU!
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.