Threat Intelligence
9/11/2017
03:30 PM
50%
50%

Credit Card Hacker Roman Seleznev Enters More Guilty Pleas

The Russian hacker already hit with a 27-year prison sentence for credit card hacking pleads guilty to two more charges.

Russian hacker Roman Seleznev, in two separate cases, pleaded guilty Friday to one count of participating in a racketeering enterprise and also one count of conspiracy to commit bank fraud, the Department of Justice (DOJ) announced.

The 33-year-old Seleznev, who also goes by aliases Track2, Bulba, and Ncux, is scheduled to be sentenced Dec. 11. The DOJ was not immediately available to comment on the sentence it will seek.

It could add more time to the unprecedented 27-year prison sentence he received in April for credit card hacking. In the April case, Seleznev was convicted of 38 counts of hacking into point-of-sale computers to steal credit card data.

In the two most recent cases, a federal court in Georgia is overseeing his bank fraud conspiracy case and a Nevada federal court is handling the racketeering case.

In November 2008, Seleznev worked as a "casher" when he and other hackers attacked a Georgia company, which processed credit and debit card transactions. After infiltrating the company's computer system, the group made off with 45.5 million debit card numbers and stole $9.4 million from 2,100 ATMs across the globe, the DOJ says, noting the heist job was performed in less than 12 hours.

In the second case, Seleznev pleaded guilty to one count of "participation in a racketeering enterprise." As with the earlier April case, he was found to have teamed up with the international credit card and identification theft ring Carder.su in 2009. Carder.su provides a platform for members to sell compromised credit card data and counterfeit IDs on the dark web.

Seleznev joined Carder.su just as federal authorities had become aware of his identity and had begun to track his movements on the Carder.su marketplace.

The April case hit Seleznev for hacking point-of-sale computers at more than 500 US businesses and stealing more than $169 million from their customers by posting their credit card data on dark web sites. But in the recent Nevada case, federal agents went after his relationship with Carder.su.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Seleznev engaged in high-volume sales of compromised credit card data and personal ID information to Carder.su members. He created an automated sales site that allowed Carder.su members to log in and purchase pilfered credit card data and advertised this site on Carder.su websites, according to the DOJ. Seleznev sold the compromised card account data for approximately $20 per account and the DOJ estimates victims lost at least $51 million as a result of the Carder.su ring's activities.

Seleznev shared information about Carder.su's processes and internal policies, noting the credit card crime ring required a recommendation from two members in good standing before a new member was allowed into the group. He also revealed that members communicated via email, chatrooms, private messaging systems, and virtual networks, all of which were encrypted, according to the DOJ report.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Cybersecurity's 'Broken' Hiring Process
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/11/2017
How Systematic Lying Can Improve Your Security
Lance Cottrell, Chief Scientist, Ntrepid,  10/11/2017
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO Advisor,  10/12/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.