Threat Intelligence

9/11/2017
03:30 PM
50%
50%

Credit Card Hacker Roman Seleznev Enters More Guilty Pleas

The Russian hacker already hit with a 27-year prison sentence for credit card hacking pleads guilty to two more charges.

Russian hacker Roman Seleznev, in two separate cases, pleaded guilty Friday to one count of participating in a racketeering enterprise and also one count of conspiracy to commit bank fraud, the Department of Justice (DOJ) announced.

The 33-year-old Seleznev, who also goes by aliases Track2, Bulba, and Ncux, is scheduled to be sentenced Dec. 11. The DOJ was not immediately available to comment on the sentence it will seek.

It could add more time to the unprecedented 27-year prison sentence he received in April for credit card hacking. In the April case, Seleznev was convicted of 38 counts of hacking into point-of-sale computers to steal credit card data.

In the two most recent cases, a federal court in Georgia is overseeing his bank fraud conspiracy case and a Nevada federal court is handling the racketeering case.

In November 2008, Seleznev worked as a "casher" when he and other hackers attacked a Georgia company, which processed credit and debit card transactions. After infiltrating the company's computer system, the group made off with 45.5 million debit card numbers and stole $9.4 million from 2,100 ATMs across the globe, the DOJ says, noting the heist job was performed in less than 12 hours.

In the second case, Seleznev pleaded guilty to one count of "participation in a racketeering enterprise." As with the earlier April case, he was found to have teamed up with the international credit card and identification theft ring Carder.su in 2009. Carder.su provides a platform for members to sell compromised credit card data and counterfeit IDs on the dark web.

Seleznev joined Carder.su just as federal authorities had become aware of his identity and had begun to track his movements on the Carder.su marketplace.

The April case hit Seleznev for hacking point-of-sale computers at more than 500 US businesses and stealing more than $169 million from their customers by posting their credit card data on dark web sites. But in the recent Nevada case, federal agents went after his relationship with Carder.su.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Seleznev engaged in high-volume sales of compromised credit card data and personal ID information to Carder.su members. He created an automated sales site that allowed Carder.su members to log in and purchase pilfered credit card data and advertised this site on Carder.su websites, according to the DOJ. Seleznev sold the compromised card account data for approximately $20 per account and the DOJ estimates victims lost at least $51 million as a result of the Carder.su ring's activities.

Seleznev shared information about Carder.su's processes and internal policies, noting the credit card crime ring required a recommendation from two members in good standing before a new member was allowed into the group. He also revealed that members communicated via email, chatrooms, private messaging systems, and virtual networks, all of which were encrypted, according to the DOJ report.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17208
PUBLISHED: 2018-09-19
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell me...
CVE-2018-17205
PUBLISHED: 2018-09-19
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not ex...
CVE-2018-17206
PUBLISHED: 2018-09-19
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVE-2018-17207
PUBLISHED: 2018-09-19
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.
CVE-2017-2855
PUBLISHED: 2018-09-19
An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully compromise the device by creating a rogue HT...