Combi Security: the cybercrime gang that ran a fake security company
One of the most damaging card-theft gangs in US history ran what looked like a legitimate cybersecurity company, complete with a website and job openings, but with no real customers.[2][3] This case file covers how the FIN7 group used that front, how it stole more than 15 million payment card records, and the one control that would have exposed it.
What happened
From at least 2015, a group known as FIN7 broke into the computer networks of more than 100 US companies, many of them restaurant chains, hotels and retailers. Its targets were the card terminals at checkout. Federal prosecutors said the group breached more than 6,500 point-of-sale terminals at more than 3,600 business locations in 47 states and Washington, D.C., and took more than 15 million customer card records.[3][4] Chains named as victims in the case included Chipotle, Chili's, Arby's, Red Robin and Jason's Deli.[1][2]
To recruit staff and look respectable, the group set up Combi Security, a company that claimed offices in Russia and Israel and presented itself as a penetration-testing firm, meaning a business companies hire to test their own defenses.[3] The US Attorney's office later called it a fake cybersecurity company with a phony website and no legitimate customers.[2]
In January 2018, a Ukrainian national named Fedir Hladyr, the group's systems administrator, was arrested in Dresden, Germany. Two other alleged senior members were arrested in Poland and Spain in 2018.[1][3] The stolen card data had been sold on criminal marketplaces online.[3]
How it worked
The front company did two jobs. For recruits, it made criminal work look like an ordinary tech job: people could be hired to do what sounded like authorized security testing. For the outside world, it gave the operation a legitimate-looking name and web presence.[2][4] Hladyr himself joined the group through Combi Security, according to prosecutors.[2]
The break-ins started with email. Staff at a restaurant or hotel would receive an email made to look like ordinary business correspondence, with a file attached. The group often followed up with a phone call to the same employee, urging them to open it. Opening the file installed malware that let the group into the network and, eventually, onto the card terminals.[3][4]
Hladyr's job, prosecutors said, was to keep the group's server network running, collect the stolen card data, manage its communication channels and supervise other members.[1][2]
What it cost
Hladyr was extradited to Seattle in 2018 and pleaded guilty in September 2019 to conspiracy to commit wire fraud and conspiracy to commit computer hacking.[1][2] On April 16, 2021, he was sentenced to 10 years in federal prison and ordered to pay $2.5 million in restitution. He told the court he regretted his involvement with Combi Security.[1][2]
The US Attorney's office estimated that the group's overall losses to banks, merchants, card companies and consumers exceeded $3 billion. By the time of sentencing, prosecutors put the card records taken in the US at more than 20 million.[2] This page uses the more conservative 15 million figure from the original charges.
The missing control
The missing control: verifying employers and vendors independently. That means confirming a company is who it says it is through sources it does not control, such as business registries, known clients and past work, before you trust it with your systems, your staff or your career.
Combi Security had a website and a story, and that was enough. A few independent checks would have shown a firm with no real clients and no traceable history. The same habit protects businesses from the other half of the scheme: a message from a stranger claiming to be a customer, followed by a pushy phone call, deserves a check before anyone opens the attachment.[2][4]
What to do in your business
- Vet any security or IT vendor before access. Check the business registration, ask for 2 client references you can call yourself, and confirm the people on the contract are real.
- Get authorization in writing. Any security testing on your systems should have a signed scope, named testers and a start and end date. Unscheduled testing is an incident.
- Treat call-to-open as a red flag. Train staff that a phone call urging them to open an emailed file is a warning sign, not reassurance.
- Keep card terminals separate. Ask your payment provider about point-to-point encryption and keep checkout systems on a separate network from office computers.
- Tell job seekers in your life. If a friend or family member lands a remote security job, suggest they verify the employer independently before starting.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Record: FIN7 hacker sentenced to 10 years in prison
- US Attorney's Office, Western District of Washington: High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison
- US Department of Justice: Three members of notorious international cybercrime group FIN7 in custody for role in attacking over 100 US companies
- FBI: How cyber crime group FIN7 attacked and stole data from hundreds of US companies