Case file · FAKE SECURITY FIRM

Combi Security: the cybercrime gang that ran a fake security company

Published 2026-09-29 · 4 min read · Missing control: Verify employers and vendors independently

One of the most damaging card-theft gangs in US history ran what looked like a legitimate cybersecurity company, complete with a website and job openings, but with no real customers.[2][3] This case file covers how the FIN7 group used that front, how it stole more than 15 million payment card records, and the one control that would have exposed it.

What happened

From at least 2015, a group known as FIN7 broke into the computer networks of more than 100 US companies, many of them restaurant chains, hotels and retailers. Its targets were the card terminals at checkout. Federal prosecutors said the group breached more than 6,500 point-of-sale terminals at more than 3,600 business locations in 47 states and Washington, D.C., and took more than 15 million customer card records.[3][4] Chains named as victims in the case included Chipotle, Chili's, Arby's, Red Robin and Jason's Deli.[1][2]

To recruit staff and look respectable, the group set up Combi Security, a company that claimed offices in Russia and Israel and presented itself as a penetration-testing firm, meaning a business companies hire to test their own defenses.[3] The US Attorney's office later called it a fake cybersecurity company with a phony website and no legitimate customers.[2]

In January 2018, a Ukrainian national named Fedir Hladyr, the group's systems administrator, was arrested in Dresden, Germany. Two other alleged senior members were arrested in Poland and Spain in 2018.[1][3] The stolen card data had been sold on criminal marketplaces online.[3]

How it worked

The front company did two jobs. For recruits, it made criminal work look like an ordinary tech job: people could be hired to do what sounded like authorized security testing. For the outside world, it gave the operation a legitimate-looking name and web presence.[2][4] Hladyr himself joined the group through Combi Security, according to prosecutors.[2]

The break-ins started with email. Staff at a restaurant or hotel would receive an email made to look like ordinary business correspondence, with a file attached. The group often followed up with a phone call to the same employee, urging them to open it. Opening the file installed malware that let the group into the network and, eventually, onto the card terminals.[3][4]

Hladyr's job, prosecutors said, was to keep the group's server network running, collect the stolen card data, manage its communication channels and supervise other members.[1][2]

What it cost

Hladyr was extradited to Seattle in 2018 and pleaded guilty in September 2019 to conspiracy to commit wire fraud and conspiracy to commit computer hacking.[1][2] On April 16, 2021, he was sentenced to 10 years in federal prison and ordered to pay $2.5 million in restitution. He told the court he regretted his involvement with Combi Security.[1][2]

The US Attorney's office estimated that the group's overall losses to banks, merchants, card companies and consumers exceeded $3 billion. By the time of sentencing, prosecutors put the card records taken in the US at more than 20 million.[2] This page uses the more conservative 15 million figure from the original charges.

The missing control

The missing control: verifying employers and vendors independently. That means confirming a company is who it says it is through sources it does not control, such as business registries, known clients and past work, before you trust it with your systems, your staff or your career.

Combi Security had a website and a story, and that was enough. A few independent checks would have shown a firm with no real clients and no traceable history. The same habit protects businesses from the other half of the scheme: a message from a stranger claiming to be a customer, followed by a pushy phone call, deserves a check before anyone opens the attachment.[2][4]

What to do in your business

Watch the case
The cybercrime gang that ran a fake security companyDrops 2026-12-11
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Record: FIN7 hacker sentenced to 10 years in prison
  2. US Attorney's Office, Western District of Washington: High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison
  3. US Department of Justice: Three members of notorious international cybercrime group FIN7 in custody for role in attacking over 100 US companies
  4. FBI: How cyber crime group FIN7 attacked and stole data from hundreds of US companies