{"id":7426,"date":"2017-04-24T10:17:44","date_gmt":"2017-04-24T18:17:44","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/04\/24\/news-1217\/"},"modified":"2017-04-24T10:17:44","modified_gmt":"2017-04-24T18:17:44","slug":"news-1217","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/04\/24\/news-1217\/","title":{"rendered":"The Backstory Behind Carder Kingpin Roman Seleznev&#8217;s Record 27 Year Prison Sentence"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Mon, 24 Apr 2017 16:37:23 +0000<\/strong><\/p>\n<p><strong>Roman Seleznev<\/strong>,\u00a0a 32-year-old Russian cybercriminal and prolific credit card thief, was sentenced Friday to 27 years in federal prison. That is a record punishment for hacking violations in the United States and by all accounts one designed to send a message to criminal hackers everywhere. But a close review of the case suggests that Seleznev&#8217;s record sentence was severe in large part because the evidence against him was substantial\u00a0and yet he declined to cooperate with prosecutors prior to his trial.<\/p>\n<div id=\"attachment_39175\" style=\"width: 250px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-39175\" title=\"Wikipedia\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/04\/Maldives_orthographic_projection.svg_.png\" alt=\"Maldives_(orthographic_projection).svg\" width=\"240\" height=\"240\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/04\/Maldives_orthographic_projection.svg_-150x150.png 150w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/04\/Maldives_orthographic_projection.svg_.png 553w\" sizes=\"auto, (max-width: 240px) 100vw, 240px\" \/><\/p>\n<p class=\"wp-caption-text\">The Maldives is a South Asian island country, located in the Indian Ocean, situated in the Arabian Sea. Source: Wikipedia.<\/p>\n<\/div>\n<p>The son of an influential Russian politician, Seleznev made international headlines in 2014 after he was <a href=\"http:\/\/www.reuters.com\/article\/2014\/07\/08\/us-usa-cybersecurity-arrest-idUSKBN0FD0Z020140708\" target=\"_blank\">captured<\/a> while vacationing in <a href=\"https:\/\/en.wikipedia.org\/wiki\/Maldives\" target=\"_blank\">The Maldives<\/a>, a popular vacation spot for Russians and one that <a href=\"https:\/\/krebsonsecurity.com\/2011\/06\/chronopay-co-founder-arrested\/\" target=\"_blank\">many Russian cybercriminals<\/a> previously <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2011\/09\/GusevViagra.jpg\" target=\"_blank\">considered<\/a> to be\u00a0out of reach for\u00a0western law enforcement agencies.<\/p>\n<p>However, U.S. authorities were able to negotiate a secret deal with the Maldivian government to apprehend Seleznev. Following his capture, Seleznev was whisked away to Guam briefly before being transported to Washington state to stand trial for computer hacking charges.<\/p>\n<p>The\u00a0U.S. Justice Department says the laptop found with him when he was arrested contained more than 1.7 million stolen credit card numbers, and that evidence presented at trial showed that Seleznev earned tens of millions of dollars defrauding more than 3,400 financial institutions.<\/p>\n<p>Investigators also reportedly <a href=\"http:\/\/www.seattletimes.com\/seattle-news\/crime\/seattle-jury-convicts-russian-man-of-massive-business-hacking-id-theft-scheme\/\" target=\"_blank\">found a smoking gun: a password cheat sheet<\/a> that linked Seleznev to a decade&#8217;s worth of criminal hacking.<\/p>\n<p>Seleznev was initially identified as a major cybercriminal by U.S. government investigators in 2011, when prosecutors in Nevada named him as part of a conspiracy involving\u00a0more than three dozen\u00a0popular merchants on\u00a0<strong>carder[dot]su<\/strong>, a bustling fraud forum where he and other\u00a0members openly marketed various cybercrime-oriented services.<\/p>\n<p>Known by the hacker handle &#8220;nCux,&#8221; Seleznev operated multiple online shops that sold stolen credit and debit card data. According to <a href=\"http:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/Seleznev-Indictment-CR11-0070RAJ-1.pdf\" target=\"_blank\">Seleznev\u2019s indictment in the Nevada case<\/a>, he was part of a group that hacked into restaurants between 2009 and 2011 and planted malicious software to steal card data from store point-of-sale devices.<\/p>\n<p><a href=\"http:\/\/www.seattletimes.com\/seattle-news\/crime\/seattle-jury-convicts-russian-man-of-massive-business-hacking-id-theft-scheme\/\" target=\"_blank\">In Seattle\u00a0on Aug. 25, 2016<\/a>, Seleznev was convicted\u00a0of 10 counts of wire fraud, eight counts of intentional damage to a protected computer, nine counts of obtaining information from a protected computer, nine counts of possession of 15 or more unauthorized access devices and two counts of aggravated identity theft.<\/p>\n<p><span class=\"pullquote pqleft\">\u201cSimply put, Roman Seleznev has harmed more victims and caused more financial loss than perhaps any other defendant that has appeared before the court,\u201d federal prosecutors charged\u00a0in\u00a0their sentencing memorandum.<\/span> \u201cThis prosecution is unprecedented.\u201d<\/p>\n<p>Seleznev&#8217;s lawyer <strong>Igor Litvak<\/strong> called his client&#8217;s sentence &#8220;draconian,&#8221; saying\u00a0that Seleznev was gravely injured in a 2011 terrorist attack in Morocco, has Hepatitis B and is not well physically.<\/p>\n<p>Litvak noted that his client also faces two more prosecutions &#8212; in Georgia and Nevada,\u00a0and that his client is likely to be shipped off to Nevada soon.<\/p>\n<p>&#8220;It&#8217;s unprecedented, yes, but it&#8217;s also a draconian sentence for a person who\u00a0is very gravely ill,&#8221; Litvak said in an interview with KrebsOnSecurity. &#8220;He&#8217;s not going to live that long. He&#8217;s going to die in jail. I&#8217;m certain of that.&#8221;<br \/> <span id=\"more-39163\"><\/span><\/p>\n<h4>ANALYSIS<\/h4>\n<p>As for the severity of his sentence, Seleznev did himself no favors by rededicating himself to his carding empire after having been clearly marked by U.S. investigators in the 2011 indictment as a key figure in an online\u00a0organized crime ring.<\/p>\n<p>Many of the documents related to Seleznev&#8217;s prosecution and conviction in Washington state last week remain sealed, as he still faces federal criminal hacking charges in Nevada and Georgia. But former <a href=\"https:\/\/books.google.com\/books?id=njLIn0uv5KgC&amp;pg=PA178&amp;lpg=PA178&amp;dq=sporaw+exploit+s600&amp;source=bl&amp;ots=0zY3GWbOOw&amp;sig=r77oJFz9EYCqEG8wYfVSJFLSOi8&amp;hl=en&amp;sa=X&amp;ved=0ahUKEwij-JnLo73TAhWHL48KHccGBxgQ6AEIKTAB#v=onepage&amp;q=sporaw%20exploit%20s600&amp;f=false\" target=\"_blank\">black hat Russian hacker<\/a> turned political and cybersecurity blogger <strong>Andrey &#8220;Sporaw&#8221; Sporov<\/strong> <a href=\"http:\/\/sporaw.livejournal.com\/466632.html\" target=\"_blank\">published snippets<\/a> from documents apparently related to Seleznev&#8217;s prosecution indicating that investigators with the\u00a0<strong>U.S. Secret Service and FBI<\/strong>\u00a0met with the <strong>Russian Federal Security Service<\/strong> (FSB) in 2009 to discuss Seleznev&#8217;s activities,\u00a0presenting &#8220;substantial&#8221; evidence that Seleznev was a bigtime cybercrook.<\/p>\n<p><div id=\"attachment_28295\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/10\/2packcc.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-28295 size-large\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/10\/2packcc-600x365.png\" alt=\"The 2pac[dot]cc credit card shop that Seleznov operated.\" width=\"600\" height=\"365\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/10\/2packcc-285x173.png 285w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/10\/2packcc-600x365.png 600w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/10\/2packcc.png 1246w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">2pac[dot]cc credit card shop that Seleznov operated, among others.<\/p>\n<\/div>\n<p>Seleznev&#8217;s online alter ego nCux reportedly\u00a0got word of the meeting, and was soon after seen deleting his identities on hacker forums and saying he was closing up shop:<\/p>\n<blockquote>\n<p>&#8220;As U.S. Probation noted, the information that U.S. law enforcement was investigating Seleznev &#8216;clearly got back to Mr. Seleznev,&#8217;&#8221; reads the document. &#8220;Indeed, Seleznev had his own contacts inside the FSB. In chat messages between Seleznev and an associate from 2008, Seleznev stated that he had obtained protection through the law enforcement contacts in the computer crime squad of the FSB. Later, in 2010, Seleznev told another associate that the FSB knew his identity and was working with the FBI.&#8221;.<\/p>\n<\/blockquote>\n<p>But nCux didn&#8217;t go away, he merely <a href=\"https:\/\/krebsonsecurity.com\/2014\/10\/seleznev-arrest-explains-2pac-downtime\/\" target=\"_blank\">reinvented himself as &#8220;Bulba,&#8221;<\/a> operating a number of carding sites including track2[dot]name, bulba[dot]cc, and 2Pac[dot]cc. These sites sold tens of thousands of &#8220;dumps,&#8221; data that thieves encode onto new plastic cards and use to buy high-priced electronics and gift cards from big box retailers. Seleznev&#8217;s sites specialized in selling tens of thousands of dumps at a time to criminal groups and street gangs operating throughout the United States<\/p>\n<p><div id=\"attachment_26786\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/bulbaoncarder.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-26786 size-large\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/bulbaoncarder-600x401.png\" alt=\"A private mesasge between card merchant &quot;Bulba&quot; and an interested buyer on the fraud bazaar carder[dot]pro.\" width=\"600\" height=\"401\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/bulbaoncarder-285x190.png 285w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/bulbaoncarder-600x401.png 600w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/07\/bulbaoncarder.png 1016w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p class=\"wp-caption-text\">A private mesasge between card merchant &#8220;Bulba&#8221; and an interested buyer on the fraud bazaar carder[dot]pro.<\/p>\n<\/div>\n<p>Seleznev reportedly used this money to live an extravagant lifestyle, buying up properties in Bali, Indonesia. Photographs seized from Seleznev show his associates with large bundles of cash, at luxurious resorts, and posing for photographs next to flashy sports\u00a0cars. Just before his capture, Seleznev reportedly spent over $20,000 to stay in a resort in the Maldives and boasting of having rented the most expensive accommodations there.<\/p>\n<p>Sporov&#8217;s documents describe Seleznev&#8217;s years to evade law enforcement officials following his then-sealed indictment in Nevada:<\/p>\n<blockquote>\n<p>&#8220;Seleznev remained at large for over three years. During this period, Seleznev carefully evaded apprehension, employing practices like buying last-minute plane tickets to avoid giving authorities advance notice of his travel plans. Seleznev obtained an account with the U.S. Court\u2019s PACER system, which he monitored for criminal indictments naming him or his nicknames. He avoided travel to countries that had entered into extradition treaties with the United States. Indeed, when Seleznev was finally confronted by U.S. agents in the Maldives, his first words were to question whether the United States had an extradition treaty with the Maldives.&#8221;<\/p>\n<\/blockquote>\n<p>The defendant also apparently burned through multiple lawyers, almost all of whom appear to have advised him to seek a plea deal with the U.S. government:<\/p>\n<blockquote>\n<p>&#8220;Seleznev repeatedly attempted to manipulate and protract these proceedings, resulting in a cumulative delay of 26 months, and six sets of counsel, between his capture and trial&#8230;.Transcripts of jail calls previously submitted to the Court reveal that, in the days leading up to the hearing, Seleznev and his father resolved to delay the hearing so that they could work on a secret strategy they elliptically referred to as &#8216;Uncle Andrey\u2019s option.&#8217; To manufacture the delay, Seleznev\u2019s father suggested that Seleznev either &#8216;get sick&#8217; or &#8216;completely stop the communication with the lawyers.&#8217;&#8221;<\/p>\n<\/blockquote>\n<p>Seleznev is the son of <strong>Valery Seleznev<\/strong>, a prominent member of the Russian Duma (Russia&#8217;s parliament) and is considered an ally of <strong>President Vladimir Putin<\/strong>. As the Seattle Times <a href=\"http:\/\/www.seattletimes.com\/seattle-news\/crime\/seattle-jury-convicts-russian-man-of-massive-business-hacking-id-theft-scheme\/\" target=\"_blank\">wrote<\/a> at Seleznev&#8217;s conviction in 2016, &#8220;federal prosecutors accused Seleznev and his father of plotting to tamper with witnesses and <a class=\"content-link\" href=\"http:\/\/www.seattletimes.com\/seattle-news\/crime\/feds-say-accused-russian-hacker-at-seatac-detention-center-may-be-plotting-escape\/\">possibly discussing an escape<\/a> from the Federal Detention Center in SeaTac. The assertions were based on recorded conversations, according to the government.&#8221;<\/p>\n<div id=\"attachment_39198\" style=\"width: 337px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-39198\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/04\/seleznevdoj.png\" alt=\"Seleznev posing with a sports car in Red Square. Image: DOJ.\" width=\"327\" height=\"448\" \/><\/p>\n<p class=\"wp-caption-text\">Seleznev posing with a sports car in Red Square. Image: DOJ.<\/p>\n<\/div>\n<p>Perhaps Mr. Seleznev thought his father&#8217;s influence\u00a0and\/or his own apparent connections with Russian law enforcement officials would rescue him. Maybe Seleznev believed\u00a0he could prevail against the U.S. government in court.<\/p>\n<p>But it seems clear that Seleznev&#8217;s\u00a0record 27-year sentence had at least as much to do\u00a0with the impact of his crimes as it did\u00a0the enormity of the charges and evidence against him combined with his refusal to cooperate with investigators.<\/p>\n<p>Seleznev&#8217;s lawyer <strong>Igor Litvak<\/strong> said his client declined a plea deal prior to his trial, and by the time Seleznev had changed his mind the trial was over and the government no longer needed the information he could offer. Prosecutors sought to put him\u00a0away for 35 years: They got seven years shy of that request.<\/p>\n<p>&#8220;The prosecution said if he would have cooperated this case would have turned out very differently,&#8221; Litvak said.<\/p>\n<p>The docket for Seleznev&#8217;s case is <a href=\"http:\/\/ia902504.us.archive.org\/22\/items\/gov.uscourts.wawd.174096\/gov.uscourts.wawd.174096.docket.html\" target=\"_blank\">available here<\/a>\u00a0and includes a number of unsealed documents related to this case.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/04\/the-backstory-behind-carder-kingpin-roman-seleznevs-record-27-year-prison-sentence\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/04\/Maldives_orthographic_projection.svg_.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Mon, 24 Apr 2017 16:37:23 +0000<\/strong><\/p>\n<p>Roman Seleznev, a 32-year-old Russian cybercriminal and prolific credit card thief, was sentenced Friday to 27 years in federal prison. That is a record punishment for hacking violations in the United States and by all accounts one designed to send a message to criminal hackers everywhere. But a close review of the case suggests that Seleznev&#8217;s record sentence was severe in large part because the evidence against him was substantial and yet he declined to cooperate with prosecutors prior to his trial.    The son of an influential Russian politician, Seleznev made international headlines in 2014 after he was captured while vacationing in The Maldives, a popular vacation spot for Russians and one that many Russian cybercriminals previously considered to be out of reach for western law enforcement agencies. He was whisked away to Guam briefly before being transported to Washington state to stand trial for computer hacking charges.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[12071,6627,11128,12072,12073,10644,12074,12075,12076,179],"class_list":["post-7426","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-bulba","tag-fbi","tag-fsb","tag-igor-litvak","tag-ncux","tag-other","tag-roman-seleznev","tag-secret-service","tag-valery-seleznev","tag-vladimir-putin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7426"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7426\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7426"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}