Eight indicted for $9 million hack

A U.S. jury charges eight people for an attack on RBS WorldPlay

A U.S. grand jury in Atlanta has indicted eight people related to hacking into a computer network operated by credit-card processing vendor RBS WorldPlay and stealing US$9 million.

Indicted Tuesday were Sergei Tsurikov, 25, of Tallinn, Estonia; Viktor Pleshchuk, 28, of St. Petersburg, Russia; Oleg Covelin, 28, of Chisinau, Moldova; and a person known only as Hacker 3. They were charged in a 16-count indictment of conspiracy to commit wire fraud, wire fraud, conspiracy to commit computer fraud, computer fraud, access device fraud and aggravated identity theft.

Also indicted in U.S. District Court for the Northern District of Georgia were Igor Grudijev, 31, Ronald Tsoi, 31, Evelin Tsoi, 20, and Mihhail Jevgenov, 33, each of Tallinn, on a charge each of access device fraud.

The indictment alleges that the group used sophisticated hacking techniques to compromise the data encryption that was used by RBS WorldPay to protect customer data on payroll debit cards, which are used by companies to pay employees. Using a payroll debit card, employees are able to withdraw their regular salaries from an ATM.

Once the encryption on the card-processing system was compromised, the hacking ring allegedly raised the account limits on compromised accounts, and then provided a network of so-called "cashers" with 44 counterfeit payroll debit cards, the U.S. Department of Justice said.

Those counterfeit cards ere used to withdraw more than $9 million from more than 2,100 ATMs in about 280 cities worldwide, including cities in the U.S., Russia, Ukraine, Estonia, Italy, Hong Kong, Japan and Canada.

The $9 million loss happened in less than 12 hours last November.

The hackers then allegedly sought to destroy data stored on the card-processing network in order to conceal their hacking activity, the DOJ said.

The indictment alleges that the cashers were allowed to keep 30 percent to 50 percent of the stolen funds, but transmitted the rest of the funds back to Tsurikov, Pleshchuk and other co-defendants.

After discovering the unauthorized activity, RBS WorldPay, a division of the Royal Bank of Scotland, immediately reported the breach.

Several overseas law-enforcement agencies cooperated in the investigation. Estonian Central Criminal Police apprehended Tsurikov, Ronald Tsoi, Evelin Tsoi and Jevgenov in Estonia earlier this year. Each is facing related charges in Estonia. Tsurikov is also in custody in Estonia and is pending extradition to the U.S.

Cooperation between the Hong Kong Police Force and the U.S. Federal Bureau of Investigation also led to a parallel investigation in Hong Kong, resulting in the identification and arrest of two individuals who were responsible for withdrawing RBS WorldPay funds from ATMs there.

The Netherlands Police Agency National Crime Squad High Tech Crime Unit and the Netherlands National Public Prosecutor's Office also provided significant assistance, the DOJ said.

Tsurikov, Pleshchuk, Covelin and Hacker 3 each face a maximum sentence of up to 20 years in prison for conspiracy to commit wire fraud and each wire fraud count; up to five years in prison for conspiracy to commit computer fraud; up to five or 10 years in prison for each count of computer fraud; a two-year mandatory minimum sentence for aggravated identity theft; and fines up to $3.5 million dollars.

The charges against Grudijev, the Tsois and Jevgenov carry a maximum of up to 15 years in prison for each count and a fine of up to $250,000. The indictment also seeks criminal forfeiture of $9.4 million from the defendants.

"The charges brought against this highly sophisticated international hacking ring were possible only because of unprecedented international cooperation with our law enforcement partners, particularly between the United States and Estonia," Lanny Breuer, assistant attorney general in the DOJ's Criminal Division, said in a statement.

Sally Quillian Yates, the acting U.S. attorney in the Northern District of Georgia, said the assistance of RBS WorldPlay and other law enforcement agencies helped solve the case.

"Last November, in just one day, an American credit card processor was hacked in perhaps the most sophisticated and organized computer fraud attack ever conducted," she said in a statement.

"Today, almost exactly one year later, the leaders of this attack have been charged. This investigation has broken the back of one of the most sophisticated computer hacking rings in the world."

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags hackersUSA governmenthacklegalcybercrime

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?