Cyber Crime

Russian police detained cybercriminals who broke into the accounts of 700,000 customers of popular Internet stores

The Ministry of Internal Affairs of the Russian Federation and Group-IB have detained cybercriminals who broke into the accounts of 700,000 customers of popular Internet stores

The Administration “K” of the MIA of Russia, with the assistance of Group-IB, an international company specializing in the prevention of cyberattacks and the development of information security products, detained two cybercriminals who were breaking into and stealing the accounts of loyalty program members from popular online stores, payment systems and bookmakers. In total, about 700,000 accounts were compromised, 2,000 of which the hackers put up for sale for $5 each. The detainees admitted on the spot that they had earned at least 500,000 rubles. However, the real amount of damage remains to be determined.

The investigation began in November 2015, after a large-scale cyberattack was made on the website of a large online store to gain access to the personal accounts of the store’s loyalty program members, who received bonuses for purchases. In a month, about 120,000 accounts were compromised.

It was discovered that the attackers had collected compromised account information from various Internet services on hacker forums and used special programs to automatically guess passwords of accounts on the website of the online store.

The cybercriminals took advantage of the fact that many users of the website use the same login/password pair on several resources. If the logins and passwords came up on the website of the store under attack, they hacked those personal accounts. The hackers checked the amount of the accumulated bonuses and sold the compromised accounts on hacker forums at a price of $5 per account or 20-30% of the nominal balance of the accounts. The buyers then used them to pay for products with the bonuses.

It was quickly revealed that the hackers were engaged in more than selling compromised accounts. They also offered services for “hijacking” accounts—changing the phone number and e-mail on the accounts of the online store. The cost of that “service” was 10% of the bonus balance on the account.

To cover their tracks and hamper the companies’ security services, the hackers launched their attacks from different IP-addresses, using anonymizers and changing the digital fingerprint of the browser (User-Agent). In all, requests for authorization came from more than 35,000 unique IP addresses.

After large retailers began to check all orders with payment bonuses carefully in early 2016, the hackers switched to other lesser-known online stores. In addition, the hackers began to work on tips—information about new online stores with bonus programs and coupon services where it was possible to access personal accounts, for which the attackers promised to pay up to 50% of the amount received from the further sale of the compromised accounts.

In the course of the investigation, Group-IB specialists established the identities of the intruders. The leader of the group was a resident of Ryazan Region, born in 1998, and his partner, who provided technical support for their joint online store, resided in Astrakhan Region and was born in 1997. In May 2018, both were detained by the Administration “K” of the MIA of Russia. During a search, evidence of their unlawful activities was seized, along with narcotics. The cybercriminals were charged under part 2 of article 272 (“Illegal Accessing of Computer Information “) and article 228 (“Illegal Acquisition, Storage, Transportation, … of Narcotic Drugs “) of the Criminal Code of the Russian Federation. The suspects have confessed. The investigation is continuing.

About the author: Group-IB Team

Group-IB is a leading international company specializing in the prevention of cyberattacks and the development of information security products. It is the first Russian supplier of Threat Intelligence solutions, used in reports of Gartner, Forrester and the IDC. The company is a permanent member of the World Economic Forum. Group-IB has the largest laboratory of computer forensics in Eastern Europe, as well as CERT-GIB, a round-the-clock center for rapid response to cyber incidents. In 2017, the company was the leader on the Russian cyber threats research market, according to the IDC.

To prevent cyberattacks, Group-IB has created a line of products for the early detection of threats, including the Secure Portal fraud prevention system on corporate and government portals and online stores, which identifies unauthorized access to private accounts, and the acquisition and use of stolen cards, electronic wallets, bonuses and promotional codes for purchases, as well as phishing websites and social engineering.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Russia, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog.…

36 mins ago

DOJ arrested the founders of crypto mixer Samourai for facilitating $2 Billion in illegal transactions

The U.S. Department of Justice (DoJ) announced the arrest of two co-founders of a cryptocurrency mixer…

59 mins ago

Google fixed critical Chrome vulnerability CVE-2024-4058

Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…

6 hours ago

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

18 hours ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

1 day ago

US offers a $10 million reward for information on four Iranian nationals

The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…

1 day ago

This website uses cookies.