Carbanak started as a bank robbery. By the time investigators had traced it fully, it had become something more interesting and more troubling: proof that organized crime could operate with the patience, discipline, and technical sophistication previously associated only with nation-state espionage operations. The group that ran Carbanak - eventually charged and partially dismantled under the name FIN7, though the relationship between Carbanak and FIN7 remains contested - stole between $1 billion and $3 billion from financial institutions and retail companies across more than 40 countries over roughly a decade. They did it not by breaching payment systems or breaking encryption, but by spending months watching how banks actually worked, then impersonating bank employees well enough to fool the bank's own systems.
The Carbanak malware was first documented publicly by Kaspersky Lab in February 2015, though the campaign had been running since at least 2013. Kaspersky's report described attacks against more than 100 banks in 30 countries, with individual bank losses averaging $10 million and the total estimated at $1 billion or more. The report described the methodology in enough detail to make clear this was not typical criminal hacking: the attackers spent three to four months inside each target bank's network before attempting any financial transactions, using that time to learn exactly how the bank's employees processed legitimate transfers.
The Initial Access and Reconnaissance Phase
Carbanak's initial access mechanism was consistent across victims: spear-phishing emails carrying Word documents with embedded exploits. The exploits targeted older vulnerabilities in Microsoft Office and Windows that many corporate environments had not yet patched. The emails were crafted to appear legitimate - internal bank communications, regulatory notices, financial reports - with subject lines and content specific enough to the target that a busy employee in a financial institution might not question them.
Once the exploit executed and Carbanak was installed, it operated silently. The malware's primary function during the initial phase was reconnaissance: capturing screenshots every 20 seconds, logging keystrokes, recording video of specific applications (bank transaction systems, email clients, file servers), and identifying the user's role and the systems they had access to. This data was exfiltrated to command and control servers over encrypted channels that mimicked legitimate HTTPS traffic.
The reconnaissance phase was not rushed. Three to four months of detailed observation allowed the attackers to build a complete picture of how each specific bank's internal processes worked. They watched employees log into the SWIFT messaging system. They observed how internal fund transfers were initiated and approved. They noted the dollar thresholds that triggered additional approval requirements, the names of employees with transaction authority, and the exact sequences of actions required to move money between accounts.
The Theft Methodology: Four Approaches
Carbanak used different theft mechanisms depending on what the compromised bank's systems permitted. The group had developed four primary approaches, each exploiting a different aspect of banking infrastructure.
The first approach targeted ATM networks. After gaining access to systems that managed ATM software, the attackers could instruct specific ATMs to dispense cash at specific times. Money mules - people recruited for cash pickup - would be positioned at the designated ATMs at the right moment and collect the cash as it dispensed. This required coordination between the attackers, the money mules, and the timing - but once the necessary access was established inside the bank's ATM management system, each ATM attack could yield tens of thousands of dollars in fifteen minutes.
The second approach used SWIFT - the international messaging system that financial institutions use to communicate and execute transfers. Having watched SWIFT operators for months, the attackers could use legitimate bank employee credentials and authentic-looking SWIFT messages to initiate transfers to accounts they controlled in other countries. These transfers were designed to fall within normal operating parameters and would only be detected if the receiving institution questioned them - which rarely happened immediately.
The third approach manipulated online banking systems to inflate account balances and then withdraw the inflated amounts. This required access to the database systems underlying retail banking platforms - possible after months of internal reconnaissance and lateral movement. An account with a legitimate balance of $1,000 would be briefly adjusted to $10,000, the $9,000 surplus withdrawn, and the balance corrected afterward. The manipulation window was narrow enough that many instances were never detected.
The fourth approach targeted e-payment systems - the backend infrastructure supporting various electronic payment networks. Having identified the system and its operators, the attackers could redirect legitimate payments to controlled accounts or initiate fraudulent payments that looked like legitimate system activity.
The Evolution to FIN7 and Retail Targeting
By 2015, the group - or a closely related group sharing personnel, tools, and infrastructure - had expanded beyond banking into retail and hospitality, where they targeted point-of-sale systems to steal payment card data. This operation became known as FIN7, though the security industry debates whether FIN7 and Carbanak are the same organization or related but distinct groups. Mandiant, which named and tracked FIN7, treated them as separate. Europol and the US DOJ, in their 2018 indictments, treated them as variations of the same criminal organization.
FIN7's retail targeting was technically different from Carbanak's bank attacks but operationally similar in its patience. Initial access was still via spear-phishing, often with sophisticated lures - fake job applications, restaurant supply orders, vendor invoices. Once inside a retail organization's network, the attackers mapped the point-of-sale infrastructure, found the systems where card data was processed, and installed memory-scraping malware (similar to the BlackPOS used in the Target breach) to capture track-2 card data at the moment of transaction.
FIN7 operated against restaurant chains, hotel groups, and retailers across the United States at significant scale. Victims documented by the DOJ included Chipotle, Chili's, Arby's, Red Robin, Sonic, Panera Bread, Jason's Deli, Emerald Queen Casino, and dozens more. The total estimated card theft was in the tens of millions of payment card records.
The Organizational Structure
What made Carbanak/FIN7 unusual, and what became clear from the 2018 arrests, was its organizational sophistication. This was not a loose collective of hackers but a structured criminal enterprise with defined roles, management hierarchy, and human resources functions.
Three Ukrainian nationals arrested in 2018 held distinct management roles: Dmytro Fedorov managed the FIN7 information technology systems and supervised the development of new hacking tools; Fedir Hladyr served as systems administrator and communications manager; Andrii Kolpakov was a supervisor of hacking teams. These roles implied dozens of people below them.
The DOJ's charging documents described a company structure. FIN7 used a front company called Combi Security, nominally a legitimate security firm based in Russia and Israel, to recruit developers and security researchers. Job advertisements on legitimate job boards promised interesting security work. New employees might work for months doing what appeared to be legitimate security research before realizing the actual nature of their employer. Some employees interviewed by FBI investigators afterward said they had not known they were working for a criminal organization - a claim that was viewed skeptically in some cases but plausibly in others, given how compartmentalized the organization was.
The Arrests and Prosecutorial Strategy
The arrests in 2018 followed a years-long international investigation involving the FBI, Europol, and law enforcement agencies in Ukraine, Spain, and Georgia. Three individuals were arrested in different countries in rapid succession. Andrii Kolpakov was arrested in Spain in June 2018 and extradited to the United States. Fedir Hladyr was arrested in Dresden and extradited in 2018, ultimately cooperating with prosecutors. Dmytro Fedorov was arrested in Ukraine.
Hladyr's cooperation was significant for what it revealed about the operation's infrastructure and structure. His sentencing memorandum, filed in late 2020, described the organization in substantial detail - the management hierarchy, the division between infrastructure management and hacking teams, the use of encrypted communications, the recruitment methods. He was sentenced to ten years. Kolpakov, who did not cooperate, received twelve years. Fedorov's case proceeded separately in Ukraine.
The 2023 arrest and guilty plea of Maksim Silnikau (also known as J.P. Morgan and Maksym Silnikov), a Belarusian and Ukrainian dual national, added another dimension. Silnikau was charged with operating Ransom Cartel ransomware and the Reveton ransomware - but also with being a key figure in the broader financial crime ecosystem that FIN7 operated within. His extradition from Spain to the United States, and subsequent guilty plea to RICO charges, represented the US's continued prosecution strategy of treating financial cybercrime organizations as racketeering enterprises rather than individual actors.
The $1 Billion Figure and Its Meaning
The "$1 billion stolen" figure that became attached to Carbanak deserves examination. This figure came from Kaspersky's February 2015 report and was widely repeated. The actual methodology behind it - multiplying the number of confirmed victim institutions by average estimated losses - involves uncertainty at each step. Banks that were victims were not always willing to confirm losses. The "average" was based on cases where Kaspersky had detailed visibility. The figure may be accurate, may be conservative, or may be an overestimate, depending on factors that external researchers cannot verify.
What the figure obscures as much as it reveals is the distribution of losses. The billion-dollar total is not a single transaction or even a few large ones - it is hundreds of individual bank heists, each in the millions, conducted over years across dozens of countries. This distribution matters because it implies a scale of operation that can only be sustained by an organization with significant human capital, technical infrastructure, and geographic reach. The criminal organization that produced this outcome was not small.
The $1 billion figure also matters as a benchmark for thinking about what organized cybercrime can achieve with nation-state levels of patience and operational discipline applied to financial crime. Carbanak demonstrated that sophisticated, long-duration intrusion methodology developed for espionage could be profitably applied to theft - that the same techniques used by state actors to read classified files could be used by criminal organizations to steal money. This convergence of methodology, even with divergent objectives, has made the defensive problem significantly harder.
The Continuing FIN7 Operation
Despite the 2018 arrests, FIN7 did not stop operating. Mandiant and other threat intelligence firms documented continuing FIN7 activity through 2019, 2020, and beyond - new infrastructure, updated malware, campaigns against new victims. The arrests had disrupted the organization but not destroyed it. The Combi Security front company infrastructure was replaced with new front companies. New operators filled the roles vacated by the arrested individuals.
In 2021, FIN7 was observed recruiting security researchers on legitimate job boards for positions at a fake cybersecurity company - the same Combi Security methodology rebranded. Researchers hired through these listings described receiving tasks that were clearly offensive tool development, some of which they completed before realizing the context. The organizational methodology had survived the leadership arrests essentially intact.
By 2023-2024, FIN7 had been linked to ransomware operations - the same personnel and infrastructure observed in historical FIN7 campaigns appeared in Clop, BlackBasta, and other ransomware affiliate activity. This evolution from financial theft to ransomware follows the broader criminal ecosystem's economic shift: per-victim revenue from ransomware can exceed years of card fraud profits in a single successful attack against a large enterprise. The organization adapted to where the money was, as it always had.