Showing posts with label U.S. Justice Department. Show all posts
Showing posts with label U.S. Justice Department. Show all posts

Monday, August 31, 2020

Chinese National Charged With Destroying Hard Drive During FBI Investigation Into The Possible Transfer Of Sensitive Software To China


The U.S. Justice Department released the below information:

A Chinese national and researcher at the University of California, Los Angeles has been arrested on federal charges of destroying evidence to obstruct an FBI investigation after he was observed throwing a damaged hard drive into a dumpster outside his apartment, the Justice Department announced today.

Guan Lei, 29, of Alhambra, was arrested pursuant to a one-count criminal complaint unsealed this afternoon during his initial appearance in United States District Court.

The criminal complaint alleges that Guan, who was in the U.S. on a J-1 non-immigrant visa, threw a damaged hard drive into a trash dumpster near his residence on July 25. 

 The FBI recovered the damaged hard drive after Guan was not allowed to board a flight to China and after Guan refused the FBI’s request to examine his computer.  The affidavit in support of the complaint notes that the internal hard drive “was irreparably damaged and that all previous data associated with the hard drive appears to have been removed deliberately and by force.”

According to the complaint, Guan is being investigated for possibly transferring sensitive U.S. software or technical data to China’s National University of Defense Technology (NUDT) and falsely denying his association with the Chinese military – the People’s Liberation Army – in connection with his 2018 visa application and in interviews with federal law enforcement.

Guan later admitted that he had participated in military training and wore military uniforms while at NUDT.  One of Guan’s NUDT faculty advisors in China was also a lieutenant general in the PLA who developed computers used by the PLA General Staff Department, the PLA General Armament Department, Air Force, military weather forecasts, and nuclear technology.  

NUDT is “suspected of procuring U.S.-origin items to develop supercomputers with nuclear explosive applications” and has been placed on the Department of Commerce’s Entity List for nuclear nonproliferation reasons, according to the affidavit.

In addition to destroying the hard drive, the complaint alleges that Guan concealed digital storage devices from investigators and falsely told federal officials that he had not had any contact with the Chinese consulate during his nearly two-year stay in the U.S.

During his initial appearance this afternoon, Guan was ordered detained by a United States Magistrate Judge, who scheduled an arraignment for Sept. 17, 2020 .

A criminal complaint contains allegations that a defendant has committed a crime. Every defendant is presumed innocent until and unless proven guilty beyond a reasonable doubt.

The felony offense of destruction of evidence carries a statutory maximum sentence of 20 years in federal prison.

This case is being investigated by the FBI, Homeland Security Investigations, and U.S. Customs and Border Protection. The U.S. Department of State’s Diplomatic Security Service has provided substantial assistance during the investigation.

This case is being prosecuted by Assistant U.S. Attorneys Will Rollins and George Pence of the Terrorism and Export Crimes Section.

Saturday, October 19, 2019

Chinese National Sentenced To 40 Months In Prison For Conspiring To Illegally Export Military And Space-Grade Technology From The United States To China


The U.S. Justice Department released the below information:
On October 16, 2019, United States District Judge Diane J. Humetewa sentenced Tao Li, a 39-year-old Chinese national, to 40 months in prison, followed by three years of supervised release.  Li had previously pleaded guilty to conspiring to export military- and space-grade technology to the People’s Republic of China without a license in violation of the International Emergency Economic Powers Act. 
“This case is one of many involving illegal attempts to take U.S. technology to China.  Li attempted to procure highly sensitive U.S. military technology in violation of our export control laws.  Such laws are in place to protect our national security, and the Department of Justice will continue to vigorously enforce them,” said Assistant Attorney General John C. Demers. “We don’t take these crimes lightly and we will continue to pursue them.”
“If you steal our military and space technology, you should expect to go to prison,” said Michael Bailey, United States Attorney for the District of Arizona. “But for the diligent work of HSI and the Defense Criminal Investigative Service, our nation’s security would’ve been damaged by Mr. Li.”
“Li’s sentencing was the result of a highly successful joint investigative effort with our law enforcement partners and the U.S. Attorney’s Office that prevented U.S. military technology from falling into the wrong hands,” said Bryan D. Denny, Special Agent in Charge of the Defense Criminal Investigative Service, Western Field Office.  “It also reaffirms our commitment to protecting America from this type of activity and, equally so, serves as a warning to those intent on illegally exporting our technologies that the Defense Criminal Investigative Service and its partners will pursue these crimes relentlessly.”
“This sentence is well deserved and further demonstrates the lengths of criminal activity by those who seek to engage in illegally obtaining sophisticated materials,” said Scott Brown, Special Agent in Charge for Homeland Security Investigations (HSI) Phoenix. “One of HSI’s top priorities is preventing U.S. military products and sensitive technology from falling into the hands of those who might seek to harm America or its interests. We will continue to aggressively pursue violators wherever they may be.” 
Between December 2016 and January 2018, Li worked with other individuals in China to purchase radiation-hardened power amplifiers and supervisory circuits and illegally export them from the United States to China.  The electronic components sought by Li are capable of withstanding significant levels of radiation and extreme heat, and as a result, are primarily used for military and space applications.  Due to the technological capabilities of the electronic components sought by Li and the significant contribution that the components could make to a foreign country’s military and space programs, both parts required an export license from the U.S. Department of Commerce, Bureau of Industry and Security, prior to being sent out of the United States. Notwithstanding the licensing requirement, the Department of Commerce has a policy of denial to export these types of electronic components to the People’s Republic of China.
Between December 2016 and January 2018, Li, who resided in China, used multiple aliases to contact individuals in the United States, including representatives of United States-based private companies, to try to obtain the electronic components. Additionally, Li and his coconspirators agreed to pay a “risk fee” to illegally export the electronic components to China.  In furtherance of his request, Li wired money from a bank account in China to a bank account in Arizona.  Li was arrested in September 2018 at Los Angeles International Airport, as Li attempted to travel from China to Arizona to meet with one of the undercover agents. 
The investigation in this case was conducted by HSI and DCIS.  The prosecution was handled by Todd M. Allison and David Pimsner, Assistant United States Attorneys, District of Arizona, Phoenix, with assistance from Scott Claffee, Trial Attorney, Department of Justice National Security Division.

Wednesday, September 25, 2019

Former Intelligence Officer Convicted Of Attempted Espionage Sentenced To 10 Years In Federal Prison


The U.S. Justice Department released the below information:
A former Defense Intelligence Agency (DIA) officer, who pleaded guilty in March to attempting to communicate, deliver, or transmit information involving the national defense of the United States to the People’s Republic of China, will serve 10 years in federal prison.  U.S. District Judge Dee Benson imposed the sentence Tuesday afternoon in Salt Lake City.
Ron Rockwell Hansen, 60, of Syracuse, Utah, was arrested June 2, 2018, on his way to the Seattle-Tacoma International Airport in Seattle, Washington, as he was preparing to board a flight to China while in possession of SECRET military information. 
“One of three ex-US intelligence officers recently convicted of acting on behalf of the People’s Republic of China, Ron Rockwell Hansen received hundreds of thousands of dollars for betraying his country and former colleagues,” said Assistant Attorney General of National Security John C. Demers.  “These cases show the breadth of the Chinese government’s espionage efforts and the threat they pose to our national security.  Our intelligence professionals swear an oath to protect our country’s most closely held secrets and the National Security Division will continue to relentlessly pursue justice against those who violate this oath.”
“The Chinese government continues to attempt to identify and recruit current and former members of the United States intelligence community.  This is a very troubling trend. These individuals must remain vigilant and immediately report any suspicious activity. The Hansen case is an example of what will happen to those who violate the public’s trust and risk our national security by disclosing classified information,” said U.S. Attorney John W. Huber for the District of Utah.
“Ron Hansen was willing to betray his oath and his country for financial gain,” said Special Agent in Charge Paul Haertel of the FBI’s Salt Lake City Field Office.  "This case brings to light that not all spies are foreign adversaries.  Insider threats pose a significant national security risk, and the FBI will continue to aggressively investigate those who put our country and citizens at risk.”
Hansen retired from the U.S. Army as a Warrant Officer with a background in signals intelligence and human intelligence.  He speaks fluent Mandarin-Chinese and Russian, according to court documents. Upon retiring from active duty, DIA hired Hansen as a civilian intelligence case officer in 2006. Hansen held a Top Secret clearance for many years, and signed several non-disclosure agreements during his tenure at DIA and as a government contractor. 
As Hansen admitted in the plea agreement, in early 2014, agents of a Chinese intelligence service targeted him for recruitment, and he began meeting with them regularly in China.  During these meetings, the agents described to Hansen the type of information that would interest Chinese intelligence.  Hansen stipulated that during the course of his relationship with Chinese intelligence, he received hundreds of thousands of dollars in compensation for information he provided them.
Between May 24, 2016, and June 2, 2018, Hansen admitted he solicited national security information from an intelligence case officer working for the DIA.  Hansen admitted knowing that the Chinese intelligence services would find the information valuable, and he agreed to act as a conduit to sell that information to the Chinese.  He advised the DIA case officer how to record and transmit classified information without detection, and how to hide and launder any funds received as payment for classified information.  He admitted he now understands that the DIA case officer reported his conduct to the DIA and subsequently acted as a confidential human source for the FBI.
Hansen admitted meeting with the DIA case officer on June 2, 2018, and receiving individual documents containing national defense information that he had previously solicited.  The documents he received were classified. The documents included national security information related to U.S. military readiness in a particular region -- information closely held by the federal government. Hansen did not possess a security clearance nor did he possess a need to know the information contained in the materials. 
As a part of his plea agreement, Hansen admitted he reviewed the documents, queried the case officer about their contents, and took written notes which contained information determined to be classified.  He advised the DIA case officer that he would remember most of the details about the documents he received that day and would conceal notes about the material in the text of an electronic document he would prepare at the airport before leaving for China.  He admitted he intended to provide the information he received to the agents of the Chinese Intelligence Service with whom he had been meeting.  He also admitted knowing that the information was to be used to the injury of the United States and to the advantage of a foreign nation.
As a part of the plea agreement, Hansen has agreed to forfeit property acquired from or traceable to his offense, including property used to facilitate the crime.
The case was handled by Assistant U.S. Attorneys Robert A. Lund, Karin Fojtik, Mark K. Vincent and Alicia Cook of the District of Utah, and Trial Attorneys Patrick T. Murphy, Matthew J. McKenzie and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section.  Prosecutors from the U.S. Attorney’s Office for the Western District of Washington assisted with this case.
The prosecution is the result of an investigation by special agents of the FBI, IRS-Criminal Investigation, U.S. Department of Commerce, the U.S. Department of Defense, U.S. Army Counterintelligence, and the Defense Intelligence Agency. 

Tuesday, July 30, 2019

Texas Man Convicted Of Conspiracy To Commit Theft Of Trade Secrets


The U. S. Justice Department released the below information:
A Texas man was convicted today by a federal jury in Washington D.C. of conspiracy to commit theft of trade secrets.
Following a nine-day trial, Shan Shi, 54, of Houston, Texas, was convicted of one count of conspiracy to commit theft of trade secrets.  Shi was originally indicted in June 2017 for conspiracy to commit theft of trade secrets, and a superseding indictment containing one count of conspiracy to commit economic espionage and one count of conspiracy to commit money laundering charges issued in April 2018.  Shi was acquitted on the other charges. 
“Shan Shi and his coconspirators went to great lengths to cash in on the Chinese government’s desire to obtain syntactic foam technology,” said Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division.  “As this case demonstrates, the Department of Justice is and will remain on the front lines of defending U.S. companies against the theft of their trade secrets.”
“The jury’s verdict makes clear that Shan Shi conspired to steal trade secrets by poaching employees from a U.S. company and enticing them to bring technical data to his company,” said Assistant Attorney General for National Security John C. Demers.  “He did this against the backdrop of China’s strategic plan to close the gap between China and United States in buoyancy technology and with the benefit of millions of dollars of funding from China.  Like our many other prosecutions implicating China’s economic aggression, this case exemplifies both the threat to American companies and our commitment to confront it.”  
“We take very seriously the theft of intellectual property that was developed in the United States through long years of research, development, and innovation,” said U.S. Attorney Jessie K. Liu for the District of Columbia.  “Shi chose to steal the secrets of a U.S. company rather than do the hard work necessary to succeed honestly in the free market.  He is now being held accountable for that choice.”
“Shan Shi attempted to obtain sophisticated U.S. technology with both military and civilian uses for the ultimate benefit of China,” said Assistant Director John Brown of the FBI’s Counterintelligence Division.  “It is no secret that China is determined to achieve superiority in virtually all high-tech areas, and the FBI is equally determined to stop individuals who commit illegal acts to help China achieve its goals.  The stakes are high both for U.S. national security and for American companies who invest so much money and time on research and development.”
“FBI Houston’s elite counterintelligence investigators worked for years to dismantle Mr. Shi’s prolific network and bring him to justice,” said Special Agent in Charge Perrye K. Turner of the FBI’s Houston Field Office.  “Our highly trained agents and intelligence analysts work every day to protect American businesses from unscrupulous foreign adversaries.  We are pleased by today’s verdict, and we will continue to aggressively protect America's economic security and intellectual property from those who would do us harm.”
Evidence introduced at trial established that Shi conspired with others to steal trade secrets from a Houston-based company, Trelleborg Offshore, relating to syntactic foam, a strong, lightweight material with commercial and military uses that is essential for deep-sea oil and gas drilling.  In public statements of its national priorities, China has made clear its desire to develop this technology.  Shi sought to obtain information about syntactic foam for the benefit of CBM-Future New Material Science and Technology Co. Ltd. (CBMF), a Chinese company based in Taizhou, and for the ultimate benefit of the People’s Republic of China.  Four of Shi’s codefendants—some of whom worked at Trelleborg—had pleaded guilty to conspiring to steal trade secrets, and two testified as cooperating witnesses at trial.  From 2014 to 2017, CBMF sent Shi’s company in Houston approximately $3.1 million from China in order to promote Shi’s activity in the United States. 
Sentencing has been set for Oct. 25, 2019. 
The FBI’s Houston Field Office conducted the investigation.  Senior Counsel Joss Nichols of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorneys Jeffrey Pearlman and Luke Jones for the District of Columbia are prosecuting the case. 

Thursday, May 2, 2019

Former CIA Officer Pleads Guilty To Conspiracy To Commit Espionage


The U.S. Justice Department released the below information:
A former Central Intelligence Agency (CIA) case officer pleaded guilty today to conspiring to communicate, deliver and transmit national defense information to the People’s Republic of China.  Assistant Attorney General for National Security John C. Demers, U.S. Attorney G. Zachary Terwilliger for the Eastern District of Virginia, Assistant Director for Counterintelligence John Brown of the FBI and Assistant Director in Charge Nancy McNamara of the FBI’s Washington Field Office made the announcement after Senior U.S. District Judge T.S. Ellis III accepted the plea.
According to court documents, Jerry Chun Shing Lee, 54, left the CIA in 2007 and began residing in Hong Kong.  In April 2010, two Chinese intelligence officers (IOs) approached Lee and offered to pay him for national defense information he had acquired as a CIA case officer.  The IOs also told Lee they had prepared for him a gift of $100,000 cash, and they offered to take care of him “for life” in exchange for his cooperation.
Beginning sometime in May 2010 and continuing into at least 2011, Lee received requests for information, or taskings, from the Chinese IOs.  The majority of the taskings asked Lee to reveal sensitive information about the CIA, including national defense information.  On May 14, 2010, Lee made or caused to be made a cash deposit of $138,000 HKD (approximately $17,468 in USD) into his personal bank account in Hong Kong.  This would be the first of hundreds of thousands of dollars (USD equivalent) in cash deposits Lee made or caused to be made into his personal HSBC account from May 2010 through December 2013.
“This is the third case in less than a year in which a former US intelligence officer has pled or been found guilty of conspiring with Chinese intelligence services to pass them national defense information,” said Assistant Attorney General Demers.  “Every one of these cases is a tragic betrayal of country and colleagues.  The National Security Division will continue to prosecute individuals like Lee who abuse their former access to classified information for financial gain while threatening the security of America.  Many thanks to the agents, analysts and prosecutors whose work led to today’s outcome.”
“Those Americans entrusted with our government’s most closely held secrets have a tremendous responsibility to safeguard that information,” said U.S. Attorney Terwilliger.  “Instead of embracing that responsibility and honoring his commitment to not disclose national defense information, Lee sold out his country, conspired to become a spy for a foreign government, and then repeatedly lied to investigators about his conduct.  This prosecution should serve as a warning to others who would compromise our nation’s secrets and betray our country’s trust.  My thanks to the prosecutors, agents and our intelligence community partners for their terrific work on this important case.”
“Today, Mr. Lee accepts responsibility not only for his crimes but also for their dangerous ramifications” said Assistant Director Brown.  “By knowingly aiding a foreign government, Mr. Lee put our country’s national security at serious risk and also threatened the safety and personal security of innocent people, namely his former intelligence colleagues.  He deserves to answer for his treachery and he will do so as a result of the dedication of the FBI’s Counterintelligence Division, the Washington Field Office, and the Department of Justice in pursuing this case.”
“Today's guilty plea is an example of how the FBI and the Department of Justice successfully pursue threats to our nation's security and intelligence,” said Assistant Director McNamara.  “U.S. Government employees are entrusted by the American people to keep our country safe and secure from adversaries.  The targeting of former U.S. security clearance holders by Chinese intelligence services is a constant threat we face, and the FBI will continue to combat these threats and guard our nation against those who conspire to compromise our national security.  I would like to thank the hardworking people of the FBI who work each day to defend our security and intelligence.”
On May 26, 2010, Lee created on his laptop computer a document that described, among other things, certain locations to which the CIA would assign officers with certain identified experience, as well as the particular location and timeframe of a sensitive CIA operation.  After Lee created this document, he transferred it from his laptop to a thumb drive.  The document included national defense information of the United States that was classified at the Secret level.
In August 2012, the FBI conducted a court-authorized search of a hotel room in Honolulu, Hawaii registered in Lee’s name.  The search revealed that Lee possessed the thumb drive within his personal luggage.  The FBI forensically imaged the thumb drive and later located the document in the unallocated space of the thumb drive, meaning that it had been deleted.  The search also revealed that Lee possessed a day planner and an address book that contained handwritten notes made by Lee that related to his work as a CIA case officer prior to 2004.  These notes included, among other things, intelligence provided by CIA assets, true names of assets, operational meeting locations and phone numbers, and information about covert facilities.
During 2012, Lee had a series of interviews with the CIA.  Throughout these interviews, in response to questions about what the IOs had wanted from him, Lee intentionally failed to disclose that he had received taskings from them.  In May 2013, the FBI conducted three interviews with Lee.  During one of those interviews, Lee admitted that he had received taskings but stated that he had not kept the written requests because they would tend to incriminate him.
The FBI interviewers also confronted Lee with the sensitive document discovered on the thumb drive.  Lee falsely denied that he possessed it, claimed not to know who created it, and denied knowing why it would have been on his computer.  He also denied deleting the document.  Approximately one week later, in another FBI interview, Lee admitted that he created the document in response to two taskings from the IOs and transferred it to a thumb drive.  He also said he thought about giving it to the IOs but never did.
In a January 2018 interview with the FBI, Lee falsely denied that he ever kept any work-related notes at home.  When shown a photocopy of the front covers of the day planner and address book described above, as well as a copy of his handwriting therein, Lee falsely denied that he possessed the notebooks while transiting through Hawaii in August 2012.  Lee also falsely denied that either of the books contained notes from asset meetings but conceded that any such notes would be classified.  Further, Lee falsely denied that he ever put the sensitive document on a thumb drive, notwithstanding the fact that he had admitted having done so when interviewed by FBI agents in May 2013.  Finally, Lee also falsely told the interviewing agents that in drafting this document he was writing down things “more [like] a diary thing,” notwithstanding the fact that in May 2013 he had told FBI agents that he had created the document in response to two taskings from the Chinese IOs.
Lee pleaded guilty to conspiracy to deliver national defense information to aid a foreign government and faces a maximum penalty of life in prison when sentenced on Aug. 23, 2019.  Actual sentences for federal crimes are typically less than the maximum penalties.  A federal district court judge will determine any sentence after taking into account the U.S. Sentencing Guidelines and other statutory factors.
Assistant U.S. Attorney Neil Hammerstrom and Trial Attorneys Patrick T. Murphy and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section are prosecuting the case.

Saturday, March 16, 2019

Former Defense Intelligence Officer Pleads Guilty To Attempted Espionage


The U.S. Justice Department released the below information:
Ron Rockwell Hansen, 58, a resident of Syracuse, Utah, and a former Defense Intelligence Agency (DIA) officer, pleaded guilty today in the District of Utah in connection with his attempted transmission of national defense information to the People’s Republic of China.  Sentencing is set for Sept. 24, 2019. 
Assistant Attorney General for National Security John C. Demers, U.S. Attorney John Huber for the District of Utah and Special Agent in Charge Paul Haertel of the FBI’s Salt Lake City Field Office announced the charges.
Hansen retired from the U.S. Army as a Warrant Officer with a background in signals intelligence and human intelligence.  He speaks fluent Mandarin-Chinese and Russian.  DIA hired Hansen as a civilian intelligence case officer in 2006.  Hansen held a Top Secret clearance for many years, and signed several non-disclosure agreements during his tenure at DIA and as a government contractor.
As Hansen admitted in the plea agreement, in early 2014, agents of a Chinese intelligence service targeted Hansen for recruitment and he began meeting with them regularly in China.  During those meetings, the Chinese agents described to Hansen the type of information that would interest the Chinese intelligence service.  During the course of his relationship with the agents of the Chinese intelligence service, Hansen received hundreds of thousands of dollars in compensation for information he provided them, including information he gathered at various industry conferences.  Between May 24, 2016 and June 2, 2018, Hansen solicited from an intelligence case officer working for the DIA national defense information that Hansen knew the Chinese intelligence service would find valuable.  Hansen agreed to act as a conduit to sell that information to the Chinese.  Hansen advised the DIA case officer how to record and transmit classified information without detection, and explained how to hide and launder any funds received as payment for classified information.  The DIA case officer reported Hansen’s conduct to the DIA and subsequently acted as a confidential human source for the FBI.
As Hansen further admitted in the plea agreement, Hansen met with the DIA case officer on June 2, 2018, and received from that individual documents containing national defense information that Hansen previously solicited.  The documents Hansen received were classified. The information in the documents related to the national defense of the United States in that it related to United States military readiness in a particular region and was closely held by the United States government.  Hansen reviewed the documents, queried the DIA case officer about their contents, and took written notes about the materials relating to the national defense information.  Hansen advised the DIA case officer that he would remember most of the details about the documents he received that day and would conceal some notes about the material in the text of an electronic document that Hansen would prepare at the airport before leaving for China.  Hansen intended to provide the information he received to the agents of the Chinese intelligence service with whom he had been meeting, and Hansen knew that the information was to be used to the injury of the United States and to the advantage of a foreign nation.
Hansen pleaded guilty to one count of attempting to gather or deliver national defense information to aid a foreign government.  The plea agreement calls for an agreed-upon sentence of 15 years.
Special agents of the FBI, IRS, U.S. Department of Commerce, the Department of Defense, U.S. Army Counterintelligence, and the Defense Intelligence Agency were involved in the investigation. 
The prosecution was handled by Assistant U.S. Attorneys Robert A. Lund, Karin Fojtik, Mark K. Vincent and Alicia Cook of the District of Utah, and Trial Attorneys Patrick T. Murphy, Matthew J. McKenzie and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section.  Prosecutors from the U.S. Attorney’s Office for the Western District of Washington assisted with this case.

Saturday, February 16, 2019

One American And One Chinese National Indicted In Tennessee For Conspiracy To Commit Theft Of Trade Secrets And Wire Fraud


The Justice Department released the below information:
A grand jury sitting in Greeneville, Tennessee has returned an indictment against Xiaorong You, a/k/a Shannon You, 56, of Lansing, Michigan, and Liu Xiangchen, 61, of Shandong Province, China for conspiracy to steal trade secrets related to formulations for bisphenol-A-free (BPA-free) coatings.  You was also indicted on seven counts of theft of trade secrets and one count of wire fraud.
Assistant Attorney General National Security John C. Demers, U.S. Attorney J. Douglas Overbey of the Eastern District of Tennessee, FBI Executive Assistant Director for the National Security Branch Jay Tabb, and Special Agent in Charge Troy Sowers of the FBI’s Knoxville Field Office made the announcement.
“The conduct alleged in today’s indictment exemplifies the rob, replicate and replace approach to technological development,” said Assistant Attorney General Demers.  “Xiaorong You is accused of an egregious, premediated theft and transfer of trade secrets worth more than $100 million for the purpose of setting up a Chinese company that would compete with the American companies from which the trade secrets were stolen.  Unfortunately, China continues to use its national programs, like the ‘Thousand Talents,’ to solicit and reward the theft of our nation’s trade secrets and intellectual property, but the Justice Department will continue to prioritize investigations like these, to ensure that China understands that this criminal conduct is not an acceptable business or economic development practice.” 
“Our office is committed to working closely with our federal, state and local partners to identify and prosecute those who engage in illegal and deceptive practices to steal trade secret and protected information from companies who spend millions of dollars to develop it,” said U.S. Attorney Overbey.  “Not only can theft of this information be potentially devastating to our American companies, it could also pose a threat to our overall national and economic security.”
“The facts laid out in this indictment show the conspirators engaged in blatant criminal activity,” said Executive Assistant Director Tabb.  “They didn't stop at going after technical secrets belonging to just one company.  They allegedly targeted multiple companies and made off with trade secrets at an estimated value of almost 120 million dollars.  As this case demonstrates, the FBI is determined to do everything possible to bring to justice those who try to steal secrets belonging to American companies.”
"As this indictment highlights, theft of trade secrets from American companies is an emerging economic threat, even here in East Tennessee," said Special Agent in Charge Sowers.  "The tireless work of our agents and prosecutors in this case underscores the FBI's commitment to protecting American ingenuity."
The BPA-free trade secrets allegedly stolen by these individuals belonged to multiple owners and cost an estimated total of at least $119,600,000 to develop.  Until recently, bisphenol-A (BPA) was used to coat the inside of cans and other food and beverage containers to help minimize flavor loss, and prevent the container from corroding or reacting with the food or beverage contained therein.  However, due to the discovered potential harmful effects of BPA, companies began searching for BPA-free alternatives. These alternatives are difficult and expensive to develop.
From December 2012 through Aug. 31, 2017, You was employed as Principal Engineer for Global Research by a company in Atlanta, which had agreements with numerous companies to conduct research and development, testing, analysis and review of various BPA-free technologies.  Due to her extensive education and experience with BPA and BPA-free coating technologies, she was one of a limited number of employees with access to trade secrets belonging to the various owners.  From approximately September 2017 through June 2018, You was employed as a packaging application development manager for a company in Kingsport, Tennessee, where she was one of a limited number of employees with access to trade secrets belonging to that company.
Details of the conspiracy are included in the indictment on file with the U.S. District Court.  The indictment alleges that You, Liu, and a third co-conspirator formulated a plan in which You would exploit her employment with the two American employers to steal trade secrets and provide the information for the economic benefit of trade secrets the Chinese company that Liu managed, which would manufacture and profit from products developed using the stolen trade secrets.  In exchange, Liu would cause the Chinese company to reward You for her theft, by helping her receive the Thousand Talent and another financial award, based on the trade secrets she stole, and by giving You an ownership share of a new company that would “own” the stolen trade secrets in China.  The conspirators also agreed to compete with U.S. and foreign companies, including some of the owners of the stolen stolen trade secrets, in China and elsewhere, by selling products designed, developed and manufactured using the stolen trade secrets.
The charges contained in this indictment are merely allegations, and the defendants are presumed innocent unless and until proven guilty beyond a reasonable doubt in a court of law. 
The case is being investigated by the FBI’s Knoxville Field Office.
The government’s case is being prosecuted by the Eastern District of Tennessee and the National Security Division’s Counterintelligence and Export Control Section.

Wednesday, November 14, 2018

Former U.S. Navy Captain Pleads Guilty And Former Master Chief Petty Officer Sentenced In Sweeping U.S. Navy Corruption And Fraud Probe


The U.S. Justice Department released the below information:
A retired U.S. Navy captain pleaded guilty to criminal conflict of interest charges and a former U.S. Navy master chief was sentenced to 17 months in prison today on corruption charges.  The defendants are among the latest U.S. Navy officials to plead guilty and be sentenced in the expansive corruption and fraud investigation involving foreign defense contractor Leonard Glenn Francis and his Singapore-based ship husbanding company, Glenn Defense Marine Asia (GDMA).
Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division, U.S. Attorney Adam L. Braverman of the Southern District of California, Director Dermot F. O’Reilly of the Defense Criminal Investigative Service (DCIS) and Director Andrew L. Traver of the Naval Criminal Investigative Service (NCIS) made the announcement.
Jeffrey Breslau, (seen on the left in the above 2012 photo) 52, of Cumming, Georgia, pleaded guilty to one count of criminal conflict of interest before U.S. District Judge Janis Sammartino of the Southern District of California.  Breslau was charged in September 2018.  Retired Master Chief Ricarte Icmat David, 62, of Concepcion, Tarlac, Philippines, was sentenced by Judge Sammartino, who also ordered him to serve a year of supervised release and pay restitution of $30,000.  David was charged in August 2018 and pleaded guilty in September to one count of conspiracy to commit honest services wire fraud.
According to admissions made as part of his guilty plea, from October 2009 until July 2012, Breslau was a captain in the U.S. Navy assigned as director of public affairs for the U.S. Pacific Fleet, headquartered in Pearl Harbor, Hawaii.  As part of his duties, Breslau was involved in devising the U.S. Navy’s public affairs communications strategy, and provided public affairs guidance to Pacific Fleet components and other U.S. Navy commands.  From August 2012 until July 2014, Breslau was assigned to the commanding officer for the Joint Public Affairs Support Element in Norfolk, Virginia, where he was responsible for leading joint crisis communications teams. 
Breslau admitted that from March 2012 until September 2013, while serving in the above roles for the U.S. Navy, he provided Francis with public relations consulting services, including providing advice on how to respond to issues and controversies related to Francis’s ship husbanding business with the U.S. Navy.  These included issues related to port visit costs, allegations of malfeasance such as the unauthorized dumping of waste, disputes with competitors, and issues with Pacific Fleet and contracting personnel.  During the course of his consulting agreement with Francis, Breslau authored, reviewed or edited at least 33 separate documents; authored at least 135 emails providing advice to Francis; provided at least 14 instances of “talking points” in advance of meetings between Francis and high ranking U.S. Navy personnel; and “ghostwrote” numerous emails on Francis’s behalf to be transmitted to U.S. Navy personnel.  During the course of this consulting agreement, Francis paid Breslau approximately $65,000 without Breslau disclosing the agreement to the U.S. Navy, Breslau admitted.    
As part of his guilty plea, David admitted that he was assigned various logistics positions with the U.S. Navy’s Seventh Fleet, including with the Fleet Industrial Supply Center in Yokosuka, Japan from June 2001 to July 2004; on the USS Essex from July 2004 to August 2007; on the USS Kitty Hawk from September 2007 to August 2008; and on the USS George Washington from September 2008 to July 2010.  In these positions, David was responsible for ordering and verifying goods and services for the ships on which he served, including from contractors during port calls.  Throughout this period, David received from Francis various things of value, including five star hotel rooms during every port visit, he admitted.  
David further admitted that he repeatedly facilitated fraud on the United States by allowing Francis and GDMA to inflate the husbanding invoices to bill for services never rendered.  For example, David instructed Francis to inflate invoices for the USS Essex’s anticipated November 2007 port visit to the Philippines.  As David transitioned to a new position aboard the nuclear aircraft carrier USS Kitty Hawk, on or about May 8, 2008, Francis’s company paid approximately 84,637.00 Hong Kong Dollars (HKD) for hotel reservations at the Grand Hyatt Hong Kong for U.S. Navy personnel assigned to the USS Kitty Hawk including 10,396 HKD for David’s four-night stay in a Harbor View Room, David admitted.
Francis pleaded guilty in 2015 to bribery and fraud charges, admitting that he presided over a massive, decade-long conspiracy involving “scores” of U.S. Navy officials, tens of millions of dollars in fraud and millions of dollars in bribes and lavish gifts, including luxury travel, airline upgrades, five-star hotel accommodations, top-shelf alcohol, the services of prostitutes, Cuban cigars, Kobe beef and Spanish suckling pigs.
So far, 33 defendants have been charged and 22 have pleaded guilty, many admitting to accepting things of value from Francis in exchange for helping the contractor win and maintain contracts and overbill the Navy by millions of dollars.
The case was investigated by DCIS, NCIS and the Defense Contract Audit Agency.  The case is being prosecuted by Assistant Chief Brian R. Young of the Criminal Division’s Fraud Section and Assistant U.S. Attorneys Mark W. Pletcher, Patrick Hovakimian and Robert Huie of the Southern District of California. 


You can also read my Counterterrorism magazine piece on the Fat Leonard scandal via the below link:

www.pauldavisoncrime.com/2017/03/my-piece-on-fat-leonard-us-navy-bribery.html 

Saturday, October 20, 2018

Russian National Charged With Interfering In U.S. Political System


The U.S. Justice Department released the below information:
A criminal complaint was unsealed in Alexandria, Virginia, today charging a Russian national for her alleged role in a Russian conspiracy to interfere in the U.S. political system, including the 2018 midterm election. Assistant Attorney General for National Security John C. Demers, U.S. Attorney G. Zachary Terwilliger of the Eastern District of Virginia, and FBI Director Christopher Wray made the announcement after the charges were unsealed.
“Today’s charges allege that Russian national Elena Alekseevna Khusyaynova conspired with others who were part of a Russian influence campaign to interfere with U.S. democracy,” said Assistant Attorney General Demers. “Our nation is built upon a hard-fought and unwavering commitment to democracy. Americans disagree in good faith on all manner of issues, and we will protect their right to do so. Unlawful foreign interference with these debates debases their democratic integrity, and we will make every effort to disrupt it and hold those involved accountable.”
“The strategic goal of this alleged conspiracy, which continues to this day, is to sow discord in the U.S. political system and to undermine faith in our democratic institutions,” said U.S. Attorney Terwilliger. “This case demonstrates that federal law enforcement authorities will work aggressively to investigate and prosecute the perpetrators of unlawful foreign influence activities, and that we will not stand by idly while foreign actors obstruct the lawful functions of our government. I want to thank the agents and prosecutors for their determined work on this case.”
“This case serves as a stark reminder to all Americans: Our foreign adversaries continue their efforts to interfere in our democracy by creating social and political division, spreading distrust in our political system, and advocating for the support or defeat of particular political candidates,” said Director Wray. “We take all threats to our democracy very seriously, and we’re committed to working with our partners to identify and stop these unlawful influence operations. Together, we must remain diligent and determined to protect our democratic institutions and maintain trust in our electoral process.”
According to allegations in the criminal complaint, Elena Alekseevna Khusyaynova, 44, of St. Petersburg, Russia, served as the chief accountant of “Project Lakhta,” a Russian umbrella effort funded by Russian oligarch Yevgeniy Viktorovich Prigozhin and two companies he controls, Concord Management and Consulting LLC, and Concord Catering. Project Lakhta includes multiple components, some involving domestic audiences within the Russian Federation and others targeting foreign audiences in the United States, members of the European Union, and Ukraine, among others.
Khusyaynova allegedly managed the financing of Project Lakhta operations, including foreign influence activities directed at the United States. The financial documents she controlled include detailed expenses for activities in the United States, such as expenditures for activists, advertisements on social media platforms, registration of domain names, the purchase of proxy servers, and “promoting news postings on social networks.” Between January 2016 and June 2018, Project Lakhta’s proposed operating budget totaled more than $35 million, although only a portion of these funds were directed at the United States. Between January and June 2018 alone, Project Lakhta’s proposed operating budget totaled more than $10 million. 
The alleged conspiracy, in which Khusyaynova is alleged to have played a central financial management role, sought to conduct what it called internally “information warfare against the United States.” This effort was not only designed to spread distrust towards candidates for U.S. political office and the U.S. political system in general, but also to defraud the United States by impeding the lawful functions of government agencies in administering relevant federal requirements. 
The conspirators allegedly took extraordinary steps to make it appear that they were ordinary American political activists. This included the use of virtual private networks and other means to disguise their activities and to obfuscate their Russian origin. They used social media platforms to create thousands of social media and email accounts that appeared to be operated by U.S. persons, and used them to create and amplify divisive social and political content targeting U.S. audiences. These accounts also were used to advocate for the election or electoral defeat of particular candidates in the 2016 and 2018 U.S. elections. Some social media accounts posted tens of thousands of messages, and had tens of thousands of followers.
The conspiracy allegedly used social media and other internet platforms to address a wide variety of topics, including immigration, gun control and the Second Amendment, the Confederate flag, race relations, LGBT issues, the Women’s March, and the NFL national anthem debate. Members of the conspiracy took advantage of specific events in the United States to anchor their themes, including the shootings of church members in Charleston, South Carolina, and concert attendees in Las Vegas; the Charlottesville “Unite the Right” rally and associated violence; police shootings of African-American men; as well as the personnel and policy decisions of the current U.S. presidential administration.
The conspirators’ alleged activities did not exclusively adopt one ideological view; they wrote on topics from varied and sometimes opposing perspectives. Members of the conspiracy were directed, among other things, to create “political intensity through supporting radical groups” and to “aggravate the conflict between minorities and the rest of the population.” The actors also developed playbooks and strategic messaging documents that offered guidance on how to target particular social groups, including the timing of messages, the types of news outlets to use, and how to frame divisive messages.
The criminal complaint does not include any allegation that Khusyaynova or the broader conspiracy had any effect on the outcome of an election. The complaint also does not allege that any American knowingly participated in the Project Lakhta operation.

The investigative team received exceptional cooperation from private sector companies, such as Facebook and Twitter.
Assistant U.S. Attorney Jay V. Prabhu and Special Assistant U.S. Attorney Alex Iftimie are prosecuting the case, with assistance of Trial Attorneys Matthew Y. Chang and Patrick T. Murphy of the National Security Division’s Counterintelligence and Export Control Section.
A copy of this press release is located on the website of the U.S. Attorney’s Office for the Eastern District of Virginia. Related court documents and information is located on the website of the District Court for the Eastern District of Virginia or on PACER by searching for Case No. 1:18-mj-464.
A criminal complaint contains allegations that a defendant has committed a crime. Every defendant is presumed to be innocent until proven guilty beyond a reasonable doubt in a court of law.

Friday, September 7, 2018

North Korean Regime-Backed Programmer Charged With Conspiracy To Conduct Multiple Cyber Attacks And Intrusions


The U.S. Justice Department released the below information:
A criminal complaint was unsealed today charging Park Jin Hyok (박진혁; a/k/a Jin Hyok Park and Pak Jin Hek), a North Korean citizen, for his involvement in a conspiracy to conduct multiple destructive cyberattacks around the world resulting in damage to massive amounts of computer hardware, and the extensive loss of data, money and other resources (the “Conspiracy”). 
The complaint alleges that Park was a member of a government-sponsored hacking team known to the private sector as the “Lazarus Group,” and worked for a North Korean government front company, Chosun Expo Joint Venture (a/k/a Korea Expo Joint Venture or “KEJV”), to support the DPRK government’s malicious cyber actions. 
The Conspiracy’s malicious activities include the creation of the malware used in the 2017 WannaCry 2.0 global ransomware attack; the 2016 theft of $81 million from Bangladesh Bank; the 2014 attack on Sony Pictures Entertainment (SPE); and numerous other attacks or intrusions on the entertainment, financial services, defense, technology, and virtual currency industries, academia, and electric utilities. 
The charges were announced by Attorney General Jeff Sessions, FBI Director Christopher A. Wray, Assistant Attorney General for National Security John C. Demers, First Assistant United States Attorney for the Central District of California Tracy Wilkison and Assistant Director in Charge Paul D. Delacourt of the FBI’s Los Angeles Field Office.
In addition to these criminal charges, Treasury Secretary Steven Mnuchin announced today that the Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated Park and KEJV under Executive Order 13722 based on the malicious cyber and cyber-enabled activity outlined in the criminal complaint.
“Today’s announcement demonstrates the FBI’s unceasing commitment to unmasking and stopping the malicious actors and countries behind the world’s cyberattacks,” said FBI Director Christopher Wray.  “We stand with our partners to name the North Korean government as the force behind this destructive global cyber campaign.  This group’s actions are particularly egregious as they targeted public and private industries worldwide – stealing millions of dollars, threatening to suppress free speech, and crippling hospital systems.  We’ll continue to identify and illuminate those responsible for malicious cyberattacks and intrusions, no matter who or where they are.”
 “The scale and scope of the cyber-crimes alleged by the Complaint is staggering and offensive to all who respect the rule of law and the cyber norms accepted by responsible nations,” said Assistant Attorney General Demers. “The Complaint alleges that the North Korean government, through a state-sponsored group, robbed a central bank and citizens of other nations, retaliated against free speech in order to chill it half a world away, and created disruptive malware that indiscriminately affected victims in more than 150 other countries, causing hundreds of millions, if not billions, of dollars’ worth of damage.  The investigation, prosecution, and other disruption of malicious state-sponsored cyber activity remains among the highest priorities of the National Security Division and I thank the FBI agents, DOJ prosecutors, and international partners who have put years of effort into this investigation.”
“The complaint charges members of this North Korean-based conspiracy with being responsible for cyberattacks that caused unprecedented economic damage and disruption to businesses in the United States and around the globe,” said First Assistant United States Attorney Tracy Wilkison. “The scope of this scheme was exposed through the diligent efforts of FBI agents and federal prosecutors who were able to unmask these sophisticated crimes through sophisticated means. They traced the attacks back to the source and mapped their commonalities, including similarities among the various programs used to infect networks across the globe. These charges send a message that we will track down malicious actors no matter how or where they hide. We will continue to pursue justice for those responsible for the huge monetary losses and attempting to compromise the national security of the United States.”
“We will not allow North Korea to undermine global cybersecurity to advance its interests and generate illicit revenues in violation of our sanctions,” said Treasury Secretary Steven Mnuchin.  “The United States is committed to holding the regime accountable for its cyber-attacks and other crimes and destabilizing activities.”
Park is charged with one count of conspiracy to commit computer fraud and abuse, which carries a maximum sentence of five years in prison, and one count of conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison. 
About the Defendant Park and Chosun Expo Joint Venture
According to the allegations contained in the criminal complaint, which was filed on June 8, 2018 in Los Angeles federal court, and posted today:  Park Jin Hyok, was a computer programmer who worked for over a decade for Chosun Expo Joint Venture (a/k/a Korea Expo Joint Venture or “KEJV”).  Chosun Expo Joint Venture had offices in China and the DPRK, and is affiliated with Lab 110, a component of DPRK military intelligence.  In addition to the programming done by Park and his group for paying clients around the world, the Conspiracy also engaged in malicious cyber activities.  Security researchers that have independently investigated these activities referred to this hacking team as the “Lazarus Group.”  The Conspiracy’s methods included spear-phishing campaigns, destructive malware attacks, exfiltration of data, theft of funds from bank accounts, ransomware extortion, and propagating “worm” viruses to create botnets.
The Conspiracy’s Cyber Attacks, Heists, and Intrusions
The complaint describes a broad array of the Conspiracy’s alleged malicious cyber activities, both successful and unsuccessful, and in the United States and abroad, with a particular focus on four specific examples. 
Targeting the Entertainment Industry
In November 2014, the conspirators launched a destructive attack on Sony Pictures Entertainment (SPE) in retaliation for the movie “The Interview,” a farcical comedy that depicted the assassination of the DPRK’s leader.  The conspirators gained access to SPE’s network by sending malware to SPE employees, and then stole confidential data, threatened SPE executives and employees, and damaged thousands of computers.  Around the same time, the group sent spear-phishing messages to other victims in the entertainment industry, including a movie theater chain and a U.K. company that was producing a fictional series involving a British nuclear scientist taken prisoner in DPRK.
Targeting Financial Services
In February 2016, the Conspiracy stole $81 million from Bangladesh Bank.  As part of the cyber-heist, the Conspiracy accessed the bank’s computer terminals that interfaced with the Society for Worldwide Interbank Financial Telecommunication (SWIFT) communication system after compromising the bank’s computer network with spear-phishing emails, then sent fraudulently authenticated SWIFT messages directing the Federal Reserve Bank of NY to transfer funds from Bangladesh to accounts in other Asian countries.  The Conspiracy attempted to and did gain access to several other banks in various countries from 2015 through 2018 using similar methods and “watering hole attacks,” attempting the theft of at least $1 billion through such operations.
Targeting of U.S. Defense Contractors
In 2016 and 2017, the Conspiracy targeted a number of U.S. defense contractors, including Lockheed Martin, with spear-phishing emails. These malicious emails used some of the same aliases and accounts seen in the SPE attack, at times accessed from North Korean IP addresses, and contained malware with the same distinct data table found in the malware used against SPE and certain banks, the complaint alleges. The spear-phishing emails sent to the defense contractors were often sent from email accounts that purported to be from recruiters at competing defense contractors, and some of the malicious messages made reference to the Terminal High Altitude Area Defense (THAAD) missile defense system deployed in South Korea. The attempts to infiltrate the computer systems of Lockheed Martin, the prime contractor for the THAAD missile system, were not successful.
Creation of Wannacry 2.0
In May 2017, a ransomware attack known as WannaCry 2.0 infected hundreds of thousands of computers around the world, causing extensive damage, including significantly impacting the United Kingdom’s National Health Service.  The Conspiracy is connected to the development of WannaCry 2.0, as well as two prior versions of the ransomware, through similarities in form and function to other malware developed by the hackers, and by spreading versions of the ransomware through the same infrastructure used in other cyber-attacks.
Park and his co-conspirators were linked to these attacks, intrusions, and other malicious cyber-enabled activities through a thorough investigation that identified and traced: email and social media accounts that connect to each other and were used to send spear-phishing messages; aliases, malware “collector accounts” used to store stolen credentials; common malware code libraries; proxy services used to mask locations; and North Korean, Chinese, and other IP addresses.  Some of this malicious infrastructure was used across multiple instances of the malicious activities described herein.  Taken together, these connections and signatures—revealed in charts attached to the criminal complaint—show that the attacks and intrusions were perpetrated by the same actors.  
Accompanying Mitigation Efforts
Throughout the course of the investigation, the FBI and the Department provided specific information to victims about how they had been targeted or compromised, as well as information about the tactics and techniques used by the conspiracy with the goals of remediating any intrusion and preventing future intrusions.  That direct sharing of information took place in the United States and in foreign countries, often with the assistance of foreign law enforcement partners. The FBI also has collaborated with certain private cybersecurity companies by sharing and analyzing information about the intrusion patterns used by the members of the conspiracy.
In connection with the unsealing of the criminal complaint, the FBI and prosecutors provided cybersecurity providers and other private sector partners detailed information on accounts used by the Conspiracy in order to assist these partners in their own independent investigative activities and disruption efforts.
The maximum potential sentences in this case are prescribed by Congress and are provided here for informational purposes only, as any sentencings of the defendant will be determined by the assigned judge.
This case is being prosecuted by Assistant United States Attorneys Stephanie S. Christensen, Anthony J. Lewis, and Anil J. Antony of the United States Attorney’s Office for the Central District of California, and DOJ Trial Attorneys David Aaron and Scott Claffee of the National Security Division’s Counterintelligence and Export Control Section.  The Criminal Division’s Office of International Affairs provided assistance throughout this investigation, as did many of the FBI’s Legal Attachés, and foreign authorities around the world.
The charges contained in the criminal complaint are merely accusations and the defendant is presumed innocent unless and until proven guilty. 

Wednesday, August 1, 2018

Three Members of Notorious International Cybercrime Group “Fin7” In Custody For Role In Attacking Over 100 U.S. companies


The U.S. Justice Department released the below information:

Three high-ranking members of a sophisticated international cybercrime group operating out of Eastern Europe have been arrested and are currently in custody facing charges filed in U.S. District Court in Seattle, announced Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division, U.S. Attorney Annette L. Hayes for the Western District of Washington and Special Agent in Charge Jay S. Tabb Jr. of the FBI Seattle Field Office.

According to three federal indictments unsealed today, Ukrainian nationals Dmytro Fedorov, 44, Fedir Hladyr, 33, and Andrii Kopakov, 30, are members of a prolific hacking group widely known as FIN7 (also referred to as the Carbanak Group and the Navigator Group, among other names).  Since at least 2015, FIN7 members engaged in a highly sophisticated malware campaign targeting more than 100 U.S. companies, predominantly in the restaurant, gaming, and hospitality industries.  As set forth in indictments, FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers, which the group used or sold for profit. 

In the United States alone, FIN7 successfully breached the computer networks of companies in 47 states and the District of Columbia, stealing more than 15 million customer card records from over 6,500 individual point-of-sale terminals at more than 3,600 separate business locations.  Additional intrusions occurred abroad, including in the United Kingdom, Australia, and France.  Companies that have publicly disclosed hacks attributable to FIN7 include such familiar chains as Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin and Jason’s Deli.  Additionally in Western Washington, FIN7 targeted other local businesses. 

“The three Ukrainian nationals indicted today allegedly were part of a prolific hacking group that targeted American companies and citizens by stealing valuable consumer data, including personal credit card information, that they then sold on the Darknet,” said Assistant Attorney General Benczkowski.  “Because hackers are committed to finding new ways to harm the American public and our economy, the Department of Justice remains steadfast in its commitment to working with our law enforcement partners to identify, interdict, and prosecute those responsible for these threats.”

“Protecting consumers and companies who use the internet to conduct business – both large chains and small ‘mom and pop’ stores -- is a top priority for all of us in the Department of Justice,” said U.S. Attorney Hayes.  “Cyber criminals who believe that they can hide in faraway countries and operate from behind keyboards without getting caught are just plain wrong.  We will continue our longstanding work with partners around the world to ensure cyber criminals are identified and held to account for the harm that they do – both to our pocketbooks and our ability to rely on the cyber networks we use.”

“The naming of these FIN7 leaders marks a major step towards dismantling this sophisticated criminal enterprise,” said Special Agent in Charge Tabb.  “As the lead federal agency for cyber-attack investigations, the FBI will continue to work with its law enforcement partners worldwide to pursue the members of this devious group, and hold them accountable for stealing from American businesses and individuals.”

Each of the three FIN7 conspirators is charged with 26 felony counts alleging conspiracy, wire fraud, computer hacking, access device fraud, and aggravated identity theft. 

In January 2018, at the request of U.S. officials, foreign authorities separately arrested Ukrainian Fedir Hladyr and a second FIN7 member, Dmytro Fedorov.  Hladyr was arrested in Dresden, Germany, and is currently detained in Seattle pending trial.  Hladyr allegedly served as FIN7’s systems administrator who, among other things, maintained servers and communication channels used by the organization and held a managerial role by delegating tasks and by providing instruction to other members of the scheme.  Hladyr’s trial is currently scheduled for Oct. 22.

Fedorov, a high-level hacker and manager who allegedly supervised other hackers tasked with breaching the security of victims’ computer systems, was arrested in Bielsko-Biala, Poland.  Fedorov remains detained in Poland pending his extradition to the United States.

In late June 2018, foreign authorities arrested a third FIN7 member, Ukrainian Andrii Kolpakov in Lepe, Spain.  Kolpakov, also alleged to be a supervisor of a group of hackers, remains detained in Spain pending the United States’ request for extradition.

According to the indictments, FIN7, through its dozens of members, launched numerous waves of malicious cyberattacks on numerous businesses operating in the United States and abroad.  FIN7 carefully crafted email messages that would appear legitimate to a business’ employee, and accompanied emails with telephone calls intended to further legitimize the email. Once an attached file was opened and activated, FIN7 would use an adapted version of the notorious Carbanak malware in addition to an arsenal of other tools to ultimately access and steal payment card data for the business’ customers. Since 2015, FIN7 sold the data in online underground marketplaces. (Supplemental document “How FIN7 Attacked and Stole Data” explains the scheme in greater detail.)

FIN7 used a front company, Combi Security, purportedly headquartered in Russia and Israel, to provide a guise of legitimacy and to recruit hackers to join the criminal enterprise.  Combi Security’s website indicated that it provided a number of security services such as penetration testing.  Ironically, the sham company’s website listed multiple U.S. victims among its purported clients. 

The charges in the indictments are merely allegations, and the defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

The indictments are the result of an investigation conducted by the Seattle Cyber Task Force of the FBI and the U.S. Attorney’s Office for the Western District of Washington, with the assistance of the Justice Department’s Computer Crime and Intellectual Property Section and Office of International Affairs, the National Cyber-Forensics and Training Alliance, numerous computer security firms and financial institutions, FBI offices across the nation and globe, as well as numerous international agencies. Arrests overseas were executed in Poland by the “Shadow Hunters” from CBŚP (Polish Central Bureau of Investigation); in Germany by the LKA Sachsen - Dezernat 33, (German State Criminal Police Office) and the Polizeidirektion Dresden (Dresden Police); and in Spain the Grupo de Seguridad Logica within the Unidad de Investigación Technologica of the Cuerpo Nacional de Policía (Spanish National Police)..

This case is being prosecuted by Assistant U.S. Attorneys Francis Franze-Nakamura and Steven Masada of the Western District of Washington with assistance from Trial Attorney Anthony Teelucksingh of the Justice Department’s Computer Crime and Intellectual Property Section.