CASE DOSSIER
sentenced
U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
Docket: 2:11-cr-00070 Court: U.S. District Court for the Western District of Washington Opened: 2011-03-03 Sector: Retail, Hospitality, Small Business
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$169.0 million
Caused verified financial fraud losses of $169 million to 3,700 financial institutions.
Techniques
4
Verified mappings
Defendants
1
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the Western District of Washington.
- Primary Target Sector: Retail, Hospitality, Small Business.
- Documented Financial Loss: $169.0 million.
- 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.
Procedural & Incident Timeline
2014-07-05 arrest
Seleznev arrested by U.S. Secret Service in the Maldives with a laptop containing 1.7 million stolen credit cards.
2016-08-25 verdict
Jury finds Seleznev guilty of 38 federal felony counts including wire fraud and computer hacking.
2017-04-21 sentencing
Sentenced to 324 months (27 years) in federal prison, the longest computer hacking sentence in U.S. history at the time, and ordered to pay $169,879,276 restitution.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Roman Valerevich Seleznev | Russian Federation | sentenced | 324 mo | None | Mastermind behind POS point-of-sale malware operations. Sentenced to 27 years in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1046 | Network Service Discovery Discovery | "Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389." | Trial Transcript Day 4, Page 82 | reviewed |
| T1110 | Brute Force Credential Access | "He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems." | Trial Transcript Day 5, Page 112 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops." | Trial Exhibit 14-A | reviewed |
| T1588.002 | Obtain Tool Resource Development | "Seleznev purchased specialized memory scraping tools and POS card harvesting scripts from Russian underground forums." | Trial Transcript Day 6, Page 140 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding), No. 2:11-cr-00070 (U.S. District Court for the Western District of Washington 2011), https://cyberattackcaselibrary.pages.dev/cases/us-v-seleznev-track2/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-seleznev-track2" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>