FIN7 has been profiled by multiple security and law-enforcement sources as a Russian-speaking cybercrime group that evolved from large-scale payment-card theft into ransomware operations. The group is described as operating with a corporate-like structure, using front companies including Combi Security, IPC, and Bastion Secure to recruit technical staff, and relying on phishing, software supply-chain compromise, and mailed BadUSB devices for initial access. Researchers and government reporting tie FIN7 to a broad toolkit including Carbanak, Bateleur, Griffon/Harpy, Lizar, Cobalt Strike, and PowerShell-based tooling, while intelligence reporting says investigators obtained insight into the gang’s internal organization, infrastructure, victim targeting, and member communications.
U.S. prosecutors said FIN7 compromised hundreds of companies, breached more than 6,500 point-of-sale terminals across over 3,600 business locations, and stole more than 20 million payment-card records, causing losses estimated above $1 billion; in one case, high-level member Andrii Kolpakov was sentenced to seven years in prison. Separate reporting and government assessments say FIN7 later moved into big-game-hunting ransomware and was linked to Sodinokibi, DarkSide, and later BlackMatter, though attribution to ALPHV remained unconfirmed by ANSSI. Reporting on DarkSide’s collapse after the Colonial Pipeline incident also showed affiliates publicly disputing unpaid ransom shares on the XSS forum, underscoring the instability inside the ransomware ecosystem tied to groups that security researchers have associated with FIN7.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
ANSSI says Bastion Secure was identified in October 2021 as a likely FIN7 front company. It copied the website of Convergent Network Solutions Ltd and recruited programmers, system administrators, and reverse engineers.
On June 24, 2021, the U.S. Department of Justice announced that Andrii Kolpakov was sentenced to seven years in prison and ordered to pay $2.5 million in restitution. The sentence related to his role as a high-level FIN7 hacker and manager.
A second claim appeared four days after the first, and three more claims were posted on March 19 and March 20, according to BleepingComputer. The later four claims did not receive a reply from the forum administrator.
BleepingComputer reports that the first DarkSide affiliate claim for unpaid ransom share was issued on March 14 on the XSS forum. The administrator later approved compensation from DarkSide's 22-bitcoin escrow deposit.
BleepingComputer reports that DarkSide emerged in August 2020 and quickly became one of the most prolific ransomware groups. It later made at least $90 million in nine months.
The DOJ says Andrii Kolpakov pleaded guilty in June 2020 to conspiracy to commit wire fraud and conspiracy to commit computer hacking. The plea concerned his role as a high-level FIN7 member.
ANSSI assesses that FIN7 shifted from payment-card theft to big-game-hunting ransomware operations beginning in 2020. The report links the group to Sodinokibi affiliation and to operating DarkSide and later BlackMatter.
ANSSI says that since 2020, FIN7 has used mailed BadUSB devices sent through the U.S. postal system to employees in HR, IT, and management roles. The devices were disguised with fake BestBuy gift cards and executed PowerShell commands when connected.
The DOJ states that Andrii Kolpakov was involved with FIN7 from at least April 2016 until his arrest in June 2018. He managed other hackers tasked with breaching victim systems.
ANSSI reports that after the arrest of around 50 Carbanak members in 2015, the group fragmented into smaller groups including FIN7 and Cobalt Gang. This positioned FIN7 as a distinct but related successor grouping.
According to ANSSI and DOJ, since 2015 FIN7 stole more than 20 million payment-card records from over 6,500 point-of-sale terminals. The stolen data was sold on underground marketplaces or used for fraud.
The DOJ says that since at least 2015, FIN7 conducted a sophisticated malware campaign against hundreds of U.S. companies, especially in restaurant, gambling, and hospitality sectors. The campaign ultimately breached businesses in all 50 states and Washington, D.C.
ANSSI identifies Combi Security as a fake cybersecurity company used by FIN7 to recruit low-cost intrusion specialists. It was active from 2015 to 2018.
ANSSI says Carbanak began using the Carbanak backdoor in February 2014. The malware was described as a variant of Anunak and ultimately related to Carbep.
The ANSSI report says Carbanak targeted point-of-sale systems used in hotels and restaurants in the United States and Europe in 2014. This marked expansion into payment-card theft from hospitality environments.
The ANSSI report states that Carbanak was active from 2013 to 2015, conducting financially motivated attacks against banking information systems and payment systems. It stole more than $45 million and carried out fraudulent SWIFT transfers and ATM manipulation.
BleepingComputer says DarkSide abruptly shut down about a week before the article was published, telling affiliates it had lost access to its public-facing servers. The group said the shutdown followed pressure from the United States after the Colonial Pipeline attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcebleepingcomputer.com
Open sourceprodaft.com
Open sourceprodaft.com
Open sourceprodaft.com
Open sourceprodaft.com
Open sourceprodaft.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.