Who are the two major hackers Russia just received in a prisoner swap?
Full article1,515 words · extracted from arstechnica.com · click to collapse
friends in high places
Both men committed major financial crimes—and had powerful friends.
Credit: Getty Images
Credit: Getty Images
As part of today’s blockbuster prisoner swap between the US and Russia, which freed the journalist Evan Gershkovich and several Russian opposition figures, Russia received in return a motley collection of serious criminals, including an assassin who had executed an enemy of the Russian state in the middle of Berlin.
But the Russians also got two hackers, Vladislav Klyushin and Roman Seleznev, each of whom had been convicted of major financial crimes in the US. The US government said that Klyushin “stands convicted of the most significant hacking and trading scheme in American history, and one of the largest insider trading schemes ever prosecuted.” As for Seleznev, federal prosecutors said that he has “harmed more victims and caused more financial loss than perhaps any other defendant that has appeared before the court.”
What sort of hacker do you have to be to attract the interest of the Russian state in prisoner swaps like these? Clearly, it helps to have hacked widely and caused major damage to Russia’s enemies. By bringing these two men home, Russian leadership is sending a clear message to domestic hackers: We’ve got your back.
But it also helps to have political connections. To learn more about both men and their exploits, we read through court documents, letters, and government filings to shed a little more light on their crimes, connections, and family backgrounds.
Vladislav Klyushin
In court filings, Vladislav Klyushin claimed to be a stand-up guy, the kind of person who paid for acquaintances’ medical bills and local monastery repairs. He showed, various letters from friends suggested, “extraordinary compassion, generosity, and civic and charitable commitment.”
According to the US government, though, Klyushin made tens of millions of dollars betting for and against (“shorting”) US companies by using hacked, nonpublic information to make stock trades. He was arrested in 2021 after arriving in Switzerland on a private jet but before he could get into the helicopter that would have taken him to a planned Alps ski vacation.
Klyushin never met his father, he said, a man who drank “excessively” and then was killed during a car theft gone bad when Klyushin was 14. Klyushin’s mother was only 19 when she had him, and the family “occasionally had limited food and clothing.” Klyushin tried to help out by joining the workforce at 13, but he managed to graduate high school, college, and even graduate school, ending up with a doctorate.
After various jobs, including a stint at the Moscow State Linguistic University, Klyushin took a job at M-13, a Moscow IT company that did penetration testing and “Advanced Persistent Threat emulation”—that is, M-13 could be hired to act just like a group of hackers, probing corporate or government cybersecurity. Oddly enough for an infosec company, M-13 also offered investment advice; give them your money and fantastic returns were promised, with M-13 keeping 60 percent of any profits it made.
This was not mere puffery, either. According to the US government, the M-13 team “had an improbable win rate of 68 percent” on its stock trades, and it “generated phenomenal, eight-figure returns,” turning $9 million into $100 million (“a return of more than 900 percent during a period in which the broader stock market returned just over 25 percent,” said the government).
But Klyushin and his associates were not stock-picking wizards. Instead, they had begun hacking Donnelly Financial and Toppan Merrill, two “filing agents” that many large companies use to submit quarterly and annual earning reports to the Securities and Exchange Commission. These reports were uploaded to the filing agents’ systems several days before their public release. All the M-13 team had to do was liberate the files early, read through them, and buy up stocks of companies that had overperformed while shorting stocks of companies that had underperformed. When the reports went public a few days later and the markets responded to them, the M-13 team made huge returns. Klyushin himself earned several tens of millions of dollars between 2018 and 2020.
To avoid consequences for this flagrantly illegal behavior, all Klyushin had to do was stay in Russia—or, at least, not visit or transit through a country that might extradite him to the US—and he could keep buying up yachts, cars, and real estate. That’s because Russia—along with China and Iran, the largest three sources of hackers who attack US targets—doesn’t do much to stop attacks directed against US interests. As the US government notes, none of these governments “respond to grand jury subpoenas and rarely if ever provide the kinds of forensic information that helps to identify cybercriminals. Nor do they extradite their nationals, leaving the government to rely on the chance that an indicted defendant will travel.”
But when you have tens of millions of dollars, you often want to spend it abroad, so Klyushin did travel—and got nabbed upon his arrival in Switzerland. He was extradited to the US in 2021, was found guilty at trial, and was sentenced to nine years in prison and the forfeiture of $34 million. It is unclear if the US government was able to get its hands on any of that money, which was stashed in bank accounts around the world.
Klyushin’s fellow conspirators have wisely stayed in Russia, so with his release as part of today’s prisoner swap, all are likely to enjoy their ill-gotten gains without further consequence. One of Klyushin’s colleagues at M-13, Ivan Ermakov, is said to be a “former Russian military intelligence officer” who used to run disinformation programs “targeting international anti-doping agencies, sporting federations, and anti-doping officials.”
Roman Seleznev
Images of Seleznev with stacks of cash were found on his laptop following his 2014 arrest in the Maldives. Credit: Department of Justice
Roman Seleznev from Vladivostok, Russia, was involved in much more pedestrian, lowbrow cybercrime: stealing credit card numbers, bundling them together into easy-to-purchase packages, and selling them on “carding” websites from 2009 to 2013. But he did it at a massive scale that made him a prime target for US law enforcement.
His technique was to hack point-of-sale computers, often at small businesses, and siphon off the credit card data as the businesses rang up their normal transactions. This earned him “tens of millions of dollars,” according to the US government, but it cost his victims “more than $169 million in losses” and forced some small businesses, like Seattle’s Broadway Grill, into bankruptcy.
Like Klyushin, Seleznev couldn’t resist spending his money outside of Russia. In 2014, he was picked up by police in the Maldives, where he had a laptop that held “more than 1.7 million stolen credit card numbers.” He may have believed he was safe because the Maldives had no formal extradition agreement with the US, but the Americans convinced the Maldives government to arrest and extradite Seleznev anyway. (Russia called this a “kidnapping.”) He was sent to the US, where he was hit with a blizzard of charges in multiple districts and sentenced to several overlapping prison sentences—the longest one was for 27 years. At the time, this was the harshest hacking sentence ever issued by an American judge.
In a letter filed with one of the courts where he was being prosecuted, Seleznev attributed his decisions in part to a difficult childhood in which he watched his mother die from alcohol poisoning and in which he was injured in a Moroccan terrorist bombing, which took him more than a year to recover from and led to his divorce. “Please understand I was a desperate child who grew into a desperate man,” he wrote.
In 2017, while preparing for a sentencing in Georgia, Seleznev wrote another short letter to his judge in which he said that he was “sincerely sorry for all that I did to the victims of my crimes. My actions are inexcusable. I can only attribute those actions to my own stupidity, poor judgment, and wrong decisions… I was a desperate, lonely child trying to survive in this world—however, I have chosen the wrong path. Instead of creating things I was destroying them. I thought it was an easy way; it appears it was the wrong way.”
Seleznev went on to say that he had been working 15-hour days in the Georgia prison where he was incarcerated, “sweeping and mopping floors, serving trays, doing laundry for inmates, [and] painting walls,” for which he received $18.48 every month. Acknowledging that this was a small sum, Seleznev said that he wanted the money put toward his restitution because it is “important for me to know that I am paying my debt to the American society.”
Why did Russia care so much about getting a major credit card thief back? As The New York Times noted in a 2017 story about him, “Mr. Seleznev is the son of Valery Seleznev, an outspoken member of the Duma, the lower house of the Russian Parliament, and a close political ally of President Vladimir V. Putin of Russia.”
Listing image: Getty Images
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/08/who-are-the-two-major-hackers-russia-just-received-in-a-prisoner-swap/