Putin/Trump Arms Control then Sanctions

Leaked Document Reveals Putin Lobbied Trump on Arms Control

Vladimir Putin presented President Donald Trump with a series of requests during their private meeting in Helsinki last month, including new talks on controlling nuclear arms and prohibiting weapons in space, according to a Russian document obtained by POLITICO.

A page of proposed topics for negotiation, not previously made public, offers new insights into the substance of the July 16 dialogue that even Trump’s top advisers have said they were not privy to at the time. Putin shared the contents of the document with Trump during their two-hour conversation, according to a U.S. government adviser who provided an English-language translation. Details in the single page agenda for the meeting shows Mr. Putin remains interested in maintaining continued cooperation with the US on nuclear weapons.

A source who did not wish to be identified after obtaining the page translated from Russian into English by Politico, said: “This is, ‘We want to get out of the dog house and engage with the US on a broad range of security issues.” The document fails to address questions raised about what the Russian government meant last month when it said “cooperation in Syria” would be discussed between the two presidents and what they agreed to as a result.

Further murkiness fanned the flames of suspicion after Dan Coats, US Director of National Intelligence, told reporters he was “not in a position to either understand fully or talk about what happened in Helsinki.” Politico

Primer saludo entre Donald Trump y Vladimir Putin en el G20 | El Imparcial photo

Treaty Structure: The Treaty between the United States of America and the Russian Federation on Measures for the Further Reduction and Limitation of Strategic Offensive Arms also known as the New START Treaty.

Strategic Offensive Reductions: The Treaty between the United States of America and the Russian Federation on Measures for the Further Reduction and Limitation of Strategic Offensive Arms, also known as the New START Treaty, entered into force on February 5, 2011. Under the Treaty, the United States and Russia must meet the Treaty’s central limits on strategic arms by February 5, 2018; seven years from the date the Treaty entered into force. Each Party has the flexibility to determine for itself the structure of its strategic forces within the aggregate limits of the Treaty. These limits are based on the rigorous analysis conducted by Department of Defense planners in support of the 2010 Nuclear Posture Review.

Aggregate limits:

  • 700 deployed intercontinental ballistic missiles (ICBMs), deployed submarine-launched ballistic missiles (SLBMs), and deployed heavy bombers equipped for nuclear armaments;
  • 1,550 nuclear warheads on deployed ICBMs, deployed SLBMs, and deployed heavy bombers equipped for nuclear armaments (each such heavy bomber is counted as one warhead toward this limit);
  • 800 deployed and non-deployed ICBM launchers, SLBM launchers, and heavy bombers equipped for nuclear armaments.

Verification and Transparency: The Treaty has a verification regime that combines appropriate elements of the 1991 START Treaty with new elements tailored to the limitations and structure of this Treaty. Verification measures under the Treaty include on-site inspections and exhibitions, data exchanges and notifications related to strategic offensive arms and facilities covered by the Treaty, and provisions to facilitate the use of national technical means for treaty monitoring. To increase confidence and transparency, the Treaty also provides for an annual exchange of telemetry on an agreed number of ICBM and SLBM launches.

Treaty Duration: The Treaty’s duration is ten years, unless superseded by a subsequent agreement. The Parties may agree to extend the Treaty for a period of no more than five years. The Treaty includes a withdrawal clause that is standard in arms control agreements. The 2002 Moscow Treaty terminated when the New START Treaty entered into force.

No Constraints on Missile Defense and Conventional Strike: The Treaty does not constrain testing, development, or deployment of current or planned U.S. missile defense programs or long-range conventional strike capabilities.

What is the difference between a “Type One” and a “Type Two” inspection?

The New START Treaty provides for 18 on-site inspections per year. There are two basic types of inspections. Type One inspections focus on sites with deployed and non-deployed strategic systems; Type Two inspections focus on sites with only non-deployed strategic systems. Permitted inspection activities include confirming the number of reentry vehicles on deployed ICBMs and deployed SLBMs, confirming numbers related to non-deployed launcher limits, counting nuclear weapons onboard or attached to deployed heavy bombers, confirming weapon system conversions or eliminations, and confirming facility eliminations. Each side is allowed to conduct ten Type One inspections and eight Type Two inspections annually.

Meanwhile, standing with lab results and in solidarity with Britain:

FNC: Russia used “chemical or biological weapons” to try to assassinate a former British spy, the U.S. said on Wednesday, adding that new sanctions would be imposed on the country for the attack.

“Following the use of a ‘Novichok’ nerve agent in an attempt to assassinate UK citizen Sergei Skripal and his daughter Yulia Skripal, the United States, on August 6, 2018, determined under the Chemical and Biological Weapons Control and Warfare Elimination Act of 1991 (CBW Act) that the Government of the Russian Federation has used chemical or biological weapons in violation of international law or has used lethal chemical or biological weapons against its own nationals,” the State Department said in a statement.

“Following a 15-day Congressional notification period, these sanctions will take effect upon publication of a notice in the Federal Register, expected on or around August 22, 2018,” the department continued.

Skripal and his daughter were poisoned by the military-grade nerve agent in the British town of Salisbury in March.

Britain earlier accused Russia of being behind the attack, which the Kremlin has vehemently denied.

On March 15, President Trump, French President Emmanuel Macron and German Chancellor Angela Merkel and British Prime Minister Theresa May said in a joint statement that they “abhorred” the attack against Skripal.

“It is an assault on U.K. sovereignty and any such use by a State party is a clear violation of the Chemical Weapons Convention and a breach of international law. It threatens the security of us all,” the statement read.

Skripal was discharged from a U.K. hospital in May, following his daughter’s April release.

Since the March attack, two other British nationals with no ties to Russia have been poisoned by the substance.

The Process for Fallen Troops’ Identities

When her duty day is over, Army Sgt. 1st Class Jennifer Owen often wonders if she did enough to help identify fallen service members.

A lab worker examines personal effects that may have belonged to a fallen service member.

Army Sgt. 1st Class Jennifer Owen, a morgue noncommissioned officer for the Defense POW/MIA Accounting Agency, examines a personal effect that may have belonged to a fallen service member in a laboratory at Joint Base Pearl Harbor-Hickam, Hawaii, March 12, 2018. Army photo by Sean Kimmons

As the noncommissioned officer in charge of the morgue at the Defense POW/MIA Accounting Agency, which is tasked to account for more than 82,000 Americans missing from past conflicts, she analyzes human remains and personal effects in hopes to close a cold case.

“At the end of the day, I have to be able to look in the mirror and say I’ve done my best,” she said. “And when I get up in the morning, I say I’m going to do better, because these families have been waiting years and years.”

Owens is one of about 100 service members and civilians who work at the agency’s laboratories here and at Offutt Air Force Base in Nebraska. Each year, the labs identify the remains of around 200 Americans that are then reunited with families.

On Aug. 1, more than 50 cases containing remains believed to be those of American service members were provided to DPAA by North Korea.

The remains are now undergoing further analysis and identification at the labs.

The painstaking work, which can take months to years to complete, is Owen’s passion. Whenever a positive identification comes in, she said, it is as if the service member’s name is given back.

‘These Are All Heroes’

“What drives me the most is that these are heroes,” she said, looking across a lab holding hundreds of unknown remains. “These are all heroes [who] have a name and a family.”

Each year, DPAA conducts up to 80 investigation and recovery team missions throughout the world to pinpoint last known locations of missing Americans and to attempt to excavate their remains.

“The work is complex, the work is difficult, and it takes that dedication, that passion … to be able to perform this solemn obligation that we make to the nation and to the families,” said Kelly McKeague, the agency’s director.

The joint agency, which employs many service members and veterans, has agreements with nearly 50 nations that assist in its missions, he added.

Most of the missing fell at World War II battle sites in the Pacific region. There are also almost 7,700 service members unaccounted for from the Korean War, with the majority believed to be in North Korea.

DPAA teams were allowed to conduct missions in North Korea from 1996 to 2005, but operations were halted as diplomatic relations deteriorated in the region. Agency officials hope these missions could soon start up again.

Before he became the agency’s lab director, John Byrd had the opportunity to help recover Americans who fought in North Korea at the Battle of Unsan. The 1950 battle pitted Chinese forces against American and South Korean troops.

When remains are identified by his staff it is always a testament to good field and lab work that solved the decades-old case, Byrd said.

“It’s extremely gratifying,” he said, “and it kind of keeps you grounded where you know why you’re here and why you’re doing this work.”

DNA Testing

A majority of DPAA cases involve some type of DNA testing. Samples are taken from the remains and sent to the Armed Forces DNA Identification Lab in Delaware.

To help this process, family members who have a missing loved one are encouraged to provide a DNA sample that will serve as a comparison.

If no reference samples are on file, a battalion of professional genealogists working for service casualty offices will try to locate family members.

Many times their starting point is the service member’s home address from the 1940s, if they served in World War II. This makes it extremely difficult to track down a living family member as the years pass on.

“It’s one of the greatest challenges of all. How do you find close family members of a missing serviceman from 1944?” Byrd asked. “It’s not easy. Some [cases] we run into dead-ends and we can’t find anybody.”

The Defense Department has kept dental records of troops dating back to World War I that can be used to help in the identification process.

In 2005, the agency also discovered another method that has proved successful. Many troops who served in early conflicts had to get chest X-rays as part of a tuberculosis screening when they first signed up.

Like the dental records, these radiographs were stored in a warehouse by the DoD. DPAA later obtained thousands of copies of them. Lab personnel use them as a comparison tool, since the shape of each person’s chest is different.

“The process of comparing this induction chest x-ray to an x-ray we take from the remains is analogous to doing fingerprint comparison,” Byrd said. “It’s a very similar kind of mindset that you take when you look at the two side-by-side; you’re looking for commonalities and differences.”

When a service member is identified, family members often come to the lab so they can participate in escorting the remains back home, he said. For those who work at the lab, those family member visits make the months or years of work seem worthwhile.

“When you have a family member come in and the staff who actually worked on the case get to meet them, they get to see the tangible results of their hard work,” Byrd said. “It’s definitely a boost to their morale.”

In the Field

Before that sort of closure can start for families, recovery teams spend weeks at a time doing the grunt work of excavating sites.

Army Capt. Brandon Lucas, who serves as a team leader, recalled his team digging nearly 20 feet into the ground in Laos in search of an F-4 Phantom fighter pilot who vanished during the Vietnam War.

A lab worker holds an item under a magnifying panel.

Army Sgt. 1st Class Jennifer Owen, a morgue noncommissioned officer for the Defense POW/MIA Accounting Agency, examines a personal effect that may have belonged to a fallen service member in a laboratory at Joint Base Pearl Harbor-Hickam, Hawaii, March 12, 2018. Army photo by Sean Kimmons

While no remains were found on that mission, they were still able to confidently close the site and shift efforts elsewhere.

Then there was another mission in Slovenia, where the tail gunner of a bomber aircraft from World War II went missing.

When his plane crashed, the gunner was the only one in his aircrew killed. Residents later buried him next to a church.

As Lucas’ team arrived at the site, the townspeople still knew about the crash and the gunner. Residents regularly visited his team, often bringing Lucas and the others food and drinks. An elderly woman even told him that for decades she would clean the grave site once a week.

When his team recovered the remains, a somber tone spread through the community.

“A lot of them actually shed tears when we found the remains,” Lucas said. “It was special to them and it was special to me.”

The poignant moment, along with others he has experienced during missions, galvanized the meaning of the mission for him.

“I’m potentially bringing back a fallen comrade,” Lucas said. “I would want to know that if it was me lost out there somebody is trying to recover me and give my family closure.”

Maritime Recovery

Recovery missions also extend out into the sea, where many service members have disappeared as a result of aircraft crashes or ships sunk.

While she served as commander of the 8th Theater Sustainment Command, Army Maj. Gen. Susan A. Davidson was an advocate for her unit to support the solemn mission.

The unit regularly supplies DPAA with highly-trained Army divers from the 7th Engineer Dive Detachment, who often work on the sea floor with no visibility and use a suction hose to remove loose sediment from recovery sites.

On a barge, team members then sift through the sediment for the remains or personal effects of those missing.

When divers returned to Hawaii, she encouraged them to share their experiences and what they got out of the mission with others in the unit.

“They come back a different person and they have a different respect for our Army and for what we do,” Davidson said.

Back at the lab, Owen and others strive to identity those heroes who have been found.

“I feel that I am part of something so much bigger that I can contribute to,” she said.

Chinese/Russian Subs Prowling East Coast, Atlantic

In a press gaggle today, a member of the media asked Secretary of Defense Mattis:

Q:  Mr. Secretary, you stated you’re watching submarines in the North Atlantic and elsewhere.  But are Russia and China putting more submarines out to look at the United States than they have since the Cold War?   

SEC. MATTIS:  Yes, we always keep an eye on the — on the submarines at sea.  And I’d prefer not to say anymore than that.  Thanks.

Humm, okay let’s go deeper.

The Navy reactivated a the fleet responsible for overseeing the East Coast and the North Atlantic. The 2nd Fleet was deactivated in 2011 and Secretary Mattis upped the defense strategy earlier this year.

We do know that the Russians are snooping around all undersea telecommunications cables used by NATO. The Russian submarines are equipped with anti-submarine missiles and little is published about the Chinese submarines. Meanwhile, the United States has deployed patrols using manned and unmanned surface ships, attack submarines and air surveillance by the P-8 Poseidon, a sub hunting warplane.

Crew | USS SOUTH DAKOTA SSN 790

The most advanced US advanced fast attack submarine named the USS South Dakota is equipped with the most advanced technology including advanced stealth features.

“China is improving the lethality and survivability of its attack submarines and building quieter, high-end diesel and nuclear-powered submarines,” he said.
Both China and Russia have also increased their presence in the Indo-Asia-Pacific region, where Harris said 230 of the world’s 400 foreign submarines are operating.
Roughly 160 of those 230 submarines belong to China, North Korea, and Russia, according to Harris.
Forbes said the United States must also develop a strategy to counter Chinese and Russian activity in “gray zones” where they are incrementally expanding their presence by strategically “fighting and competing” through military posturing.
China’s claims in the South China Sea represent one glaring example as to how they’ve been able to successfully implement this type of strategy in a way that allows them to expand their military reach without engaging in direct confrontation, according to Forbes.

Meanwhile, a significant upgrade has taken place and that is to SOSUS.

Now, in what may be the biggest upgrade to the Navy’s fixed undersea surveillance system since the Cold War, General Dynamics has been recently awarded a contract by the Office of Naval Research to develop the Deep Reliable Acoustic Path Exploitation System (DRAPES). DRAPES appears to be part of a suite of upgrades to the Navy’s submarine detection capabilities to cope with expanding fleets of advanced submarines around the world.

When the Cold War ended, the U.S. Navy no longer faced a “peer threat” to its control of the seas and many capabilities and weapons necessary for defeating advanced adversary ships and submarines were decommissioned. Research for more advanced follow-on technology was also put on hold. After operating 30 undersea surveillance sites around the world during the Cold War, the Navy has only three operational today. But as Russia, and especially China, have developed larger and more advanced submarine fleets, the U.S. Navy has had to re-learn old Cold War anti-submarine warfare competencies while developing new capabilities to tackle more challenging modern submarine technology.

While the Navy says relatively little about the advanced sub-hunting capabilities of the Integrated Undersea Surveillance System (IUSS), of which SOSUS is a part, some IUSS systems have received more public attention. The afloat Surveillance Towed Array Sensor System (SURTASS) is a small fleet of civilian-crewed ships that carry sensitive towed listening (passive) arrays that can detect submarines from great distances. These ships grabbed headlines in 2009 when the SURTASS ship USNS Impeccable was harassed by Chinese Maritime Militia while operating in the vicinity of China’s South China Sea submarine bases on Hainan Island. The SURTASS ships have also received technical upgrades since the Cold War. The introduction of the Low Frequency Active (LFA) capability, an “active” system that transmits low frequency “pings” that bounce off of submarine hulls and are then picked up by the existing passive SURTASS arrays dramatically increases their ability to detect submarines at great distances.

By contrast, little is known publicly about the SOSUS networks after the Cold War. Defense Systems reports that DRAPES, like SOSUS, will be a fixed passive listening system with a new communications capability to transmit its data. Mobile systems like SURTASS have the advantage of being able to get closer to possible contacts and follow them, but can only be in one place at a time, and must eventually return to port. Fixed systems like SOSUS, and now DRAPES, have the advantage of providing permanent coverage over target areas and then “cueing” a mobile sensor capability, like a ship or aircraft, to zero in on a submarine it detects.

One reason there were 30 IUSS sites during the Cold War is that the SOSUS systems had to be connected to collection facilities by underwater cable, requiring sites to be relatively local to the target area. But DRAPES will apparently use a new underwater communications system to transmit the acoustic data it collects to the three remaining Navy Operational Processing Facilities (NOPFs). These facilities combine data from the static SOSUS networks and SURTASS ships to provide “detection, localization, and tracking of submarines.” DRAPES’ ability to provide wide coverage from a fixed location in the ocean, apparently without the need for additional NOPF facility footprints, would be a substantial improvement over the old SOSUS network.

As China and Russia have asserted themselves anew as “pacing competitors,” as described by Undersecretary of Defense Robert Work, the U.S. Navy has taken a renewed interest in its traditional Cold War antisubmarine warfare mission. Together, DRAPES and SURTASS promise to provide a persistent, long-range ability to detect adversary submarines around the globe. Using cueing data from those platforms, improved local anti-submarine assets like the P-8 Poseidon sub hunter aircraft (which replaces the 50 year-old P-3 Orion) and surface combatants with new, improved towed sonar arrays of their own, like the Multi-Function Towed Array, can then close on a target, and track or engage it as needed.

Russia Posturing to Own Space, then China?

The U.S. military will soon be using lasers to shoot down ...

photo

Right now, miles above your head, there are fleets of robotic, weaponized satellites poised to do battle as the world’s superpowers await the opening salvo in a very real cosmic chess match.

When it comes to Russia, the real cause for concern surrounds a mysterious object known cryptically as 2014-28E. The object first appeared in space soon after the launch of three Russian military communication satellites. Initially, many believed 2014-28E was just another piece of debris left over from the launch. Not long afterward, however, this hunk of space junk began to swiftly change orbit, demonstrating an onboard propulsion system. What exactly 2014-28E is is still unknown, as the Russians have remained tight-lipped on the matter. Many experts fear that these actions signal that the Russians have revived their allegedly-defunct operation known as Istrebitel Sputnik (meaning “Satellite Fighter”), a covert Soviet-era ASAT program.

Russian and Chinese officials have continuously accused the United States of spying on the Chinese Space Station with a top-secret space toy known officially as X-37B. This craft is essentially an unmanned version of the Space Shuttle with a payload bay that’s roughly the size of a pickup truck bed. However, what exactly will be carried and what has been carried on its previous three missions is classified. So too is the entire X-37B budget. Many aeronautic experts dispute claims that the U.S. is using this craft to spy on the Chinese Space Station — but, the complete lack of transparency from U.S. officials hasn’t helped thaw frigid relations between the involved parties.

And the X-37B definitely isn’t the only trick the U.S. has up its proverbial sleeve. Some of America’s most sophisticated ASAT technology is in development as we speak. DARPA, the research and development wing of the U.S. Department of Defense, is now quickly moving along with its Phoenix initiative. The program is based around the concept of a series of robotic craft with the ability to repair damaged satellites from the scraps parts of other defunct satellites already in orbit. Again, from a foreign military perspective, if a satellite has the ability to build something, that satellite also has the intrinsic ability to dismantle something — say, an enemy satellite. More here from Digital Trends.

Russia Will Fight to Be World’s Top Space Power, Agency Chief Says

Russia is ready to do “serious battle” for the title of leading space power in the world, the head of the country’s state space agency has said.

Moscow’s Roscosmos has become the subject of some ridicule, following budget cuts and high-profile setbacks, including a recent botched launch that resulted in the loss of a multimillion dollar silo of satellites. The agency still regards itself as heir to Russia’s Soviet legacy of space exploration and Russian President Vladimir Putin has repeatedly urged officials to recapture that status in the world, telling agency employees last month that Roscosmos needed “breakthrough successes” to do so.

Roscosmos Director Dmitry Rogozin gave a defiant message on the agency’s ambitions.

“We are not looking to surrender leadership in space to anyone,” Rogozin said at the opening of a satellite equipment manufacturing plant in Yaroslavl region. The director, who served as Russia’s deputy prime minister until May, admitted that the agency had “fallen behind from the leading positions” in recent years.

08_06_Rogozin Moscow Mayor Sergei Sobyanin (front left) gestures at Russian President Vladimir Putin (front center) and others as they visit a space exhibition in Moscow, on April 12. Maxim Shipenkov/AFP/Getty Images

Roscosmos unveiled a brand new spaceport in eastern Russia in 2016, although Putin reportedly reprimanded senior officials in private after the launching ceremony, which he had gone to watch, suffered a 24-hour delay. More here.

Just two years ago:

So why is there so much global interest in space at the moment, including in Australia, and what are countries around the world doing up there right now?

Space remains ‘hugely contested’ in 2018

Modern militaries rely on satellites that feed them vital intelligence.

As a result, “counterspace” weapons have become a rising area of interest, and earlier this year, US intelligence agencies warned that China and Russia were both working on “destructive counterspace weapons” for use in a future conflict.

The potential weapons US intelligence agencies were concerned about included both ground-launched missiles capable of taking out enemy satellites, as well as “directed-energy weapons” that could blind or damage the sensors on satellite instruments.

The US intelligence agencies said in their report that both China and Russia would probably have operational weapons within a few years.

China last month launched a communications satellite named Magpie Bridge that is currently sitting in a special orbit near the moon, giving it a view of both the Earth and the so-far-unexplored dark side of the Moon.

That feat was praised in official Chinese state media Xinhua as a “world first”.

The plan is for the satellite to beam continuous images of the dark side of the moon, with China looking set to become the first country to land a rover there later this year.

China is also planning on setting up a permanent robotic base on the lunar surface in the next 10 years, and is hoping for a manned mission in the 2030s.

Eligible Receiver 97, Red Team Being Applied Today for Cyber Hacks?

An early classified Defense Department cybersecurity exercise named “Eligible Receiver 97” (ER97) featured a previously unpublicized series of mock terror attacks, hostage seizures, and special operations raids that went well beyond pure cyber activities in order to demonstrate the potential scope of threats to U.S. national security posed by attacks in the cyber domain, according to recently declassified documents and a National Security Agency (NSA) video posted today by the nongovernmental National Security Archive at The George Washington University.

“Joint Exercise Eligible Receiver 97”, run during the Clinton presidency, is frequently pointed to as a critical event in the United States’ appreciation of threats in cyber space. The exercise led directly to the formation of what would eventually become United States Cyber Command (USCYBERCOM) and informed key studies such as the formative Marsh Report on critical infrastructure protection. Despite the significance of ER97, however, very little is publicly known about the exercise itself.

ER97 involved an NSA Red Team playing the role of North Korean, Iranian and Cuban hostile forces whose putative aim was to attack critical infrastructure as well as military command-and-control capabilities to pressure the U.S. government into changing its policies toward those states. An interagency Blue Team was required to provide recommendations to personnel enacting defensive responses. Until now, only two phases out of three (infrastructure and command-and-control) had been publicly known.  The video and documents posted today provide new details about the third phase involving kinetic attacks in the physical domain – i.e. more traditional terrorist assaults on civilian targets – which were built upon intelligence gathered through the Red Team’s successes. Read more here on the declassified files.

*** With all the cyber terror going on today in the United States, are we doing more ‘red team’ exercises? Perhaps some of those tactics are paying off many years later.

3 Carbanak (FIN7) Hackers Charged With Stealing 15 Million ...

Three Members of Notorious International Cybercrime Group “Fin7” in Custody for Role in Attacking Over 100 U.S. Companies

Victim Companies in 47 U.S. States; Used Front Company ‘Combi Security’ to Recruit Hackers to Criminal Enterprise

          SEATTLE – Three high-ranking members of a sophisticated international cybercrime group operating out of Eastern Europe have been arrested and are currently in custody facing charges filed in U.S. District Court in Seattle, announced U.S. Attorney Annette L. Hayes, Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division and Special Agent in Charge Jay S. Tabb Jr. of the FBI’s Seattle Field Office.

According to three federal indictments unsealed today, Ukrainian nationals Dmytro Fedorov, 44, Fedir Hladyr, 33, and Andrii Kolpakov, 30, are members of a prolific hacking group widely known as FIN7 (also referred to as the Carbanak Group and the Navigator Group, among other names).  Since at least 2015, FIN7 members engaged in a highly sophisticated malware campaign to attack more than 100 U.S. companies, predominantly in the restaurant, gaming, and hospitality industries.  As set forth in the indictments, FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers which were used or sold for profit.

In the United States alone, FIN7 successfully breached the computer networks of businesses in 47 states and the District of Columbia, stealing more than 15 million customer card records from over 6,500 individual point-of-sale terminals at more than 3,600 separate business locations.  Additional intrusions occurred abroad, including in the United Kingdom, Australia, and France.  Companies that have publicly disclosed hacks attributable to FIN7 include such familiar chains as Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin and Jason’s Deli.  Additionally here in Western Washington FIN7 targeted the Emerald Queen Casino (EQC) and other local businesses.  The Emerald Queen Casino was able to stop the intrusion and no customer data was stolen.

“Protecting consumers and companies who use the internet to conduct business – both large chains and small ‘mom and pop’ stores — is a top priority for all of us in the Department of Justice,” said U.S. Attorney Annette L. Hayes.  “Cyber criminals who believe that they can hide in faraway countries and operate from behind keyboards without getting caught are just plain wrong.  We will continue our longstanding work with partners around the world to ensure cyber criminals are identified and held to account for the harm that they do – both to our pocketbooks and our ability to rely on the cyber networks we use.”

“The three Ukrainian nationals indicted today allegedly were part of a prolific hacking group that targeted American companies and citizens by stealing valuable consumer data, including personal credit card information, that they then sold on the Darknet,” said Assistant Attorney General Benczkowski.  “Because hackers are committed to finding new ways to harm the American public and our economy, the Department of Justice remains steadfast in its commitment to working with our law enforcement partners to identify, interdict, and prosecute those responsible for these threats.”

“The naming of these FIN7 leaders marks a major step towards dismantling this sophisticated criminal enterprise,” said Special Agent in Charge Jay S. Tabb Jr., of the FBI’s Seattle Field Office.  “As the lead federal agency for cyber-attack investigations, the FBI will continue to work with its law enforcement partners worldwide to pursue the members of this devious group, and hold them accountable for stealing from American businesses and individuals.”

Each of the three FIN7 conspirators is charged with 26 felony counts alleging conspiracy, wire fraud, computer hacking, access device fraud, and aggravated identity theft.

In January 2018, at the request of U.S. officials, foreign authorities separately arrested Ukrainian Fedir Hladyr and a second FIN7 member, Dmytro Fedorov.  Hladyr was arrested in Dresden, Germany, and is currently detained in Seattle pending trial.  Hladyr allegedly served as FIN7’s systems administrator who, among other things, maintained servers and communication channels used by the organization and held a managerial role by delegating tasks and by providing instruction to other members of the scheme.  Hladyr’s trial is currently scheduled for October 22, 2018.

Fedorov, a high-level hacker and manager who allegedly supervised other hackers tasked with breaching the security of victims’ computer systems, was arrested in Bielsko-Biala, Poland.  Fedorov remains detained in Poland pending his extradition to the United States.

In late June 2018, foreign authorities arrested a third FIN7 member, Ukrainian Andrii Kolpakov in Lepe, Spain.  Kolpakov, also is alleged to be a supervisor of a group of hackers, remains detained in Spain pending the United States’ request for extradition.

According to the indictments, FIN7, through its dozens of members, launched numerous waves of malicious cyberattacks on numerous businesses operating in the United States and abroad.  FIN7 carefully crafted email messages that would appear legitimate to a business’ employee, and accompanied emails with telephone calls intended to further legitimize the email. Once an attached file was opened and activated, FIN7 would use an adapted version of the notorious Carbanak malware in addition to an arsenal of other tools to ultimately access and steal payment card data for the business’ customers. Since 2015, many of the stolen payment card numbers have been offered for sale through online underground marketplaces. (Supplemental document “How FIN7 Attacked and Stole Data” explains the scheme in greater detail.)

FIN7 used a front company, Combi Security, purportedly headquartered in Russia and Israel, to provide a guise of legitimacy and to recruit hackers to join the criminal enterprise.  Combi Security’s website indicated that it provided a number of security services such as penetration testing.  Ironically, the sham company’s website listed multiple U.S. victims among its purported clients.

 

The charges in the indictments are merely allegations, and the defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

The indictments are the result of an investigation conducted by the Seattle Cyber Task Force of the FBI and the U.S. Attorney’s Office for the Western District of Washington, with the assistance of the Justice Department’s Computer Crime and Intellectual Property Section and Office of International Affairs, the National Cyber-Forensics and Training Alliance, numerous computer security firms and financial institutions, FBI offices across the nation and globe, as well as numerous international agencies. Arrests overseas were executed in Poland by the “Shadow Hunters” from CBŚP (Polish Central Bureau of Investigation); in Germany by LKA Sachsen – Dezernat 33, (German State Criminal Police Office) and the Polizeidirektion Dresden (Dresden Police); and in Spain by the Grupo de Seguridad Logica within the Unidad de Investigación Technologica of the Cuerpo Nacional de Policía (Spanish National Police).

This case is being prosecuted by Assistant U.S. Attorneys Francis Franze-Nakamura and Steven Masada of the Western District of Washington, and Trial Attorney Anthony Teelucksingh of the Justice Department’s Computer Crime and Intellectual Property Section.

how_fin7_attacked_and_stole_data.pdf