Ukrainians hacked restaurants in Lynnwood and Everett

A cybercrime group stole more than 15 million customer records from across the U.S.

EVERETT — The Eastern European hackers were as sophisticated as they were prolific.

Their reach was worldwide.

In the U.S. alone, they breached computer networks of businesses in 47 states, stealing more than 15 million customer credit and debit card records from roughly 3,600 separate businesses, mainly in the restaurant, casino and hospitality industries.

The list of infiltrated businesses included a restaurant off Everett Mall Way and another off 196th Street in Lynnwood in March of 2017, according to a 32-page federal indictment released Wednesday.

The Department of Justice announced Wednesday that three high-ranking members of a cybercrime group have been arrested and are in custody facing charges filed in U.S. District Court in Seattle. Court papers identified the suspects as Ukrainian nationals who are part of a hacking group known as FIN7, also called the Carbanak Group and the Navigator Group.

The trio were arrested in Germany, Poland and Spain, said U.S. Attorney Annette Hayes from the Western District of Washington. They’re accused of wire fraud, conspiracy to commit wire and bank fraud, aggravated identity theft and conspiracy to commit computer hacking, among other charges.

Hayes said she hopes the arrests send a message to “these hackers (who) think they can hide behind keyboards in far away places.”

At the same time, Hayes said, “we are under no illusion that we have taken this group down all together.”

“The investigation is not over,” said Jay Tabb, special agent in charge for the FBI’s Seattle Field Office. The FBI has been working with law enforcement worldwide, he said.

“The naming of these FIN7 leaders marks a major step towards dismantling this sophisticated criminal enterprise,” Tabb said.

FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers that were used or sold on the Darknet for profit. Hacks also occurred in the United Kingdom, Australia, France and other countries. Some of the companies that disclosed being hacked included Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin and Jason’s Deli. One of the restaurants that fell victim to the cyber ploy was a Chipotle along Everett Mall Way, according to an address listed in the federal indictment.

FIN7 crafted email messages that would appear legitimate, sometimes inquiring about making a catering order. Once an attached file was opened and activated, malware would be used to access and steal payment card data.

The tactic is known as spear phishing.

Samples of the emails look benign. A fictitious James Anhil, for instance, in May 2017 was requesting “a takeout order for tomorrow for 11 a.m.” The email instructed the restaurant worker to open a file for the order.

“It’s completely opaque to them,” Tabb said.

FIN7 also used a front company, believed to be headquartered in Russia and Israel, to provide a guise of legitimacy and recruit hackers, according to the Department of Justice. “Ironically,” the justice department wrote, “the sham company’s website listed multiple U.S. victims among its purported clients.”

Eric Stevick: 425-339-3446; stevick@heraldnet.com.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Vernon Streeter looks over the fence at the Skykomish Substation operated by Puget Sound Energy on Monday, Nov. 4, 2024 in Skykomish, Washington. (Olivia Vanni / The Herald)
‘Doesn’t make any sense’: Skykomish residents decry increased outages

Community members are frustrated about power outages and a lack of communication from Puget Sound Energy.

Glacier Peak, elevation 10,541 feet, in the Glacier Peak Wilderness of Mount Baker–Snoqualmie National Forest in Snohomish County, Washington. (Caleb Hutton / The Herald) 2019
2 years later, Glacier Peak seismometers delayed again

The U.S. Forest Service planned to install them in 2023. Now, officials are eyeing 2026.

Washington Attorney General Bob Ferguson speaks at the Snohomish & Island County Labor Council champions dinner on Tuesday, Oct. 10, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Ferguson, WA Democrats prepare for new era of showdowns with Trump

Gov.-elect Bob Ferguson and Attorney General-elect Nick Brown are readying their legal teams.

Benson Boone (Photo provided by AEG Presents)
Monroe’s Benson Boone snags Grammy nomination for Best New Artist

The Monroe High grad this year has opened for Taylor Swift and won an MTV Video Music Award.

Lynnwood
Lynnwood caregiver accused of $674K check fraud

Prosecutors allege Sheila Saluquen defrauded the elderly owner of a car dealership for over a year.

Deborah Rumbaugh
‘Very hostile work environment’: Stanwood-Camano school supe resigns

Superintendent Deborah Rumbaugh said Tuesday she’ll be gone at the end of the school year.

The I-5, Highway 529 and the BNSF railroad bridges cross over Union Slough as the main roadways for north and southbound traffic between Everett and Marysville. (Olivia Vanni / The Herald)
After a monthslong lane closure, Highway 529 bridge to reopen Monday

A five-month closure of the northbound bridge between Everett and Marysville has frustrated drivers. It’ll soon be over.

Melinda Grenier serves patrons at her coffee truck called Hay Girl Coffee during the third annual Arlington Pride event in Arlington, Washington on Sunday, June 2, 2024. (Annie Barker / The Herald)
After long waits for permits, Snohomish County vendors may find relief

Food truck owners can now, with conditions, get some temporary permit fees waived. But those conditions are difficult to meet.

Logo for news use featuring the municipality of Lake Stevens in Snohomish County, Washington. 220118
1 dead after crash into pole in Lake Stevens

A man crashed at the intersection of 91st Avenue NE and Highway 204 just before 9 p.m. Wednesday, officials said.

Snohomish County Superior Courthouse in Everett, Washington on February 8, 2022.  (Kevin Clark / The Herald)
WA court system outage means firearm sales on hold

Buyers must wait until the Washington State Patrol can access databases for background checks.

Snohomish County Council listens to George Skiles talk about his findings in an audit of the Snohomish County Executive Office on Wednesday, Nov. 13, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Audit questions hiring practices in Snohomish County exec’s office

The report was presented to the County Council on Wednesday. It includes several recommendations.

David Hope, a Everett AquaSox ticket holder since 1994, talks about the stadium proposal presented to the public during a community information session on Tuesday, Nov. 12, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett residents voice support, concerns over AquaSox stadium

On Tuesday, the city presented potential plans for a new or renovated stadium and fielded questions.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.