Russian computer hackers operating in Colorado and 15 other states used data-mining viruses to steal thousands of credit card numbers from U.S. residents in 20 states
They sold them on the darknet for more than $3.6 million.
Criminals use software to access hidden websites and blogs on the darknet so they can operate anonymously.
A web of conspirators in Colorado and 15 other states funneled money back to accounts set up in the Russian Federation.
Source: https://www.denverpost.com/2018/02/26/russian-hackers-colorado-stolen-credit-card-numbers/
TPRM report: https://scoringcyber.rankiteo.com/company/moneygram-international
"id": "mon19578622",
"linkid": "moneygram-international",
"type": "Data Leak",
"date": "02/2018",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Thousands',
'location': ['Colorado',
'15 other states',
'20 states'],
'type': 'Individuals'}],
'attack_vector': 'Data-mining viruses',
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': 'Thousands',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Credit card numbers'},
'description': 'Russian computer hackers operating in Colorado and 15 other '
'states used data-mining viruses to steal thousands of credit '
'card numbers from U.S. residents in 20 states. They sold them '
'on the darknet for more than $3.6 million. Criminals use '
'software to access hidden websites and blogs on the darknet '
'so they can operate anonymously. A web of conspirators in '
'Colorado and 15 other states funneled money back to accounts '
'set up in the Russian Federation.',
'impact': {'data_compromised': 'Credit card numbers',
'financial_loss': '$3.6 million',
'payment_information_risk': 'High'},
'initial_access_broker': {'data_sold_on_dark_web': True,
'entry_point': 'Data-mining viruses'},
'motivation': 'Financial Gain',
'threat_actor': 'Russian computer hackers',
'title': 'Russian Hackers Steal Credit Card Numbers and Sell on Darknet',
'type': 'Data Breach'}