FireEye has identified a set of financially motivated intrusion
operations being carried out by an actor we have dubbed FIN10.
Beginning as early as 2013 and continuing through at least 2016, we
have observed FIN10 primarily targeting casinos and mining
organizations in North America, with a focus on Canada.
We believe the primary goal of FIN10 is to steal corporate business
data, files, records, correspondence and customer PII for the purposes
of extorting victim organizations for the non-release of stolen data.
The group primarily demands as ransom in Bitcoins that equates to
anywhere from nearly $125,000 to more than $600,000.
Download our report,
FIN10: Anatomy
of a Cyber Extortion Operation, to learn more about FIN10, including:
Additionally, FireEye provides many tips for dealing and interacting
with threat actors such as FIN10. Some of these recommendations include:
Although FireEye has observed FIN10 primarily targeting casinos and
mining organizations in North America (predominately in Canada), all
organizations from around the world must be prepared to detect and
respond to threats from this group and other bad actors.
Learn more
about FIN10 and how best to prevent, detect and respond to breaches.