FIN6 is a financially motivated cybercrime group known for breaking into retailers and hospitality businesses to steal payment-card data. FireEye reported in 2016 that some FIN6-linked breaches were associated with more than 10 million cards identified on an underground card shop. Its methods later expanded beyond in-store point-of-sale (PoS) systems to include e-commerce checkout pages and, according to Mandiant, ransomware.
What is FIN6?
MITRE ATT&CK identifies FIN6 as group G0037 and describes it as a cybercrime group that steals payment-card data to sell for profit. The group has also been associated with the names Magecart Group 6, ITG08, Skeleton Spider, TAAL and Camouflage Tempest. Its reported targets have included retailers and hospitality businesses.
FireEye Threat Intelligence reported in 2016 that FIN6-linked victim data had appeared on an underground card shop as far back as 2014. In some cases, the shop displayed more than 10 million cards associated with breaches linked to the group. That figure describes cards identified on the shop in FireEye’s reporting; it is not a claim that every card was taken in one incident or that all were necessarily stolen directly by FIN6.
How did FIN6 steal cards from PoS systems?
FIN6’s reported activity involved gaining access to a business network, moving through it toward payment systems, collecting card data, and sending that data out for monetization. MITRE ATT&CK procedure examples document the following behaviors:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Gain access and expand it: Use of valid accounts and exploitation for privilege escalation, followed by network and service discovery.
- Reach systems that handle payments: Use of Windows services and remote services to move within a compromised environment.
- Collect card data: Scripts and malware were used to collect payment-card data from compromised PoS systems. Visa’s February 2019 report identifies TRINITY, also called FrameworkPOS, in FIN6 PoS compromises.
- Stage and transfer data: MITRE records compression and remote staging, followed by HTTP POST exfiltration. Its examples also include PowerShell, Cobalt Strike and antivirus disabling.
- Sell stolen data: FireEye traced FIN6-linked data to an underground card shop, where listings sometimes exceeded 10 million cards.
How did the group move from PoS attacks to e-commerce skimming?
Visa’s February 2019 report describes a shift in approach when FIN6’s PoS deployment was blocked: investigators observed malicious code injected into e-commerce checkout pages to steal card-not-present (CNP) data. In this kind of attack, the target is the online checkout experience rather than a payment terminal in a store. Visa wrote that FIN6 “has fully incorporated targeting CNP environments into their criminal methodology.”
The distinction matters to merchants because securing PoS devices alone does not protect payment details entered on a website. Checkout code and the systems that can change it are also sensitive payment assets.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
How did FIN6 make money, and what changed with ransomware?
In the card-theft operation documented by FireEye, stolen payment data was offered through an underground card shop. Mandiant reported on April 4, 2019, that FIN6 had also expanded into ransomware deployments to monetize access to organizations that did not have payment-card data worth stealing. The reporting describes ransomware as an additional way to profit from compromised access, not as a replacement that proves the group stopped stealing cards.
| Approach | What is targeted | How the activity is monetized | Evidence described |
|---|---|---|---|
| PoS compromise | Payment-card data on compromised in-store systems | Sale of stolen card data on an underground card shop | MITRE ATT&CK; FireEye Threat Intelligence, 2016 |
| E-commerce skimming | Card-not-present data entered on checkout pages | Card-data theft and sale | Visa, February 2019 |
| Ransomware | Organizations whose access could be monetized even without payment-card data | Ransomware deployment | Mandiant, April 4, 2019 |
What can merchants do to reduce the risk?
The controls below are defensive measures mapped to the behaviors reported by MITRE, Visa and Mandiant. They are not a guarantee against compromise; they aim to make access harder, expose unauthorized changes sooner and support a faster response.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Protect PoS and checkout environments: Segment payment systems from general business networks and limit which users and services can reach them. Treat online checkout code and the systems that deploy it as high-value assets.
- Watch for unauthorized checkout changes: Use application-integrity monitoring and review or alert on unexpected scripts and changes to payment pages.
- Limit and protect administrative credentials: Restrict privileged access to named users and systems, and monitor for unusual account use or remote-service activity.
- Use endpoint detection and response: Look for suspicious PowerShell or other script activity, discovery behavior, attempts to disable antivirus, and unexpected data staging.
- Monitor outbound traffic: Investigate unusual transfers, including unexpected HTTP POST activity from PoS or checkout-related systems.
- Maintain an incident-response plan: Define how to isolate affected systems, investigate potential payment-data exposure, and restore trusted PoS and checkout environments.
These measures address risks to payment information; merchants should also follow the payment-security requirements applicable to their business and payment environment.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




