Federal prosecutors charged four Vietnamese nationals in an indictment alleging that FIN9, a financially motivated cybercrime group, attacked U.S. companies from at least May 2018 through October 2021. The U.S. Attorney’s Office for the District of New Jersey unsealed the indictment on June 20, 2024, saying victim companies collectively suffered more than $71 million in losses.
The figure describes alleged losses across companies—not necessarily $71 million in cash personally taken by the defendants. The indictment contains accusations, and the available case materials do not establish convictions, guilty pleas, sentencing, arrests, or a later disposition.
What the FIN9 indictment says
The case was filed in the U.S. District Court for the District of New Jersey under reference 2019R00508/APTNSL on January 11, 2024, then unsealed five months later. According to the Justice Department announcement, the alleged campaign targeted companies across the United States and combined network intrusion with theft and resale of valuable digital and financial assets.
Prosecutors describe FIN9 as a financially motivated criminal group. The allegations focus on phishing, vendor compromise, theft of information and employee benefits, gift-card fraud, identity abuse and laundering—not on espionage or ransomware as the primary business model.
#1 Best Overall
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
The four defendants and their alleged charges
DOJ identified the defendants and aliases as follows. Membership in FIN9 and the conduct listed remain allegations.
| Defendant | Alias listed by DOJ | Charge categories DOJ says applied |
|---|---|---|
| Ta Van Tai | “Quynh Hoa,” “Bich Thuy” | Computer-fraud/extortion conspiracy; wire-fraud conspiracy; two intentional-damage counts; money-laundering conspiracy; aggravated identity theft; identity-fraud conspiracy |
| Nguyen Viet Quoc | “Tien Nguyen” | Computer-fraud/extortion conspiracy; wire-fraud conspiracy; two intentional-damage counts; aggravated identity theft; identity-fraud conspiracy; not the money-laundering count listed for the other defendants |
| Nguyen Trang Xuyen | None listed | Computer-fraud/extortion conspiracy; wire-fraud conspiracy; two intentional-damage counts; money-laundering conspiracy; not the identity-theft counts listed for Tai and Quoc |
| Nguyen Van Truong | “Chung Nguyen” | Computer-fraud/extortion conspiracy; wire-fraud conspiracy; two intentional-damage counts; money-laundering conspiracy; not the identity-theft counts listed for Tai and Quoc |
The names, aliases and count differences come from the indictment and DOJ’s accompanying release.
Alleged attack chain
The government’s account describes a progression from access to monetization:
Rank #2
- Protects the whole household. Secure your entire home network on up to 10 devices simultaneously with one subscription. Works with Windows, macOS, iOS, Android, Linux, Amazon Fire TV, and web browsers.
- Offers thousands of VPN servers worldwide. Connect to thousands of ultra-fast VPN servers in 224+ locations for smooth 4K streaming, low-ping gaming, and quick downloads.
- Stops common online threats. Enable our next-gen antivirus to catch malicious downloads, stop dangerous phishing links, and block intrusive ads to keep your browsing experience clean and fast.
- Protects your private details. Stop hackers and network snoops from intercepting your sensitive personal information, banking details, or passwords while you browse.
- Generates, stores, and auto-fills passwords. Our password manager keeps track of your passwords so you don’t have to. Sync your passwords across every device you own and get secure access to your accounts with just a few clicks.
- Initial access: phishing and other unauthorized-access methods allegedly opened a path into company systems.
- Third-party compromise: prosecutors allege that trusted vendors or service providers were compromised to reach downstream organizations. A supply-chain compromise does not, by itself, mean a vendor knowingly participated.
- Discovery: after entering networks, the defendants allegedly looked for employee-benefit systems, gift-card information, personally identifiable information, credit-card data and other non-public company information.
- Extraction or diversion: the alleged activity included stealing or attempting to steal data, digital employee benefits and funds.
- Conversion and concealment: DOJ says stolen gift cards were sold, while stolen identities were used to open cryptocurrency-exchange and server-hosting accounts. Tai, Xuyen and Truong allegedly sold gift cards, including through a peer-to-peer cryptocurrency marketplace account registered under a false name.
In practical terms, the alleged chain was: phishing or vendor access → internal discovery → benefits or payment-data abuse → resale, cryptocurrency transactions or identity-based concealment.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What the group allegedly targeted
- Non-public company information
- Employee benefits and rewards
- Digital gift cards and gift-card data
- Employee and customer personally identifiable information
- Credit-card information
- Company funds
This combination matters because it extends beyond a conventional data breach. A compromised rewards platform can create direct financial losses even when attackers do not empty a bank account.
The alleged gift-card incident
One example attributed to the indictment and reported by BleepingComputer involved an employee-recognition and rewards system. Approximately 7,617 gift cards worth about $1 million were allegedly issued to accounts controlled by the attackers. That incident illustrates one alleged operation; it is not an explanation for the entire $71 million figure.
Rank #3
- Protects the whole household. Secure your entire home network on up to 10 devices simultaneously with one subscription. Works with Windows, macOS, iOS, Android, Linux, Amazon Fire TV, and web browsers.
- Offers thousands of VPN servers worldwide. Connect to thousands of ultra-fast VPN servers in 224+ locations for smooth 4K streaming, low-ping gaming, and quick downloads.
- Stops common online threats. Enable our next-gen antivirus to catch malicious downloads, stop dangerous phishing links, and block intrusive ads to keep your browsing experience clean and fast.
- Protects your private details. Stop hackers and network snoops from intercepting your sensitive personal information, banking details, or passwords while you browse.
- Sends alerts when your data leaks. Our Dark Web Monitor Pro will warn you if your email addresses or credit card details are spotted in underground hacker sites, so you can take action to protect your accounts and payment information.
What “more than $71 million in losses” means
DOJ says victim companies collectively suffered more than $71 million in losses. The wording does not establish that the defendants personally obtained $71 million, that every dollar was a direct cash transfer, or that the amount represents one company’s loss.
The alleged loss total can encompass several forms of harm, including:
- Direct theft or diversion of funds
- Employee-benefit and gift-card value taken or misdirected
- Fraud enabled by stolen identities or payment-card information
- Costs and business losses associated with compromised systems and data
The indictment and DOJ announcement are the controlling sources for the allegation; public summaries do not provide a defendant-by-defendant allocation of the total.
Rank #4
- ONGOING PROTECTION Download instantly & install protection for 20 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Charges and statutory maximum penalties
DOJ listed these statutory maximums:
| Charge | Maximum stated by DOJ |
|---|---|
| Conspiracy to commit fraud, extortion and related activity involving computers | Up to five years |
| Conspiracy to commit wire fraud | Up to 20 years |
| Each intentional-damage-to-a-protected-computer count | Up to 10 years per count |
| Conspiracy to commit money laundering | Up to 20 years |
| Aggravated identity theft | Mandatory consecutive two-year term |
| Conspiracy to commit identity fraud | Up to 15 years |
These are charge-specific statutory ceilings, not predicted sentences. They are not added mechanically to produce a certain outcome. Any sentence would depend on convictions, the federal sentencing guidelines, judicial findings and other factors.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Timeline
| Date | What the record shows |
|---|---|
| At least May 2018 | Prosecutors allege the conspiracy began. |
| May 2018–October 2021 | The alleged intrusions, thefts and attempted thefts occurred during this period. |
| January 11, 2024 | The indictment was filed in the District of New Jersey. |
| June 20, 2024 | The indictment was unsealed and DOJ announced the charges. |
| June 24–25, 2024 | BleepingComputer and The Hacker News published secondary coverage. |
Secondary overviews are available from The Hacker News and BleepingComputer.
Investigation, jurisdiction and legal status
The case is being brought in federal court in New Jersey. DOJ credited the FBI Newark Cyber Squad and FBI Little Rock Cyber Squad with investigative work.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- Dual USB-A & USB-C Bootable Drive – works on almost any desktop or laptop (Legacy BIOS & UEFI). Run Kali directly from USB or install it permanently for full performance. Includes amd64 + arm64 Builds: Run or install Kali on Intel/AMD or supported ARM-based PCs.
- Fully Customizable USB – easily Add, Replace, or Upgrade any compatible bootable ISO app, installer, or utility (clear step-by-step instructions included).
- Ethical Hacking & Cybersecurity Toolkit – includes over 600 pre-installed penetration-testing and security-analysis tools for network, web, and wireless auditing.
- Professional-Grade Platform – trusted by IT experts, ethical hackers, and security researchers for vulnerability assessment, forensics, and digital investigation.
- Premium Hardware & Reliable Support – built with high-quality flash chips for speed and longevity. TECH STORE ON provides responsive customer support within 24 hours.
An indictment is a formal accusation, not a finding of guilt. DOJ expressly stated that the defendants are presumed innocent unless and until proven guilty. The cited materials establish the filing and allegations but do not independently verify a later conviction, plea, sentencing, extradition or arrest status for any defendant.
Why the case matters for companies and finance teams
The allegations show why financial controls cannot stop at banks and payment processors. Organizations should treat employee-rewards platforms, gift-card issuance, vendor credentials and identity data as money-moving systems.
Quick Recap
- Restrict and continuously review third-party access.
- Require strong authentication and anomaly alerts for rewards and benefits administrators.
- Monitor unusual gift-card volume, recipient changes and rapid issuance.
- Separate approval and fulfillment privileges for benefits and payments.
- Watch for accounts opened with employee or customer identities at cryptocurrency and hosting providers.
- Have an incident process that links security, finance, legal and affected vendors.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




