UN

FIN6

High ConfidenceMedium Threat

Skeleton Spider • ITG08 • Magecart Group 6

FIN6 is a financially motivated cybercrime group that has been active since at least 2015, initially focusing on stealing payment card data from point-of-sale systems in retail and hospitality sectors. The group has since evolved to include ransomware deployment, using Ryuk and LockerGoga in their operations. FIN6 is known for their methodical approach, often spending months inside victim networks conducting reconnaissance before monetizing their access. They have stolen millions of payment card records and caused significant financial damage through ransomware attacks.

Origin: Unknown
Sponsor: Cybercriminal (No State Sponsor)
Active: 2015 - Present
Victims: 200+ organizations
Advanced
Active
Financial Gain
Risk Assessment
68
Composite Risk Score
Medium Risk
ARCS Compliance72
Escalation Risk70
Grievance Index60
Infrastructure Impact68
History & Evolution

FIN6 is a financially motivated cybercrime group that has been active since at least 2015, initially focusing on stealing payment card data from point-of-sale systems in retail and hospitality sectors. The group has since evolved to include ransomware deployment, using Ryuk and LockerGoga in their operations. FIN6 is known for their methodical approach, often spending months inside victim networks conducting reconnaissance before monetizing their access. They have stolen millions of payment card records and caused significant financial damage through ransomware attacks.

Targeting

Target Sectors

RetailHospitalityE-commerce

Target Regions

United StatesEurope
Attribution & Affiliations

Attributed to Cybercriminal (No State Sponsor) (Unknown). Attribution confidence: High.

Intelligence Assessment
Medium
Threat Level
Moderately
Targeting
Moderately
Adaptability
Medium
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

FIN6 is expected to continue operations targeting Retail sectors.

Timeline of Key Events
2015
Major

First observed activity of FIN6

2024
Moderate

Continued active operations