Russian hacker Roman Seleznev sentenced to 27 years for theft, sale of 2M+ CC numbers resulting in $170M+ in losses, the longest hacking-related sentence in US
Federal prosecutors have yet to capture or convict the foreign computer criminals believed to be behind the hackings of big retailers like Target and Neiman Marcus.
Context & Ripple Effects
This sentencing closes out a case that has been running through federal court since Seleznev was convicted last August on charges of stealing and selling more than two million credit card numbers. It lands alongside a string of related prosecutions: Vladimir Drinkman's guilty plea in a scheme that took over 160 million card numbers, and a five-year sentence handed to the builder of Citadel malware, which infected some 11 million machines.
The New York Times framing matters as much as the number: prosecutors still have not captured or convicted the foreign criminals believed responsible for the retailer breaches at Target and Neiman Marcus. So the record sentence is being imposed on defendants the US can actually get its hands on, while the biggest alleged offenders remain out of reach.
First-order effects
- Seleznev receives 27 years — the longest hacking-related sentence in US history — after facing a potential 40 years at conviction, setting a new ceiling for what federal courts will impose for card-theft operations.
- The named victims' losses, $170M-plus across two million-plus card numbers, now have a judicial endpoint even though the retailers whose breaches remain unsolved get no equivalent closure.
Second-order effects
- For other Russian nationals in US crosshairs, the calculus shifts toward plea deals and cooperation: Drinkman pleaded guilty rather than face trial, and the later five-year sentence for a Russian extradited in 2019 shows extradition plus prosecution remains the repeatable playbook.
- Rival malware and carding operators absorb a deterrence signal calibrated by these sentences — five years for Citadel, 27 for card theft — which may push sentencing negotiations toward earlier cooperation from arrested suspects.
Third-order effects
- If the pattern holds, US cybercrime enforcement consolidates around whoever can be physically seized or extradited, producing long sentences for mid-tier operatives while the principals behind major retail breaches stay beyond reach — an asymmetry between punishment delivered and harm attributed.
- A track record of escalating sentences gives federal prosecutors a precedent ladder for future hacking cases, making multi-decade terms the reference point rather than the exception.
The trend: US courts are treating multi-decade prison terms for captured Russian cybercriminals as their primary deterrent instrument, even as the perpetrators of the largest retail breaches remain unprosecuted.