Russian hacker Roman Seleznev sentenced to 27 years for theft, sale of 2M+ CC numbers resulting in $170M+ in losses, the longest hacking-related sentence in US
Nicole Perlroth / New York Times :
Context & Ripple Effects
The sentencing closes out a case that has been running through federal court since Seleznev was convicted last August on charges of stealing and selling more than 2 million credit card numbers, where the exposure was up to 40 years. The 27-year term lands at the top of the range prosecutors sought and makes him the benchmark for hacking sentences in the US.
It also fits a string of convictions against Russian nationals in US courts: Vladimir Drinkman pleaded guilty in a scheme that took 160M+ card numbers, and the builder of Citadel malware drew five years for infections that caused $500M+ in losses.
First-order effects
- Seleznev moves from conviction to a 27-year term — the longest hacking-related sentence in US history — removing any realistic prospect of a short stay or negotiated release.
- Federal prosecutors now have a precedent tying sentence length directly to dollar losses ($170M+) rather than just technical intrusion counts.
Second-order effects
- Other Russian defendants in the pipeline face a starker plea calculus: Drinkman's cooperation path versus Seleznev's trial-and-maximum-sentence path shows cooperating early can be worth decades.
- The gap between Seleznev's 27 years and the five-year terms given lower-loss offenders like the Citadel malware builder gives defense lawyers a quantified sentencing grid built on loss figures.
Third-order effects
- If extradition-plus-harsh-sentencing remains the pattern — echoed later by the five-year sentence given a Russian citizen extradited in 2019 for tax-preparer hacks — large-scale financial cybercrime gets treated in US courts closer to violent-crime severity than to traditional computer crime.
- For Russian-speaking carding networks, the structural message is that selling stolen data at scale, not just breaching systems, is what triggers maximum exposure, pushing monetization further underground or toward jurisdictions without extradition.
The trend: US courts are escalating sentences for large-scale financial cybercrime into record territory, using extradition to project that reach onto hackers operating from Russia.