
THREAT‑WATCH
Threat Actors
FIN7
Carbon Spider, Sangria Tempest
A financially motivated group active since around 2013, historically known for targeting point-of-sale systems and, more recently, for links to multiple ransomware affiliate operations.
FIN7 originally focused on stealing payment card data from retail and hospitality point-of-sale systems using spear-phishing to gain initial access. Over its long operational history it has repeatedly reorganized under different front-company identities and has been linked by researchers to ransomware deployment through affiliations with multiple ransomware-as-a-service brands over the years. Its longevity and repeated reinvention make it one of the most persistent financially motivated threat groups tracked by the security industry.
Target Sectors
Retail, hospitality, restaurants, and increasingly a broader range of sectors as it has diversified beyond point-of-sale theft.