RESCATOR▊
In December 2013, forensics teams picking through the Target breach — some 40 million payment cards — found a name written inside the malware itself: Rescator. The same handle was, at that exact moment, selling those cards by the million in his own underground shop and advertising them as "our base," carder-speak for stolen it myself. Brian Krebs chased the handle for a decade: a false trail to Odessa, a $10,000 offer not to publish, the Home Depot encore, then a cold case. In December 2023 Krebs named a Moscow man, Mikhail Shefel — who by then had legally changed his surname to Lenin. And in November 2024 the quarry did the one thing nobody on the wanted-poster side of this genre ever does: he called the reporter, confirmed it all on video chat, complained that he was broke, blamed the whole masterminding on somebody else — and pitched Krebs on going into business together.
Hi, how are you? … Maybe we can open business?
Mikhail Shefel — the man who sold the Target and Home Depot cards — messaging Brian Krebs the day after confirming he was Rescator, proposing a joint venture with the reporter who spent a decade unmasking him
- WHO
- Mikhail Shefel — "Rescator," "MikeMike," later "Getsend"; b. May 28, 1986, Moscow; legally changed his surname to Lenin in 2018 FACT
- SCENE
- Former vice president of payments at ChronoPay, the Russian high-risk payment processor of Spam Nation fame; by his own account, technical director of the long-running Lampeduza carding community and proprietor of rescator[.]la and its sibling card shops
- THE DRAMA
- The handle stamped inside the Target-breach malware and the seller of the ~40 million Target cards (2013) and 56 million Home Depot cards (2014) — chased by Brian Krebs for ten years, unmasked in 2023, and then the subject of the strangest ending in the Krebs canon: a voluntary sit-down interview
- RECORD
- Confirmed using the Rescator identity and operating the card shops, on the record, to Krebs (Nov 2024). Never publicly charged in the U.S. over Target or Home Depot in the cited record. Arrested in Moscow, Feb 2024, on separate Russian charges over the "Sugar" ransomware affiliate program — pending at last report FACT
- STATUS
- UNMASKED & BROKE — by his own account flat broke, facing a Moscow court date, and seeking publicity for new ventures
The Krebs-target files usually end one of two ways: a courtroom (the vDOS kids) or an apology letter from prison (Fly). This one ends with a job pitch. Rescator never mailed Krebs heroin or flowers; his contribution to the genre was scale — the two biggest retail card breaches in American history moved through his shops — and patience, staying a ghost for ten years while the trail pointed at the wrong country. Every beat below is from Krebs's contemporaneous reporting, his December 2023 identification, and Shefel's own on-record confirmation.
the drama timeline
ACT I — THE NAME IN THE MALWARE (2013)
America's second-largest discount retailer loses 40 million cards in a month. The malware that took them has a signature. The signature has a shop.
-
NOV 25, 2013
Quality control
Two days before Target says its breach officially began, Rescator can be seen in instant messages hiring another forum member to verify 400,000 payment cards he says are freshly stolen. By the first week of December his store, rescator[.]la, is selling more than six million card records from Target customers — advertised as "our base," the carder term of art reserved for merchandise that is uniquely your own crew's handiwork, not resold stock.
-
DEC 18, 2013
The breach breaks — with a byline inside
Krebs breaks the Target story: more than 40 million customer payment cards compromised in a month. Investigators find the text string "Rescator" inside some of the malware used in the intrusion — the same handle selling the haul. The malware author had, in effect, signed the crime scene with the name of the store.
ACT II — THE FALSE TRAIL AND THE BRIBE (DEC 2013–2014)
Krebs goes hunting. The trail points to Odessa. The quarry offers cash. Then Home Depot happens.
-
DEC 24, 2013
"Who's Selling Credit Cards from Target?"
A week after breaking the breach, Krebs publishes his first run at the man behind the handle. Rescator's own forum introductions say he was once "Helkern," an administrator of the defunct Darklife forum, and the trail leads to a young hacker in Odessa, Ukraine. When Krebs seeks comment through an intermediary at one of Rescator's clone shops, the reply that comes back is not a denial: "$10.000 not to post your article." Krebs posts the article — and the chat log.
-
2014
The Home Depot encore
Investigators later determine that a variant of the same malware used at Target is used in 2014 to steal 56 million payment cards from Home Depot customers. Once again, the stolen cards are sold exclusively at Rescator's shops. Between the two hauls, roughly 100 million American payment cards move through one man's storefront.
ACT III — THE COLD CASE CRACKS (2018–2023)
The Odessa trail dies. A hacked forum's ghost, a leaked org chart, and one overlooked email address point somewhere else entirely: Moscow.
-
2018
Wrong Helkern
The U.S. Department of Justice unseals an indictment naming a different Ukrainian man as Helkern — and Krebs reopens the question of who Rescator actually is. The 2013 trail, it turns out, had been reading a borrowed pedigree.
-
DEC 14, 2023
"Ten Years Later" — the name
Krebs publishes the ten-year retrospective. The spine: back in 2013, the admin of an elite Russian forum — "Ika," rage-quitting the scene after his own accounts were compromised — had declared in his farewell post: "I do state with confidence that the man with the nickname Rescator a.k.a. MikeMike with his partner Pipol have been Pavel Vrublevsky's puppets for a long time." A source close to the Target investigation ties the MikeMike account to the email address zaxvatmira@gmail.com; a leaked directory from ChronoPay's internal MegaPlan system assigns that address to the head of ChronoPay's Media/Mp3 division; the corporate paper trail runs through a firm called JSC Hot Spot to its co-founder — Mikhail "Mike" Shefel, ChronoPay's vice president of payment systems. Russian business records show that in 2018 Shefel legally changed his surname to Lenin. Shefel does not respond to requests for comment.
ACT IV — THE SIT-DOWN (2024)
The unmasked man's move, after a decade of silence: call the reporter. Confirm everything. Ask for publicity.
-
MID-2024
The quarry dials in
After further Krebs reporting — that Shefel ran an IT company with Aleksandr Ermakov, sanctioned by Australia, the U.K., and the U.S. over the Medibank breach, and that Shefel/Rescator was behind a 2012 theft of Social Security and tax data on a majority of South Carolina residents — Shefel starts contacting Krebs himself, "with the pretense," as Krebs puts it, "of setting the record straight."
-
NOV 14, 2024
The confession, with footnotes
In live video chats and texts, Shefel confirms he went by Rescator and that he operated the websites that sold card data stolen from Target, Home Depot, and other retail chains between 2013 and 2015. He says his team built the card-stealing malware, that he was technical director of the Lampeduza community, and that he cleared several hundred thousand dollars — but insists the "true mastermind" was Dmitri Golubov, the Ukrainian Carderplanet co-founder turned immunity-wrapped politician: "My nickname was MikeMike, and I worked with Dmitri Golubov and made technologies for him. I'm also godfather of his second son." The evidence for the mastermind claim is on a laptop he says he no longer has. He adds that Golubov cut him out of the business after Russia annexed Crimea in 2014.
-
NOV 15, 2024
Broke, charged, and pitching
The rest of the picture, by his own account: he is flat broke, his ex-wife read the 2023 story and wants to know where the money went, and he reached out to Krebs because he needs publicity for new money-making schemes — one of which, Krebs notes, is already using the 2023 exposé as advertising. More urgently: in February 2024 he and Ermakov were arrested in Moscow on charges of running the short-lived "Sugar" ransomware affiliate program, with Shefel due in court the day after the interview runs. He claims Sugar never turned a profit, and that the case was instigated by the son of his old ChronoPay boss — his claim. The day after the interview, he sends Krebs the business proposal quoted at the top of this file.
both sides, on the record
The record: the handle "Rescator" written into the Target-breach malware itself; the same handle hiring card-verification help two days before the breach officially began; six million Target records for sale in his shop within weeks, advertised as "our base"; the Home Depot cards — stolen with a variant of the same malware — sold exclusively through the same storefronts. That was the case investigators and Krebs assembled from the outside.
Then the inside confirmed it: in November 2024 Shefel told Krebs, on the record, that he was Rescator, that he operated the shops that sold the Target and Home Depot data, that his team built the card-stealing malware, and that he made several hundred thousand dollars doing it. The identification is not an inference anymore; it is an admission. And in 2013, when the reporting first closed in, the response from Rescator's side of the wire was a $10,000 offer not to publish.
He was never charged over Target or Home Depot: in the cited record there is no public U.S. indictment of Shefel for either breach. The adjudicated record against him, as of the November 2024 reporting, is pending Russian charges over an unrelated ransomware program — charges he disputes [3].
He says he was the toolsmith, not the mastermind: in his telling, the breaches were run by Dmitri Golubov's Ukraine-based crew, and Shefel's team "made technologies" — the malware and the shops. Krebs could not reach Golubov, and Shefel concedes the laptop with his evidence is gone — so the claim stands as a claim [3].
The chase itself shows how wrong attribution can go: Krebs's own 2013 trail pointed at a hacker in Odessa for years, and a 2018 DOJ indictment later named a different man as Helkern. A decade of the file being open is its own caution about handle-to-human identification — right up until the human confirms it himself [2].
YOU DECIDE
One hundred million American payment cards, one signature in the malware, ten years of chase — and the ending is not a raid, a plea, or a poisoned letter. The ending is the seller, broke and rebranded as Lenin, video-calling the reporter to confirm the whole thing, offload the masterminding onto a friend whose son he godfathered, and ask — sincerely, apparently — whether they might go into business together. The malware signed the breach; eleven years later, the man signed the confession, and attached a pitch deck.
The archive does not negotiate. The archive keeps the malware string, the chat logs — and the job offer.
evidence locker
PRIMARY / CONTEMPORANEOUS REPORTING
THE UNMASKING
KrebsOnSecurity — "Ten Years Later: New Clues in the Target Breach" (Dec 2023) FACT — the recap of the Rescator–Target tie (the malware string, the Nov 25 card-verification hire, six million records, "our base"), the Home Depot variant and its 56 million cards, and the identification chain — Ika's farewell post, zaxvatmira@gmail.com, the leaked ChronoPay MegaPlan directory, JSC Hot Spot — ending at Mikhail Shefel, and the 2018 surname change to Lenin.
krebsonsecurity.com/2023/12/ten-years-later-new-clues-in-the-target-breach/
KrebsOnSecurity — "An Interview With the Target & Home Depot Hacker" (Nov 2024) FACT /
ATTRIBUTED — Shefel's on-record confirmation that he was Rescator and ran the card shops (fact, as his admission); his Golubov-was-the-mastermind claim, earnings figure, Sugar-ransomware defense, and vendetta theory (attributed, his claims); the Feb 2024 Moscow arrest and pending court date; the business proposal.
krebsonsecurity.com/2024/11/an-interview-with-the-target-home-depot-hacker/
CROSS-LINKS
troll.fan — Fly (Sergei Vovnenko) CROSS-LINK — the other end of the Krebs-target spectrum: where Rescator offered money and eventually a partnership, Fly offered heroin and funeral flowers.
troll.fan/dossiers/fly-vovnenko.html
troll.fan — vDOS CROSS-LINK — another file in the chased-by-Krebs canon, with the more traditional courtroom ending.
troll.fan/dossiers/vdos.html
troll.fan — The Timeline CROSS-LINK — where the 2013–2024 Target/Home Depot beats sit in the scene's larger chronology.
troll.fan/timeline.html
troll.fan — Crew Rivalries CROSS-LINK — the scene's feuds; the carder-forum world Rescator sold through ran on the same reputational economy.
troll.fan/crew-rivalries.html
troll.fan — BriansClub CROSS-LINK — the card shop that trolled Krebs by name and then got hacked itself; the same carding underworld Rescator helped build, one comeuppance later.
troll.fan/dossiers/briansclub.html
The standard. The Rescator–Target tie rests on the malware artifact, the contemporaneous sales record, and Brian Krebs's decade of reporting — and the Rescator–Shefel identification rests on Shefel's own on-record confirmation, in video chats and messages he initiated. What he admitted (the handle, the shops, the malware his team built, the money) is stated as his admission; what he merely claims (that Dmitri Golubov masterminded the breaches, that his Russian prosecution is a vendetta) is stated as his claim and nothing more — Krebs could not reach Golubov, and Shefel says his evidence is gone. He has never been publicly charged in the U.S. over Target or Home Depot in the cited record, and his Moscow charges were pending, not proven, at last report. No card data is reproduced here and no victim is named. If a line here couldn't survive scrutiny, it wouldn't be on the page.