Menu
Browse

Rescator

Primary URL Location Industry
rescator[.]cc
Country Russia
Technology Icon
Technology
Profile

Rescator operated an underground marketplace that focused on the sale of stolen credit card data obtained from major retail breaches such as those affecting Target, Home Depot and Sally Beauty. The platform allowed buyers to search for compromised cards using geographic criteria, enabling targeted fraud based on location. Transactions were processed exclusively through direct Bitcoin payments, with no escrow service to protect either party. This model facilitated rapid, anonymous exchanges of illicit financial information.

According to the available reporting, Rescator’s operations included the upload of millions of card details to various carding forums. The scale of this activity gave the marketplace a notable presence within the underground carding ecosystem. A rival hacker temporarily defaced the site, displaying a taunting message and media content, which highlighted the visibility of the operation.

The organisation’s headquarters is listed as being located in Russia, while the individual behind the alias is described as a Ukrainian hacker. Rescator is distinguished by its specialization in geographic filtering of stolen card data and its reliance on Bitcoin‑only payments without escrow protections. The suspected operator has been identified as Andrey Hodirevski, although his direct involvement in the hacking activities remains unconfirmed. These characteristics combine to position Rescator as a distinct actor in the illicit market for payment card information.

Incidents
Linked incidents available to members
1 incident