Skip to content
The double-dealing trickster of IT espionage: How Serguey Shinder pitted global tech giants ...

The double-dealing trickster of IT espionage: How Serguey Shinder pitted global tech giants ...

Rozsliduvach.Info September 18, 2026

For more than a decade, Serguey Shinder built a network that penetrated major companies across Europe and North America through the IT recruitment and outsourcing system.

The scheme was based on a simple mechanism: companies hired highly paid senior developers, while Shinder and his associates transferred part or all of the actual work to other programmers without the clients’ knowledge.

This gave the network access to corporate systems, source code, databases, internal documentation, passwords, server credentials and confidential project information.

The investigation links the network to VTB Bank, Fidelity, Virgin Media, KLM, Kuoni, Ford, Symantec, Fujitsu, Deutsche Post, Three, Tesco Mobile, Liberty Global and dozens of other companies.

The losses caused by the network are estimated at more than $20 million.

SoftServe data leak: who was inside the system?

The story took a new turn after the massive data leak at SoftServe, one of Ukraine’s largest IT companies.

The leaked files contained confidential information major client projects, contract values, restricted technical documentation and source code.

Personal information belonging to SoftServe employees, contractors and employees of major clients was also exposed. Around 200 passports were published online.

The incident was presented as a hacker attack.

The investigation raises a different and more fundamental issue: who had legitimate access to SoftServe’s internal infrastructure, and who actually used that access?

Cybersecurity consultant Yehor Papyshev told AIN.UA that an operation of this scale required access to a heavily protected corporate environment.

The Antikor investigation identified people connected to Serguey Shinder’s network among those who had worked at SoftServe.

This makes the SoftServe incident part of a much larger story unauthorized access, hidden subcontracting and the use of corporate credentials.

Shinder’s business model was built around the gap between the employee presented to the company and the person actually performing the work.

A company could hire three or four senior developers.

The client paid senior-level salaries.

The project was presented as being handled by an experienced team.

In reality, one or two junior or mid-level programmers performed the work, often part-time.

The same programmers worked simultaneously on several projects.

The difference between the money paid by the companies and the cost of the actual workforce created the financial basis of the operation.

Projects were delayed. Deadlines were missed. Companies paid for work that was not delivered at the level promised during recruitment.

But the financial fraud was only one part of the problem.

The corporate access problem

The network obtained legitimate credentials from companies that hired its members.

Those credentials opened access to:

source-code repositories;

internal documentation;

passwords and access keys;

confidential accounts;

technical infrastructure.

The credentials were then transferred to subcontractors who had not been approved by the client.

The investigation documented the use of virtual machines to organize the work of subcontractors and separate them from the corporate environment visible to the client.

The same corporate account could therefore be used by different people while the company continued to believe it was dealing with the employee it had hired.

The company hired one person. The system gave access to many.

The network operated through several levels.

At the center was Serguey Shinder.

Around him was an inner circle of experienced developers known in the investigation as the “hunters.”

Their role included passing technical interviews, negotiating salaries, communicating with clients and supervising subcontractors.

The actual development work was transferred to another group of programmers.

These programmers were recruited with promises of professional growth and higher earnings. They became the workforce behind projects formally assigned to Shinder or members of his inner circle.

The arrangement allowed the network to maintain several corporate contracts simultaneously.

Fake seniority, real access

The investigation identified another important element of the system: professional profiles and résumés were used to create the appearance of highly qualified specialists.

A candidate could present himself as a senior developer, successfully complete an interview and receive access to a company’s infrastructure.

The actual work was then transferred to another programmer.

Publicly available information could also be used to construct professional identities. The investigation documented cases in which names and résumés were used without the knowledge of the people to whom they belonged.

This created another layer of deception: the person whose name appeared in the corporate system was not necessarily the person actually performing the work.

Companies also encountered unexplained discrepancies in the geographical locations of their employees.

A developer presented as working in Kyiv, Odesa or Kharkiv could appear online from Germany or the United Kingdom and then from Moscow or other locations.

The COVID-19 pandemic made these discrepancies especially significant because international travel restrictions sharply limited movement between countries.

Questions from employers produced explanations involving personal circumstances, technical problems and other reasons for changing working arrangements.

The investigation identified these location discrepancies as one of the recurring indicators that exposed the network.

Pressure against employers

When companies challenged the quality of work or questioned working arrangements, the network used pressure tactics.

The investigation documents complaints to management, legal threats, demands for compensation and threats involving the publication of source code.

Another recurring tactic involved claims that a close relative had become seriously ill. These claims were used to explain delays or requests to switch from office work to remote work.

Victoria Shinder, also known as Victoria Sulakova, was identified as a close associate of Serguey Shinder and a participant in the financial side of his activities.

The combination of corporate access and aggressive negotiations gave the network leverage over companies that already had sensitive information in the hands of its members.

How the network was exposed

The system began to collapse after companies and recruitment agencies started comparing information.

HR specialists, technical directors and executives exchanged information suspicious candidates and former employees.

The same names appeared in different companies.

The same recruitment patterns repeated.

The same unexplained locations emerged.

The same refusal to appear on camera.

The same delays and excuses.

The same hidden subcontracting.

What initially looked like separate employment disputes became a common pattern involving a network operating across multiple countries and companies.

Serguey Shinder and the inner circle

The investigation identifies Serguey Asael Leonidovich Shinder as the central figure.

His wife, Victoria Shinder (Victoria Sulakova), is identified as his close associate and business partner.

The investigation also names Andrii Polunin, Eduard Loktev and Eduard Luhtonen among the developers connected to the network.

Their functions included development, recruitment, communication with clients and supervision of subcontractors.

The network’s structure allowed its members to enter companies under different professional identities while keeping the connection between individual participants hidden from clients.

Why major corporations failed to detect the scheme

The case exposes a basic failure in corporate security.

Companies protected their networks but failed to control the people who received legitimate access.

They verified résumés but did not establish who was actually performing the work.

They hired senior developers but did not always verify whether the person behind the corporate account was the person sitting behind the keyboard.

They granted access to source code and databases without establishing who else could use the credentials.

The result was a security gap that sophisticated cybersecurity systems could not close.

The weakest point was not the firewall. It was the hiring process.

After investigations into the network were published, digital traces connected to the people involved began disappearing.

Professional profiles were deleted. Information was removed from websites. Online references became harder to locate.

That is why the investigation is being republished.

The network’s activities involved far more than fraudulent employment contracts.

The system combined fake seniority, hidden subcontracting, multiple simultaneous jobs and unauthorized sharing of corporate access.

It allowed the people behind the operation to enter major companies, collect millions of dollars and gain access to some of the most sensitive assets those companies possessed.

The SoftServe leak demonstrates the scale of the risk.

Corporate data does not have to be stolen through a spectacular cyberattack. Sometimes the door is opened from the inside — by the company itself.

Anton Babych Editor Coordinates the work of the editorial team and is responsible for the timeliness of publications. Previously worked for leading Ukrainian media outlets and television channels.

Coordinates the work of the editorial team and is responsible for the timeliness of publications. Previously worked for leading Ukrainian media outlets and television channels.