#1
The Tatarstan Ministry of Internal Affairs has recognized the online flower delivery service "Russian Bouquet" and its partners as victims in a criminal case. Kazan programmer Aslan Shigapov discovered a technical vulnerability in the ordering system on the company's website and until March 2022 placed orders for flowers at a reduced price. The stolen products were then resold through a free classifieds service. The total damage amounted to more than 1 million rubles, which was fully reimbursed by the accused before the trial. The victims petitioned to terminate the criminal case due to reconciliation of the parties, but the court partially granted this.

Circumstances of the case
Aslan Shigapov was charged with unauthorized access to computer information and fraud on an especially large scale. For the latter crime, he faced up to 10 years in prison. The Sovetsky District Court of Kazan found Shigapov guilty and sentenced him to a suspended sentence of one year in prison with the same probationary period. If he does not violate the law within a year, the punishment will not be carried out.

Theft scheme
According to the investigation, Shigapov placed flower orders through the rus-buket.ru website, using a vulnerability in the system. This vulnerability allowed him to change the payment amount by sending the server data on the full payment of the order, while the minimum amounts were debited from his accounts. Thus, he placed more than 50 orders for amounts ranging from 900 rubles to 102 thousand rubles. The largest order included bouquets of 202 roses and tulips, the total cost of which was 102 thousand rubles, but only 5 rubles were paid.

As established in the court verdict, the theft scheme consisted of the fact that when paying for the placed order, Shigapov returned to the previous stage, stopped loading the web page and modified the data on the cost of the order. After making changes, the payment process was resumed with the new cost, which allowed him to significantly reduce costs.

Shigapov acted as an intermediary and offered his clients to choose a bouquet on the service's website, but pay him directly. The orders were placed not only in Russia, including Kazan, Naberezhnye Chelny, Nizhnekamsk, Moscow and Volgograd, but also abroad - to Thailand, Turkey and Kazakhstan. The stolen goods included not only flower arrangements, but also plush toys and sweets. He found clients through acquaintances and ads on Avito, and accepted payments on his card, through YuMoney or through third parties.

Another detail: Shigapov carried out his activities during working hours, using the computer of his employer, ServiceMontazhIntegratsiya LLC. In March 2022, police officers reported Shigapov's actions to the enterprise's economic security service, after which he was fired at his own request. The verdict

lists the names of the stolen bouquets: "Princess's Dream", "Pink Pearl", "Happy Bear", "Notes of Love", "Birdsong", "Royal Garden", bouquets of 101 roses and others.

Victims and Damages
The victims include six companies associated with the Russian Bouquet service, including Vebindustriya and its partners. The victims' lawyer, Yulia Prushinskaya, stated that for each delivered order, the Russian Bouquet company was obliged to pay partner salons, which led to significant losses. The court estimated the total damage at 1 million 22 thousand rubles, including orders that were not fulfilled. Before filing a complaint with the police, company representatives reported an unknown hacker who had broken into their site, which made it possible to quickly identify the theft scheme.

Court decision
The court took into account mitigating circumstances: full admission of guilt, assistance to the investigation, compensation for damages, Shigapov's young age and his positive characteristics. The judge partially dismissed the case on the episode of illegal access to computer information, but issued a guilty verdict on the article on fraud. The system unit and hard drive seized from Shigapov were confiscated to the state.

The verdict came into force.

source : https://realnoevremya.ru/articles/323873...-rus-buket