I got a notification at 2am once — my phone buzzing on the nightstand, that specific alert tone I had set for server emergencies. One of my hosting clients was getting hammered. A brute-force attack, thousands of login attempts per minute, all from a single Russian IP address. I sat there in the dark, laptop on my chest, watching the authentication logs scroll faster than I could read them. Someone on the other side of the planet was methodically trying to break into a system I was responsible for, and all I could do was watch and react. Block one IP, another one appears. Tighten one rule, they find a different angle. That feeling — the helplessness of watching an attack happen in real time — stayed with me for days.

Now multiply that feeling by a thousand. That is what PayPal’s engineers lived through in the year 2000, except their attackers were not just trying to get in. They were already inside, and they were stealing real money.

The Hackers from Chelyabinsk

The story begins in Chelyabinsk, — an industrial city in Russia, east of the Ural Mountains, known mostly for its Soviet-era weapons factories and, later, for the meteor that exploded over it in 2013. In the late 1990s, two young men from Chelyabinsk were building a different kind of reputation.

Vasily Gorshkov, who used the alias “Kvakin” online, and Alexey Ivanov, who went by “Subbsta”, were technically gifted programmers. They had the kind of skills that, in Silicon Valley, would have landed them six-figure engineering jobs. But they were not in Silicon Valley. They were in a Russian city where the average salary was a few hundred dollars a month, and the legitimate tech economy barely existed.

So they turned those skills to fraud.

Their operation was sophisticated. They broke into the networks of US financial companies, stole credit card numbers and personal information, then used that data to create fake PayPal accounts, manipulate eBay auctions, and siphon money through a web of stolen identities. According to Jimmy Soni’s account in The Founders, the losses attributed to their operation reached as high as $1.5 million.

For a company like PayPal — which in 2000 was still a startup burning through venture capital and fighting for survival — that kind of fraud was not just a financial problem. It was an existential one. Every dollar lost to fraud was a dollar that pushed the company closer to running out of money entirely.

“Crime in Progress”

Inside PayPal, the fraud problem felt overwhelming. Max Levchin, the company’s co-founder and CTO, had built PayPal’s technology from scratch. He was a cryptography expert, a systems thinker, someone who approached problems with mathematical precision. But fraud was not a clean engineering problem. It was messy, human, and constantly evolving.

John Kothanek, who ran PayPal’s fraud investigations, became the company’s point man for working with law enforcement. He and Levchin spent months tracking patterns, cataloguing the attacks, and building cases they could hand to the FBI. It was tedious, unglamorous work — the kind of thing that never shows up in startup mythology but determines whether a company survives.

“The fraud was not a distraction from the business. The fraud was the business problem.” — paraphrased from Jimmy Soni, The Founders

I know that feeling from a smaller scale. When I was running my hosting company, there was a stretch where I spent more time dealing with security incidents than building the product. Cleaning up compromised accounts, explaining to clients why their sites had been defaced, hardening configurations that I should have hardened months earlier. You start to wonder whether you are running a technology company or a security company. At PayPal, that question was existential — if they could not solve fraud, the entire business model collapsed.

The Sting

The FBI’s plan was audacious. They knew that Gorshkov and Ivanov were talented hackers, but they also knew something else — the two men genuinely wanted legitimate tech careers. They were looking for real work in the West. The FBI decided to use that desire against them.

Agents created a fictitious company called Invita Security, complete with a website and business cards. They reached out to Gorshkov and Ivanov, posing as executives at this supposed security firm, and offered them what every talented programmer in a dead-end economic situation dreams of: well-paid consulting work, a chance to demonstrate their skills, and a trip to the United States.

The hackers flew to Seattle for their “job interviews.”

Think about that for a moment. Two men with genuine technical talent, born into a place with almost no legitimate outlets for that talent, flew halfway around the world because someone offered them a real job. And it was a trap.

I grew up in Sarajevo during the siege. I know something about how geography shapes your options. When you are born in the wrong place at the wrong time, the distance between who you become and who you could have been is not about character — it is about circumstance. Gorshkov and Ivanov had the skills to be security engineers at any major tech company. Instead, they became cybercriminals, and when someone finally offered them a legitimate path, it turned out to be an FBI operation.

I am not excusing what they did. They stole money from real people. But I cannot help noticing that the thing the FBI exploited — their genuine desire for legitimate work — tells you something about how talent gets wasted when opportunity does not exist.

The Arrest and the Aftermath

During the fake job interviews, the FBI asked Gorshkov and Ivanov to demonstrate their hacking skills on Invita’s systems — which were, of course, FBI-controlled machines designed to capture every keystroke. The hackers, eager to impress their prospective employers, showed exactly what they could do.

Then the handcuffs came out.

Operation Flyhook made headlines. It was one of the first major international cybercrime stings, and it raised legal questions that still echo today — about jurisdiction, about the legality of the FBI accessing computers in Russia as part of the investigation, and about the boundaries of law enforcement in cyberspace.

Gorshkov was sentenced to three years in federal prison. Ivanov received four years. The case sent a clear message to international hackers that the US was willing to go to considerable lengths — including setting up entire fake companies — to pursue cybercrime.

But here is the part of the story that sticks with me: after serving his sentence, Ivanov pursued legitimate technology work in the United States. The thing the FBI had used as bait — a real career in tech — turned out to be what Ivanov actually wanted all along. He had the talent. He just did not have the opportunity the first time around.

The Problem That Built the Moat

Here is where the story turns, and where it matters most for anyone building a company.

The fraud crisis that Gorshkov, Ivanov, and dozens of other bad actors inflicted on PayPal nearly killed the company. There were months when fraud losses threatened to overwhelm the entire business. Levchin and his engineering team were fighting fires constantly, and the board was asking hard questions about whether the model could ever work.

But PayPal did not just survive the fraud crisis. It built something from it.

The fraud detection systems that Levchin and his team developed under pressure — the pattern recognition algorithms, the risk scoring models, the automated flagging tools — became one of PayPal’s core competitive advantages. No competitor could easily replicate them, because no competitor had been through the same trial by fire. The systems were not built in a lab based on theoretical models. They were built in the field, in response to real attacks, refined through thousands of real fraud cases.

“PayPal’s fraud systems became a moat that competitors couldn’t easily cross.” — paraphrased from Jimmy Soni, The Founders

I think about this every time someone asks me what running a hosting company for fifteen years taught me. The honest answer is: the problems that almost broke the business taught me the most. Every security incident I dealt with made me better at prevention. Every angry client call taught me something about communication. Every server failure taught me something about redundancy. The knowledge I carry today — the thing that makes me a better Cloud Engineer — was forged in fifteen years of things going wrong.

PayPal’s story is the same pattern at a much larger scale. The fraud crisis did not just test them. It built them. It turned a payments app into a company with proprietary technology that no one else had, because no one else had been forced to build it under the same pressure.

What Stays With Me

The PayPal fraud story has three layers, and each one teaches something different.

The first is about security — that the threats are real, they are persistent, and the only response is to build systems that are smarter than the attackers. If you run any kind of technology business, you are a target. The question is not whether someone will try to break in, but whether you will be ready when they do.

The second is about talent and circumstance — that two men with world-class technical skills ended up as criminals because the place they were born did not give them a legitimate path. Ivanov’s post-prison career in tech proves the point. The talent was always there. The opportunity was not.

The third is about resilience — that the worst thing that happens to your company can become the best thing, if you build from it instead of just surviving it. PayPal did not just patch the holes. They built a fortress, and that fortress became the foundation of a company worth hundreds of billions of dollars.

I sat in the dark that night, watching those logs scroll, feeling powerless against an attacker I could not see. PayPal’s engineers sat in their offices in Palo Alto feeling the same thing, except the stakes were a hundred times higher. They responded by building something that no one could take from them. That is the lesson I keep coming back to: the crisis is not the end of the story. It is the beginning of the next chapter.

Sources

  • Soni, Jimmy. The Founders: The Story of PayPal and the Entrepreneurs Who Shaped Silicon Valley. New York: Simon & Schuster, 2022. Chapter 17: “Crime in Progress.”
  • United States Department of Justice. Russian Computer Hacker Sentenced to Three Years in Prison. Press release, October 2002.
  • United States v. Gorshkov, No. CR00-550C (W.D. Wash. 2001). Case documents regarding Operation Flyhook and the FBI sting operation.