Tuesday, December 15, 2009

Document Details Help TJX Hacker Gave Prosecutors

Kim Zetter writes on Threat Level:

Admitted TJX hacker Albert Gonzalez has identified two Russian accomplices who helped him hack into numerous companies and steal more than 130 million credit and debit card numbers.

Gonzalez told prosecutors that the hackers breached at least four card processing companies, as well as a series of foreign banks, a brokerage house and several retail store chains, according to a sentencing memo filed by his lawyer on Tuesday that was incorrectly redacted.

The document reveals that six months after his May 2008 arrest, Gonzalez located and provided prosecutors with the “complicated” and “lengthy” password to decrypt his laptop, which contained “a vast array of historical data and communications” that helped the government indict other members of Gonzalez’s team, and could be used in future search warrants. It also reveals that Gonzalez drew prosecutors a map that helped them find more than $1.1 million that he had buried in his parents’ backyard.

Gonzalez is scheduled to be sentenced on Dec. 21 in two cases out of New York and Massachusetts involving hacks into TJX, Dave & Busters restaurant chain and numerous other companies, though his sentencing is likely to be delayed. On Tuesday, the government asked for an 8-12 week continuance to give Gonzalez a psychological examination, following a defense claim that the hacker suffers from Asperger’s syndrome and may not have the “capacity to knowingly evaluate the wrongfulness of his actions.” That information was revealed in an exhibit filed with the sentencing memo that describes a psychological evaluation Gonzalez underwent with a psychologist hired by the defense.

More here.

Monday, March 22, 2010

U.S. Secret Service Paid TJX Hacker $75,000 a Year

Kim Zetter writes on Threat Level:

Convicted TJX hacker Albert Gonzalez earned $75,000 a year working undercover for the U.S. Secret Service, informing on bank card thieves before he was arrested in 2008 for running his own multimillion-dollar card-hacking operation.

The information comes from one of Gonzalez’s best friends and convicted accomplices, Stephen Watt. Watt pleaded guilty last year to creating a sniffer program that Gonzalez used to siphon millions of credit and debit card numbers from the TJX corporate network while he was working undercover for the government.

Watt told Threat Level that Gonzalez was paid in cash to protect his status as a confidential informant. The Secret Service said it would not comment on payments made to informants. Gonzalez’s attorney did not respond to a call for comment.

More here.

Wednesday, October 22, 2008

Hackers' Mind-Set: They've Done Nothing Wrong

Jon Swartz writes on USA Today:

Albert Gonzalez appeared to be a reformed hacker. But the onetime government informant was a central character in what Justice Department officials claim was an international cybercrime syndicate that ripped off tens of millions of credit and debit card numbers from large U.S. retailers.

Irving Jose Escobar seemed nothing more than a tough Miami kid with a long rap sheet. Yet last year, he pleaded guilty to his role in a multimillion-dollar scam in Florida tied to Gonzalez's exploit.

What they shared, based on indictments in their separate cases, are key roles in the massive cyberheist at TJX, parent of retailers T.J. Maxx and Marshalls, and the credit card scams that resulted. First disclosed by TJX in January 2007, it is believed to be the largest such theft.

It is unclear whether Gonzalez and Escobar know each other. But each was involved in different scams tied to TJX, according to their respective indictments. The divergent sagas of the hacker Gonzalez and streetwise Escobar represent bookends of the vast digital crime. According to psychiatrists, hackers and computer-security experts, they represent the vanguard of cybercrooks: young, misguided males who rationalize that they've done nothing wrong.

More here.

Thursday, March 25, 2010

TJX Hacker Gets 20 Years in Prison

Kim Zetter writes on Threat Level:

Convicted TJX hacker Albert Gonzalez was sentenced to 20 years in prison on Thursday for leading a gang of cyberthieves who stole more than 90 million credit and debit card numbers from TJX and other retailers.

The sentence for the largest computer-crime case ever prosecuted is the lengthiest ever imposed in the United States for hacking or identity-theft. Gonzalez was also fined $25,000. Restitution, which will likely be in the tens of millions, was not decided Thursday.

Clean-cut, wearing a beige jail uniform and wireframe glasses, the 28-year-old Gonzalez sat motionless at his chair during Thursday’s proceedings, his hands folded in front of him.

Before the sentence was pronounced, Gonzalez told the court he deeply regrets his crimes, and is remorseful for having taken advantage of the personal relationships he’d forged. “Particularly one I had with a certain government agency … that gave me a second chance in life,” said the hacker, who had worked as a paid informant for the Secret Service. “I blame nobody but myself.”

More here.

Monday, August 31, 2009

Albert Gonzalez' Attorney Says His Client 'Not Ringleader'

A Reuters newswire article by Ross Kerber, via MSNBC, reports that:

An attorney for the hacker whom U.S. authorities painted as an organizer of one of the largest payment-card thefts ever said his client was no ringleader.

"He wasn't directing traffic or anything," attorney Rene Palomino told Reuters in a telephone interview on Monday.

Albert Gonzalez, a 28-year-old from Miami, last week agreed to plead guilty to charges in Boston that he helped engineer the theft of more than 40 million card numbers from retailers like TJX Cos. and BJ's Wholesale Club.

Earlier this month in New Jersey, the U.S. Justice Department also charged Gonzalez and two others with conspiring to steal another 130 million payment card numbers, the most ever.

Both cases put Gonzalez at the center of the action — especially bold conduct since authorities say he was a Secret Service informant earlier this decade.

Palomino also described his client as a less-important figure than the Boston case made out, saying he was one of 11 co-conspirators worldwide, some still at large. "Did he have knowledge? Yes. But others were also involved," Palomino said.

More here.

Tuesday, December 22, 2009

Former Morgan Stanley Coder Gets 2 Years in Prison for TJX Hack

Kim Zetter writes on Threat Level:

The two great friends talked every day and shared information about all of their exploits — sexual, narcotic and hacking — according to prosecutors. Now another thing they’ll have to share information about is their experience in federal prison.

While accused TJX hacker kingpin Albert Gonzalez awaits a possible sentence of 17 years or more in prison, one of his best friends and accomplices was sentenced on Tuesday in Boston to two years for his role in what the feds are calling “the largest identity theft in our nation’s history.”

Stephen Watt, a 25-year-old former Morgan Stanley software engineer, pleaded guilty last December to creating a custom sniffing program dubbed “blabla” that Gonzalez and other hackers used to siphon millions of credit and debit card numbers from TJX’s network. The breach cost TJX $200 million, according to its 2009 SEC filing.

Watt’s lawyer had sought a sentence of probation.

But instead the 7-foot-tall coder who once had a bright professional future got two years in federal prison and three years of probation. A spokeswoman for the U.S. attorney’s office in Massachusetts said the judge also ordered Watt to pay restitution to TJX in the amount of $171.5 million.

More here.

Tuesday, December 08, 2009

TJX Hacker to Plead Guilty to Heartland Breach

Kim Zetter writes on Threat Level:

Admitted TJX intruder Albert Gonzalez has entered into a plea agreement on charges that he hacked into Heartland Payment Systems, Hannaford Brothers, 7-Eleven and two other unnamed national retailers.

The revelation comes in a filing made by Gonzalez’s attorney in U.S. District Court in New Jersey, where the Heartland charges were filed in August.

A federal judge on Tuesday officially transferred the New Jersey case to Massachusetts, where Gonzalez is seeking to merge it with two other cases in which he’s already pleaded guilty.

Gonzalez, a former Secret Service informant known by the online nicks “segvec” and “Cumbajohnny,” was charged in New Jersey in August, along with two unnamed Russian hackers. They were accused of stealing more than 130 million debit and credit cards from card-processing company Heartland and the other target companies.

More here.

Friday, March 19, 2010

Unprecedented 25-Year Sentence Sought for TJX Hacker

Kevin Poulsen writes on Threat Level:

Computer hacker Albert Gonzalez deserves a quarter-century behind bars for leading a gang of cyberthieves who stole tens of millions of credit and debit card numbers from a transaction processor and several giant retail chains, federal prosecutors argued in a court filing Thursday night.

“[T]he sentences would be the longest ever imposed in an identity theft case and among the longest imposed for a financial crime, which is appropriate because Gonzalez was at the center of the largest and most costly series of identity thefts in the nation’s history,” wrote Boston-based assistant U.S. attorney Stephen Heymann. “He knowingly victimized a group of people whose population exceeded that of many major cities and some states.”

The government also disputed a defense claim that Gonzalez suffers from Asperger’s disorder, a mild form of autism that was grounds for a slightly reduced sentence in a previous hacking prosecution.

Gonzalez, 28, is set for sentencing next week on three indictments covering virtually every headline-making bank-card theft in recent years, including intrusions at TJX, DSW Shoe Warehouse, Office Max, Hannaford Brothers, 7-Eleven, and Heartland Payment Systems, which alone exposed magstripe data on 130 million credit and debit cards. He performed the intrusions while an informant for the Secret Service.

More here.

Thursday, April 15, 2010

Final Conspirator in Credit Card Hacking Ring Gets 5 Years

Kim Zetter writes on Threat Level:

Damon Patrick Toey, the “trusted subordinate” to TJX hacker Albert Gonzalez, was sentenced in Boston on Thursday to 5 years in prison.

He also received a $100,000 fine and three year’s supervised release, according to the Justice Department.

Toey, 25, helped Gonzalez breach the networks of numerous companies through SQL injection attacks in 2007 and 2008 and also served as a vendor selling stolen card data. Upon his arrest in May 2008, he provided information that investigators say likely helped persuade Gonzalez to plead guilty last year to what prosecutors are calling the most serious and largest identity-theft crimes ever prosecuted.

Toey was the last of six U.S. defendants sentenced for the crimes. In all, federal judges have handed out nearly 38 years against Gonzalez and his crew, with Gonzalez getting the stiffest sentence by far.

More here.

Thursday, August 20, 2009

Gonzalez's Lawyer to Contend He Was Not The Kingpin of Heartland, Hannaford Breaches

Jaikumar Vijayan writes in ComputerWorld:

The attorney for Albert Gonzalez, the man indicted Monday on charges related to the massive data thefts at Heartland Payment Systems and four other retailers, claims it was another member of Gonzalez's gang who was the real leader of the heists.

In an interview with the New York Times, Gonzalez's lawyer, Rene Palomino, said he was prepared to argue that the person who organized the break-ins at Heartland and elsewhere was really Damon Patrick Toey of Miami.

Palomino said Toey is the individual who was identified only as "P.T," an unindicted co-conspirator in Monday's indictment papers. Palomino also told the Times that one of the unnamed Russian conspirators mentioned in the indictment is an individual named Maksym Yastremskiy, who is currently serving a 30-year sentence in a Turkish prison.

Toey was one of 11 individuals, including Gonzalez, who were indicted last year on charges related to the data thefts at TJX Companies Inc., Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

More here.

Tuesday, March 23, 2010

TJX Accomplice Gets Probation for Selling Browser Exploit

Kim Zetter writes on Threat Level:

A computer security professional who provided Internet Explorer exploit code that helped hackers penetrate TJX and other companies was sentenced Tuesday in Boston to three years probation and a $10,000 fine.

Jeremy Jethro, 29, was paid $60,000 in cash by convicted TJX hacker Albert Gonzalez for a zero-day exploit against Microsoft’s browser, which Gonzalez and his co-conspirators used to obtain unauthorized access to company networks and steal more than 90 million credit and debit card numbers.

Jethro pleaded guilty to a misdemeanor conspiracy charge for providing the malware. Under Tuesday’s sentence, Jethro will be confined at home, under electronic monitoring, for the first six months of his three-year-long probation. His attorney did not respond to a call for comment.

More here.

Monday, March 29, 2010

TJX Accomplice Sentenced to 7 Years in Prison

Kim Zetter writes on Threat Level:

A hacker who helped TJX hacker Albert Gonzalez and others gain access to corporate networks was sentenced to 7 years and one day on Monday .

Christopher Scott, 27, pleaded guilty to breaching the wireless access points of several retailers between 2003 and 2007 to siphon credit and debit card numbers, which he then passed to Gonzalez. Prosecutors say that together the men pilfered nearly 20 million credit and debit cards, which retailers say led to $200 million in losses from fraud.

They used the cards to obtain cash advances from ATMs or sold the account information to other carders, who encoded the data to blank and counterfeit bank cards for fraudulent use. Scott’s take from the crimes was at least $400,000, according to prosecutors. He was paid in cash and with pre-paid bank cards and used the money to rent limos and partied with up to 10 women at a time, prosecutors say, and later bought a car, jewelry and $400,000 house.

The government is seeking forfeiture of $400,000, nine computers and an array of other electronic goods from Scott. Restitution will be determined at a future hearing.

More here.

Monday, September 15, 2008

One Man Pleads Guilty in TJX Breach Case

Ross Kerber writes in The Boston Globe:

Federal prosecutors won a guilty plea yesterday from one of 11 men who made up a ring that was charged last month with the largest data theft case in history, involving tens of millions of customers of retailers, including TJX Cos. of Framingham and BJ's Wholesale Club of Natick.

Separately the government also said it has evidence the group breached the security of many more businesses than previously disclosed.

At a hearing in federal District Court in Boston yesterday afternoon, Damon Patrick Toey, 23, of Miami, pleaded guilty to multiple charges, including wire fraud, credit card fraud, and aggravated identity theft. Prosecutors alleged he helped the accused ringleader, Albert Gonzalez, to break through the computer security of a number of retail stores in the Miami area.

Gonzalez himself appeared at a second hearing later in the day and pleaded not guilty to a set of similar charges.

Prosecutors said both men were key players in a loose-knit ring spanning countries from China to Ukraine that stole or trafficked in more than 40 million payment cards in all, causing more than $400 million in damages. The ring initially accessed customer data by using laptops to penetrate wireless networks of retail stores, from which they were able to access the companies' servers.

More here.

Tuesday, August 05, 2008

U.S. Dept. of Justice Charges 11 in Theft of 40 Million Card Numbers

A Reuters newswire article, via The New York Times, reports that:

The Justice Department said on Tuesday that it had charged 11 people in the theft of tens of millions of credit and debit card numbers of customers shopping at major retailers, including TJX Companies, in one of the largest reported identity-theft incidents on record.

The United States Attorney in Boston said those charged were involved in the theft of more than 40 million credit and debit card numbers.

TJX, of Framingham, Mass., which owns the Marshall’s and TJ Maxx chains, was the hardest hit by the ring, acknowledging in March 2007 that information from 45.7 million credit cards was stolen from its computers.

The charges focus on three people from the United States, three from the Ukraine, two from China, one from Estonia and one from Belarus.

The authorities said that the scheme was spearheaded by a Miami man named Albert Gonzalez, who hacked into the computer systems of retailers including TJX, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW Inc. The numbers were then stored on computer servers in the United States and Eastern Europe.

They then sold the information to people in the United States and Europe, who used it to withdraw tens of thousands of dollars at a time from automated teller machines, the authorities said.

More here.

Monday, August 17, 2009

TJX Hacker Charged with Heartland, Hannaford Breaches

Kim Zetter writes on Threat Level:

The constellation of hacks connected to the TJX hacker is growing.

Albert “Segvec” Gonzalez, a former Secret Service informant who is already awaiting trial over his involvement in the TJX hack, has been indicted by a federal grand jury in New Jersey, along with two unnamed Russia-based conspirators, with hacking into Heartland Payment Systems, the New Jersey based card processing company, as well as Hannaford Brothers, 7-Eleven, Inc, and two unnamed national retailers, according to the indictment unsealed Monday.

Prosecutors say they’re investigating other breaches and have not ruled out Gonzalez’s involvement in even more intrusions.

“[The fact that] we’re not seeing a huge array of hackers capable of doing this, but rather a more select group, demonstrates that there is a level of sophistication involved in these hacks,” said Assistant U.S. Attorney Erez Liebermann from the Justice Department’s New Jersey district office.

According to the court document, the hackers stole more than 130 million credit and debit card numbers from Heartland and Hannaford combined, which authorities believe constitutes the largest data breach and identity theft case ever prosecuted in the U.S. But these are just the latest in a string of high-profile breaches that have been connected to Gonzalez.

More here.

Thursday, March 11, 2010

TJX Hacking Conspirator Gets 4 Years

Kim Zetter writes on Threat Level:

Humza Zaman, a co-conspirator in the hack of TJX and other companies, was sentenced Thursday in Boston to 46 months in prison and fined $75,000 for his role in the conspiracy. The sentence matches what prosecutors were seeking.

Zaman, a 33-year-old former programmer at Barclays Bank, was charged with laundering between $600,000 and $800,000 for hacker Albert Gonzalez, who is currently awaiting sentencing on charges that he and others hacked into TJX, Office Max, Heartland Payment Systems and numerous other companies to steal data on more than 100 million credit and debit card accounts.

Zaman pleaded guilty in April to one count of conspiracy. His sentence includes three years of supervised release with the condition that Zaman must disclose his conviction to any future employer. Upon release, Zaman will not be barred from using computers.

More here.

Thursday, January 08, 2009

Carder Linked to TJX Hack Jailed for 30 Years by Turkish Court

John Leyden writes on The Register:

A Ukrainian fraudster linked to the infamous TJX hack was sentenced to a 30 year prison sentence in Turkey on unrelated charges this week.

Maksym Yastremskiy (AKA Maksik) was found guilty of hacking into the computer systems of 12 Turkish banks, as well as committing computer fraud against them, according to local reports. The court also reportedly fined Yastremskiy $23,200.

Yastremskiy was arrested by police in Turkey in July 2007, after visiting a nightclub in the beach resort of Kemer, in an operation US law enforcement agencies soon realised was key to unraveling the TJX hacking case.

It emerged within weeks that Yastremskiy was fencing hundreds of hundreds of thousands of credit card numbers linked to hacking attacks at US retail outlets, including TJX, through various underground carders forums. Yastremskiy was charged last August with trafficking in stolen credit card information harvested from a string of retail firms including TJX, OfficeMax, Barnes & Noble, Forever 21, DSW, and Marshall's, among others.

Alleged ringleader Albert "Segvec" Gonzalez of Miami allegedly conspired with ten other suspects (including Yastremskiy) to hack into the insecure networks maintained by the US retailers and lift 40 million credit and debit card numbers. Since the heist against TJX alone affected 45.6 million customers alone these colossal figures are, if anything, a possible underestimate of the possible extent of the crime.

More here.

Thursday, August 20, 2009

In Gonzalez Hacking Case, a High-Stakes Fight Over a Ukranian's Laptop

Kim Zetter writes on Threat Level:

When Turkish police arrested Maksym “Maksik” Yastremskiy — a Ukrainian wholesaler of stolen identity data — in July 2007, they didn’t just collar one of the most-wanted cybercriminals in the world. They also got a trove of evidence about Yastremskiy’s buyers and suppliers, all locked in an encrypted vault on his laptop computer.

Now federal prosecutors are hoping to introduce a copy of Yastremskiy’s files in its case against accused hacker Albert “Segvec” Gonzales. Chat logs and other information on the disk allegedly show that Gonzalez was Yastremskiy’s major supplier of credit and debit card numbers.

But Gonzalez’s attorney is fighting to keep the data, and similar information seized from a server in Latvia, far away from the New York court room where Gonzalez is scheduled to stand trial next month on the first of three federal indictments. The argument unfolding over the disks illustrates the challenges and controversies of using electronic evidence gathered in foreign jurisdictions, and sheds more light on the unusual methods used to investigate what authorities have called the largest identity theft case in U.S. history.

Gonzalez and his co-conspirators staged high-profile breaches at TJX, Heartland Payment Systems, Dave & Buster’s and other retailers and payment processors.

One notable revelation in the government’s own filings [.pdf] is that Yastremskiy’s arrest did not mark the first time the Secret Service gained access to his computer files. On June 14, 2006 the Secret Service worked with local authorities to conduct a “sneak-and-peek” search of Yastremskiy’s laptop while he was traveling through Dubai, in the United Arab Emirates. The agency secretly obtained a copy of the man’s hard drive in the search.

More here.

Wednesday, September 08, 2010

Report: RBS WorldPay Hacker Gets Four Years' Probation

Robert McMillan writes on PC World:

The mastermind behind one of the biggest hacking paydays in history has been sentenced to four years' probation and an US$8.9 million fine, according to published reports.

Victor Pleshchuk, 28, was sentenced to four years' probation on Wednesday, according to Bloomberg News. He is considered the leader of a group of criminals who organized a 2008 precision strike on RBS WorldPay, the payment processing division of the Royal Bank of Scotland.

In addition to the reduced sentence of probation, Pleshchuk must also pay back more than 275 million rubles ($8.9 million) to RBS WorldPay, Bloomberg reports.

Russia is trying to fight a reputation for being soft on cybercrime, but this light sentence won't do much to change that perception. Security experts say that Pleshchuk falls into the same category of highly accomplished cybercriminals as Albert Gonzalez, best known for hacking into retailer TJX Companies and the Heartland Payment Systems payment processing network. In March, Gonzalez was sentenced to 20 years in federal prison.

More here.

Thursday, September 16, 2010

Man Gets 6 Years in Prison for Laundering $2.5 Million for Carders

Kim Zetter writes on Threat Level:

A California man who served as a lynchpin for transmitting stolen money to hackers and carders in East Europe and elsewhere was sentenced on Thursday to 6 years in prison for conspiring to launder money.

Cesar Carranza, 38, also known as “uBuyWeRush,” ran a legitimate business selling liquidation and overstock merchandise online and from three California stores.

But, according to an indictment [.pdf], he also sold MSR-206’s to carders to encode stolen bank card data onto blank cards, and he served as a conduit to transmit stolen money between mules and carders.

He worked with many of the top carders in the criminal underground between 2003 and 2006, including Maksim “Maksik” Yastremskiy, a Ukrainian carder who allegedly worked with TJX hacker Albert Gonzalez and was considered by authorities to be one of the top sellers of stolen card data on the internet.

In 2003 and 2004, Carranza became an approved and trusted vendor on online criminal forums such as CarderPlanet and Shadowcrew, advertising his goods and services and dispensing advice on the best tools to use for various criminal endeavors.

More here.