Carder Linked to TJX Hack Jailed for 30 Years by Turkish Court
John Leyden writes on The Register:
A Ukrainian fraudster linked to the infamous TJX hack was sentenced to a 30 year prison sentence in Turkey on unrelated charges this week.
Maksym Yastremskiy (AKA Maksik) was found guilty of hacking into the computer systems of 12 Turkish banks, as well as committing computer fraud against them, according to local reports. The court also reportedly fined Yastremskiy $23,200.
Yastremskiy was arrested by police in Turkey in July 2007, after visiting a nightclub in the beach resort of Kemer, in an operation US law enforcement agencies soon realised was key to unraveling the TJX hacking case.
It emerged within weeks that Yastremskiy was fencing hundreds of hundreds of thousands of credit card numbers linked to hacking attacks at US retail outlets, including TJX, through various underground carders forums. Yastremskiy was charged last August with trafficking in stolen credit card information harvested from a string of retail firms including TJX, OfficeMax, Barnes & Noble, Forever 21, DSW, and Marshall's, among others.
Alleged ringleader Albert "Segvec" Gonzalez of Miami allegedly conspired with ten other suspects (including Yastremskiy) to hack into the insecure networks maintained by the US retailers and lift 40 million credit and debit card numbers. Since the heist against TJX alone affected 45.6 million customers alone these colossal figures are, if anything, a possible underestimate of the possible extent of the crime.
More
here.
In Gonzalez Hacking Case, a High-Stakes Fight Over a Ukranian's Laptop
Kim Zetter writes on Threat Level:
When Turkish police arrested Maksym “Maksik” Yastremskiy — a Ukrainian wholesaler of stolen identity data — in July 2007, they didn’t just collar one of the most-wanted cybercriminals in the world. They also got a trove of evidence about Yastremskiy’s buyers and suppliers, all locked in an encrypted vault on his laptop computer.
Now federal prosecutors are hoping to introduce a copy of Yastremskiy’s files in its case against accused hacker Albert “Segvec” Gonzales. Chat logs and other information on the disk allegedly show that Gonzalez was Yastremskiy’s major supplier of credit and debit card numbers.
But Gonzalez’s attorney is fighting to keep the data, and similar information seized from a server in Latvia, far away from the New York court room where Gonzalez is scheduled to stand trial next month on the first of three federal indictments. The argument unfolding over the disks illustrates the challenges and controversies of using electronic evidence gathered in foreign jurisdictions, and sheds more light on the unusual methods used to investigate what authorities have called the largest identity theft case in U.S. history.
Gonzalez and his co-conspirators staged high-profile breaches at TJX, Heartland Payment Systems, Dave & Buster’s and other retailers and payment processors.
One notable revelation in the government’s own filings [.pdf] is that Yastremskiy’s arrest did not mark the first time the Secret Service gained access to his computer files. On June 14, 2006 the Secret Service worked with local authorities to conduct a “sneak-and-peek” search of Yastremskiy’s laptop while he was traveling through Dubai, in the United Arab Emirates. The agency secretly obtained a copy of the man’s hard drive in the search.
More
here.
Turkish Police May Have Beaten Encryption Key Out of TJ Maxx Suspect
Chris Soghoian writes on the C|Net "surveill@nce st@te" Blog:
When criminals turn to disk encryption to hide the evidence of their crimes, law enforcement investigations can hit a brick wall. Where digital forensics software has failed to recover encryption passwords, one tried and true technique remains: violence. It is is this more aggressive form of good cop bad cop behavior which the Turkish government is alleged to have turned to, in order to learn the cryptographic keys of one of primary ringleaders in the TJ Maxx credit card theft investigation.
The 2005 theft of tens of million credit card numbers from an unsecured wireless network run by TJ Maxx stores has lead to over 150 million dollars in damages for the company. The two gentlemen behind the heist sold the pilfered credit card information to others online. Eventually, the stolen cards reached Maksym Yastremskiy, a Ukrainian citizen, and, according to media reports, a "major figure in the international sale of stolen credit card information."
Mr Yastremskiy was later arrested in 2007, while on vacation in Turkey. The US government has formally requested that Yastremskiy be extradited, and has charged him with a number of crimes including aggravated identity theft.
More
here.
Note: I was traveling on Friday and missed this -- hat-tip goes to
Schneier.
-ferg
Ukrainian Suspect Named in TJX Credit Card Probe
Ross Kerber writes in The Boston Globe:
Authorities have zeroed in on a Ukrainian man they suspect played a key role in the sale of many credit card numbers stolen from TJX Cos. in what is considered the biggest corporate data breach to date.
Officials hope the recent arrest of Maksym Yastremskiy will be a breakthrough in the investigation of who hacked into systems at TJX and other companies, said Greg Crabb, a program manager in the global investigations division of the US Postal Inspection Service. The service is among various law enforcement agencies trying to track down hackers who made off with more than 45 million credit and debit card numbers from TJX starting in 2005.
Crabb said Yastremskiy allegedly sold card numbers through online forums hosted overseas, sometimes in Cyrillic or that were password protected. He is likely the largest seller of stolen TJX numbers, Crabb said.
Prices ranged from $20 to $100 per stolen card, and the cards were sold in batches of up to 10,000, depending on factors like the credit limits of the consumer accounts being traded. Crabb said Yastremskiy is associated with at least one other Ukrainian man previously charged with similar crimes, though unrelated to the TJX case.
More
here.
Hackers Indicted for Stealing Credit and Debit Card Numbers From Dave & Buster's - UPDATE
Via PRNewswire.com.
Three defendants have been charged in a federal grand jury indictment and complaint with illegally accessing the computer systems of a national restaurant chain and stealing credit and debit card numbers from that system, Assistant Attorney General Alice S. Fisher of the Criminal Division and U.S. Attorney for the Eastern District of New York Benton J. Campbell announced today.
The 27-count indictment, returned on March 12, 2008, and unsealed today in Central Islip, N.Y., charges Maksym Yastremskiy, of Kharkov, Ukraine, and Aleksandr Suvorov, of Sillamae, Estonia, with wire fraud conspiracy, wire fraud, conspiracy to possess unauthorized access devices, access device fraud, aggravated identity theft, conspiracy to commit computer fraud, computer fraud and counts of interception of electronic communications. A one-count complaint unsealed today in Central Islip charges Albert Gonzalez of Miami with wire fraud conspiracy related to the scheme.
According to the indictment and complaint, Maksym Yastremskiy, a/k/a "Maksik," Aleksandr Suvorov, a/k/a "JonnyHell," and Albert Gonzales, a/k/a "Segvec," engaged in a scheme in which they hacked into cash register terminals at 11 Dave & Buster's Inc. (D&B) restaurants at various locations around the United States in order to acquire "track 2" credit and debit card information. The defendants then sold the stolen data to others who used it to make fraudulent purchases or re-sold it to make such purchases, causing losses to financial institutions that issued the credit and debit cards. Track 2 data includes the customer's account number and expiration date, but not the cardholder's name or other personally identifiable information.
More
here.
Hat-tip: Pogo Was Right
UPDATE: 15:15 PDT: Additional details via Threat Level here. -ferg
Man Gets 6 Years in Prison for Laundering $2.5 Million for Carders
Kim Zetter writes on Threat Level:
A California man who served as a lynchpin for transmitting stolen money to hackers and carders in East Europe and elsewhere was sentenced on Thursday to 6 years in prison for conspiring to launder money.
Cesar Carranza, 38, also known as “uBuyWeRush,” ran a legitimate business selling liquidation and overstock merchandise online and from three California stores.
But, according to an indictment [.pdf], he also sold MSR-206’s to carders to encode stolen bank card data onto blank cards, and he served as a conduit to transmit stolen money between mules and carders.
He worked with many of the top carders in the criminal underground between 2003 and 2006, including Maksim “Maksik” Yastremskiy, a Ukrainian carder who allegedly worked with TJX hacker Albert Gonzalez and was considered by authorities to be one of the top sellers of stolen card data on the internet.
In 2003 and 2004, Carranza became an approved and trusted vendor on online criminal forums such as CarderPlanet and Shadowcrew, advertising his goods and services and dispensing advice on the best tools to use for various criminal endeavors.
More
here.
Gonzalez's Lawyer to Contend He Was Not The Kingpin of Heartland, Hannaford Breaches
Jaikumar Vijayan writes in ComputerWorld:
The attorney for Albert Gonzalez, the man indicted Monday on charges related to the massive data thefts at Heartland Payment Systems and four other retailers, claims it was another member of Gonzalez's gang who was the real leader of the heists.
In an interview with the New York Times, Gonzalez's lawyer, Rene Palomino, said he was prepared to argue that the person who organized the break-ins at Heartland and elsewhere was really Damon Patrick Toey of Miami.
Palomino said Toey is the individual who was identified only as "P.T," an unindicted co-conspirator in Monday's indictment papers. Palomino also told the Times that one of the unnamed Russian conspirators mentioned in the indictment is an individual named Maksym Yastremskiy, who is currently serving a 30-year sentence in a Turkish prison.
Toey was one of 11 individuals, including Gonzalez, who were indicted last year on charges related to the data thefts at TJX Companies Inc., Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.
More
here.