News Blog

News Blog


Justice indicts three for alleged role in U.S.'s largest financial info heist

hacker, data theft, identity theftThe Justice Department yesterday announced indictments against three hackers thought to be involved in a data theft affecting 130 million credit and debit card accounts, reportedly the largest breach of financial information ever perpetrated in the U.S. 

All three are charged with two counts of the following: conspiracy to gain unauthorized access to computers, to commit fraud in connection with computers and to damage computers; and conspiracy to commit wire fraud. Each defendant faces a maximum of 35 years in prison and more than $1 million in fines or twice the monetary gain resulting from the offenses, whichever is greater, The Washington Post reports. 

The details of the case provide insight into the complexity of cyber attacks, how criminal hackers operate, and the extent of the problem. One of those indicted includes 28-year-old Miami resident Albert Gonzalez, who also goes by the aliases "segvec," "soupnazi" and "j4guar17." Gonzalez has a long history of committing computer crimes, and even pulled off this mother-of-all computer break-ins while serving as a confidential government informant. 

Law enforcement says that beginning in October 2006 Gonzalez and two other unnamed co-conspirators found ways around computer security that afforded them access to the computer systems of a number of businesses, including Heartland Payment Systems, a Princeton, N.J.–based card payment processor. After penetrating these systems, the hackers allegedly stole credit and debit card data, and then covered their tracks by sending that data to computer servers that the team operated in California, Illinois, Latvia, the Netherlands and Ukraine. 

During this time, Gonzalez was working both sides of the law, since he had served as a confidential informant to the U.S. Secret Service following his arrest in 2003 for credit card fraud in another case, the Post reports. As an informant, he participated in "Operation Firewall," helping the Justice Department, Secret Service and other law enforcement organizations in 2004 bust 30 or so members of an online network used to buy and sell stolen personal and financial data. 

Gonzalez's cyber rap sheet is a long one. In May 2008, the U.S. Attorney's Office for the Eastern District of New York charged Gonzalez for his alleged role in the hacking of a computer network run by a national restaurant chain. Massachusetts prosecutors have likewise indicted Gonzalez and others for a number of hacks affecting eight major retailers—including T. J. Maxx, Barnes & Noble, BJ's Wholesale Club, Boston Market, DSW, Forever 21, Office Max and Sports Authority. The resulting theft of data related to 40 million credit and debit cards, the Post reports. (Gonzalez has pled not guilty to those charges and will go on trial for them next year.) 

Prior to the Heartland Payment Systems break-in, the data breach case involving these retailers had been the largest data breach case in U.S. history. This means that if Gonzalez is found guilty in both cases, he will have been a key player in the U.S.'s two largest data heists. 

Gonzalez and his co-conspirators in the earlier case stole credit and debit card numbers after breaking into the retailers' wireless networks via a technique known as "wardriving," the practice of using a laptop, antenna and global positioning system to detect wireless access points and determine how they're configured. Once inside the networks, the hackers installed "sniffer" programs to capture card numbers, passwords and account information, as they were processed through the retailers' credit and debit processing networks. 

These cyber crimes have cost Heartland $32 million and TJX (the parent company of T. J. Maxx, Marshalls and other retailers) more than $200 million thus far, according to filings the companies have made with the U.S. Securities and Exchange Commission. 

Image ©iStockphoto.com/ Mike Cherim

Tags: Securities and Exchange Commission, Gonzalez, Heartland Payment Systems, TJX, TJ Maxx
More News Blog: Next: Renewable energy also better for workers' health Previous: Paper or plastic--Or neither? Seattle votes today on 20-cent fee for disposable bags

2 Comments

Add Comment
View
  1. 1. commonsenseguy 04:39 PM 8/20/09

    How dumb can companies be in the way they handle credit care information in this day and age. There is excellent software for encription available for a trivial cost. Just surch for Zimmerman encription program from Germany. The program is so good that Zimmerman had to move his operation to Gremany due to the US governments' fear of the public having such an excellent encription program that they could't bread easily.

    Reply | Report Abuse | Link to this
  2. 2. commonsenseguy 04:43 PM 8/20/09

    How dumb can companies be when storing credit card information that can be hacked. There is encription software available at a trivial cost that could prevent such a disaster. Software such as Zimmerman's encription program is one of them. His program is so good that the US government would not allow him to offer it in the US so he moved his operation to Germany.

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital
  SA Digital

Science Jobs of the Week

Email this Article

Justice indicts three for alleged role in U.S.'s largest financial info heist: Scientific American Blog

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X

About the Bering in Mind Blog

In this column presented by Scientific American Mind magazine, research psychologist Jesse Bering of Queen's University Belfast ponders some of the more obscure aspects of everyday human behavior. Ever wonder why yawning is contagious, why we point with our index fingers instead of our thumbs or whether being breastfed as an infant influences your sexual preferences as an adult? Get a closer look at the latest data as "Bering in Mind" tackles these and other quirky questions about human nature. Sign up for the RSS feed or friend Dr. Bering on Facebook and never miss an installment again.

X

About the Cross-check Blog

Every week, John Horgan takes a puckish, provocative look at breaking science. A former staff writer at Scientific American, he is the author of several books—most notably, The End of Science: Facing the Limits of Knowledge in the Twilight of the Scientific Age. He currently directs the Center for Science Writings at Stevens Institute of Technology. He lives in New York State's Hudson Highlands, where he plays ice hockey each winter to hone his cross-checking skills.

X

Expeditions Blog

Ever wonder what it's really like to be working in Antarctica or collecting core samples from the middle of the Pacific Ocean? Get a first-hand feel for scientific exploration by following the blog posts of researchers out in the field.

X

About the Extinction Countdown Blog

Several times a week, John Platt shines a light on endangered species from all over the globe, exploring not just why they are dying out but also what's being done to rescue them from oblivion. From unusual or little-known organisms like the giant spitting earthworm and the stinking hawk's-beard to popular favorites like cheetahs and koalas, Platt, a journalist specializing in environmental issues and technology, does his part to slow the countdown.

X

About the Guest Blog

The editors of Scientific American regularly encounter perspectives on science and technology that we believe our readers would find thought-provoking, fascinating, debatable and challenging. The guest blog is a forum for such opinions. The views expressed belong to the author and are not necessarily shared by Scientific American.

X

About the Solar at Home Blog

Follow Scientific American editor George Musser as he installs--or tries to install--solar photovoltaic panels on the roof of his suburban New Jersey home. You'll learn the literal nuts and bolts of going green with the sun and get energy-saving tips even if you aren't putting up panels.

Write to us with tips or comments at blog@sciam.com and follow us on Twitter: http://twitter.com/sciam.

X