iPhone app iPad app Android phone app Android tablet app More

Biggest Identity Theft Case Ever: 11 Indicted For Stealing And Selling Over 40 Million Credit Card Numbers

I Like ItI Don’t Like It
U.S. Secret Service Director Mark Sullivan, left, and U.S. Attorney General Michael Mukasey, right, listen during a news conference, in Boston, Tuesday, Aug. 5, 2008. The Department of Justice announced Tuesday that it had charged 11 people in connection with the hacking of nine major U.S. retailers and the theft and sale of more than 40 million credit and debit card numbers. The retailers included TJX, BJ's Wholesale Club, OfficeMax, and Boston Market among others. (AP Photo/Steven Senne)

BOSTON — Eleven people, including a U.S. Secret Service informant, have been charged in connection with the hacking of nine major retailers and the theft and sale of more than 41 million credit and debit card numbers, the Justice Department announced Tuesday.

The data breach is believed to be the largest hacking and identity theft case ever prosecuted by the Department of Justice, which said the suspects were charged with conspiracy, computer intrusion, fraud and identity theft.

Three of those charged are U.S. citizens while the others are from places such as Estonia, Ukraine, Belarus and China.

The indictment returned Tuesday by a federal grand jury in Boston alleges that the suspects hacked into the wireless computer networks of retailers including TJX Cos., BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW and set up programs that captured card numbers, passwords and account information.

"They used sophisticated computer hacking techniques that would allow them to breach security systems and install programs that gathered enormous quantities of personal financial data, which they then allegedly either sold to others or used themselves," Attorney General Michael Mukasey said at a news conference. "And in total, they caused widespread losses by banks, retailers, and consumers."

Mukasey called the total dollar amount of the alleged theft "impossible to quantify at this point." U.S. Attorney Michael J. Sullivan said that while most of the victims were in the United States, officials still haven't identified all the people who had a card number stolen.

"I suspect that a lot of people are unaware that their identifying information has been compromised," he said.

Sullivan said the alleged thieves weren't computer geniuses, just opportunists who used a technique called "wardriving," which involved cruising through different areas with a laptop and looking for accessible wireless Internet signals. Once they located a vulnerable network, they installed so-called "sniffer programs" that captured credit and debit card numbers as they moved through a retailer's processing networks.

The information was stored on two servers in Ukraine and Latvia _ one with more than 25 million credit and debit card numbers and another with more than 16 million numbers, Sullivan said.

The heist was a black eye for retailers like TJX. The company initially disclosed the data breach in January 2007 but said a few months later that at least 45.7 million cards were exposed to possible fraud in a breach of its computer systems that began in July 2005. Court filings by some banks that sued TJX put the number of cards affected at more than 100 million, based on estimates by officials with Visa and MasterCard, who were deposed in the suit.

In May, TJX said it won support from MasterCard-issuing banks for a settlement that will pay them as much as $24 million to cover costs from the breach. A similar agreement reached last November with Visa-card issuing banks set aside as much as $40.9 million to help banks cover costs including replacing customers' payment cards and covering fraudulent charges.

According to the indictments unsealed Tuesday, three of the defendants are U.S. citizens, one is from Estonia, three are from Ukraine, two are from China and one is from Belarus. One individual is known only by an alias online, and his place of origin is unknown.

At a press briefing in San Jose, Calif., Homeland Security Secretary Michael Chertoff said the non-U.S. citizens under indictment were part of an international stolen credit and debit card ring.

The ring operated in mainly in Eastern Europe, the Phillipines, China and Thailand, and the alleged foreign conspirators remained outside the U.S., Chertoff said.

The thefts were criminal actions committed for the personal gain of the defendants, who investigators did not consider a national security threat, Chertoff said.

Still, he said, their alleged crimes demonstrated the weaknesses of cybersecurity in the U.S.

"Today's indictments are a reminder of a growing threat that every American faces in the 21st century _ the fact that each individual's greatest asset is their names, their identity," Chertoff said.

In the Boston indictment, the alleged ringleader Albert "Segvec" Gonzalez of Miami was charged with computer fraud, wire fraud, access device fraud, aggravated identity theft and conspiracy. Gonzalez, who is in custody in New York, faces a maximum penalty of life in prison if he is convicted of all the charges.

Gonzalez was a U.S. Secret Service informant who helped the agency take over a Web site being used to transmit stolen identifiers and stolen credit card numbers, U.S. Secret Service Director Mark Sullivan said at the news conference.

"That was the first time ever that a computer system was wiretapped," he said.

But he said the Secret Service later found out that Gonzalez had also been feeding criminals information about ongoing investigations _ even warning off at least one person.

"Obviously, we weren't happy that a person working for us as an informant was double-dealing," Mark Sullivan said.

Indictments were also unsealed Tuesday in San Diego against Maksym "Maksik" Yastremskiy of Kharkov, Ukraine, and Aleksandr "Jonny Hell" Suvorov of Sillamae, Estonia. They are charged with crimes related to the sale of the stolen credit card data.

Yastremskiy was arrested when he traveled to Turkey on vacation in July 2007. He is facing related Turkish charges, and U.S. officials said they have requested his extradition.

Justice Department officials said Suvorov was arrested on the San Diego charges by German officials in March when he traveled there on vacation. He is in custody awaiting the resolution of extradition proceedings.

Indictments against Hung-Ming Chiu and Zhi Zhi Wang, both of China, and a person known only by the online nickname "Delpiero" were also unsealed in San Diego.

A Justice Department spokeswoman said those three suspects, together with five others, are still at large. Officials did not give an arraignment date for Gonzalez.

In May, federal prosecutors in New York indicted Yastremskiy, Suvorov and Gonzalez on 27 counts of fraud and identity theft. The charges stemmed from allegations that they hacked into a national restaurant chain's computerized cash registers and stole credit card information from customers. Eleven Dave & Buster's restaurants around the United States suffered at least $600,000 in losses, prosecutors said.

It was not immediately possible to reach Yastremskiy, Suvorov and Gonzalez for comment and it was not clear if they have legal representation.

___

Associated Press writers Anne D'Innocenzio in New York and Marcus Wohlsen in San Jose, Calif. contributed to this report.

BOSTON — Eleven people, including a U.S. Secret Service informant, have been charged in connection with the hacking of nine major retailers and the theft and sale of more than 41 million credit ...
BOSTON — Eleven people, including a U.S. Secret Service informant, have been charged in connection with the hacking of nine major retailers and the theft and sale of more than 41 million credit ...
Report Corrections
 
 
  • Comments
  • 9
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Recency  | 
Popularity
09:13 AM on 08/06/2008
Great news! I deal with credit card fraud in my job and I am continually baffled how these card numbers, and so many of them, were accessed, including the CVV code and correct name and billing address! Makes a lot of sense and gives me some hope....


What's there to be baffled about? When huge amounts of data are amassed sold to every taker who wants to also sell the info and fill up peoples snail mail and e-mail boxes, it's easy picking. Since these data bases cannot be adequately protected they should not be allowed. Trying to keep one step ahead of hackers is not working, do a shift in thinking and minimize and regulate the info available.
This user has chosen to opt out of the Badges program
photo
loki
cheap politicians for sale
09:46 PM on 08/05/2008
Probably doing this for the CIA or PNAC to fund some kind of un authorized military action. I would not put it past them. Especially PNAC. Remember when daddy Bush ran the CIA and they opened the fake off shore bank so they could funnel money and pay for black opts outside of the reach of US law and Congressional oversight? When it was leaked to the public back in the 80's, I think they had around 140 million US dollars in it then, cant imagine whats in it today. Im sure a lot of the missing war funds headed that way to. If they would stoop to that, I wouldnt put it past them to steal from US consumers to fund their war games. Im not saying they did, just saying I wouldnt doubt it, and one was involved with the SS.
HUFFPOST COMMUNITY MODERATOR
truthynesslover
01:01 AM on 08/06/2008
I would think the bumper crop of opium in afganistan might be enough but Ive been wrong before.Think BIG!
07:07 PM on 08/05/2008
So, now we know where that 1.9 percent growth rate in the economy in June came from.
photo
HUFFPOST SUPER USER
justpatrick
06:42 PM on 08/05/2008
While we have strong laws on the state and federal books regarding theft in general, we have very few laws on the federal books regarding data privacy and its theft, especially the concomitant and cumulative effect that the loss of data privacy has on an individual. When a citizen’s credit cards are stolen, which may be used once, the loss is defined but when their social security numbers are stolen, it has a far more wielding effect as their theft can be used to track that person, watch their bank accounts; the cumulative loss of this theft may not be defined in actual dollars so the actual effect of this time of crime is unlimited and indefinable.
photo
HUFFPOST SUPER USER
MadelineL
06:33 PM on 08/05/2008
Question - What did Mukasey buy at Forever 21? He must have gotten robbed if he actually did something in his job description.
06:24 PM on 08/05/2008
People like this should be blindfolded, handcuffed, stripped butt naked and flown and dumped in the streets of Tehran or Afghanistan.
05:24 PM on 08/05/2008
Great news! I deal with credit card fraud in my job and I am continually baffled how these card numbers, and so many of them, were accessed, including the CVV code and correct name and billing address! Makes a lot of sense and gives me some hope....
SouthernBlueBelle
Old and fed up
05:09 PM on 08/05/2008
Oh great. Sounds like a good time to toss a few cookies. Yikes