A 28-year-old Miami man was indicted Monday for the largest credit and debit card theft ever prosecuted in the U.S., with data from more than 130 million credit and debit cards stolen, the U.S. Department of Justice said.
The number of cards affected surpasses the 97 million cards compromised a couple of years ago in a data breach at U.S. retail company TJ Maxx.
Albert Gonzalez, also know as segvec, soupnazi and j4guar17, was charged, along with two unnamed co-conspirators, with using SQL injection attacks to steal credit and debit card information. Among the corporate victims named in the two-count indictment are Heartland Payment Systems, a New Jersey card payment processor; 7-Eleven, the Texas-based convenience store chain; and Hannaford Brothers, a Maine-based supermarket chain.
In May, Heartland Payment Systems said that a security breach it suffered earlier this year cost the company about $12.6 million so far, including legal costs and fines from MasterCard and Visa, which directly contributed to a US$2.5 million loss for the quarter.
Early this year, the U.S. Federal Trade Commission and the U.S. Securities and Exchange Commission began investigating Heartland Payment Systems following a massive data breach there.
Beginning in October 2006, Gonzalez and his co-conspirators researched the credit and debit card systems used by their victims and devised a sophisticated attack to penetrate their networks and steal credit and debit card data, the DOJ said. The co-conspirators used sophisticated hacker techniques to cover their tracks, the DOJ alleged.
If convicted, Gonzalez faces up to 20 years in prison on a wire fraud conspiracy charge and an additional five years in prison on a conspiracy charge, as well as a fine of US$250,000 for each charge. This new indictment came from the U.S. District Court for the District of New Jersey.
Gonzalez is in federal custody. In May 2008, the U.S. Attorney’s Office for the Eastern District of New York charged Gonzalez for his alleged role in the hacking of a computer network run by a national restaurant chain. A trial on those charges is scheduled to begin in September.
In August 2008, the DOJ announced an additional series of indictments against Gonzalez and others for a number of retail hacks affecting eight major retailers and involving the theft of data related to 40 million credit cards. Those charges were filed in Massachusetts. Gonzalez is scheduled for trial on those charges in 2010.
The charges announced today relate to a different pattern of hacking activity that targeted different corporate victims and involved different co-conspirators, the DOJ said.