TJX Hacker Charged In Heartland, Hannaford Breaches

MIAMI – A one-time government informant, who was charged last year with hacking into TJX Cos. and more than half-dozen other national chains, was among three suspects indicted yesterday with stealing data on millions of accounts from Heartland Payment Systems, Hannaford Brothers and 7-Eleven.

Processing Content

Albert Gonzalez, 28, who has been in jail since last August’s arrest in the TJX case, was charged with using malware to penetrate the three national systems–Heartland, Hannaford and 7-Eleven–then sending the data to computer servers he and his accomplices operated in California, Illinois, Latvia, the Netherlands and Ukraine.

Gonzalez, known over the Internet as "segvec" and soupnazi," is charged with two unnamed Russian co-conspirators with using a sophisticated hacker technique known as "SQL injection attack." The technique seeks to exploit computer networks by finding a way around the network’s firewall to steal credit and debit card information.

Gonzalez was charged with a dozen other suspects last August with running an international ring that hacked into computer systems at TJX, BJ’s Wholesale Club, OfficeMax, Barnes & Noble, Dave & Buster’s, Sports Authority, Forever 21 and DSM Shoes, and accessed credit card information that enabled them to steal tens of millions of dollars from credit union and bank customers. The cards data was used to either tap into credit union or bank accounts and make online purchases or to produce counterfeit cards and sue them to make physical purchases or withdraw millions of dollars in cash from hundreds of ATMs.

Authorities said Gonzalez and his accomplices drove around and scanned the wireless networks of major retailers to find security holes, known as "war driving," then installed "sniffers" on the retailers’ systems that recorded the card information, before sending it to a secure server in Latvia. The data was then sold over the Internet to traffickers who used it to create counterfeit credit and debit cards, they said.

The online thefts occurred while Gonzalez was supposed to be working as a government informant after his arrest in 2003 on similar hacking charges. But the court records have all been expunged in those cases. One was the 2003 hacking into the database at BJ’s Wholesale Club, which forced hundreds of credit unions and banks to reissue credit and debit cards that had been used at the Big Box chain.

Court records show that in November 2004, the government allowed Gonzalez to move from New Jersey to Miami, where many of the subsequent hacking incidents took place.

Prosecutors said Gonzalez is a high-school graduate and self-taught programmer who helped organize the so-called Shadowcrew, an online credit-card hacking ring, which was busted in 2006. Gonzalez wasn't charged then because he agreed to become an informant for the Secret Service following his arrest, according to court records.

 

 

 

 

 

 

 

 


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More