Search This Blog

Showing posts with label STOLEN CREDIT CARD NUMBERS. Show all posts
Showing posts with label STOLEN CREDIT CARD NUMBERS. Show all posts

Thursday, September 17, 2015

HACKER ADMITS TO ROLE IN $300 MILLION+ ATTACKS ON CORPORATE NETWORKS

FROM:  U.S. JUSTICE DEPARTMENT 
Tuesday, September 15, 2015
Russian National Admits Role in Largest Known Data Breach Conspiracy Ever Prosecuted
Hackers Targeted Major Payment Processors, Retailers and Financial Institutions Around the World

A Russian national today admitted his role in a worldwide hacking and data breach scheme that targeted major corporate networks, compromised more than 160 million credit card numbers and resulted in hundreds of millions of dollars in losses –  the largest such scheme ever prosecuted in the United States.

Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, U.S. Attorney Paul J. Fishman of the District of New Jersey and Director Joseph P. Clancy of the U.S. Secret Service made the announcement.

Vladimir Drinkman, 34, of Syktyvkar, Russia, and Moscow, pleaded guilty before Chief U.S. District Judge Jerome B. Simandle of the District of New Jersey to one count of conspiracy to commit unauthorized access of protected computers and one count of conspiracy to commit wire fraud.  Drinkman was arrested in the Netherlands on June 28, 2012, and was extradited to the District of New Jersey on Feb. 17, 2015.  Sentencing is scheduled for Jan. 15, 2016.

“This hacking ring’s widespread attacks on American companies caused serious harm and more than $300 million in losses to people and businesses in the United States,” said Assistant Attorney General Caldwell.  “As demonstrated by today’s conviction, our close cooperation with our international partners makes it more likely every day that we will find and bring to justice cyber criminals who attack America – wherever in the world they may be.  As law enforcement around the world responds to the cyber threat that affects us all, I am confident that this type of international cooperation that led to this result will be the new normal.”

“Defendants like Vladimir Drinkman, who have the skills to break into our computer networks and the inclination to do so, pose a cutting edge threat to our economic well-being, our privacy and our national security,” said U.S. Attorney Fishman.  “The crimes to which he admitted his guilt have a real, practical cost to our privacy and our pocketbooks.  Today’s guilty plea is a tribute to the skill and perseverance of the agents and prosecutors who brought him to justice.”

“This cyber case highlights the effectiveness of global law enforcement partnerships in the detection and dismantling of criminal enterprises targeting U.S. citizens,” said Director Clancy.  “The support of U.S. Attorney’s offices and the resulting plea enhances the Secret Service’s commitment to vigorously pursue transnational threats to the U.S. financial infrastructure.”

According to documents filed in this case and statements made in court, Drinkman and four co-defendants allegedly hacked into the networks of corporate victims engaged in financial transactions, retailers that received and transmitted financial data and other institutions with information that the conspirators could exploit for profit, including the computer networks of NASDAQ, 7-Eleven, Carrefour, JCP, Hannaford, Heartland, Wet Seal, Commidea, Dexia, JetBlue, Dow Jones, Euronet, Visa Jordan, Global Payment, Diners Singapore and Ingenicard.

According to the indictment in this case and statements made in court, the five defendants each played specific roles in the scheme.  Drinkman and Alexandr Kalinin, 28, of St. Petersburg, Russia, allegedly specialized in penetrating network security and gaining access to the corporate victims’ systems.  Drinkman and Roman Kotov, 34, of Moscow, allegedly specialized in mining the networks to steal valuable data.  The hackers hid their activities using anonymous web-hosting services allegedly provided by Mikhail Rytikov, 28, of Odessa, Ukraine.  Dmitriy Smilianets, 32, of Moscow, allegedly sold the information stolen by the other conspirators and distributed the proceeds of the scheme to the participants.

Drinkman and Kalinin were previously charged in New Jersey as “Hacker 1” and “Hacker 2” in a 2009 indictment charging Albert Gonzalez, 34, of Miami, in connection with five corporate data breaches, including the breach of Heartland Payment Systems Inc., which at the time was the largest ever reported.  Gonzalez is currently serving 20 years in federal prison for those offenses.  Kalinin is also charged in two federal indictments in the Southern District of New York: the first charges Kalinin in connection with hacking certain computer servers used by NASDAQ and the second charges him and another Russian hacker, Nikolay Nasenkov, with an international scheme to steal bank account information from U.S.-based financial institutions.  Rytikov was previously charged in the Eastern District of Virginia in an unrelated scheme.

Drinkman and Smilianets were arrested at the request of the United States while traveling in the Netherlands on June 28, 2012.  Smilianets was extradited on Sept. 7, 2012, and remains in federal custody.  Kalinin, Kotov and Rytikov remain at large.

The Attacks

According to documents filed in this case and statements made in court, the five defendants penetrated the computer networks of several of the corporate victims and stole user names and passwords, means of identification, credit and debit card numbers and other corresponding personal identification information of cardholders.  The conspirators allegedly acquired more than 160 million card numbers through hacking.

The initial entry was often gained using a “SQL injection attack.”  SQL, or Structured Query Language, is a type of programming language designed to manage data held in particular types of databases; the hackers allegedly identified vulnerabilities in SQL databases and used those vulnerabilities to infiltrate a computer network.  Once the network was infiltrated, the defendants allegedly placed malicious code (malware) in the system.  This malware created a “back door,” leaving the system vulnerable and helping the defendants maintain access to the network.  In some cases, the defendants lost access to the system due to companies’ security efforts, but were allegedly able to regain access through persistent attacks.

Instant message chats obtained by law enforcement revealed that the defendants allegedly targeted the victim companies for many months, waiting patiently as their efforts to bypass security were underway, sometimes leaving malware implanted in multiple companies’ servers for more than a year.

The defendants allegedly used their access to the networks to install “sniffers,” which were programs designed to identify, collect and steal data from the victims’ computer networks.  The defendants then allegedly used an array of computers located around the world to store the stolen data and ultimately sell it to others.

Selling the Data

According to documents filed in this case and statements made in court, after acquiring the card numbers and associated data – which they referred to as “dumps” – the conspirators sold it to resellers around the world.  The buyers then sold the dumps through online forums or directly to individuals and organizations.  Smilianets was allegedly in charge of sales, selling the data only to trusted identity theft wholesalers.  He allegedly charged approximately $10 for each stolen American credit card number and associated data, approximately $50 for each European credit card number and associated data and approximately $15 for each Canadian credit card number and associated data – offering discounted pricing to bulk and repeat customers.  Ultimately, the end users encoded each dump onto the magnetic strip of a blank plastic card and cashed out the value of the dump by withdrawing money from ATMs or making purchases with the cards.

Covering Their Tracks

According to documents filed in this case and statements made in court, the defendants allegedly used a number of methods to conceal the scheme.  Unlike traditional Internet service providers, Rytikov allegedly allowed his clients to hack with the knowledge he would never keep records of their online activities or share information with law enforcement.

Over the course of the conspiracy, the defendants allegedly communicated through private and encrypted communications channels to avoid detection.  Fearing law enforcement would intercept even those communications, some of the conspirators allegedly attempted to meet in person.

To protect against detection by the victim companies, the defendants allegedly altered the settings on victim company networks to disable security mechanisms from logging their actions.  The defendants also allegedly worked to evade existing protections by security software.

As a result of the scheme, financial institutions, credit card companies and consumers suffered hundreds of millions of dollars in losses – including more than $300 million in losses reported by just three of the corporate victims – and immeasurable losses to the identity theft victims in costs associated with stolen identities and false charges.

The charges and allegations contained in indictments are merely accusations and the defendants are presumed innocent unless and until proven guilty.

The case is being investigated by the U.S. Secret Service’s Criminal Investigations Division and Newark, New Jersey, Division.  The case is being prosecuted by Trial Attorney Richard Green of the Criminal Division’s Computer Crime and Intellectual Property Section, Chief Gurbir S. Grewal of the District of New Jersey’s Economic Crimes Unit and Assistant U.S. Attorney Andrew S. Pak of the District of New Jersey.  The Criminal Division’s Office of International Affairs, public prosecutors with the Dutch Ministry of Security and Justice and the National High Tech Crime Unit of the Dutch National Police also provided valuable assistance.

Saturday, August 4, 2012

HACKER GETS SEVEN YEARS IN PRISON FOR STEALING OVER 240,000 CREDIT CARD NUMBERS

FROM: U.S. DEPARTMENT OF JUSTICE
Wednesday, July 18, 2012
Hacker Sentenced to Seven Years in Prison for Role
in Two Hacking Schemes Involving a Total of More Than 240,000 Stolen Credit Card
Numbers

WASHINGTON – Aleksandr Suvorov, of Estonia, was sentenced today to seven years in prison for his role in two separate hacking schemes involving a total of more than 240,000 stolen credit card numbers.

The sentence was announced today by Assistant Attorney General Lanny A. Breuer for the Criminal Division, U.S. Attorney for the Eastern District of New York Loretta E. Lynch, U.S. Attorney for the Southern District of California Laura E. Duffy and Director of the U.S. Secret Service Mark Sullivan.

Suvorov, 28, was sentenced by U.S. District Judge Sandra J. Feuerstein in Central Islip, N.Y. Suvorov was an accomplice to Albert Gonzalez, one of the most prolific identity thieves ever prosecuted by the U.S. government.

Suvorov pleaded guilty in May 2009 to a wire fraud conspiracy charge, filed in the Eastern District of New York, for hacking into the national restaurant chain Dave & Buster’s and stealing more than 80,000 credit card numbers. In addition, Suvorov pleaded guilty in November 2011 to a trafficking in unauthorized access devices charge, originally filed in the Southern District of California, related to the sale of more than 160,000 stolen credit card numbers to an undercover agent with the U.S. Secret Service. The cases were consolidated in the Eastern District of New York for sentencing. In addition to his prison term, Suvorov was ordered to pay $675,000 in restitution and to satisfy a $300,000 asset forfeiture judgment stemming from the New York charges.

"Mr. Suvorov participated in a scheme to sell thousands of credit card numbers stolen from unsuspecting consumers," said Assistant Attorney General Breuer. "Computer hackers like Mr. Suvorov victimize businesses and individuals, posing a serious threat to their financial security. Today’s sentence sends a clear message that cyber criminals operating abroad will suffer severe consequences for their crimes."

"Suvorov reached across an ocean to victimize thousands of Americans," said U.S. Attorney Lynch. "That ocean was no protection from the reach of U.S. law enforcement, whose coordinated efforts put a stop to Suvorov and his cohorts’ criminal scheme. He will now serve his sentence in the country of his victims. Computer hackers and identity thieves who prey on innocent American consumers, businesses and financial institutions will find no refuge from U.S. criminal justice in any corner of the globe."

"This international criminal enterprise thought that they could traffic in stolen credit card information from abroad, but due to the coordinated efforts of the United States Secret Service and the Justice Department, they were wrong," said U.S. Attorney Duffy. "The agents of the San Diego field office of the United States Secret Service are to be commended for their investigative work in dismantling this organization."

"This case demonstrates the potential for criminals to inflict significant damage to our nation’s financial sector, but this investigation and the resulting sentences should serve as a warning to cyber criminals that law enforcement will continue to pursue them wherever they are," said U.S. Secret Service Director Sullivan. "The Secret Service, in conjunction with its many law enforcement partners across the United States and around the world, continues to successfully combat these crimes by adapting our investigative methodologies. We realize our success in this investigation is due to the cooperation of these partners in more than a dozen international law enforcement agencies."

According to court documents, in the New York case, Suvorov, Albert Gonzalez and a third co-conspirator devised a scheme to gain unauthorized access into the computer systems of Dave & Buster’s Inc. for the purposes of installing malicious software and extracting credit card information of the Dave & Buster’s patrons. Gonzalez, who was in Miami, sent the software, known as a "packet sniffer," to a co-conspirator in Ukraine. A packet sniffer is malicious software designed, in this case, to collect credit card information. The co-conspirator in Ukraine then provided the packet sniffer to Suvorov in Estonia. Suvorov, working with another individual, gained unauthorized access to 11 Dave & Buster’s restaurants throughout the United States, one of which was in Islandia, N.Y., and installed the packet sniffer. Suvorov and his co-conspirators ultimately obtained data from 81,005 credit cards.

Gonzalez was sentenced in March 2010 to 20 years in prison for his role in the Dave & Buster’s hack, as well as hacks into a major payment processor and several retail networks. The other co-conspirator was arrested in Turkey on related identity theft charges, and was sentenced there to 30 years in prison.

In the California case, Suvorov and an accomplice conspired to sell more than 160,000 stolen credit card numbers to a buyer in San Diego who was an undercover agent with the U.S. Secret Service. Suvorov provided the stolen credit card numbers to an accomplice, who in turn sold them to the undercover agent.

The New York case was prosecuted by Assistant U.S. Attorney William Campos of the Eastern District of New York and Trial Attorneys James Silver and Evan Williams of the Criminal Division’s Computer Crime & Intellectual Property Section (CCIPS) and was investigated by the U.S. Secret Service Criminal Investigative Division Cyber Investigations Branch. Former CCIPS Assistant Deputy Chief Howard Cox and Senior Counsel Kimberly Peretti also contributed significantly to the investigation and prosecution of this case. The California case was prosecuted by Assistant U.S. Attorney Orlando Gutierrez of the Southern District of California and investigated by the U.S. Secret Service San Diego Field Office. The Office of International Affairs in the Criminal Division provided significant assistance.
a href="http://gan.doubleclick.net/gan_click?lid=41000613802101859&pubid=21000000000397724">Furniture Event - Save up to 50% at officemax.com