Monday, August 24, 2009

THE HACKER WHO STOLE THE DETAILS OF 130 MILLION CREDIT CARDS

       The man who agreed to help nail his accomplices is now accused of the greatest identity theft spree in history By Mark Hughes

       He is handsome, he is rich hereportedly splurged US$75,000 on his own birthday one year - and has the kind of charm that could dazzle the hardest of men,says a US federal secret service agent. But it's not your daughters you need to be locking up - it's your credit cards.
       We have all known for some time that the electronic identity-theft business is burgeoning. The US Treasury Department says it knows of 55,000 cases in only 10 years. But as of now, it has its official poster boy. He is 28-year-old Albert Gonzalez, a man who allegedly has a special talent in this particular line.
       That, at least, is the contention of the authorities in New Jersey, who late last Monday unveiled criminal charges against Mr Gonzalez identifying him as the leader of a three-man ring which, between October,2006,and May,2008, successfully siphoned off the data from no fewer than 130 million credit and debit cards in the US by hacking into the networks of several retail and financial giants,including the 7-Eleven corner-shop chain.
       The charges against Mr Gonzalez and two other unidentified men apparently working out of or close to Russia are causing considerable consternation for a multitude of reasons. For one, this may be the biggest criminal case involving the theft of credit card data ever uncovered. Second, some of the details of the alleged criminal career of Mr Gonzalez are raising eyebrows. For example - why didn't the Feds cotton on to all of this before?
       It turns out that Mr Gonzalez was first detained in 2003 in connection with alleged nefarious hacking operations, but was not prosecuted after he agreed to assist the secret service in trying to nail some of his accomplices. The authorities also agreed to allow him to move from the New York area to Miami.
       Since May last year, Mr Gonzalez has been a resident of a jail in Brooklyn awaiting trial on charges of hacking into the computer system of Dave & Buster's, a national restaurant chain based in Miami. He was allegedly trying to steal card numbers.
       But later last year, the police were pointing to Mr Gonzalez again. In a separate case now pending in Boston, he was accused of being the ringleader of yet another data breach involving a series of companies, but most notably TJ Maxx retail in Massachusetts. On that occasion, prosecutors said, the ring had successfully purloined the details of 40 million cards and their activities had cost TJX which owns TJ Maxx - about $200 million.
       The new set of charges eclipses all that came before, however.
       It also opens the window on a netherworld of electronic crime that will set off new alarm bells in capitals around the world. If one man can be responsible for this number of breaches, the problem may be bigger than anyone imagined.
       If Mr Gonzalez is guilty it is also his chutzpah that shocks. He is "a very important player in a sophisticated ring that has real results at the street level of bank, retail, debit and credit card fraud", acknowledged Seth Kosto,an Assistant US Attorney in New Jersey who specialises in computer fraud.
       According to court documents filed in the TJX case in Boston, Mr Gonzalez instigated what he called an "operation to get rich or die tryin"', which involved identifying some of the biggest companies in the US and setting about assessing how vulnerable their payment systems were to being hacked.
       It is alleged that once Mr Gonzalez and his team had successfully penetrated a particular company's system, an electronic "back door"would be installed that in theory would allow them to return at any time to harvest even more credit card numbers.
       The value of data from stolen credit cards depends on the market. But, according to the latest documents filed in the case, once the information was stolen it was immediately relayed to computers controlled by the ring in different parts of the world, including California and Ukraine.
       Of course those least happy to hear details of Mr Gonzalez's alleged capers are the companies whose names feature in the latest charges, including a supermarket chain called Hannaford."We're pleased that the authorities have aggressively pursued this case to be in a position to bring an indictment against the alleged perpetrators," said Michael Norton,a spokesman for Hannaford.7-Eleven declined to comment.The Independent
       The technique
       Gonzalez allegedly used a technique known as a "SQL injection attack", a form of computer hacking which is designed to exploit security vulnerabilities in databases. This type of attack is said to have started in Russia, China and North Korea, but has become increasingly popular in the US. So much so that computer giant IBM will later this month publish a report that shows that instances of SQL injection attacks have increased by 50% in the first quarter of 2009, compared with the final quarter of 2008.SQL injection requires the hackers to gain access to the computer networks they wish to hack. The hacker would do this by somehow breaching the computer's firewall and then "injecting" software into the database, using SQL (Structured Query Language), which is a database programming language. What type of software is not known, but it would search for PINs or passwords or transaction records. The stolen data is then sent to computer servers to sell on.

No comments:

Post a Comment