Showing posts with label TJX Companies. Show all posts
Showing posts with label TJX Companies. Show all posts



TJX Hacker Gets 20 Years in Prison

Wired: BOSTON — Convicted TJX hacker Albert Gonzalez was sentenced to 20 years in prison on Thursday for leading a gang of cyberthieves who stole more than 90 million credit and debit card numbers from TJX and other retailers.
The sentence for the largest computer-crime case ever prosecuted is the lengthiest ever imposed in the United States for hacking or identity-theft. Gonzalez was also fined $25,000. Restitution, which will likely be in the tens of millions, was not decided Thursday.
Clean-cut, wearing a beige jail uniform and wireframe glasses, the 28-year-old Gonzalez sat motionless at his chair during Thursday’s proceedings, his hands folded in front of him.
Before the sentence was pronounced, Gonzalez told the court he deeply regrets his crimes, and is remorseful for having taken advantage of the personal relationships he’d forged. “Particularly one I had with a certain government agency … that gave me a second chance in life,” said the hacker, who had worked as a paid informant for the Secret Service. “I blame nobody but myself.”




Read More http://www.wired.com/threatlevel/2010/03/tjx-sentencing/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29#ixzz0jIaSDvw5

Reblog this post [with Zemanta]

Posted by John B. Frank Friday, March 26, 2010 0 comments



TJX Hacker Gets 20 Years in Prison

Wired: BOSTON — Convicted TJX hacker Albert Gonzalez was sentenced to 20 years in prison on Thursday for leading a gang of cyberthieves who stole more than 90 million credit and debit card numbers from TJX and other retailers.
The sentence for the largest computer-crime case ever prosecuted is the lengthiest ever imposed in the United States for hacking or identity-theft. Gonzalez was also fined $25,000. Restitution, which will likely be in the tens of millions, was not decided Thursday.
Clean-cut, wearing a beige jail uniform and wireframe glasses, the 28-year-old Gonzalez sat motionless at his chair during Thursday’s proceedings, his hands folded in front of him.
Before the sentence was pronounced, Gonzalez told the court he deeply regrets his crimes, and is remorseful for having taken advantage of the personal relationships he’d forged. “Particularly one I had with a certain government agency … that gave me a second chance in life,” said the hacker, who had worked as a paid informant for the Secret Service. “I blame nobody but myself.”




Read More http://www.wired.com/threatlevel/2010/03/tjx-sentencing/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29#ixzz0jIaSDvw5

Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

http://www.networkworld.com/news/2008/110408-ny-man-indicted-for-role.html

N.Y. man indicted for role in data breaches

By Jaikumar Vijayan , Computerworld , 11/04/2008



A New York man has been charged with providing co-conspirators with a 'sniffer' program for capturing payment card data as it traveled across corporate networks, apparently the latest person to be indicted in connection with data breaches at TJX Companies Inc and other major retailers.



Stephen Watt, 25, of New York, was charged in U.S. District Court in Boston on Oct. 29 with unlawful access to computers, wire fraud, aggravated identity theft and money laundering.



The indictment makes no direct mention of Watt's role in a series of breaches at major retailers such as TJX, BJ's Wholesale Club, DSW Inc., OfficeMax Inc., Boston market, Barnes and Noble Inc., Sports Authority and Forever 21.



But it names Albert Gonzalez as one of the individuals Watt supplied the sniffer programs to; Gonzalez has been indicted for his role as the alleged ring leader of the gang responsible for the retail break-ins. He has pleaded innocent to the charges.  A spokeswoman for the U.S. Attorney's office in Massachusetts Tuesday declined to comment on whether Watt's indictment is related to the retail breaches since it is not mentioned in the indictment.



Gonzalez was one of 11 people indicted in August in a massive identity theft and computer fraud scheme involving some of the largest data breaches in recent U.S. history. Gonzalez and his gang are accused of breaking into numerous retail networks and stealing payment card data -- including data on nearly 44 million cards from TJX alone -- over a five-year period starting from 2003.



The thefts relied on vulnerabilities in the wireless networks used at retail store locations: Gonzalez and others would go "war-driving" in commercial areas of Miami looking for vulnerable retail networks. Once they broke into a network, they would locate and steal "Track 2" data from the magnetic stripe on the back of payment cards, as well as PIN-block data associated with debit cards. The gang is alleged to have maintained servers in the U.S., Latvia and Ukraine that were used to store tens of millions of stolen credit and debit card numbers.



So far, two of the indicted individuals have pleaded guilty to charges in the case. In September, Damon Patrick Toey pleaded guilty to four felony counts, including wire and credit card fraud and aggravated identity theft. He is scheduled to be sentenced on Dec. 10 in U.S. District Court in Boston, and faces a maximum prison term of five years and a fine of US$250,000 on each of the counts.



That same month, Christopher Scott, 25, of Miami become the second man to plead in the case. He faces a maximum of 22 years in prison and a $1 million fine. Scott also will forfeit the $400,000 or so that he made in profits from the payment card thefts.



Court documents filed in connection with Watt's indictment, meanwhile, said he was part of a criminal gang that between 2003 and 2008 broke into several corporate networks to steal payment card information and use or sell that information to others. The stolen funds were funneled through Internet currency exchanges and bank accounts in Latvia to conceal the source, ownership and control of the money.



Watt allegedly provided a sniffer program that allowed Gonzalez and other gang members to identify and capture credit and debit card data traveling over the networks they had broken into. In January, he edited and modified a sniffer program dubbed 'blabla" that was used by the gang and stored in a server with a Latvian IP address, according to the indictment.  (see graphic below)



If convicted, Watt faces up to five years in prison, a fine of $250,000 and three years of supervised released, according to a statement released by the U.S. Attorney's office in Massachusetts








Reblog this post [with Zemanta]

Posted by John B. Frank Wednesday, November 5, 2008 0 comments

Image representing Associated Press as depicte...Image via CrunchBase

The Associated Press: Outsourcing aids many data thefts, Verizon says
By PETER SVENSSON – 11 hours ago

NEW YORK (AP) — The reliance of restaurant chains and retail stores on outside companies to handle credit-card processing and other information-technology functions is partly to blame for a rash of consumer data breaches over the last few years, according to data sleuths at Verizon Communications Inc.

Even a chain with thousands of restaurants might have only 100 employees in information technology, so it uses outside vendors for many IT functions, said Bryan Sartin, director of the investigative response team at Verizon Business.

"What happens is there's a lack of accountability on the third party," Sartin said.

Verizon's unit investigates a quarter to a third of the big, publicly announced data breaches that occur each year, and hundreds of smaller cases.

In recent years, restaurant and retail businesses have accounted for more than half of Verizon's 230 to 250 cases per year, according to a report Verizon was set to issue Thursday. It often finds that insiders at service vendors are part of the heists.

Organized data-stealing gangs "go to the call centers, the Web development companies, the content development companies, the business partners, the people who pick up the backup tapes," Sartin said. "They say ... if you hate your boss and you're in financial straits, we're your solution. Give us access to your customers. Better yet, give us your data."

In a typical case Sartin was involved in, the team was approached by a large oil company in Canada, with thousands of gas stations. Customers were finding spurious charges on their credit cards after using them at the stations.

The team soon figured out that someone at a technology vendor was responsible, but couldn't pin it down. So the investigators set a trap in the system, to see who accessed customer data.

"The trap went off on Saturday morning," Sartin said. "Hackers always think nobody's looking on Saturday mornings."

A police car headed to the vendor's office, and the culprit turned out to be a 21-year-old who supported the software that operated the gas pumps. He had sold lists of customer data to organized crime.

Many breaches don't happen through outsourcing. In one of the largest cases in recent years, the gang that stole 41 million credit and debit card numbers from chains including TJX Cos. obtained access through unsecured wireless networks, not through subcontractors' systems.

Still, Verizon's report advises companies to keep a tighter rein on contractors, including by limiting partners' access to only the data they need.
Reblog this post [with Zemanta]

Posted by John B. Frank Thursday, October 2, 2008 0 comments

Man accused in TJX data breach pleads guilty

September 12, 2008 (Computerworld) One of the 11 people arrested last month in connection with the massive data theft at TJX Companies Inc., BJ Wholesale Clubs Inc. and several other retailers pleaded guilty yesterday to four felony counts, including wire and credit card fraud and aggravated identity theft.

Damon Patrick Toey is scheduled to be sentenced on Dec. 10 in U.S. District Court in Boston. He faces a maximum prison term of five years and a fine of $250,000 on each of the counts. In addition, under the terms of the plea agreement, Toey has to forfeit all of the money he earned for his role in the data theft. It is not clear how much he may have made from the attacks, although he had about $9,500 in his possession when he was arrested in May.

Toey was one of 11 alleged hackers arrested last month in connection with a series of data thefts and attempted data thefts at TJX and numerous other companies. Besides TJX and BJ's, the list of publicly identified victims of the hackers includes DSW, OfficeMax, Boston Market, Barnes and Noble, Sports Authority and Forever 21.

In a court filing yesterday, Assistant U.S. Attorney Stephen Heymann said that there is "forensic and/or testimonial evidence" that Toey and his co-conspirators broke into "numerous" other businesses that have not been publicly identified. Heymann said he would be willing to submit the full list "in camera" to the court if needed.

The ID theft ring stole data involving more than 45 million payment cards, leaving 100 or so financial institutions vulnerable to losses from fraud, Heymann said.

The breach was made public in January 2007 by Framingham, Mass.-based TJX, which later reported in a filing with the U.S. Securities and Exchange Commission that 45.6 million credit card numbers were affected -- the largest such breach on record eclipsing the June 2005 CardSystems breach.

(CardSystems was later purchased by Solidus Networks/Pay By Touch)

The alleged thefts by Toey and his companions occurred over a five-year period, from 2003 to 2008, and were largely perpetrated -- at least, initially -- by taking advantage of vulnerabilities in the wireless networks used at retail store locations. Around mid-2007, the group, largely with the help of Toey, started launching online attacks on Web servers and databases handling payment card data. Accused gang leader Albert Gonzalez allegedly invited Toey to move into his condominium in Miami, where he stayed for free and received periodic payments in return for collaborating on the Internet-base attacks.

Many of the Internet attacks that Toey facilitated were SQL injection attacks, according to court documents.

The documents described Gonzalez, Toey and others as going "war-driving" (see War-Driving 101) in commercial areas of Miami looking for vulnerable retail networks they could attack. Once they broke into a network, they would locate and steal "Track 2" data from the magnetic stripe on the back of payment cards as well as PIN-block data associated with debit cards.

The gang allegedly used sophisticated "sniffer" programs to capture password and user account information, which they would then use to break into other corporate servers containing payment card data. The gang also had access to tools that allowed its members to decipher encrypted PINs. The stolen data was then either sold to cybercriminals in Eastern Europe and the U.S. or used to make fraudulent credit and debit cards.

Toey and his gang allegedly maintained servers in the U.S., Latvia and Ukraine that were used to store tens of millions of stolen credit and debit card numbers, according to court documents.

A spokeswoman for the prosecutor's office today said that Gonzalez made his initial court appearance yesterday and pleaded innocent to the charges against him. He remains in custody without bail. His next hearing is scheduled for sometime next month.

The next person scheduled to make a court appearance in connection with the case is Christopher Scott who appears to have played a major role in the data theft at TJX. Scott faces five felony counts, including unlawful access to computers, wire fraud, aggravated identity theft and money laundering.

On two separate occasions in July 2005, Scott compromised two wireless access points at a TJX-owned Marshall's store in Miami. He used the access to download various commands onto TJX servers containing payment card data. In September 2005, Scott and Gonzalez first started downloading payment card data from TJX servers in Framingham.

About a year after gaining access to the TJX network, Scott established a VPN connection between a TJX payment card transaction processing server and a malicious server owned by Gonzalez. That connection, in turn, was used to upload various sniffer programs to the server to capture transaction data as it was being processed.

Scott collected about $400,000 for his part in the data theft and at the time of his arrest, authorities seized about $6,000 in cash, a Rolex watch and nearly two dozen pieces of electronic equipment -- including several laptop computers, storage devices, PDAs and video recorders.

Posted by John B. Frank Saturday, September 13, 2008 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers