As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust".
There were actually four separate indictments filed, and now that we have the indictments, we'll hopefully be able to learn more about some of these more mysterious criminals.
In the first indictment, the UNITED STATES OF AMERICA v. MAKSYM YASTREMSKIY
the charges are:
18 USC Section 1029(a)(2), and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Sections 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 1956(h) - Conspiracy to Launder Monetary Instruments
18 USC Section 982 - Criminal Forfeiture
As we saw in the first part of today's post, TJX Update: The Boston Indictments, when Albert Gonzalez and friends didn't know how to turn their stolen credit cards into money, they reached out to Eastern Europe for advice. When they didn't know how to crack their PINs, they reached out to Eastern Europe for advice. When they didn't know how to make sure their sniffer programs would remain undetected, they reached out to Eastern Europe for advice.
Much of that time, they were reaching out to Maksym Yastremskiy.
From May 31, 2005 until May 30, 2006, Yastremskiy, operating in the Southern District of California and elsewhere, sold approximately 155,000 credit card numbers "with intent to defraud", for $98,000 in cash.
Maskym ran a website which was his primary mechanism for selling cards. Prices varied by the bulk, and quantities of cards were advertised on the website (presumably by himself and others) in batches from ten or a dozen, up to several hundred thousand cards or even several million.
The general practice was that Maksym would be contacted by email or chat and the subject of how to make the purchase would be discussed. Unknown buyers would wire a cash payment, usually with Western Union, to Yastremskiy or an accomlpice. Trusted purchasers were allowed to wire directly into Yastremskiy's various bank accounts.
Once the funds transfer was complete, the purchaser would be granted the requested number and type of cards through the website. The indictment gives examples such as "10 Citibank Visa (Gold)" or "20 Royal Bank of Hong Kong Master Card (Platinum)" or "12 Chase Visa (Classic)".
Maksym's charges do not specifically reference Gonzalez from Miami, nor do they name the source of the cards.
Forfeiture claim is made to property derived from many payments, including but not limited to:
$846,762.18 in E-Gold accounts
$ 87,517.36 in Parex Bank account
$3,781,436.36 in an Asia Universal Bank account
$4,862,884.96 in Western Union money transfers
$1,931,047 in US currency
The second indictment is the UNITED STATES OF AMERICA v. ALEKSANDR SUVOROV, aka Lifestyle, aka JohnnyHell, aka Dantist.
The charges brought against Suvorov are:
18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(3) and (c)(1)(A)(i) - Possession of Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Sec 2 - Aiding and Abetting
Suvorov's Conspiracy charges name Maksym as his co-conspirator (however Maksym was not charged with Conspiracy in his indictment).
The Overt Acts in the conspiracy are:
On February 10, 2006, Maksym Yastremskiy agreed to sell 160,000 unauthorized credit card account numbers to a purchaser located in San Diego, California.
On February 20, 2006, Sukorov provided Maksym (AKA Maksik) with 160,000 unauthorized credit card account numbers for purpose of re-sale.
On March 17, 2006, in exchange for $10,000 in US Currency, Maksik transferred the first 6,798 of the negotiated 160,000 unauthorized credit cards.
Suvorov received occasional payments from Maksik from May 2, 2005 until May 1, 2006 as the cards were slowly bought and the funds were received back. Over the course of this time, Suvorov received from Maksik approximately $75,000.
In the third indictment, The UNITED STATES OF AMERICA has three Defendants:
SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757
DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf
SERGEY VALERYEVICH STORCHAK, aka Fidel
The only charge against these three is:
18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices
This is such a disappointment after the charges against the Boston crowd and the first two here! What are they charged with?
On May 11, 2007 - Sergey Pavlovich negotiated the sale of 90 stolen credit cards to a purchaser in the Southern District of California.
On September 11, 2006 - Dzmitry Valeryevich Burak negotiated the sale of 30 stolen credit cards to a purchaser in the Southern District of California.
On October 10, 2007 - Sergey Valeryevich Storchak agreed to sell 64 stolen credit cards to a purchaser in the Southern District of California.
Ummmm... Big whoop.
In the fourth indictment, the UNITED STATES OF AMERICA also charges three defendants:
HUNG-MING CHIU, aka Slimbady, aka Tomaliki, aka B&Q, aka Betrmb
ZHI ZHI WANG, aka Akihikotobe, aka Attorney
FNU LNU (for those of you who don't speak Chinese OR Indictmentese, that's First Name Unknown Last Name Unknown), aka Delpiero
The charges brought are:
18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices, to Traffic Counterfeit Access Devices, and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1029(a)(1) and (c)(1)(A)(i) - Trafficking in Counterfeit Access Devices
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 2 - Aiding and Abetting
The three defendants are charged with entering into conspiracy with Maksik (Maksym Yastremskiy) and JonnyHell (that's the third way I've seen that spelled in official documents this week!) (Aleksandr Suvorov).
The Overt Acts in their conspiracy include:
On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was later filled by Hung-Ming Chiu.
On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was subsequently filled by Hung-Ming Chiu.
On September 17, 2005 - Hung-Ming Chiu discussed with Maksym "Maksik" Yastremskiy the creation of a website that could be used to distribute stolen credit card accounts. Maksik agreed that he would be the website's provider of stolen credit card account information.
On September 28, 2007 - FNU LNU, aka Delpiero, sold 100 unauthorized access devices to a purchaser in the Southern District of California.
From September 17, 2004 until September 16, 2005, Hung-Ming sold approximately 162 credit card account numbers that had been stolen or obtained with intent to defraud, for approximately $4,500 in cash.
From September 17, 2005 until September 16, 2006, he did it again, with 172 cards for which he received $5,000.
From April 18, 2007 until April 17, 2008, Delpiero sold about 350 credit card account numbers for about $4,500.
They also sold "real looking" (or counterfeit) blank plastic.
OK, we'll pause here for a moment to reflect on how ludicrous it sounds to have a single press release naming people with $20 Million in forfeiture in the same case with people who only made $4,500. This is the part where we interject that these are real bad guys doing world-wide crime! The problem is that we have to have jurisdiction, in this case in the Southern District of California, for whatever we charge them with. Before you get terribly disillusioned about the nature of these "small fish" based on the indictments, let's investigate the Affidavit of Special Agent Ryan Knisley of the United State Secret Service.
SA Knisley has been a Secret Service Agent since August 7, 2006. What we don't see in the indictments themselves is that "Pavlovich" runs a HUGE Credit card trading service known as "Dumps Market" (www.dumpsmarket.net, at the time of the indictment.)
Burak had screwed up and found himself with a Yahoo! address which was searched by the US Secret Service. As a result of that search, he was found to be trading "BIN lists" (Bank Identification Numbers) and stolen credit card numbers with Storchak.
Storchak's accounts were also searched, and it was found that the credit card numbers traded between these two actually had been used for real dollar losses of $7,000,000!
Other evidence pointed to email accounts at a site called "safe-mail". Commonly held by the criminals to be beyond the stretch of US Law Enforcement. Through the Mutual Legal Assistance Treaty, email accounts at "SAFe-mail", which resides in Israel, were also searched, and the results shared with the USSS. In those mails
more details were revealed indicating that Pavlovich was the source of many of the stolen credit cards.
Pavlovich was running DumpsMarket in Belarus. Who also cooperates with US Law Enforcement. The Belarus law enforcment folks seized Pavlovich's hard drive, made a copy, and sent it to the US Secret Service. Pavlovich's hard drive contained more than 10,000 stolen credit cards, and photographs of himself spending time with Burak and Storchak in various social settings.
So, while the actual charges brought here seem small, we MUST make them stick. This is a $7 Million Bad Guy of the variety who needs to go to jail.
Three Cheers to Southern California for taking what data they could own and deciding to press forward with it!
While it is not specifically laid out in the documents to which I have access, it is my strong belief that the Chinese defendants are in a similar situation. The small numbers in Southern California should not be seen as a measure of their insignificance as criminals, but rather as a sign that when you spread multi-million dollar crime around the entire globe, its hard to find one small set of contiguous ZIP Codes that had many losses.
Again, Three Cheers to the US Secret Service, and the US Attorney of the Southern District of California!
(All Four Indictments, and the Affadavit are included in a single 34 page PDF)
Showing posts with label TJX. Show all posts
Showing posts with label TJX. Show all posts
Friday, August 08, 2008
TJX Update: The Boston Indictments
The Boston indictments are now public and have quite a few more facts for us, and I'm so excited that I've just received the first of the San Diego indictments from their most helpful press officer!
I'm going to run this in two parts. Boston first, and then San Diego.
An incomplete story was painted by the earliest press releases, which lead the media to quickly jump on the fact that Gonzalez was a wardriver, and TJX and the other victim companies had sloppy wireless security. True, but not a complete picture.
We'll start by looking at what else we can learn from the indictments that are now available in Boston.
What's in a name? We'll start with Albert Gonzalez's A/K/A's:
cumbajohny
cj
UIN 201679996
UIN 476747
k1ngchilli
stanozololz
Unfortunately, that genius of blackhat journalism, Kevin Poulson, has beat us to the punch with this one in his Wired Blog, but what a great story it is. You'll recall in our previous blog post on this subject, TJX Reminder: We Will Arrest You, and We Will Send You To Jail, we mentioned that Albert Gonzalez was a US Secret Service Informant. Now that we know his alias, CumbaJohny, we see that Albert was the snitch for Operation Firewall, the Secret Service case that lead to the arrests of 28 members of the ShadowCrew back in October of 2004. CumbaJohny, now re-handled as Segvec, now gets to feel what its like to be on the receiving end of one of these seizures.
The Violations that Segvec faces are:
18 USC section 371 Conspiracy
18 USC section 1030(a)(5)(A)(i)Damage to Computer Systems
18 USC section 1343 Wire Fraud
18 USC section 1029(a)(3) Access Device Fraud
18 USC section 1029(c)(1)(C), 982(a)(2)(B),981(a)(1)(C) Criminal Forfeiture
28 USC section 2461(c) Criminal Forfeiture
Here's the way the Conspiracy charges stack up. First we have to establish what they conspired to do. The indictments lists "the objects of the conspiracy" this way:
The Gonzalez indictment tells quite a bit more about how they moved from WarDriving to much greater exploits.
First, Gonzalez, Toey, and Scott went wardriving around Miami, in commercial areas such as the area around U.S. 1, identifying vulnerable wireless networks. They targeted large retailers, "including, but not limited to" BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and TJX.
After infiltrating their networks, they began locating and stealing sensitive files and data, including credit card numbers.
At this point, they are just punks. This type of break-in is a dime a dozen. But then they took it further. It says they went on to install sniffer programs, monitoring and stealing password and account information as well as track 2 data.
The conspiracy broadened as they had to bring in new associates to help with decrypting the encrypted PIN numbers on their tens of millions of Track 2 reads.
The stolen data was stored on servers in Latvia, the Ukraine, and the United States, and encrypted to prevent access by others. From there, the data was sold in "dumps", cashed out, and the money was redistributed, using webmoney, ATMs, and in some cases even mailing express packages full of cash to drop boxes!
Regarding their technical skills, custom SQL injection attacks were developed to take on particularly desirable web sites. The attacks were mounted against a variety of database-driven web sites to find additional track 2 data, internal accounts, and files of large businesses.
Regarding the level of Gonzalez' conspiracy -- he used sensitive law enforcement information, which he obtained by his "cooperation" with the US Secret Service, to alert his conspirators and make sure they would not be identified and arrested.
Some particular examples illustrate the dates and players:
In 2003, Gonzalez and Scott use wireless access to steal track 2 data at BJ's Wholesale Club.
In 2004, Scott and "J.J." gain unauthorized access to the wireless network of the OfficeMax on 109th Street and US 1 in Miami, locating and downloading encrypted PINs.
Scott and J.J., unable to decrypt the PINs, passed the data to Gonzalez, who located and engaged another co-conspirator who had the necessary decryption abilities.
On July 12 and 18th, 2005, Scott accessed TJX's Marshalls department stores in Miami, using the wireless network there to compromise servers at TJX's server farm in Framingham, Massachusetts.
On September 15-16, Scott accessed the Framingham servers and retrieved the data which their sniffers had been collecting.
Beginning on May 14-15, 2006, Scott installed and configured a VPN connection between one of the TJX card transaction servers and a server obtained by Gonzalez.
On May 15, 2006, Gonzalez used ICQ to ask Yastremskiy for help in obtaining an undetectable sniffer program. Beginning on May 15 and lasting through May 20th, they established their new undetectable sniffer.
The new sniffer's data was retrieved on many dates, including October 27 and December 18, 2006.
Beginning in August of 2007, Gonzalez invited Toey to move to Miami. In exchange for cash payments and free rent, Toey began to develop an Internet-based attack on the servers at "Forever 21", with the goal of obtaining financial data.
Prior to moving to Miami, Toey worked as a broker for Gonzalez, finding customers, who would be given login credentials to retrieve the credit cards from one of the many encrypted dump sites around the Internet.
From February to May of 2006, Gonzalez collaborated with Yastremskiy to distribute OfficeMax track 2 data.
On March 13, 2008, Gonzalez used his VPN connection to TJX from a computer in Latvia to store 16 million unique credit and debit card numbers. That same day he stored more than 25 million credit and debit cards on a Ukranian server as well.
Gonzalez faces forfeiture of $1,650,000 cash, a condo in Miami, a 2006 BMW 330I, some computers, a Glock 27, a "350C Currency Counter" (wow!),
As for the further act of Gonzalez, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Christopher Scott's Indictment is much less sexy from the beginning, mostly because he has no cool hacker aliases at the beginning.
He is charged with most of the same charges, with the exception of Wire Fraud.
His forfeiture included, $400,000 in cash, eleven computers, some nice iPods, some nice monitors, and they even took his XBOX and PSPs!
Let this be a warning to you, children. If you hack into TJX, you will lose your XBOX privileges! (Oh, and go to jail for a long time, hopefully!)
As for the further acts of Scott, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Damon Patrick Toey faced the same charges as Chris Scott. He also does not get Cool Points for having many AKAs, but let's face it, Damon Toey is a cooler name than Chris Scott.
Toey's "Overt Acts" section focuses on his selling of "dumps" of cards on behalf of Gonzalez and splitting the proceeds, and his leading role in the SQL injection and other Internet-based attacks used to access corporate databases and systems, including the Forever 21 attack, where he had the leading role.
I love the actual wording of Count Two, the Access Device Fraud:
Yes, 40,000,000 is "at least" 15.
Based on the forfeiture, it looks like Damon was the Talented but Unimaginative member of the team. He forfeited only $9,500 and a few computers. But they got his XBOX too!
As for the further acts of Toey, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
I'm going to run this in two parts. Boston first, and then San Diego.
An incomplete story was painted by the earliest press releases, which lead the media to quickly jump on the fact that Gonzalez was a wardriver, and TJX and the other victim companies had sloppy wireless security. True, but not a complete picture.
We'll start by looking at what else we can learn from the indictments that are now available in Boston.
What's in a name? We'll start with Albert Gonzalez's A/K/A's:
cumbajohny
cj
UIN 201679996
UIN 476747
k1ngchilli
stanozololz
Unfortunately, that genius of blackhat journalism, Kevin Poulson, has beat us to the punch with this one in his Wired Blog, but what a great story it is. You'll recall in our previous blog post on this subject, TJX Reminder: We Will Arrest You, and We Will Send You To Jail, we mentioned that Albert Gonzalez was a US Secret Service Informant. Now that we know his alias, CumbaJohny, we see that Albert was the snitch for Operation Firewall, the Secret Service case that lead to the arrests of 28 members of the ShadowCrew back in October of 2004. CumbaJohny, now re-handled as Segvec, now gets to feel what its like to be on the receiving end of one of these seizures.
The Violations that Segvec faces are:
18 USC section 371 Conspiracy
18 USC section 1030(a)(5)(A)(i)Damage to Computer Systems
18 USC section 1343 Wire Fraud
18 USC section 1029(a)(3) Access Device Fraud
18 USC section 1029(c)(1)(C), 982(a)(2)(B),981(a)(1)(C) Criminal Forfeiture
28 USC section 2461(c) Criminal Forfeiture
Here's the way the Conspiracy charges stack up. First we have to establish what they conspired to do. The indictments lists "the objects of the conspiracy" this way:
a. Exploit vulnerabilities in wireless computer networks used at retail store locations
b. Exploit vulnerabilities used to manage large business databases
c. Gain unauthorized access to computer networks processing and storing debit and credit card transactions and other valuable data for major corporate retailers.
d. Download and steal from computer networks operated by major corporate retailers over 40 million pieces of card holders' track 2 data - the information found on the magnetic stripes of credit and debit cards, which is read by ATMs and credit card readers - as well as internal accounts and proprietary files
e. Sell stolen track 2 data in Eastern Europe, the United States and elsewhere to others for fraudulent use
f. "Cash out" stolen track 2 data by encoding the data on the magnetic stripes of blank payment cards and using these cards to obtain tens of thousands of dollars at a time from banks' ATMs
g. Conceal and launder the illegal proceeds through anonymous web currencies in the United States and Russia, and offshore bank accounts in Latvia
h. Repatriate portions of the illegal proceeds through web currency converters and ATM cards linked to Eastern European banks.
The Gonzalez indictment tells quite a bit more about how they moved from WarDriving to much greater exploits.
First, Gonzalez, Toey, and Scott went wardriving around Miami, in commercial areas such as the area around U.S. 1, identifying vulnerable wireless networks. They targeted large retailers, "including, but not limited to" BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and TJX.
After infiltrating their networks, they began locating and stealing sensitive files and data, including credit card numbers.
At this point, they are just punks. This type of break-in is a dime a dozen. But then they took it further. It says they went on to install sniffer programs, monitoring and stealing password and account information as well as track 2 data.
The conspiracy broadened as they had to bring in new associates to help with decrypting the encrypted PIN numbers on their tens of millions of Track 2 reads.
The stolen data was stored on servers in Latvia, the Ukraine, and the United States, and encrypted to prevent access by others. From there, the data was sold in "dumps", cashed out, and the money was redistributed, using webmoney, ATMs, and in some cases even mailing express packages full of cash to drop boxes!
Regarding their technical skills, custom SQL injection attacks were developed to take on particularly desirable web sites. The attacks were mounted against a variety of database-driven web sites to find additional track 2 data, internal accounts, and files of large businesses.
Regarding the level of Gonzalez' conspiracy -- he used sensitive law enforcement information, which he obtained by his "cooperation" with the US Secret Service, to alert his conspirators and make sure they would not be identified and arrested.
Some particular examples illustrate the dates and players:
In 2003, Gonzalez and Scott use wireless access to steal track 2 data at BJ's Wholesale Club.
In 2004, Scott and "J.J." gain unauthorized access to the wireless network of the OfficeMax on 109th Street and US 1 in Miami, locating and downloading encrypted PINs.
Scott and J.J., unable to decrypt the PINs, passed the data to Gonzalez, who located and engaged another co-conspirator who had the necessary decryption abilities.
On July 12 and 18th, 2005, Scott accessed TJX's Marshalls department stores in Miami, using the wireless network there to compromise servers at TJX's server farm in Framingham, Massachusetts.
On September 15-16, Scott accessed the Framingham servers and retrieved the data which their sniffers had been collecting.
Beginning on May 14-15, 2006, Scott installed and configured a VPN connection between one of the TJX card transaction servers and a server obtained by Gonzalez.
On May 15, 2006, Gonzalez used ICQ to ask Yastremskiy for help in obtaining an undetectable sniffer program. Beginning on May 15 and lasting through May 20th, they established their new undetectable sniffer.
The new sniffer's data was retrieved on many dates, including October 27 and December 18, 2006.
Beginning in August of 2007, Gonzalez invited Toey to move to Miami. In exchange for cash payments and free rent, Toey began to develop an Internet-based attack on the servers at "Forever 21", with the goal of obtaining financial data.
Prior to moving to Miami, Toey worked as a broker for Gonzalez, finding customers, who would be given login credentials to retrieve the credit cards from one of the many encrypted dump sites around the Internet.
From February to May of 2006, Gonzalez collaborated with Yastremskiy to distribute OfficeMax track 2 data.
On March 13, 2008, Gonzalez used his VPN connection to TJX from a computer in Latvia to store 16 million unique credit and debit card numbers. That same day he stored more than 25 million credit and debit cards on a Ukranian server as well.
Gonzalez faces forfeiture of $1,650,000 cash, a condo in Miami, a 2006 BMW 330I, some computers, a Glock 27, a "350C Currency Counter" (wow!),
As for the further act of Gonzalez, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Christopher Scott's Indictment is much less sexy from the beginning, mostly because he has no cool hacker aliases at the beginning.
He is charged with most of the same charges, with the exception of Wire Fraud.
His forfeiture included, $400,000 in cash, eleven computers, some nice iPods, some nice monitors, and they even took his XBOX and PSPs!
Let this be a warning to you, children. If you hack into TJX, you will lose your XBOX privileges! (Oh, and go to jail for a long time, hopefully!)
As for the further acts of Scott, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Damon Patrick Toey faced the same charges as Chris Scott. He also does not get Cool Points for having many AKAs, but let's face it, Damon Toey is a cooler name than Chris Scott.
Toey's "Overt Acts" section focuses on his selling of "dumps" of cards on behalf of Gonzalez and splitting the proceeds, and his leading role in the SQL injection and other Internet-based attacks used to access corporate databases and systems, including the Forever 21 attack, where he had the leading role.
I love the actual wording of Count Two, the Access Device Fraud:
In or about October, 2004, in the Eastern District of Virginia and elsewhere, Damon Patrick Toey, knowingly and with intent to defraud, possessed at least 15 unauthorized access devices, to wit: stolen credit and debit card numbers.
Yes, 40,000,000 is "at least" 15.
Based on the forfeiture, it looks like Damon was the Talented but Unimaginative member of the team. He forfeited only $9,500 and a few computers. But they got his XBOX too!
As for the further acts of Toey, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Tuesday, August 05, 2008
TJX Reminder: "We Will Arrest You, and We Will Send You To Jail"
As we've been watching the news since the TJX bust, there have been several times where I thought we would hear that charges for that break-in would finally come. Well, it seems today is the day! Albert Gonzalez of Miami, who is known by his hacker handle "Segvec", was charged along with two other Miami residents in Boston today, while eight others were charged in Los Angeles.
With several hundred million dollars in theft, Attorney General Michael Mukasey did a press release about the indictments. According to Mukasey's speech:
Mukasey continued, describing today's actions as a key part in the strategy of the Identity Theft Task Force, co-chaired by Mukasey and the chairman of the Federal Trade Commission, William Kovacic:
The Department of Justice Press Release goes into som emore details, naming the additional co-conspirators:
Three From Miami were charged in Boston today:
Albert Gonzalez, AKA Segvec
Christopher Scott
Damon Patrick Toey
In San Diego charges were unsealed against:
From the Ukraine:
Maksym Yastremskiy, AKA Maksik
Dzmitry Burak
Sergey Storchak (no, I don't believe this is the Deputy Minister of Finance in Russia, of the same name, who is already in prison for embezzlement...)
From the Ukraine:
Aleksander Suvorov, AKA Jonny Hell
From China:
Hung-Ming Chiu (邱黄明)
Zhi Zhi Wang (王治治)
From ????:
the unknown hacker named Delpiero (isn't that an Italian soccer player's name?)
From Belarus:
Sergey Pavolvich
The indictments in San Diego are the result of an on-going three year undercover operation run by the Secret Service.
We last discussed Albert Gonzalez in this blog posting from May 12th, under the title TJX and Dave & Busters. Gonzalez was actually working as a "Confidential Informant" for the US Secret Service when they became aware of his involvement in this case. He had come to the attention of the Service when they arrested him in 2003 for Access Device Fraud. He was re-arrested for Wire Fraud on May 8th, according to documents from the US District Court in Miami, Floriday.
Maksym Yastremskiy has been jailed longer than any of the others, having been arrested at a nightclub in Kemer, Turkey with his girlfriend, and found to be in possession of "at least 1 million" credit card credentials, many of which have been found to be TJX data. That story broke (if you speak Turkish), all the way back in August of 2007 with these two articles:
Milliyet.com.tr - August 2nd
and
Sabah.com.tr - August 3rd
We first talked about that in this blog with the story TJX: From Florida to the Ukraine?, where we discussed the Miami crew who were turning TJX cards into WalMart Gift Cards before laundering them via eBay sales of luxury items bought in Sam's Clubs.
The next to get arrested was probably Jonny Hell, whose arrest back on March 3, 2008 was recently depicted in this Der Spiegel story from June 30th.

Jonny Hell, in Der Spiegel . . .
If you'll forgive my bad translation, the story says something like:
If anyone has more information on these hackers and their other exploits, please send them in!
Gary Warner
gar@askgar.com
With several hundred million dollars in theft, Attorney General Michael Mukasey did a press release about the indictments. According to Mukasey's speech:
hey targeted at least nine major retail corporations, including the TJX Corporation, whose stores include Marshalls and TJ Maxx; BJ's Wholesale Club; Barnes and Noble; Sports Authority; Boston Market; Office Max; Dave and Busters restaurants; DSW shoe stores; and Forever 21.
Mukasey continued, describing today's actions as a key part in the strategy of the Identity Theft Task Force, co-chaired by Mukasey and the chairman of the Federal Trade Commission, William Kovacic:
And the cooperation among investigators and prosecutors throughout the United States and around the world that led to these indictments shows the promise of close coordination in tackling these problems. Cases like this send a clear message to those who might be tempted to abuse our computer networks to steal information and harm law-abiding people and businesses: If you do, we will track you down wherever you are in the world, we will arrest you, and we will send you to jail.
The Department of Justice Press Release goes into som emore details, naming the additional co-conspirators:
Three From Miami were charged in Boston today:
Albert Gonzalez, AKA Segvec
Christopher Scott
Damon Patrick Toey
In San Diego charges were unsealed against:
From the Ukraine:
Maksym Yastremskiy, AKA Maksik
Dzmitry Burak
Sergey Storchak (no, I don't believe this is the Deputy Minister of Finance in Russia, of the same name, who is already in prison for embezzlement...)
From the Ukraine:
Aleksander Suvorov, AKA Jonny Hell
From China:
Hung-Ming Chiu (邱黄明)
Zhi Zhi Wang (王治治)
From ????:
the unknown hacker named Delpiero (isn't that an Italian soccer player's name?)
From Belarus:
Sergey Pavolvich
The indictments in San Diego are the result of an on-going three year undercover operation run by the Secret Service.
We last discussed Albert Gonzalez in this blog posting from May 12th, under the title TJX and Dave & Busters. Gonzalez was actually working as a "Confidential Informant" for the US Secret Service when they became aware of his involvement in this case. He had come to the attention of the Service when they arrested him in 2003 for Access Device Fraud. He was re-arrested for Wire Fraud on May 8th, according to documents from the US District Court in Miami, Floriday.
Maksym Yastremskiy has been jailed longer than any of the others, having been arrested at a nightclub in Kemer, Turkey with his girlfriend, and found to be in possession of "at least 1 million" credit card credentials, many of which have been found to be TJX data. That story broke (if you speak Turkish), all the way back in August of 2007 with these two articles:
Milliyet.com.tr - August 2nd
and
Sabah.com.tr - August 3rd
We first talked about that in this blog with the story TJX: From Florida to the Ukraine?, where we discussed the Miami crew who were turning TJX cards into WalMart Gift Cards before laundering them via eBay sales of luxury items bought in Sam's Clubs.
The next to get arrested was probably Jonny Hell, whose arrest back on March 3, 2008 was recently depicted in this Der Spiegel story from June 30th.
Jonny Hell, in Der Spiegel . . .
If you'll forgive my bad translation, the story says something like:
The two American agents, dark suits and service-brands of the Secret service, stood motionless beside the snake of the flight-traveler at the Frankfurt airport. They waited until Aleksandr Suvorov and his friend Vika were next, arriving at terminal 1 Singapore Airlines for three weeks of recuperation in Bali for the love-pair. As Suvorov pushed his Estonian passport over the counter-bar, eyewitnesses remember, there the Special Agents Paul B. and Timothy G. stepped forward, pulled out their ID cards, and revealed it to him. "You are arrested". It was March 3rd, shortly before 22 o'clock . . .
Since then, he has waited for his delivery to the USA. He is regarded as a top international hacker, that steals sensitive data in a big style by means of Trojan horses, and then resells it. The young Estonian, who supposedly hides behind the hacker-pseudonym "Jonny Hell", belongs to "one of the biggest world-wide circles dealing in stolen credit card numbers".
If anyone has more information on these hackers and their other exploits, please send them in!
Gary Warner
gar@askgar.com
Monday, May 12, 2008
TJX and Dave & Busters
If you've visited a Dave & Busters, you know these are a great place for grown-ups to go out and play. I've been to several events at the Atlanta location, and enjoy the Virtual Reality games there. I never thought I would see a Dave & Busters story come up on the news-ticker that I have watching for new TJX stories, but that is what happened this morning.
You will probably recall the story of Maksym Yastremskiy (Maksik), a Ukrainian citizen arrested in Turkey for his role in trading enormous volumes of credit cards which could all be traced back to the TJX debacle. He was back in the news today with two other hackers, Aleksandr Suvorov (JonnyHell) from Estonia, and Albert Gonzales (Segvec). The charges are that the first two ran a scam involving the installation of packet sniffers into thte cash register systems at 11 Dave & Buster's restaurants. Just the Islandia, New York location was credited with 5,000 customer's credit card data leading to more than $600,000 in fraudulent purchases. Segvec is charged only with "wire fraud conspiracy", in that he purchased some of this data from Maksik.
The indictment was posted on the ABC News website.
The 27 counts against the first two are:
Count One: Conspiracy to Commit Wire Fraud
(knowingly and intentionally conspiring to devise a scheme and artifice to defraud D&B, its customers, and the financial institutions that issued the customers' credit and debit cards, and to obtain money and property...by means of materially false and fraudulent pretenses, representations and promises, and attempting to do so by means of wire communication in interstate and foreign commerce . . . )
Counts 2-5: Wire Fraud
(installing a packet sniffer, and reactivating it at D&B Store #2 in Islandia, New York, on 5/18/07, 6/9/07, 7/23/07, 8/14/07.)
Count 6: Conspiracy to Possess Unauthorized Access Devices
Count 7-9: Possession of Unauthorized Access Devices
(the "access device" in question being log files containing "15 or more credit and debit card account numbers".)
(Title 18, Section 1029(a)(3))
(Title 18, Section 1029(c)(1)(A)(i))
Count 10-12: Aggravated Identity Theft
(Title 18 Section 1028A(a)(1), (b), (c)(5))
Count 13: Conspiracy to Commit Computer Fraud
(Title 18 Section 371 and 3551)
Count 14-16: Unauthorized Computer Access Involving an Interstate Communication
(Title 18 Section 1030(a)(2)(C))
(Title 18 Section 1030(c)(2)(B)(i))
Count 17-19: Unauthorized Computer Access to Obtain Things of Value
(Title 18 Section 1030(a)(4))
(Title 18 Section 1030(c)(3)(A))
Count 20-23: Unlawful Transmission of Computer Codes
(Title 18 Section 1030(a)(5)(A)(i))
(Title 18 Section 1030(a)(5)(B)(i))
(Title 18 Section 1030(c)(4)(A))
Count 24-27: Interception of Electronic Communications
(Title 18 Section 2511(1)(a))
(Title 18 Section 2511(4)(a))
Oh yeah, and they are going to go for Criminal Forfeiture of all losses.
All the way back in June 2007, Maksik and Segvec are on the way towards losing their e-gold accounts, according to this testimony from US Secret Service agent Roy Dotson, who names e-gold account number 1751848 as belonging to Maksik, and 3584940 as belonging to Segvec.
From that affadavit:
Yastremskiy was arrested in Turkey in July 2007, where he remains in jail.
Suvorov was arrested in Germany in March 2008.
Gonzalez was arrested in Miami in May 2008 by the US Secret Service.
You will probably recall the story of Maksym Yastremskiy (Maksik), a Ukrainian citizen arrested in Turkey for his role in trading enormous volumes of credit cards which could all be traced back to the TJX debacle. He was back in the news today with two other hackers, Aleksandr Suvorov (JonnyHell) from Estonia, and Albert Gonzales (Segvec). The charges are that the first two ran a scam involving the installation of packet sniffers into thte cash register systems at 11 Dave & Buster's restaurants. Just the Islandia, New York location was credited with 5,000 customer's credit card data leading to more than $600,000 in fraudulent purchases. Segvec is charged only with "wire fraud conspiracy", in that he purchased some of this data from Maksik.
The indictment was posted on the ABC News website.
The 27 counts against the first two are:
Count One: Conspiracy to Commit Wire Fraud
(knowingly and intentionally conspiring to devise a scheme and artifice to defraud D&B, its customers, and the financial institutions that issued the customers' credit and debit cards, and to obtain money and property...by means of materially false and fraudulent pretenses, representations and promises, and attempting to do so by means of wire communication in interstate and foreign commerce . . . )
Counts 2-5: Wire Fraud
(installing a packet sniffer, and reactivating it at D&B Store #2 in Islandia, New York, on 5/18/07, 6/9/07, 7/23/07, 8/14/07.)
Count 6: Conspiracy to Possess Unauthorized Access Devices
Count 7-9: Possession of Unauthorized Access Devices
(the "access device" in question being log files containing "15 or more credit and debit card account numbers".)
(Title 18, Section 1029(a)(3))
(Title 18, Section 1029(c)(1)(A)(i))
Count 10-12: Aggravated Identity Theft
(Title 18 Section 1028A(a)(1), (b), (c)(5))
Count 13: Conspiracy to Commit Computer Fraud
(Title 18 Section 371 and 3551)
Count 14-16: Unauthorized Computer Access Involving an Interstate Communication
(Title 18 Section 1030(a)(2)(C))
(Title 18 Section 1030(c)(2)(B)(i))
Count 17-19: Unauthorized Computer Access to Obtain Things of Value
(Title 18 Section 1030(a)(4))
(Title 18 Section 1030(c)(3)(A))
Count 20-23: Unlawful Transmission of Computer Codes
(Title 18 Section 1030(a)(5)(A)(i))
(Title 18 Section 1030(a)(5)(B)(i))
(Title 18 Section 1030(c)(4)(A))
Count 24-27: Interception of Electronic Communications
(Title 18 Section 2511(1)(a))
(Title 18 Section 2511(4)(a))
Oh yeah, and they are going to go for Criminal Forfeiture of all losses.
All the way back in June 2007, Maksik and Segvec are on the way towards losing their e-gold accounts, according to this testimony from US Secret Service agent Roy Dotson, who names e-gold account number 1751848 as belonging to Maksik, and 3584940 as belonging to Segvec.
From that affadavit:
“Segvec”: “Segvec” is a vendor of stolen financial information on the carding
website Makafaka and accepts payment for his contraband in e-gold. A search and review of the e-gold database revealed number 2464856 – which has as its contact name “segvec.” According to information related to me from agents of New Scotland Yard’s National Terrorist Financial Investigation Unit regarding email communications they had with Douglas Jackson in April 2007, Douglas Jackson was aware that “segvec” was a Ukrainian carder.
An analysis of “segvec”’s account number 2464856 yielded the following results:
The account was created in October 2005. There were 93 transfers into the account with a value of 1524.80951 grams ($845,545.60).
20 of the 90 transactions, which total 726.623113 grams ($410,750.00) and occur between February and May 2006, are transfer of funds from account 1751848, “Maksik’s Job”
“Maksik”: “Maksik” is a known vendor of stolen credit card information, stolen
financial accounts, and fraudulent Ukranian passports on the Shadowcrew, Mazafaka, and Carderplanet carding websites and accepts payment for this contraband in e-gold. A search and review of the e-gold database revealed account number 1751848, with the account name “Maksik’s Job,” and contact email addresses of info@maksikjob.com and maksik@maksik.biz. Several memo fields in the transaction record for e-gold account number 1751848 indicate carding activity, including, for example, “1-27 order amex” (i.e., an order for a stolen American Express credit card number), “Happy H4xOr Dumps” (i.e., stolen credit card information), “For 20 classics” (i.e., a type of credit card). A search and review of the e-gold database also revealed e-gold account number 3399565, with the account name “Maksik’s account,” and containing a contact email address of Maksik@maksik.cc. A review of this account also shows many transactions with other e-gold accounts controlled by known carders, including e-gold account number 2567183 (controlled by “Lord kaisersose” – a known vendor of stolen credit card information), and e-gold account number 2874688 (controlled by “u26" – a provider of credit card pre-authorization services to vendors)
Yastremskiy was arrested in Turkey in July 2007, where he remains in jail.
Suvorov was arrested in Germany in March 2008.
Gonzalez was arrested in Miami in May 2008 by the US Secret Service.
Tuesday, September 04, 2007
TJX: From Florida to the Ukraine?
Last week the media lit up with speculations that 24 year old Ukrainian hacker, Maksym Yastremskiy, who had been arrested in Turkey on August 2nd, may be behind the TJX Credit Card hack. The Boston Globe's Ross Kerber may have had the best coverage with his story "Suspect
named in TJX credit card probe" on August 21. The story quoted Greg Crabb of the US Postal Inspection Service's global investigations division. Crabb said Maksym was "likely the largest seller of stolen TJX numbers". TJX, the financial company in the TJ Maxx conglomerate, believes that as many as 45.7 million credit cards were stolen during a breach during 2005 and 2006, which captured credit card transactions all the way back to 2003.
How's your Turkish? This August 2nd article , "Antalya'da yakalanan Ukraynalı hacker 80 bin kişiyi dolandırmış", interviews Turkish police officer, Feyzullah Arslan, who arrested Maksym after a sting in a luxury night club in Kerem, Turkey.
Using a "follow-the-money" investigative technique, the investigation began with 10 guilty pleas in Florida back in March from a crew of careless cyber criminals who had racked up millions of dollars of purchases from Wal-Mart and other Florida retailers using stolen credit cards that tracked back to TJX. The Florida investigation actually started when Gainesville police were contacted regarding two local Wal-Mart stores who had made individual gift-card sales in the amounts of $18,000 and $24,000. HINT: IF SOMEONE WANTS $24,000 IN WAL-MART GIFT CARD, THERE MAY BE A CRIME LYING ABOUT.
Those cards were used at a Sam's Club in Miami, along with many other cards, to buy large quantities of electronics and jewelry. At that time, the cards were all tracked back to TJX, and an estimate of the loss from the database hack was released in the news -- Gainesville police Sergeant Ray Barber revealed "They estimate the loss from that hack job to be around $8 million", although this particular crew had only rung up $1 million in charges so far. (See, for example: "Florida police make arrests in TJX, Winners credit card theft".
The first six, arrested March 19, were:
Irving Jose Escobar, 18
Reinier Camaraza Alvarez, 27
Julio Oscar Alberti, 33
Dianelly Hernandez, 19
Nair Zuleima Alvarez, 40
Zenia Mercedes Llorente
All ten, including the additional:
Erick Fernandez Rodriguez
Hector Alfaro Rodriguez
Alexis Arcia
Armando Ochoa
have Mugshots posted on eweek.com.

In a USA Today story a map of Irving Escobar's shopping spree, where he bought as many as 60 $400 gift cards in a single location, and then spent the money from November 1st to January 18th, is mapped out.

The big break in this first case came when an alert Wal-Mart employee followed the gift card purchases out of the store and recorded their license plate number. (For more, see the March 24, 2007 Boston Globe story by Ross Kerber, quoted here: Scam May Be Tied to Stolen TJX Data
A second Florida-based TJX gang plead guilty in late June. This group was charged with possessing 172,000 sets of credit card data, which had been used to make at least $75 Million in bogus credit card charges. Arrested in this scam were:
Miguel Alegria, 46, of Hialeah, FL
Raynier Pupo, 22, of Miami, FL
Ariel Montero, 32, of Aventura, FL
Javier Padron-Bravo, 35, of Aventura, FL
Julio Lopez, 30, of Hialeah, FL
and Anett VIllar, 26, of Hialeah, FL
Alegria, Pupo, Montero, and Padron-Bravo plead guilty to conspiracy in exchange for a plea agreement that included cooperation.
The Nashville Secret Service ran the investigation as "Operation Blinky" named for the first suspect's online name, which they co-opted as an undercover identity. For more see: TJX, Polo Data Surfaces In Another Credit Card Bust.
named in TJX credit card probe" on August 21. The story quoted Greg Crabb of the US Postal Inspection Service's global investigations division. Crabb said Maksym was "likely the largest seller of stolen TJX numbers". TJX, the financial company in the TJ Maxx conglomerate, believes that as many as 45.7 million credit cards were stolen during a breach during 2005 and 2006, which captured credit card transactions all the way back to 2003.
How's your Turkish? This August 2nd article , "Antalya'da yakalanan Ukraynalı hacker 80 bin kişiyi dolandırmış", interviews Turkish police officer, Feyzullah Arslan, who arrested Maksym after a sting in a luxury night club in Kerem, Turkey.
Using a "follow-the-money" investigative technique, the investigation began with 10 guilty pleas in Florida back in March from a crew of careless cyber criminals who had racked up millions of dollars of purchases from Wal-Mart and other Florida retailers using stolen credit cards that tracked back to TJX. The Florida investigation actually started when Gainesville police were contacted regarding two local Wal-Mart stores who had made individual gift-card sales in the amounts of $18,000 and $24,000. HINT: IF SOMEONE WANTS $24,000 IN WAL-MART GIFT CARD, THERE MAY BE A CRIME LYING ABOUT.
Those cards were used at a Sam's Club in Miami, along with many other cards, to buy large quantities of electronics and jewelry. At that time, the cards were all tracked back to TJX, and an estimate of the loss from the database hack was released in the news -- Gainesville police Sergeant Ray Barber revealed "They estimate the loss from that hack job to be around $8 million", although this particular crew had only rung up $1 million in charges so far. (See, for example: "Florida police make arrests in TJX, Winners credit card theft".
The first six, arrested March 19, were:
Irving Jose Escobar, 18
Reinier Camaraza Alvarez, 27
Julio Oscar Alberti, 33
Dianelly Hernandez, 19
Nair Zuleima Alvarez, 40
Zenia Mercedes Llorente
All ten, including the additional:
Erick Fernandez Rodriguez
Hector Alfaro Rodriguez
Alexis Arcia
Armando Ochoa
have Mugshots posted on eweek.com.
In a USA Today story a map of Irving Escobar's shopping spree, where he bought as many as 60 $400 gift cards in a single location, and then spent the money from November 1st to January 18th, is mapped out.
The big break in this first case came when an alert Wal-Mart employee followed the gift card purchases out of the store and recorded their license plate number. (For more, see the March 24, 2007 Boston Globe story by Ross Kerber, quoted here: Scam May Be Tied to Stolen TJX Data
A second Florida-based TJX gang plead guilty in late June. This group was charged with possessing 172,000 sets of credit card data, which had been used to make at least $75 Million in bogus credit card charges. Arrested in this scam were:
Miguel Alegria, 46, of Hialeah, FL
Raynier Pupo, 22, of Miami, FL
Ariel Montero, 32, of Aventura, FL
Javier Padron-Bravo, 35, of Aventura, FL
Julio Lopez, 30, of Hialeah, FL
and Anett VIllar, 26, of Hialeah, FL
Alegria, Pupo, Montero, and Padron-Bravo plead guilty to conspiracy in exchange for a plea agreement that included cooperation.
The Nashville Secret Service ran the investigation as "Operation Blinky" named for the first suspect's online name, which they co-opted as an undercover identity. For more see: TJX, Polo Data Surfaces In Another Credit Card Bust.
Subscribe to:
Posts (Atom)