On mySimon: Vinturi Essential Wine Aerator
BNET Business Network:
BNET
TechRepublic
ZDNet

August 18th, 2009

Alleged TJX hacker spun a wide web of cybercrime

Posted by Larry Dignan @ 2:15 am

Categories: General, Security

Tags: Web, Point-of-sale, Antivirus, Debit Card, Malware, Hacker, Debit Card Number, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms

Albert Gonzalez, 28, was the alleged ringleader of a cybercrime enterprise that swiped at least 170 million credit and debit card numbers in recent years.

The U.S. Department of Justice announced Monday that Gonzalez, already awaiting trial for the TJX data breach, along with two others were being indicted for five corporate data breaches (indictment, statement, Techmeme).

What’s stunning is the laundry list of companies impacted by these breaches. The list from the indictment:

  • Heartland Payment Systems
  • 7-Eleven
  • Hannaford Brothers Co.
  • And two unidentified corporate victims

Add it up and Gonzalez is connected to the theft of 130 million credit and debit card numbers, according to the Department of Justice. The TJX data breach indictment from last year tosses in 40 million card numbers. The August 2008 indictment, which named Gonzalez and others, detailed how the attackers probed TJX Companies, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

The latest indictment illustrates how Gonzalez and his two unnamed coconspirators went about their business? They typically scanned a list of Fortune 500 companies looking for victims. Once identified, Gonzalez would identify vulnerabilities—both physical and virtual. Gonzalez would identify point of sale machines, which anyone can do with a store visit, and follow up with the upload of information to serve “as hacking platforms.”

Once the attacks begun, Gonzalez would launch a SQL-injection attack. Gonzalez and his crew would add malware to find credit and debit card numbers. The gang would swap instant messages to relay their discoveries. Ultimately sniffers were set up to absorb the card data.

The indictment describes how Gonzalez was able to keep ahead of defenses. From the statement:

For example, they allegedly accessed the corporate websites only through intermediary, or “proxy,” computers, thereby disguising their own whereabouts. They also tested their malware by using approximately twenty of the leading anti-virus products to determine if any of those products would detect their malware as potentially unwanted. Furthermore, they programmed their malware to actively delete traces of the malware’s presence from the corporate victims’ networks.

There’s nothing here that is that fancy. Gonzalez was able to get the point-of-sale and payment processing from corporate Web sites. SQL injection attacks aren’t exactly cutting edge. Gonzalez was good at probing weak defenses and exploiting them. Another eye opener: It wasn’t that difficult to stay ahead of antivirus defenses.

Makes you wonder next time you go shopping.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 15 Talkback(s)
RE: Alleged TJX hacker spun a wide web of cybercrime
That's scary. I'm lucky this has never happened to me at
Marshall's (another TJX company)! www.apparelncs.com/rd_p?p=186122&t=9518&a=22601-
zdnet&gift=22601... (Read the rest)
Posted by: lovemagic Posted on: 09/08/09 You are currently: a Guest | | Terms of Use
Just goes to show no one's doing their homework  ejhonda | 08/18/09
Correction  gertruded | 08/18/09
RE: Alleged TJX hacker spun a wide web of cybercrime  mr1972 | 08/18/09
3 Clowns...  kiwiboy312009 | 08/18/09
RE: Alleged TJX hacker spun a wide web of cybercrime  TheJollyRoger1 | 08/18/09
Get a pre paid credit card  1ntense | 08/20/09
Does anyone really believe anti-malware can possibly keep up?  dkawalec | 08/18/09
RE: Alleged TJX hacker spun a wide web of cybercrime  fmosuch@... | 08/18/09
This may be a good thing  debtgazette | 08/18/09
RE: Alleged TJX hacker spun a wide web of cybercrime  Uncle Griff | 08/18/09
This is why Visa & MasterCard want PIN based txns  venkatesh.sridhar@... | 08/18/09
This is why Visa & MasterCard want PIN based txns  JOHN_TUOHY | 08/19/09
How secure is chip & PIN?  john.foggitt@... | 08/19/09
RE: Alleged TJX hacker spun a wide web of cybercrime  mikalucho@... | 08/19/09
RE: Alleged TJX hacker spun a wide web of cybercrime  lovemagic | 09/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More