Update: Mastermind of TJX, Heartland breaches to plead guilty
In deal with prosecutors, Gonzalez faces up to 25 years in prison for TJX data theft
Computerworld - Albert Gonzalez, the man accused of masterminding the massive data thefts at TJX Companies Inc., Heartland Payment Systems and several other retailers has agreed to plead guilty to charges in a 19-count indictment that includes conspiracy, wire fraud and aggravated identity theft charges.
Under an agreement with prosecutors in Boston today, Gonzalez, 28, will face a maximum of 25 years in prison and will forfeit more than $2.8 million in cash.
Gonzalez was arrested in Miami in 2008 along with 10 other individuals. He was indicted separately in federal court in Boston and in New York on charges relating to the thefts at TJX, Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.
Earlier this month, Gonzalez was also indicted in New Jersey on charges that he, along with two unidentified Russian accomplices, was responsible for huge data thefts at Heartland, Hannaford, 7-Eleven Inc. and two other unnamed retailers. Prosecutors alleged that the three were responsible for stealing data on more than 130 million credit and debit cards for the five retailers. Today's plea deal does not include his indictment on these charges.
At the time of the New Jersey indictments, Gonzalez' attorney Rene Palomino had claimed that his client had been close to agreeing to a plea bargain in connection with the charges filed against him in 2008. In an interview with Computerworld, Palomino had said that he was working with federal authorities to hammer out a new plea agreement after the indictments on the Heartland case and other charges.
Palomino had also claimed in an interview with the New York Times that he intended to argue in court that Gonzalez was not the mastermind of the Heartland breach and that it was one of his client's accomplices who had pulled off the heist.
A spokeswoman at the U.S. attorney's office in Boston said she couldn't comment on whether the plea agreement covered the indictments in New York and New Jersey. However the Reuters news service reported that today's agreement does resolve the indictments in New York. It was unclear where Reuters obtained that information, but it would to be consistent with statements that Gonzalez' attorney had made recently about the plea agreement that was being neogotiated before the indictments in New Jersey. Meanwhile, a spokesman for the U.S. attorney's office in New Jersey said today's agreement in Boston does not resolve the charges in New Jersey.
Avivah Litan, a Gartner Inc. analyst who has been following the cases, called the prison term in the proposed plea agreement reasonable. "After all, no one got physically injured or killed, and this was a white collar crime that mainly hurt the card issuing banks, which were able to recoup most -- if not all -- of their losses from the breached retailers," she said.
Massive data thefts
- Update: Mastermind of TJX, Heartland breaches to plead guilty
- Alleged data-heist kingpin is a computer addict, lawyer says
- Gonzalez's lawyer to contend he was not the kingpin of Heartland, Hannaford breaches
- Hacking kingpin negotiating plea deal with feds
- Three indicted for hack attacks on Heartland, Hannaford
- TJX data breach: At 45.6M card numbers, it's the biggest ever
- Data Protection eGuide In this eGuide, CSO and sister publications IDG News Service, Computerworld, and CIO pull together news, trend, and how-to articles about the increasingly...
- Warning: Cloud Data at Risk Experts agree that relying on SaaS vendors to backup and restore your data is dangerous. Yet that's exactly what huge portions of the...
- The Opportunities and Challenges of the Cloud In this report F5 poses questions to IDC analysts, Sally Hudson and Phil Hochmuth, on behalf of F5's customers to better understand the...
- Mobile First: Securing Information Sprawl Learn how the partnership between Box and MobileIron can help you execute a "mobile first" strategy that manages and secures both mobile apps...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!