Gonzalez gets 20 years for TJX credit card scam
Prosecutors called theft 'unparalleled'
IDG News Service - BOSTON -- As his parents and sister silently wept, hacker mastermind Albert Gonzalez was sentenced Thursday in U.S. District Court to two concurrent 20-year stints in prison for his role in what prosecutors called the "unparalleled" theft of millions of credit and debit card numbers from major U.S. retailers.
U.S. District Court Judge Patti B. Saris announced the concurrent sentences in two 2008 cases against Gonzalez, 28, a Cuban-American born in Miami, where he lived when the crimes were committed.
According to binding terms of a plea agreement Gonzalez forged with the U.S. Department of Justice, he could have received between 15 years and 25 years for the crimes.
"I stand before you humbled by these past 24 months," Gonzalez said in court, slightly expanding the time he has been incarcerated since his arrest in May 2008. "I'm guilty not only of exploiting complicated networks, but also of exploiting personal relationships," he said.
He added that he had exploited a relationship with a "government agency," a reference to a previous deal he had related to a separate criminal case in which he agreed to be an informant for the U.S. Secret Service, but provided information from that agency to one of his co-conspirators in the credit-card theft cases.
"I've impacted the lives of millions of individuals and I violated the sanctity of my parents' home," said Gonzalez, who was wearing khaki-colored jail garb and a stylish, closely shorn haircut -- quite different from the long locks he sported when he was arrested.
Gonzalez stashed more than a million dollars in a hole in the backyard of his parents' Miami home, although he drew a map for investigators to find the hidden loot and forfeited it and other ill-gotten material goods after he was arrested.
He urged Judge Saris to sentence him on the low end of the agreed-to spectrum, saying he hopes to some day prove to his parents that he loves them as much as they love him and that he wants upon his release to turn his life around.
Gonzalez and co-conspirators hacked into computer systems and stole credit card information from TJX, Office Max, DSW and Dave and Buster's, among other online retail outlets, in one of the largest -- if not the largest -- cybercrime operations targeting that sort of data thus far.
They used some of the stolen numbers to remove cash from ATM machines and sold many of the other numbers to other criminals, including those in Eastern Europe.
Gonzalez pleaded guilty to conspiracy charges in two cases related to those thefts last December and the following day entered a guilty plea in a third case involving hacking into computer networks of Heartland Payment Systems and the Hannaford Supermarkets and 7-Eleven chains, also to steal credit and debit card numbers.
The Heartland hacking was particularly damaging because the company processes transactions for major credit and debit card companies Visa and American Express.
Cybercrime Watch
- University of North Florida breach exposes data on 107,000 individuals
- Zeus Trojan bust reveals sophisticated 'money mules' operation in U.S.
- GAO slams White House for failing to lead on cybersecurity
- Man charged with attack on Web site of Fox News' Bill O'Reilly
- Heartland breach expenses pegged at $140M -- so far
- IT contractor gets five years for $2M credit union theft
- Democracy would suffer if Google left China, says MIT panel
- Gonzalez accomplice gets five years for hacking TJX
- Threat of cyberattacks from overseas high, federal IT execs say
- Botnets 'the Swiss Army knife of attack tools'


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Obtaining Fortune 500 Security without Busting your Budget
- Network Security and Compliance on a Budget Made Simple
- Controlling the Cost of File Transfers
- This solution brief explains why something as seemingly simple and straightforward as a file transfer task turns into such a costly operation. It...
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats. All Network Security White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Network Security Webcasts
