Federal prosecutors announced yesterday the indictment of five men accused of involvement in the theft of over 160 million credit card numbers. According to prosecutors, thefts by this group involved some of the largest and most notable U.S. data breaches of recent years, including Global Payments, Heartland Payment Systems, Hannaford, and NASDAQ, among others.
Payment card information is among the most sought-after information by data privacy thieves. The indictments allege that this group, based in Russia and the Ukraine, sold the stolen card data to “trusted identity theft wholesalers” for prices ranging from $10 – $50 per card. Federal prosecutors estimate that the group caused “hundreds of millions” of dollars in losses, most of which are borne by companies.
The arrests highlight the challenges faced by businesses from increasingly sophisticated data privacy thieves, and sheds light on the lengths which hackers may be willing to go when targeting companies. The indictment alleges that this group would patiently spend months penetrating corporate networks, using malware, SQL Injection and other tactics. The groups also defined specialized roles for its members, with some members dedicated to penetrating network security, others dedicated to maximizing the amount of the data obtained from the companies, and another responsible for selling the stolen data. The group also undertook measures to conceal their activities.
The men face between 5 and 30 years in prison if convicted.