Home / Blog / Albert Gonzalez: The Informant Who Stole 170 Million Credit Cards While Working for the Government
Korp Labs · Field Notes

Albert Gonzalez: The Informant Who Stole 170 Million Credit Cards While Working for the Government

 ·  4 min read  ·  By Korp VPN

In 2004, the United States Secret Service ran an operation against a large online carding forum. It worked: dozens of arrests across several countries. The key informant, who had helped identify the suspects from inside the community, was a young man from Miami named Albert Gonzalez.

He kept working for them as a paid informant, earning around $75,000 a year.

He was also, throughout that period, running the largest credit card theft operation ever recorded.

It started in a car park

The first major breach did not involve any sophisticated remote intrusion. Gonzalez and his associates drove around Miami with a laptop and a strong antenna, looking for shop wireless networks — a practice known as wardriving.

Outside a Marshalls store, they found one. The network was protected by WEP, an early wireless encryption standard that was already known to be broken; the key could be recovered by passively collecting enough traffic and doing some arithmetic. It was the security equivalent of a lock that opens if you look at it long enough.

That wireless network was not isolated from the rest of the business. From the shop's in-store systems the attackers reached the corporate network of TJX, the parent company that also owns TJ Maxx and HomeGoods. Once inside, they installed software to capture payment card data as it moved through the processing systems.

They sat there for roughly eighteen months.

The eventual count exceeded 90 million cards. At the time, it was the largest breach ever disclosed.

Then it got bigger

The TJX intrusion made Gonzalez's crew wealthy — he reportedly buried a barrel containing more than a million dollars in cash in his parents' garden — but they escalated rather than stopped.

The next phase targeted payment processors directly, the companies that handle card transactions for thousands of merchants at once. The technique shifted to SQL injection: exploiting web forms that passed user input straight into database queries, allowing an attacker to make the database run commands of their choosing.

SQL injection was not novel in 2007. It had been publicly documented for years and the defence — separating commands from data, so user input can never be interpreted as an instruction — was well understood. It simply had not been applied consistently.

Through it, they reached Heartland Payment Systems, one of the largest card processors in the country, and captured around 130 million card numbers. They also hit a supermarket chain, a convenience store chain and several retailers.

The combined total attributed to the operation is roughly 170 million cards.

The double life

The remarkable part is the overlap. While being paid to help the Secret Service investigate carding forums, Gonzalez was using his access to those same investigations to warn associates, monitor how law enforcement worked, and adjust his methods accordingly.

It ended in 2008. Gonzalez was sentenced in 2010 to twenty years in prison — at the time the longest sentence handed down in the United States for computer crime.

TJX's disclosed costs ran into the hundreds of millions. Heartland's were comparable, and the company was temporarily removed from the list of processors approved to handle major card brands.

What made it possible

Three failures, all of which remain common.

A wireless network treated as an internal one. The shop's Wi-Fi was on the same network as systems that mattered. Wireless should be treated as hostile territory that happens to be nearby, not as part of the trusted interior.

Obsolete encryption left running. WEP's weaknesses were public well before the breach. Deprecated cryptography does not fail gradually; it stops working as security while continuing to look like security, which is worse than nothing because it produces false confidence.

Unvalidated input. SQL injection is the same category of error as the Heartbleed length check: trusting data supplied by a stranger to be well-behaved.

The part that applies to you

Most readers do not run a retail network. But the wardriving phase of this story is worth sitting with, because the underlying situation has not changed — it has only become more common.

An attacker with cheap hardware, sitting within radio range, was able to reach a network he had no business reaching, and the operators had no idea he was there for a year and a half. Wireless leaks past walls. It does not respect property boundaries, and you cannot see who is listening.

Modern Wi-Fi encryption is far better than WEP, and that genuinely helps. But the practical situation on any network you do not personally control is the same one TJX faced: you cannot verify how it is configured, who else is on it, or whether the operator has left something from 2007 running in a corner.

The workable response is to stop depending on the network being trustworthy. Encrypt your traffic before it reaches the wireless link, so that anyone in radio range — or anyone who has quietly compromised the access point — gets an opaque stream rather than a readable one. On a network you control, that means current encryption standards, an isolated guest network, and no assumption that being on the Wi-Fi grants access to anything else. On networks you do not control, it means a tunnel.

Gonzalez did not defeat a strong system. He found a shop that had left a window open and waited eighteen months to see what came through it.

hacking historywifi securitydata breachencryption

Read this on a network nobody is watching

Korp VPN encrypts every packet leaving your device with AES-256 and a stealth protocol that looks like ordinary HTTPS traffic. Unlimited bandwidth, 20+ countries, a strict no-logs policy, and a 5-day free trial — from $1.60 per month.

← Previous
Heartbleed: The Two-Year-Old Bug That Leaked Half the Internet's Secrets
Next →
The Bangladesh Bank Heist: How a Spelling Mistake Stopped a $951 Million Theft

More from Korp Labs

What "No-Logs VPN" Really Means and How to Check the Claim

Almost every VPN says it keeps no logs. The phrase can mean very different things. Here is what a meaningful no-logs policy covers, and the questions that expose a weak one.

VPN vs Proxy vs Tor: What Each One Actually Protects

They all change your IP address, but they protect very different things. A plain-language comparison of VPNs, proxies and Tor, and how to pick the right one for what you are doing.

How to Test Your VPN for Leaks: DNS, IPv6 and WebRTC

A VPN can be connected and still leak your real IP address or DNS lookups. Here is how to run the three tests that matter in under five minutes, and how to fix what you find.