NEWARK, N.J. – Four Russian nationals and a Ukrainian have been charged with running a sophisticated hacking organization that penetrated computer networks of more than a dozen major American and international corporations over seven years, stealing and selling at least 160 million credit and debit card numbers, resulting in losses of hundreds of millions of dollars.
Indictments were announced Thursday in Newark, where U.S. Attorney Paul Fishman called the case the largest hacking and data breach scheme ever prosecuted in the United States.
Princeton-based Heartland Payment Systems Inc., which processes credit and debit cards for small to midsize businesses, was identified as taking the biggest hit in a scheme starting in 2007 – the theft of more than 130 million card numbers at a loss of about $200 million.
Atlanta-based Global Payment Systems, another major payment processing company, had nearly 1 million card numbers stolen, with losses of nearly $93 million, prosecutors said.
The indictment did not put a loss figure on the thefts at some other major corporations, including Commidea Ltd., a European provider of electronic payment processing for retailers. The government said hackers in 2008 covertly removed about 30 million card numbers from its computer network.
About 800,000 card numbers were stolen in an attack on the Visa network, but the indictment did not cite any loss figure.
Not all the companies the hackers infected over the years with malicious computer software suffered financial losses. Customer log-in credentials were stolen from Nasdaq and Dow Jones Inc., the indictment said, though prosecutors said Nasdaq’s securities trading platform was not affected.
The indictment said the suspects sent each other instant messages as they took control of the corporate data, telling each other, for instance: “NASDAQ is owned.” At least one man told others that he used Google news alerts to learn whether his hacks had been discovered, according to the court filing.
The defendants were identified as Vladimir Drinkman, 32, of Syktyvkar, Russia, and Moscow; Aleksander Kalinin, 26, of St. Petersburg, Russia; Roman Kotov, 32, of Moscow; Dmitriy Smilianets, 29, of Moscow; and Mikhail Rytikov, 26, of Odessa, Ukraine.
Smilianets is in U.S. custody and was expected to appear in federal court next week. His New York-based lawyer, Bruce Provda, said Smilianets was in the U.S. “sightseeing” when he was arrested. “It’s a rather complex international charge of hacking,” Provda said. “If it goes to trial, it’s going to be a lengthy trial.”
Drinkman is being held in the Netherlands pending extradition, prosecutors said. His lawyer there, Bart Stapert, did not immediately return a message. The other three defendants remained at large.
All five are charged with taking part in a computer hacking conspiracy and conspiracy to commit wire fraud. The four Russian nationals are also charged with multiple counts of unauthorized computer access and wire fraud.