Thursday, February 27, 2025
HomeCyber Security NewsA New York Man Charged for Hacking Credit Card Using SQL Injection...

A New York Man Charged for Hacking Credit Card Using SQL Injection Attacks

Published on

SIEM as a Service

Follow Us on Google News

A New York City man Vitalii Antonenko, 28, was charged for hacking, credit card trafficking, and money laundering.

Antonenko was arrested in March 2019 and detained for money laundering charges after he returned from Ukraine with computers and other digital goods that hold thousands of stolen payment card numbers.

SQL Injection to Steal Payment Card Data

Antonenko and co-conspirators used the SQL injection attack method to steal credit card data from vulnerable networks and extracted Payment Card Data and other personally identifiable information (PII).

Then they transfer the stolen data for sale on online darknet marketplaces that are used to exchange various illicit goods.

According to the complaint, Antonenko and two co-conspirators sold stolen credit cards by using multiple carding websites according to reports.

Law enforcement agencies tracked the activity for more than two years purchasing personally identifiable information and stolen payment card numbers paying in bitcoin for American Express and Mastercard numbers.

The agents tracked the bitcoin transaction through the blockchain, that has more than 19,000 address controlled by the hacker group.

“As alleged in the indictment, Antonenko and co-conspirators scoured the internet for computer networks with security vulnerabilities that were likely to contain credit and debit card account numbers, expiration dates, and card verification values (Payment Card Data) and other personally identifiable information (PII),” reads DoJ press release.

Antonenko and co-conspirator sold the data to others and used Bitcoin, as well as cash to disguise their nature, location, source, ownership, and control.

Cybercriminals use cryptocurrency to avoid government scrutiny and law enforcement. The anonymous nature of the cryptocurrencies makes them more attractive.

Antonenko may face up to 25 years in prison and fine up to $750,000 for money laundering conspiracy. “Sentences are imposed by a federal district court judge based on the U.S. Sentencing Guidelines and other statutory factors.”

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has...

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000...

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has...

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000...