Saturday, December 9, 2023

A New York Man Charged for Hacking Credit Card Using SQL Injection Attacks

A New York City man Vitalii Antonenko, 28, was charged for hacking, credit card trafficking, and money laundering.

Antonenko was arrested in March 2019 and detained for money laundering charges after he returned from Ukraine with computers and other digital goods that hold thousands of stolen payment card numbers.

SQL Injection to Steal Payment Card Data

Antonenko and co-conspirators used the SQL injection attack method to steal credit card data from vulnerable networks and extracted Payment Card Data and other personally identifiable information (PII).

Then they transfer the stolen data for sale on online darknet marketplaces that are used to exchange various illicit goods.

According to the complaint, Antonenko and two co-conspirators sold stolen credit cards by using multiple carding websites according to reports.

Law enforcement agencies tracked the activity for more than two years purchasing personally identifiable information and stolen payment card numbers paying in bitcoin for American Express and Mastercard numbers.

The agents tracked the bitcoin transaction through the blockchain, that has more than 19,000 address controlled by the hacker group.

“As alleged in the indictment, Antonenko and co-conspirators scoured the internet for computer networks with security vulnerabilities that were likely to contain credit and debit card account numbers, expiration dates, and card verification values (Payment Card Data) and other personally identifiable information (PII),” reads DoJ press release.

Antonenko and co-conspirator sold the data to others and used Bitcoin, as well as cash to disguise their nature, location, source, ownership, and control.

Cybercriminals use cryptocurrency to avoid government scrutiny and law enforcement. The anonymous nature of the cryptocurrencies makes them more attractive.

Antonenko may face up to 25 years in prison and fine up to $750,000 for money laundering conspiracy. “Sentences are imposed by a federal district court judge based on the U.S. Sentencing Guidelines and other statutory factors.”

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Website

Latest articles

Exploitation Methods Used by PlugX Malware Revealed by Splunk Research

PlugX malware is sophisticated in evasion, as it uses the following techniques to avoid...

TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities

Hackers exploit Outlook and WinRAR vulnerabilities because these widely used software programs are lucrative...

Bluetooth keystroke-injection Flaw: A Threat to Apple, Linux & Android Devices

An unauthenticated Bluetooth keystroke-injection vulnerability that affects Android, macOS, and iOS devices has been...

Atlassian Patches RCE Flaw that Affected Multiple Products

Atlassian has been discovered with four new vulnerabilities associated with Remote Code Execution in...

Reflectiz Introduces AI-powered Insights on Top of Its Smart Alerting System

Reflectiz, a cybersecurity company specializing in continuous web threat management, proudly introduces a new...

SLAM Attack Gets Root Password Hash in 30 Seconds

Spectre is a class of speculative execution vulnerabilities in microprocessors that can allow threat...

Akira Ransomware Exploiting Zero-day Flaws For Organization Network Access

The Akira ransomware group, which first appeared in March 2023, has been identified as...

Endpoint Strategies for 2024 and beyond

Converge and Defend

What's the pulse of Unified Endpoint Management and Security (UEMS) in Europe? Join us live to uncover the strategies that are defining endpoint security in the region.

Related Articles