A New York Man Charged for Hacking Credit Card Using SQL Injection Attacks

A New York City man Vitalii Antonenko, 28, was charged for hacking, credit card trafficking, and money laundering.

Antonenko was arrested in March 2019 and detained for money laundering charges after he returned from Ukraine with computers and other digital goods that hold thousands of stolen payment card numbers.

SQL Injection to Steal Payment Card Data

Antonenko and co-conspirators used the SQL injection attack method to steal credit card data from vulnerable networks and extracted Payment Card Data and other personally identifiable information (PII).

Then they transfer the stolen data for sale on online darknet marketplaces that are used to exchange various illicit goods.

According to the complaint, Antonenko and two co-conspirators sold stolen credit cards by using multiple carding websites according to reports.

Law enforcement agencies tracked the activity for more than two years purchasing personally identifiable information and stolen payment card numbers paying in bitcoin for American Express and Mastercard numbers.

The agents tracked the bitcoin transaction through the blockchain, that has more than 19,000 address controlled by the hacker group.

“As alleged in the indictment, Antonenko and co-conspirators scoured the internet for computer networks with security vulnerabilities that were likely to contain credit and debit card account numbers, expiration dates, and card verification values (Payment Card Data) and other personally identifiable information (PII),” reads DoJ press release.

Antonenko and co-conspirator sold the data to others and used Bitcoin, as well as cash to disguise their nature, location, source, ownership, and control.

Cybercriminals use cryptocurrency to avoid government scrutiny and law enforcement. The anonymous nature of the cryptocurrencies makes them more attractive.

Antonenko may face up to 25 years in prison and fine up to $750,000 for money laundering conspiracy. “Sentences are imposed by a federal district court judge based on the U.S. Sentencing Guidelines and other statutory factors.”

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Redline Malware Using Lua Bytecode to Challenge the SOC/TI Team to Detect

The first instance of Redline using such a method is in a new variant of Redline Stealer malware that McAfee…

1 hour ago

Threat Actor Claims Selling of Dell Database with 49M User Records

A threat actor reportedly sells a database containing 49 million user records from Dell, one of the world's leading technology…

5 hours ago

Google Blocks 2.28M Malicious Apps Entering The Play Store

A safe and trusted Google Play experience is our top priority. We leverage our SAFE (see below) principles to provide…

6 hours ago

LightSpy Malware Actively Targeting MacOS Devices

BlackBerry reported a new iOS LightSpy malware, but Huntress researchers found it to be a macOS variant targeting Intel or…

7 hours ago

New Android Malware Mimic As Social Media Apps Steals Sensitive Data

A new RAT malware has been discovered to be targeting Android devices. This malware is capable of executing additional commands…

7 hours ago

Safari Vulnerability Exposes EU iOS Users to Malicious Marketplaces

A serious concern has arisen for iPhone users in the European Union as a newly discovered flaw in Apple's Safari…

7 hours ago