Albert Gonzalez looked like an ordinary IT guy from Miami. He bought his first computer at 12, reportedly hacked NASA at 14, and by his early twenties ran Shadow Crew, an online marketplace where about 4,000 members traded 1.5 million stolen credit and ATM cards along with fake passports and Social Security cards. When the Secret Service’s Operation Firewall caught him in Newark carrying 15 fake cards, he avoided prison by becoming a paid informant.
This episode follows the double life that came next. While working with the Secret Service by day, Gonzalez and his crew cracked weak store Wi-Fi from parked cars, planted sniffer programs, and took 45.6 million card numbers from TJX and other retailers. Then he went bigger, using SQL injection to pull 130 million cards from Heartland Payment Systems. A sloppy return trip to a Dave and Buster’s finally exposed him, and the story ends with buried cash, a 20 year sentence, and a retail industry forced to rethink security.
- Shadow Crew ran like a legitimate marketplace, with moderators who forced sellers to refund buyers when stolen card numbers turned out to be invalid.
- His crew went war driving along US Route 1 in Miami, cracking the outdated WEP encryption on store networks within minutes from the parking lot.
- Before releasing his malware, Gonzalez tested it against 20 leading antivirus programs to make sure it would go undetected.
- Agents arrested him in May 2008 at the National Hotel in Miami Beach and found $1.6 million in cash, $1.1 million of it buried in a drum in his parents’ backyard.
- In 2011 he tried to withdraw his guilty plea by claiming his informant status meant he had acted under public authority. The court rejected it, and he was released in September 2023.
Leave a Reply