The Heartland Payment Systems breach of 2008 was the largest card data theft in history at the time - 130 million credit and debit card numbers stolen from a payment processor whose entire business was handling transaction data securely. The attacker was Albert Gonzalez, who had already been arrested once for card fraud, served as a federal informant, and then continued running card theft operations while cooperating with the Secret Service. The breach was discovered not by Heartland's own security but by Visa and Mastercard notifying Heartland that its customers were experiencing unusually high rates of fraudulent transactions.
Gonzalez operated at the intersection of online criminality and federal cooperation in a way that is still not fully understood. After his initial arrest for the Dave & Buster's breach in 2003, he became a Secret Service informant while simultaneously continuing to orchestrate card data thefts at scale. His eventual sentence of 20 years - the longest ever imposed for computer crime at the time - reflected both the scale of the Heartland breach and the extraordinary breach of trust involved in conducting massive fraud while serving as a government informant.
SQL Injection Into a Payment Processor
Heartland Payment Systems was a major payment processor handling transactions for over 250,000 businesses - restaurants, retailers, small merchants - routing their card transactions through Heartland's infrastructure. The breach began with a SQL injection attack against Heartland's external-facing web application in late 2007 or early 2008. The initial SQL injection gave Gonzalez's team a foothold from which they could deploy packet-sniffing malware on Heartland's internal network.
The critical technique was the deployment of a sniffer on the payment network segment. Payment card data flows through processor networks in a specific way: transactions come in from merchants, the processor validates and routes them, and responses go back. Even if individual data elements are encrypted during transmission, there are points in the processing pipeline where the card data must exist in plaintext to be validated. Gonzalez's team targeted those points - placing their sniffer to capture card data as it transited Heartland's network in unencrypted form during the validation step.
Albert Gonzalez and the Shadowcrew to TJX Pipeline
Albert Gonzalez's career in card fraud traced an arc from forum organizer to sophisticated network attacker. He ran Shadowcrew, one of the earliest organized card fraud forums, until the Secret Service arrested him in 2003. After his arrest, Gonzalez became an informant for the Secret Service's Electronic Crimes Task Force - a cooperation that helped dismantle Shadowcrew. But while providing this cooperation, Gonzalez continued to orchestrate card theft operations under the handle "soupnazi."
The attacks he ran during his informant period included the TJX breach (2007, approximately 94 million cards, then the largest known card breach), the Dave & Buster's breach, and various smaller retailers. The Heartland breach was the culmination - the application of the same network intrusion and packet-sniffing methodology he had developed against retail POS networks, now applied directly to a payment processor.
Gonzalez worked with co-conspirators in Eastern Europe - specifically two Russian nationals who had the technical expertise to develop the custom SQL injection tools and network sniffers used in the attacks. The collaboration followed a pattern common in organized cybercrime: US-based operators providing access and logistical knowledge, Eastern European technical specialists providing the attack tools.
Discovery and Aftermath
Heartland did not discover the breach through its own security operations. In January 2009, Visa and Mastercard notified Heartland that its customers were appearing at unusually high rates in fraud reports. Heartland then investigated and discovered the sniffer malware, which had been running for months. Heartland's CEO Robert Carr went public with unusual transparency about the breach - appearing on television, naming the attack methodology explicitly, and advocating for industry changes. This approach was notable contrast to the typical corporate breach response of minimization and delay.
Heartland was removed from Visa and Mastercard's lists of PCI-compliant processors in the aftermath, which effectively threatened its ability to operate. It was reinstated after demonstrating remediation. The company settled fraud claims from card issuers for approximately $110 million and paid additional settlements to Visa, Mastercard, and American Express. Gonzalez was sentenced to 20 years concurrent on the Heartland and TJX charges in 2010. His Russian co-conspirators were identified and charged but remained outside US jurisdiction.