EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/criminal-hacking/albert-gonzalez-heartland-2009
379/430

File EL-0052CriticalResolvedCriminal Hacking / Payment Card Data Theft

Albert Gonzalez Heartland Payment and TJX Credit Card Hack

Also filed as Heartland Payment Systems Breach · TJX Credit Card Data Theft

This incident involved the theft of millions of credit and debit card records from major retailers and payment processors. The data was primarily sourced from Heartland Payment Systems and TJX Companies. The breach exposed sensitive payment card information, leading to massive financial losses and regulatory scrutiny.

  • #credit-card-fraud
  • #heartland-payment-systems
  • #tjx-companies
  • #data-breach
  • #payment-card-industry-pci
Notoriety8/10
Event
11 Aug 2009
Disclosed
11 Aug 2009
Target
Heartland Payment Systems
Actor
Albert Gonzalez
Scale
130.0M records
Status
Resolved

01Summary

The breach, disclosed in August 2009, involved the unauthorized access and exfiltration of payment card data from Heartland Payment Systems, a major payment processor, and TJX Companies, a retailer group. The stolen data included credit and debit card numbers, expiration dates, and associated personal identifying information. Investigators determined that the breach was executed by Albert Gonzalez, who utilized his technical skills to compromise the systems. The sheer volume of data—estimated to exceed 130 million cards—made it one of the largest payment card data breaches in history. The subsequent investigation led to federal charges against Gonzalez, resulting in a high-profile criminal prosecution and conviction.

02Background

The late 2000s saw a rapid increase in digital commerce, making payment processing systems increasingly valuable targets for criminal enterprises. Heartland Payment Systems, due to its central role in processing transactions for numerous retailers, represented a high-value target. The incident highlighted the critical need for robust security protocols within the entire payment card ecosystem.

03Key revelations

  1. 01The scale of the breach, affecting over 130 million payment cards.
  2. 02The involvement of two major entities: Heartland Payment Systems and TJX Companies.
  3. 03The successful criminal prosecution of Albert Gonzalez for the theft.

04Technical analysis

The attack vector was believed to involve exploiting vulnerabilities within the payment processing infrastructure, allowing the attacker to siphon data streams. The method focused on intercepting data before it was fully encrypted or processed, a technique known as man-in-the-middle or direct database exfiltration. The specific technical details of the exploit were kept confidential by law enforcement, but the goal was clearly the mass harvesting of raw cardholder data.

Attack vector
Exploitation of vulnerabilities within the payment processing network/database.
Attack method
Data exfiltration and theft of cardholder data.
Initial access
Compromised internal network access or exploited third-party vendor access.
Lateral movement
Internal network traversal to reach centralized data repositories.
Exfiltration
Bulk data transfer (siphoning) of cardholder records.
Malware type
Stealer

Vulnerabilities exploited

  • Payment Processing System Vulnerabilities

MITRE ATT&CK techniques

  • T1022

05Threat actor

Albert Gonzalez was an individual criminal hacker who specialized in exploiting vulnerabilities in large, centralized data processing systems. His motivation was purely financial, leveraging the stolen data for sale on underground markets.

Aliases

  • Albert Gonzalez

MITRE groups

  • T1115

Known members

  • Albert Gonzalez

Attribution sources

  • FBI
  • Department of Justice (DOJ)

06Victims and impact

Additional victims

  • TJX Companies

Countries affected

  • United States

07Data exposed

Data types

  • Credit Card Numbers
  • Debit Card Numbers
  • Expiration Dates
  • CVV/Security Codes (potentially)
  • Personal Identifying Information (PII)

Notable documents

  • Court Filings related to Wire Fraud and Bank Fraud

08Financial damage

Damage included regulatory fines, remediation costs, and estimated fraud losses, amounting to hundreds of millions of dollars.

09Timeline

  1. 2009-08-11Breach discovered and publicly disclosed.
  2. 2009-08-11Initial data exfiltration period.
  3. 2010-01-01Resolution of criminal charges and initial remediation efforts.

10Key figures

  • Albert GonzalezPrimary Perpetrator · Self-Employed/CriminalAmericanConvicted and sentenced to federal prison.

11On the record

The sheer volume of data stolen highlighted systemic weaknesses in the payment card industry's security protocols.

Industry Analysts, Post-breach analysis

12Reaction and fallout

Public reaction

The public reaction was one of alarm regarding the vulnerability of digital commerce and the perceived failure of major financial institutions to protect consumer data. It spurred increased consumer awareness regarding payment security.

Political impact

The incident intensified regulatory pressure on the payment card industry, leading to stricter compliance requirements and increased scrutiny from federal regulators regarding data handling and security standards.

13Legal

The case resulted in a major federal criminal prosecution against Albert Gonzalez. The conviction set a precedent for the criminal liability of individuals who exploit systemic weaknesses in critical financial infrastructure.

Prosecutions

  • Albert GonzalezConvicted
    Charge
    Wire Fraud, Bank Fraud, Conspiracy
    Jurisdiction
    United States Federal
    Sentence
    Multiple years in federal prison

Civil lawsuits

  • Class-action lawsuits filed by affected consumers and businesses.

14Aftermath

Policy changes

  • Increased adoption and enforcement of PCI DSS (Payment Card Industry Data Security Standard) requirements.
  • Stricter federal guidelines on data retention and disposal for financial institutions.

Regulatory changes

  • Enhanced oversight by financial regulatory bodies (e.g., OCC, CFPB) regarding third-party vendor risk management.

Security improvements

  • Widespread adoption of tokenization and encryption for cardholder data at rest and in transit.
  • Implementation of multi-factor authentication (MFA) across payment processing networks.

15Significance and legacy

Significance

This breach is historically significant because it exposed the massive scale of vulnerability in the payment card ecosystem, demonstrating that centralized processing hubs could be compromised to steal data on a consumer scale. It directly contributed to the tightening of global standards like PCI DSS and increased the focus on end-to-end encryption in digital commerce.

Legacy

The incident permanently shifted the industry's focus from perimeter defense to data-centric security models. It accelerated the move toward tokenization and reduced the reliance on storing raw Primary Account Numbers (PANs) within merchant or processor systems.

16Disclosure and media

Authentication
Law Enforcement Investigation

Media partners

  • The New York Times
  • Reuters
  • Associated Press

Publishing organisations

  • FBI
  • Department of Justice

17Field notes

  1. 01The sheer number of cards stolen made it one of the largest single data theft events in the history of the payment card industry.
  2. 02The incident spurred the development and mandatory adoption of advanced encryption techniques across multiple sectors.

18Resolution

The criminal case against Gonzalez was resolved through conviction and sentencing. The industry response involved massive security overhauls and regulatory compliance efforts.

19Sources

Official documents

  • DOJ Indictments and Court Records

References

  1. [1]FBI Cybercrime Reports
  2. [2]PCI Security Standards Council Advisories
Fact sheetEL-0052

Dates

Event
11 Aug 2009
Started
11 Aug 2009
Ended
11 Aug 2009
Duration
1 days
Discovered
11 Aug 2009
Disclosed
11 Aug 2009
Resolved
1 Jan 2010
Ongoing
No

Target

Organisation
Heartland Payment Systems
Type
Financial Institution
Sector
Payment Processing
Country
United States

Actor

Name
Albert Gonzalez
Type
Individual Hacker
Nationality
American
Motivation
Financial gain through the sale and use of stolen payment card data.
Attribution
High
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
Multiple counts of wire fraud, bank fraud, and conspiracy; sentenced to multiple years in federal prison.

Data

Records
130,000,000
Volume
Over 130 million records
Sensitivity
Top Secret
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.