Case file · HEARTLAND 2008

How the Heartland breach happened: 130 million cards and an informant

Published 2026-09-29 · 4 min read · Missing control: Encrypt card data in transit internally

While his crew was breaking into one of America's biggest card processors, Albert Gonzalez was on the U.S. Secret Service payroll as an informant, earning about $75,000 a year.[3] This case file covers how the Heartland Payment Systems breach worked, how it became what prosecutors called the largest card data breach ever charged in the United States, and the one control that would have made the stolen data useless.

What happened

Years earlier, Gonzalez had been arrested for fraudulent ATM withdrawals in New York and was put to work undercover for the Secret Service, helping bring down an online card-fraud forum whose members were arrested in October 2004. The agency paid him in cash.[3] At the same time, with 2 co-conspirators, he was running his own operation. Starting in October 2006, the group went after the networks of large retailers and processors.[1]

One target was Heartland Payment Systems, a New Jersey company that handled card payments for about 175,000 merchants, some 100 million card transactions a month.[5] Attackers got into its network in late 2007 and planted software that quietly collected card data for months.[4]

Gonzalez was arrested in May 2008 over earlier retail breaches.[3] On January 20, 2009, Heartland announced that it had found malicious software in its processing system after the card brands alerted it to suspicious activity.[5] On August 17, 2009, federal prosecutors charged Gonzalez and 2 others with stealing data on more than 130 million credit and debit cards from Heartland, 7-Eleven and the Hannaford supermarket chain.[1]

How they got in

According to the indictment, the group got past the companies' firewalls using SQL injection, a well-known type of attack where a website accepts malicious input and passes it straight to the database behind it.[1] At Heartland, the underlying flaw had been sitting in the system for several years before it was used.[4]

Once inside, they installed sniffer programs, software that watches traffic on a network and copies whatever passes by.[2] At Heartland, card numbers, expiration dates and some cardholder names flowed between internal systems without encryption, so the sniffers could read them as they went past.[4][5] Heartland's chief executive said afterward that the malware could collect unencrypted data in motion.[5] Prosecutors said the stolen data was sent to servers the group ran in California, Illinois, Latvia, the Netherlands and Ukraine.[1]

Heartland had passed its payment card industry security assessment in April 2008, while the intruders were inside.[5] Passing a checklist did not mean the data was protected on every internal hop.

What it cost

Gonzalez pleaded guilty. On March 25 and 26, 2010, he was sentenced to 20 years, and then 20 years and 1 day, in federal prison, to run concurrently, for the Heartland case and the earlier retail breaches.[2] Agents had also recovered more than $1 million in cash that he directed them to, buried in a barrel in his parents' backyard.[3]

Heartland's market value fell by half after the announcement, and it had spent more than $32 million on legal, forensic and settlement costs by August 2009.[4] It later agreed to pay $60 million to settle with Visa and up to $41.4 million with MasterCard to cover card-issuer losses and costs.[6]

The missing control

The missing control: encrypting card data as it moves inside the network. Heartland protected the perimeter and passed its audit, but inside the network card numbers traveled in plain text.

If card data had been encrypted from the moment it was captured until it reached the card networks, the sniffers would have collected scrambled records worth nothing to the buyers. The break-in might still have happened, but the payoff would not. Heartland's own answer after the breach was exactly this: it championed end-to-end encryption and built terminals that encrypt data at the point of swipe.[4][5]

What to do in your business

Watch the case
The card thief who was also a Secret Service informantDrops 2026-11-16
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. U.S. Department of Justice: Alleged international hacker indicted for massive attack on U.S. retail and banking networks
  2. U.S. Department of Justice: Leader of hacking ring sentenced for massive identity thefts from payment processor and U.S. retail networks
  3. CNN: Secret Service paid hacker $75,000 a year
  4. Federal Reserve Bank of Philadelphia: Heartland Payment Systems: Lessons learned from a data breach (January 2010)
  5. Dark Reading: Heartland CEO provides more details on big data breach
  6. Dark Reading: Heartland reaches $41 million settlement with MasterCard over data breach