CASE DOSSIER
sentenced
U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)
Docket: 1:08-cr-10223 Court: U.S. District Court for the District of Massachusetts Opened: 2008-08-05 Sector: Retail, Financial Payment Processors
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$200.0 million
Direct merchant and bank losses in excess of $200 million across TJX and Heartland.
Techniques
2
Verified mappings
Defendants
1
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the District of Massachusetts.
- Primary Target Sector: Retail, Financial Payment Processors.
- Documented Financial Loss: $200.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Mastermind of the largest credit card theft operation in history at the time, hacking TJX Companies, BJ's Wholesale Club, OfficeMax, and Heartland Payment Systems, stealing over 130 million payment cards.
Procedural & Incident Timeline
2008-05-07 arrest
Gonzalez arrested in a Miami Beach hotel room by U.S. Secret Service agents.
2009-08-28 plea
Pleads guilty to 19 counts of conspiracy, computer fraud, wire fraud, and aggravated identity theft.
2010-03-25 sentencing
Sentenced to 240 months (20 years) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Albert Gonzalez | United States | sentenced | 240 mo | None | Mastermind of TJX, Dave & Buster's, and Heartland payment breaches. Sentenced to 20 years in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks." | Indictment ¶ 14, Page 6 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Installed packet sniffer utilities inside Heartland's payment processing network that captured unencrypted credit card magnetic stripe data during authorization." | Indictment ¶ 22, Page 10 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems), No. 1:08-cr-10223 (U.S. District Court for the District of Massachusetts 2008), https://cyberattackcaselibrary.pages.dev/cases/us-v-albert-gonzalez-tjx-heartland/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-albert-gonzalez-tjx-heartland" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>