The indictment returned in Newark on 17 August 2009 had two counts and three defendants. One was Albert Gonzalez, 28, of Miami, held in the Metropolitan Detention Center in Brooklyn and already under indictment in New York and Massachusetts over other breaches. The other two were identified only as Hacker 1 and Hacker 2, "both in or near Russia". The companies named were Heartland Payment Systems of Princeton, 7-Eleven and Hannaford Brothers, two more were left unidentified, and more than 130 million credit and debit card numbers were said to have gone. The Justice Department believed it the largest hacking and identity theft case it had ever prosecuted. Count one charged conspiracy against computers — unauthorised access, fraud and damage — and count two conspiracy to commit wire fraud: up to 35 years.

The method, as the grand jury set it out, began with a reading list. Between October 2006 and May 2008 the conspirators scanned the Fortune 500 list and corporate websites for weaknesses, and Gonzalez and a man the indictment called P.T. visited the targets' shops to see which checkout terminals they used. Computers leased in New Jersey, California, Illinois, Latvia, the Netherlands and Ukraine served as staging posts. The way in was SQL injection: commands typed into a web form and passed to the database behind it. Inside, they compared notes by instant message and installed sniffers that caught card data in real time as it was processed. They came in through proxies, ran their malware past about twenty leading anti-virus products first, and wrote it to delete its own traces.

Heartland had told its part on 20 January 2009, the day Barack Obama was inaugurated. It had begun receiving reports of fraud from MasterCard and Visa late in 2008, and only the week before had investigators found malicious software planted on its processing network. It processed about 100 million transactions a month for more than 250,000 businesses. Names, card numbers and expiry dates had been taken; Social Security numbers, unencrypted PINs and addresses had not. "At this point, though, we don't know the magnitude of what was grabbed," said Robert Baldwin, its president, who put the timing down to legal reviews. Hannaford had disclosed in March 2008: 4.2 million card numbers exposed, at least 1,800 already used in fraud. In August a grand jury put one defendant's name to both.

He had once worked the other side. Arrested in New Jersey in 2003 over ATM and debit card fraud, Gonzalez — CumbaJohnny on the carding forum ShadowCrew — spent more than a year helping the Secret Service watch it, until Operation Firewall, run from the service's Newark field office, arrested 28 people in October 2004. As segvec he went back to work from Miami. Authorities seized $1.6 million in cash, $1.1 million of it in plastic bags in a drum buried in his parents' back garden. On 28 August his lawyer filed notice that he would plead guilty to all nineteen Massachusetts counts, for fifteen to twenty-five years, forfeiting a Miami condominium, a BMW and three Rolex watches. The pleas are September's and December's; the twenty-year sentence and the men behind the pseudonyms, July 2013's.

Also that month · 6–10 August

Aimed at One Account

From about six in the morning California time on Thursday 6 August 2009, Twitter stopped answering. It was down outright for two hours or more — about three, by Wired's count — and in its defence the company shut down much of the interface its third-party applications depended on, leaving them unusable into the next day. Facebook reported "degraded service for some users", LiveJournal faltered, and Google said only that "a handful of non-Google sites" had been hit. Max Kelly, Facebook's chief security officer, said the flood was aimed at one man with accounts on all of them: "It was a simultaneous attack across a number of properties targeting him to keep his voice from being heard." He gave his name to the Guardian as Georgy, a 34-year-old economics lecturer speaking from Tbilisi, who wrote as Cyxymu — a Latinised spelling of Sukhumi, the city whose ethnic Georgians his blog set out to gather after they fled it in 1993; it was the eve of the first anniversary of the five-day war over South Ossetia. He said he was "certain the order came from the Russian government", but offered no evidence, and who ordered or ran the attack was never established. Biz Stone, a Twitter co-founder, would go no further than "geopolitical".

Also that month · 27–28 August

The Key Kept for Backups

At about 18:00 UTC on 27 August 2009 someone logged into minotaur.apache.org — people.apache.org to the Apache Software Foundation's committers, and the seed host for most of its sites — with the SSH key of an account that backed up the ApacheCon site from a third-party host. That host, running CentOS, had been fully compromised and most of its logs destroyed; Apache suspected local root flaws Red Hat had patched on 24 August. The intruders left CGI scripts in www.apache.org's files, and Apache's rsync jobs carried them to the production web servers. At about 07:00 on 28 August they called the scripts over HTTP for remote shells; at about 07:45 the infrastructure team noticed rogue processes on eos, the Solaris machine serving the sites, and within ten minutes shut down every machine involved. The foundation's report, on 2 September, said code repositories, downloads and users had at no time been at risk, credited ZFS snapshots and a mix of operating systems, and named its own failings: unrestricted keys, deployment that copied whatever it found, CGI enabled everywhere. Apache was broken into again, through its bug tracker, in April 2010.

India desk · August 2009

Not Visible on the Card

From 1 August 2009 a card's number, expiry date and the three digits on its back stopped being enough to pay an Indian website. The Reserve Bank of India's circular of 18 February, issued under section 18 of the Payment and Settlement Systems Act 2007 and signed by G. Padmanabhan, a chief general manager, required banks to add "additional authentication/validation based on information not visible on the cards" to every online card-not-present transaction, telephone orders excepted for the time being, and to alert cardholders to every such payment of ₹5,000 or more, on pain of the Act's penalties. Banks answered with Verified by Visa and MasterCard SecureCode, a password registered with the bank beforehand and asked for at each purchase.

The circular was six months older than the Newark indictment, but the two describe one trade from opposite ends: the conspirators, the indictment said, sought to sell their numbers to people who would use them for fraudulent purchases, and in India a stolen number alone was now meant to be useless online. The rule widened rather than softened. Telephone orders were brought under it in January 2011; since 1 October 2022 merchants may not keep card numbers at all, only tokens; and a foreign ride-hailing company that called the second factor antiquated found in 2014 that it would not bend. The fraud our India desk warns about now needs no card number: it talks the owner into moving the money.

AI Tech desk · August 2009

Fuego beats a 9-dan on the small board

On 21 and 22 August 2009, at an IEEE conference on Jeju Island, South Korea, Fuego, an open-source Go program from the University of Alberta, played two games on the small nine-by-nine board against Taiwan's Chou Chun-hsun, a 9-dan professional. As White it won the first by 2.5 points, which its authors called the first time a program had won at that size on even terms against a top-ranked player; as Black it lost the second. Earlier in the month, in Buenos Aires, Pocket Fritz 4, running Mark Uniacke's HIARCS engine on an HTC Touch HD phone with a 528MHz processor, won the Mercosur Cup unbeaten with 9½ points from ten against a field including several grandmasters, drawing only with Diego Valerga. On 31 August Google announced nine more languages for Translate, Swahili, Welsh and Yiddish among them, making 51; Franz Och of Google Research warned that quality would be "noticeably rougher" than in French or Spanish. Fuego's method, Monte Carlo tree search, was later joined to deep neural networks to make AlphaGo.

Digital Guard desk · August 2009

Apple slips a malware check into Snow Leopard

On 25 August 2009 the Register reported what testers had found in the final builds of Mac OS X 10.6, unannounced by Apple: a list, XProtect.plist, against which Snow Leopard checked files downloaded through Safari, Mail, iChat and a few other programs, warning that a match would damage the computer. It knew two trojans, RSPlug and iServices, and ignored anything already on the disk. Snow Leopard went on sale on 28 August; on 2 September Intego, a Mac anti-virus vendor, reported that the check missed two RSPlug variants and anything inside .mpkg installers. Virus Bulletin's August comparative on Windows Vista had denied certification to twelve of thirty-five products, among them CA's home suite, for a pop-up reporting unspecified threats on clean machines that CA insisted was a bug, and Symantec Endpoint Protection, which missed two of some 2,500 samples of a Virut strain and ended Symantec's unbroken run of 44 passes; Symantec blamed a brief adjustment to its detection. Apple's list gained daily updates after Mac Defender; XProtect still runs in macOS.

⏳ Time capsule — August 2009

  • On 8 August Sonia Sotomayor took the judicial oath from Chief Justice John Roberts at the Supreme Court in Washington, becoming its first Hispanic justice and the third woman to sit on it; the Senate had confirmed her two days earlier by 68 votes to 31.
  • On 16 August, in the 100 metres final of the World Championships at Berlin's Olympiastadion, Usain Bolt ran 9.58 seconds, 0.11 inside the world record he had set in Beijing a year earlier to the day; Tyson Gay was second in 9.71.
  • At 1.30 in the morning of 29 August, Indian time, ISRO lost radio contact with Chandrayaan-1, India's first mission to the Moon, after 312 days and more than 3,400 orbits of a mission planned for two years. Its project director, M. Annadurai, declared the mission over.
  • On 30 August the Democratic Party of Japan won 308 of the 480 seats in the lower house, removing the Liberal Democratic Party, which had governed almost without interruption since 1955; Yukio Hatoyama became prime minister on 16 September.
Where it stands today — 2026

A method anyone could follow

August 2009 put the card-theft economy into a court file, and what the file described was ordinary: a list of large companies, a walk past the tills, a flaw as old as web forms and a sniffer on the wire. Newark's case against Gonzalez closed within months; the trade did not. Magnetic-stripe data went on leaving American tills — about forty million cards at Target in December 2013, about 56 million at Home Depot in September 2014 — and injection, the way in, still headed the Open Web Application Security Project's list of web risks in 2017 and stood third in 2021. India took the other road the same month, making a stolen number worth less at home rather than harder to steal, and has kept tightening the rule since.

The attack on Twitter set a pattern that seventeen years have not retired: to reach one person, knock over the platform he stands on. The lecturer at its centre called himself "not such a famous blogger", and a service used, by comScore's count, by some 45 million people went dark for a morning to get at him. Seven years later botnets built from security cameras buried a single journalist's website (September 2016) and then, through its DNS provider, took Twitter off the air again (October 2016). Apache's answer set the better precedent: a full account of its own failings within a week, and another, hour by hour, after the next intrusion in April 2010. Openness did not prevent the second break-in; it made both of them legible.