Government made me do it, imprisoned TJX hacker claims

Albert Gonzalez, who is serving a 20-year sentence, wants to reverse his guilty plea

By Jaikumar Vijayan, Computerworld |  Security, data protection, hacking Add a new comment

Convicted hacker Albert Gonzalez, who is currently serving a 20-year prison sentence after pleading guilty to the massive hacks at TJX, Heartland and numerous retailers, now claims that he thought he was authorized and directed by the government to carry out the illegal activities.

In a petition filed last month, first reported by Wired , Gonzalez informed the U.S. District Court for the District of Massachusetts that he would like to withdraw his guilty plea and asked the court to vacate its sentence.

In his 25-page petition, Gonzalez blamed his attorneys Martin Weinberg and Rene Palomino for not properly representing him or informing him about his defense options. Gonzalez also claimed that his lawyers did not appeal his sentence as he had asked them to.

Gonzalez was arrested in Miami in 2008 along with 10 other individuals on charges relating to the thefts at TJX, Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

Later he was also charged with the break-ins at Heartland Payment Systems, Hannaford, 7-Eleven and two other unnamed retailers. Gonzalez was indicted in three different states, New York, Massachusetts and New Jersey for his crimes. Prosecutors alleged that Gonzalez and his international gang of cyber criminals stole data on more than 130 million debit and credit cards over a multi-year period.

In Sept. 2009, Gonzalez, pleaded guilty to 20 counts of conspiracy, computer fraud, wire fraud, access device fraud and aggravated identity theft. He was sentenced to two concurrent 20 year terms by federal courts in Massachusetts and NJ.

In his petition, Gonzalez claims that all of the criminal activities that he admitted to in court were actually done with the full knowledge and the direction of the United States Secret Service.

As previously known, Gonzalez noted that he had begun working as a confidential informant for the Secret Service back in 2003 soon after he was busted in connection with a series of ATM thefts. Gonzalez claims that over the next several years, he helped the Secret Service infiltrate various carder gangs and hacking groups, leading to the arrests of many of them.

Gonzalez' petition details his interactions with two of his Secret Service handlers, who he claims treated him almost like another member of the agency and took him to different parts of the country for undercover work.

"The Agents had me infiltrating chat rooms setting people up and then the Agents would bust them," he offers as one example of the work he claims to have done for the government. "On one occasion I was taken to California for a week to help Agents there with undercover operation that resulted in arrests and convictions," Gonzalez said in his petition.

At the time of his arrest, Gonzalez said he firmly believed he was "authorized to engage in the cyber crimes I was participating in, in order to gather intelligence on National and International cyber criminals and I was doing my job to the best of my abilities," Gonzalez said. He said he was being paid $1,200 a month for his work.

According to Gonzalez, his illegal activities were done to establish trust with other cybercriminals so he could make contact with more of them and expose their acitivities to law enforcement.

Gonzalez said Palomino did not advise him of the availability of the "Public Authority" defense that he could have used to defend his actions. Under the public authority defense, any individual who is "acting under the actual or believed exercise of public authority on behalf of a law enforcement agency" can claim immunity against illegal conduct arising from his actions, Gonzalez said in his petition.

Gonzalez also asked for his guilty pleas to be withdrawn. According to him, the only reason he pleaded guilty to the indictments in all three states was because his attorney and prosecutors told him he would benefit by doing so. Gonzalez claims in his petition that he was informed if he agreed to plead guilty to all three cases, all of the cases would be transferred to Boston, where it would go before one judge and he would receive just one sentence.


Originally published on Computerworld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question