Dutch courts cleared the extradition of Russian national Vladimir Drinkman to the United States in a case prosecutors described as the largest hacking and data-breach conspiracy ever prosecuted there. U.S. authorities alleged Drinkman and four co-defendants used SQL injection, malware backdoors, and network sniffers to penetrate payment processors, retailers, and financial institutions, stealing more than 160 million credit and debit card numbers over several years and causing hundreds of millions of dollars in losses. Victims named in court filings included Heartland Payment Systems, 7-Eleven, Hannaford, Carrefour, JetBlue, Global Payments, Dow Jones, and NASDAQ, though prosecutors said the NASDAQ intrusion did not affect its trading platform.
The prosecution tied the operation to the broader payment-card theft ecosystem exposed in earlier cases involving Albert Gonzalez, who had already been accused of orchestrating some of the largest U.S. retail breaches. After his transfer to the United States, Drinkman later admitted his role in the conspiracy, marking a major step in a long-running investigation into an international crew that allegedly harvested card data from corporate networks and sold it through criminal resellers. The case underscored how a small group of Russian and Eastern European defendants allegedly sustained long-term access inside major companies and monetized stolen payment data at unprecedented scale.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Vladimir Drinkman admitted his role in the massive hacking and payment-card theft conspiracy prosecuted in New Jersey. His plea marked a significant prosecutorial milestone in the long-running case.
The U.S. Justice Department announced that Vladimir Drinkman had been extradited from the Netherlands to face charges in New Jersey. He was accused of participating in the largest known data-breach prosecution in the United States.
The Hague District Court approved the extradition of Russian national Vladimir Drinkman to the United States, rejecting defense objections and a competing Russian request. U.S. authorities sought him over his alleged role in the massive payment-card theft conspiracy.
A federal indictment unsealed in New Jersey charged five men in a global hacking scheme that allegedly stole more than 160 million credit and debit card numbers from payment processors, retailers, and financial institutions. Prosecutors said the operation caused hundreds of millions of dollars in losses and involved victims including Heartland, 7-Eleven, Carrefour, JCP, Hannaford, JetBlue, Global Payment, Dow Jones, and NASDAQ.
Dutch authorities arrested Vladimir Drinkman and Dmitriy Smilianets in 2012 in connection with the long-running payment-card hacking conspiracy. Their arrests were later cited in the U.S. indictment unsealed in New Jersey.
Albert Gonzalez's lawyer said he had been nearing a global plea agreement covering multiple major hacking cases before the New Jersey indictment intervened. The report described the indictment as disrupting negotiations that could have resolved several active prosecutions.
U.S. prosecutors brought a New Jersey indictment tied to breaches at Heartland Payment Systems, 7-Eleven, and Hannaford Bros., alleging theft of more than 130 million payment-card numbers. The case identified Albert Gonzalez as a central figure and charged additional foreign conspirators.
A Businessweek report examined the Heartland Payment Systems breach and its implications for payment security. This reflects public disclosure and industry response to one of the key victim intrusions in the later criminal case.
Heartland Payment Systems publicly disclosed a major intrusion affecting payment-card data. The breach later became one of the central incidents in the broader U.S. hacking conspiracy case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcechicagotribune.com
Open sourcebits.blogs.nytimes.com
Open sourcecomputerworld.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.