Albert Gonzalez was awaiting trial on allegations that he orchestrated the largest data breach in history when the scale of his crimes began to come into focus. The 24-year-old Miami man had been living a double life: by day, a government informant helping the U. S. Secret Service hunt cyber criminals; by night, the very thing he was supposed to be fighting.

His target was the heart of the American financial system. Over the course of his criminal career, Gonzalez would breach the defenses of some of the nation’s largest corporations, stealing the credit card information of more than 170 million customers and causing hundreds of millions of dollars in losses. Born in Cuba in 1981, Gonzalez moved to the U. S.
and attended South Miami High School. While other kids his age were playing volleyball on the beach or surfing, he was drawn to computers. His parents bought him his first computer when he was 12, hoping he would use it for schoolwork and games. Instead, he used it to explore the then-unfamiliar world of hacking.
His first known intrusion came two years later, at age 14, under the alias “soupnazi,” inspired by a character from the sitcom “Seinfeld. ” He managed to break into NASA’s servers. The FBI traced the intrusion not to a foreign enemy or international hacker ring, but to a teenager sitting in his modest Miami home. Agents visited him at his high school, shocking those who knew him.
The encounter did not deter him. While still in high school, Gonzalez discovered IRC, an early online chat network where he joined hacker rooms and spent hours learning and sharing advanced hacking techniques. He graduated in 1999 and soon traveled to meet Stephen Watts, a friend he had made in those chat rooms. Neither knew they would later become partners in crime.
Gonzalez enrolled at Miami-Dade College but dropped out within weeks, bored by introductory computer courses that he had already mastered. He moved to New York City, where he landed jobs at two firms in succession, but both positions ended quickly. By 2002, his savings were running out and he needed an income. That is when Gonzalez turned to hacking full-time.
He joined Shadowcrew, an online forum where cyber criminals bought and sold stolen credit card numbers, social security cards, and other data used for computer crimes. He quickly rose to become one of its leaders and a forum moderator, earning money through fraudulent credit cards. In 2003, Gonzalez was arrested while withdrawing cash from an ATM using phony credit cards. An undercover NYPD officer had been watching him.
Authorities initially thought he was a lone hacker, but soon realized they had captured the moderator of Shadowcrew. Facing a significant sentence, Gonzalez made an offer: in exchange for avoiding criminal prosecution, he would become an informant and help law enforcement catch other cyber criminals. He was recruited for Operation Firewall, a federal cybercrime task force. Gonzalez helped authorities arrest dozens of Shadowcrew members in 2004.
But he later admitted his motives were not loyal to the government. He claimed his loyalty was always to the hacker community, and he used his time with the agencies to study how investigators worked and understand what they knew about cybercrime. Because he was the only Shadowcrew leader not prosecuted, members suspected he was the leak. Fearing for his safety, authorities moved him back to Miami in late 2004.
In Miami, Gonzalez began exploring vulnerabilities in corporate wireless networks. Many companies had adopted Wi-Fi quickly in the early 2000s without adequate security, and he exploited those weaknesses. He used a technique called war driving, which involved sitting in a car in a store parking lot with a laptop and a high-powered antenna, intercepting the store’s Wi-Fi signals to break into its network and reach corporate servers. To launch his own criminal operation, Gonzalez recruited people he trusted: Stephen Watts, now working in the IT department at Morgan Stanley, and Christopher Scott, an old friend from IRC chat rooms.
They called themselves the “Get Rich or Die Tryin’ crew,” named after the 50 Cent album. Scott used war driving to steal more than 400,000 card accounts from DSW and BJ’s Wholesale Club, passing them to Gonzalez to cash out. While running this operation, Gonzalez continued working as a paid informant for the Secret Service in Miami. His lifestyle, however, was that of a rich businessman.
He bought new cars and condos, stayed in luxury hotel suites, and spent thousands of dollars at expensive restaurants and clubs. He once threw himself a birthday party that cost over $75,000, renting a penthouse duplex in New York and flying two Miami DJs up to perform. In 2005 and 2006, he and his friends attended the Winter Music Conference in South Beach, booking top-tier suites and indulging in “magic milkshakes” made with ecstasy, mushrooms, LSD, and ice cream. Gonzalez eventually grew bored with war driving and wanted a new intellectual challenge.
He turned to SQL injection, a technique that allowed him to hack companies from anywhere in the world by exploiting vulnerabilities in commercial websites. He recruited Patrick Toey, a hacker friend facing financial problems, and together they wrote code that chained encrypted IP address proxies to hide their location. They reviewed Fortune 500 companies, gathered intelligence on their systems, and attacked through company websites, using malware to download customer credit card data before removing their digital footprints and installing back doors for future access. By the end of 2007, the crew had breached more than 50 million credit card accounts from companies including Target, TJX, OfficeMax, and Barnes & Noble.
The group would go on to steal 120 million more cards. In several cases, the stolen data was not even protected. Gonzalez expanded internationally, forming a cartel with Maxim Yastremskiy, a Ukrainian, to sell stolen card accounts across Asia, Europe, and America, and he added two European hackers to break into American card payment processors. Suspicion began to mount in the spring of 2008.
While returning from a reconnaissance mission in Miami, Gonzalez and Toey were chased by Secret Service agents in a sports car. The two escaped and drove to Gonzalez’s condo, but their luck ran out weeks later. In May 2008, Albert Gonzalez and Stephen Watts were arrested at an ultra-luxury hotel in Miami. Agents found a pistol, two laptops, and $25,000 in cash in the suite.
During questioning, Gonzalez revealed that he had buried a barrel containing $1 million in cash in the backyard of his parents’ house. The break in the case came from Gonzalez’s Ukrainian partner. Maxim Yastremskiy had been apprehended in July 2007, and investigators found millions of stolen card numbers on his laptop. When they decrypted his hard drive and examined stored chats, the other hacker turned out to be Albert Gonzalez.
Patrick Toey was also arrested and provided crucial information about Gonzalez’s operations in exchange for a reduced sentence. After decrypting data on Gonzalez’s computers, federal agents realized the full scope of the illegal operations run by their trusted informant. Eleven members of the “Get Rich or Die Tryin'” crew were indicted, accused of costing corporations more than $200 million, though investigators said the true scale could not be quantified. Stephen Watts pleaded guilty and admitted to writing code for Gonzalez’s hacking empire, but insisted he was unaware his code was being used for illegal financial activities, and claimed he never made money from the crimes.
He was sentenced to two years in prison and ordered to pay a share of $180 million in damages. Gonzalez, in his official statement, said he regretted his crimes and claimed he committed them to help a friend facing family and financial problems. He said he never thought about the impact of his actions on the millions of people affected and expressed deep sorrow for the consequences. His attorney also submitted a psychiatric report stating that Gonzalez’s actions were consistent with descriptions of Asperger’s disorder and internet addiction.
Patrick Toey had already turned against Gonzalez and received a five-year sentence for cooperating with authorities. Knowing there was no escape, Gonzalez pleaded guilty and fully cooperated, sharing every detail of how he had stolen so many credit card numbers. On March 25, 2010, Gonzalez was sentenced to 20 years in prison for hacking the systems of different companies and stealing information from more than 170 million credit cards. The next day, a federal judge handed him another 20 years for hacking Heartland Payment Systems, a U.
S. -based payment processing company. Gonzalez was ordered to forfeit more than $1. 65 million, a Miami condo, a Glock 27 firearm, IBM and Toshiba laptops, a 2006 BMW 330i, a Nokia cell phone, a Tiffany diamond ring, and three Rolex watches.
He is serving his sentence at the Federal Medical Center in Lexington and was expected to be released in 2025 based on time served and good behavior. His story remains one of the largest financial crimes ever recorded.