October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Two Russian Nationals Sentenced in the Broader Hacking Conspiracy That Included Heartland Payment Systems

The 2018 sentencing of Vladimir Drinkman and Dmitriy Smilianets involved a multinational card-theft conspiracy, not a Heartland-only case. Here is how their roles and sentences compared with Albert Gonzalez’s.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Vladimir Drinkman and Dmitriy Smilianets were sentenced in New Jersey on February 14, 2018, for their admitted roles in a multinational payment-card data-theft conspiracy. Drinkman received 144 months in prison and Smilianets received 51 months and 21 days. Heartland Payment Systems was one of many targets; the 2018 case was not a Heartland-only prosecution. Albert Gonzalez, the U.S. leader of the prosecuted ring, had already received a 20-year-and-one-day sentence in 2010 for related cases involving Heartland, 7-Eleven and Hannaford.

What the 2018 sentences covered

The Justice Department announced the sentences on February 15, 2018, after U.S. District Judge Jerome B. Simandle imposed them the previous day in Camden, New Jersey. Both defendants had pleaded guilty in September 2015.

Defendant Role described by prosecutors Sentence Supervised release
Vladimir Drinkman Network intrusion and data-mining specialist 144 months (12 years) 3 years
Dmitriy Smilianets Seller of stolen payment-card data and distributor of proceeds 51 months and 21 days 5 years

The Justice Department’s account is available at its February 2018 sentencing release. Dark Reading published its contemporary report on February 16, 2018, under the narrower Heartland-focused headline.

Who did what in the conspiracy?

The five-person operation had specialized jobs rather than identical “hacker” roles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Drinkman and Alexandr Kalinin were described as breaking through network security and obtaining access to victim systems.
  • Drinkman and Roman Kotov allegedly searched compromised networks for valuable information.
  • Mikhail Rytikov allegedly provided anonymous web-hosting services intended to hide the activity.
  • Smilianets sold stolen data, known as “dumps,” to identity-theft wholesalers and distributed proceeds among participants.

Drinkman and Smilianets admitted their roles and were sentenced. The February 2018 release said Kalinin, Kotov and Rytikov remained at large; descriptions of their conduct therefore remain allegations, not convictions.

How Heartland fit into the case

Heartland Payment Systems was one corporate victim in a much larger international campaign. The earlier New Jersey indictment, announced in 2009, alleged theft of more than 130 million credit- and debit-card numbers from five companies, with prosecutors attributing the vast majority to the Heartland intrusion. The indictment and victim list are summarized by the Justice Department at this page.

The later sentencing release described the complete conspiracy as obtaining more than 160 million card numbers from numerous networks. These figures cover different scopes:

  • More than 130 million: the five-victim, Heartland-centered New Jersey indictment.
  • More than 160 million: the broader multinational conspiracy and its wider victim set.

They should not be treated as competing measurements of Heartland alone. The broader list named payment and retail networks including Heartland, NASDAQ, 7-Eleven, Hannaford, Carrefour and JCPenney, as well as JetBlue and other companies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the attacks worked

The prosecution described a multi-stage process, presented here at a historical, non-operational level:

  1. Initial access: attackers used SQL injection against vulnerable, database-driven systems.
  2. Persistence: malware and back doors helped them retain access.
  3. Collection: network “sniffers” captured payment-card data moving through compromised environments.
  4. Staging and transfer: stolen records were stored on computers in multiple countries.
  5. Monetization: Smilianets sold the records through underground channels.
  6. Concealment: the group used encrypted communications, anonymous hosting, disabled logging and efforts to bypass security software and erase evidence.

According to the Justice Department, court documents and instant messages described prices of about $10 for a U.S. card record, $50 for a European record and $15 for a Canadian record, with discounts for bulk or repeat purchases. Those figures were allegations reported in court and Justice Department materials, not a verified universal price list.

Albert Gonzalez’s earlier sentence

Gonzalez was the central U.S. defendant in the Heartland-related New Jersey prosecution. Prosecutors said he supplied malware, helped other participants bypass antivirus software and firewalls, and assisted access to payment-card networks.

In March 2010, he received 20 years and one day in the New Jersey case involving Heartland, 7-Eleven and Hannaford. That sentence ran concurrently with a 20-year sentence in the Boston case and related proceedings. It also included three years of supervised release and a $25,000 fine in New Jersey, in addition to a fine imposed in the other case. The Justice Department’s sentencing account is at this release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is therefore inaccurate to say Gonzalez received 20 years solely for Heartland. His punishment covered connected hacking cases and multiple corporate victims. The 2018 sentences were later judgments for Drinkman and Smilianets’ roles in the larger conspiracy.

Timeline from intrusion to sentencing

Date Event
2007–2008 Intrusions and payment-card thefts described in the prosecutions occurred.
August 2009 Gonzalez and two Russian co-conspirators were indicted in New Jersey.
March 2010 Gonzalez was sentenced in the related cases.
June 28, 2012 Drinkman and Smilianets were arrested in the Netherlands.
September 7, 2012 Smilianets was extradited to the United States.
February 17, 2015 Drinkman was extradited to the United States.
September 2015 Drinkman and Smilianets pleaded guilty.
February 14, 2018 Judge Simandle imposed their sentences.

The long interval reflects international arrests, extradition proceedings, investigation and prosecution—not a newly discovered 2018 breach.

How investigators built the case

The investigation combined Secret Service cyber work, evidence from court filings and instant-message communications, cooperation with Dutch authorities, and information supplied by Gonzalez. Arrests in the Netherlands followed by extradition showed that operating infrastructure and defendants across borders did not necessarily prevent a U.S. prosecution, although it made the process lengthy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the case still matters to payment organizations

The episode illustrates risks that remain relevant to payment businesses without implying that later technologies or regulations were caused by this case alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Limit the amount of raw card data stored or transmitted by using hosted payment pages, tokenization or point-to-point encryption where appropriate.
  • Segment payment environments from ordinary corporate networks.
  • Monitor for persistence, unusual data movement and attempts to disable logging or security tools.
  • Keep tamper-resistant logs so investigators can reconstruct long-dwell intrusions.
  • Maintain a tested incident-response plan involving legal counsel, payment partners, insurers and forensic specialists.
  • Treat PCI DSS compliance as an ongoing control program, not only an annual paperwork exercise.

These measures reduce exposure but do not eliminate phishing, account takeover, supplier compromise, insider risk or weaknesses in a company’s own systems.

130 million versus 160 million cards

The two headline numbers describe different legal scopes. The approximately 130-million figure came from the 2009 Heartland-centered indictment covering five corporate victims. The more than 160-million figure came from the Justice Department’s later description of the entire multinational conspiracy and its broader victim set. Neither figure means that all records came from Heartland.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.