Recommended Free Tools
Federal prosecutors alleged that a group compromised RBS WorldPay’s payroll debit-card system and coordinated a rapid ATM cash-out worth more than $9 million. On November 10, 2009, the U.S. Department of Justice announced indictments against four people in the alleged intrusion and a separate set of access-device-fraud indictments against four others. These were charges, not findings of guilt.
How prosecutors said the RBS WorldPay scheme worked
According to the Justice Department’s November 10, 2009 announcement, the main group allegedly compromised encryption protecting customer data on payroll debit cards and raised account limits. Prosecutors said the group then supplied cashers with 44 counterfeit payroll debit cards. Those cashers allegedly used them to withdraw funds from ATMs, keeping a portion and sending the bulk back to defendants. The DOJ announcement described the alleged mechanics; it did not establish them as proven facts.
The cash-out was alleged to have exceeded $9 million at more than 2,100 ATMs in at least 280 cities worldwide in less than 12 hours. Prosecutors said cashers were allowed to keep 30–50% of the funds. Every figure here is an allegation reported by DOJ in 2009, not a present-day measurement or an independently established total.
Who was indicted?
The November 10, 2009 DOJ announcement said a federal grand jury in Atlanta indicted Sergei Tsurikov, Viktor Pleshchuk, Oleg Covelin, and a person identified as “Hacker 3” on charges arising from the alleged network intrusion. DOJ separately announced access-device-fraud indictments against Igor Grudijev, Ronald Tsoi, Evelin Tsoi, and Mihhail Jevgenov. An indictment formally alleges criminal conduct; it is not a conviction.
#1 Best Overall
How many people’s information may have been exposed?
The alleged 44-card cash-out and the possible breach exposure are different measures. A contemporaneous Dark Reading report said RBS WorldPay reported that personal information for 1.5 million cardholders and other people may have been affected, and that Social Security numbers for up to 1.1 million may have been accessed. Those figures describe possible data exposure as reported in 2009; they do not mean that 1.5 million people’s cards were used in the alleged ATM withdrawals. Dark Reading’s November 11, 2009 report distinguishes the broader exposure claim from the indictment’s alleged use of 44 counterfeit cards.
Why the case crossed borders
DOJ said the investigation involved U.S. authorities and law-enforcement partners in Estonia, Hong Kong, and the Netherlands. In the announcement, Assistant Attorney General Lanny A. Breuer credited international cooperation, particularly between the United States and Estonia, with making the charges possible. The cross-border investigation reflected the alleged division between network intrusion, card production, and ATM cash-outs across multiple locations.
Rank #2
What the 2009 announcement did—and did not—establish
DOJ said the indictment sought criminal forfeiture of $9.4 million and described maximum penalties that could apply if defendants were convicted. A requested forfeiture is not proof that funds were ultimately forfeited, and maximum statutory penalties are not sentences. The sources cited here do not establish the complete later outcome of every defendant’s case.
Acting U.S. Attorney Sally Quillian Yates called it “perhaps the most sophisticated and organized computer fraud attack ever conducted.” That was her characterization at the time of the announcement, not an independently established ranking.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




