Subway restaurant hacker sentenced to 21 months

A Romanian hacker, who pleaded guilty to compromising the credit card processing systems of Subway restaurants in 2011, has been sentenced to 21 months in prison.

On Monday, a U.S. District Court judge in New Hampshire sentenced 27-year-old Cezar Butu after he pleaded guilty on Sept. 17, 2011 to one count of conspiracy to commit access device fraud.

Butu was one of four Romanian hackers charged with remotely hijacking credit card processing systems of more than 150 Subway restaurants, as well as other retailers in the United States, which resulted in more than $10 million in losses, according to federal prosecutors.

A news release from the U.S. Department of Justice detailed the admission from Butu, saying that from 2009 to 2011, he participated in a Romanian-based conspiracy, which involved hacking into hundreds of U.S.-based point-of-sale (POS) systems to steal consumers' financial information. 

Prosecutors said Butu also attempted to sell, or otherwise transfer, the stolen payment card data to other co-conspirators. As well, he admitted to gathering payment card data belonging to approximately 140 cardholders over the course of his spree.

Butu and co-conspirators scanned the internet to identify vulnerable POS systems, then logged in to the targeted devices either by guessing the passwords or using password-cracking programs, according to prosecutors. They then installed keyloggers on the systems to record any data keyed into or swiped through the machines. The recorded data was electronically transferred back to the attackers' servers.

Other co-conspirators in the case include Iulian Dolan, who pleaded guilty to charges and consented to a seven-year prison sentence as part of a plea agreement. His is scheduled to be sentenced April 4. 

Adrian-Tiberiu Oprea, who has not pleaded guilty, is scheduled to be tried Feb. 20 in U.S. District Court in New Hampshire. The fourth man suspected of involvement, Florin Radu, remains at large.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.