CASE DOSSIER sentenced

U.S. v. Max Ray Vision (Iceman / CardersMarket)

Docket: 3:07-cr-00624 Court: U.S. District Court for the Northern District of California Opened: 2007-09-10 Sector: Financial Services, Retail

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$86.0 million
Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Financial Services, Retail.
  • Documented Financial Loss: $86.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Exploit Public-Facing Application. Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.

Operational & Financial Fallout

Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges. Impacted Financial Services, Retail infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Exploit Public-Facing Application. Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1190 →

Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.

Artifacts & Tooling: T1190 Exploit Public-Facing Application
Real-World Blast Radius & Operational Fallout

Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges. Impacted Financial Services, Retail infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2007-09-08 arrest

Vision arrested at his San Francisco apartment by federal agents.

2009-06-29 plea

Pleads guilty to two counts of wire fraud conspiracy.

2010-02-12 sentencing

Sentenced to 168 months (14 years) in federal prison and ordered to pay $27.5 million in restitution.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Max Ray Vision United States sentenced 168 mo None Operator of CardersMarket carding forum; sentenced to 14 years in federal prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts." Indictment ¶ 14, Page 7 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Max Ray Vision (Iceman / CardersMarket), No. 3:07-cr-00624 (U.S. District Court for the Northern District of California 2007), https://cybercaselibrary.com/cases/us-v-vision-cardersmarket/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-vision-cardersmarket" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>