{
  "id": "case-max-vision-cardersmarket",
  "slug": "us-v-vision-cardersmarket",
  "title": "U.S. v. Max Ray Vision (Iceman / CardersMarket)",
  "summary": "Former white-hat computer security analyst turned master cybercriminal who operated CardersMarket, hacking rival criminal forums to steal their user databases and monopolize illicit credit card trafficking.",
  "case_number": "3:07-cr-00624",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2007-09-10",
  "status": "sentenced",
  "victim_sector": "Financial Services, Retail",
  "victim_country": "United States",
  "loss_amount_usd": 86000000,
  "loss_amount_note": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges.",
  "first_seen_at": "2004-01-01T00:00:00Z",
  "last_updated_at": "2026-07-28T14:00:00Z",
  "actor_slug": "cardersmarket",
  "defendant_slugs": [
    "max-vision"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vision",
      "source_url": "https://www.justice.gov/archive/criminal/cybercrime/press-releases/2010/visionSent.pdf",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2007-09-08",
      "description": "Vision arrested at his San Francisco apartment by federal agents."
    },
    {
      "event_type": "plea",
      "event_date": "2009-06-29",
      "description": "Pleads guilty to two counts of wire fraud conspiracy."
    },
    {
      "event_type": "sentencing",
      "event_date": "2010-02-12",
      "description": "Sentenced to 168 months (14 years) in federal prison and ordered to pay $27.5 million in restitution."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
    "blast_radius": "Stole approximately 2 million credit card numbers, causing $86 million in fraudulent charges. Impacted Financial Services, Retail infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts.",
        "technical_artifacts": [
          "T1190",
          "Exploit Public-Facing Application"
        ],
        "mitre_technique_id": "T1190"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}