Vietnamese hacker running online identity theft service affecting 200M Americans sentenced to 13 years
Brian Krebs / Krebs on Security :
Context & Ripple Effects
The 13-year sentence closes out an arc that began in March 2015, when the Justice Department charged two Vietnamese citizens and a Canadian with siphoning more than a billion email addresses from email providers. Krebs' reporting identifies the operator as "Hieupc", who by the time of his later profile was running an identity theft service grossing $125K a month before his arrest.
The sentence lands in a stretch where US courts have been ratcheting up punishment for foreign hackers: Romanian hacker Marcel Lehel Lazar drew 52 months for aggravated identity theft in 2016, and Russian hacker Roman Seleznev received a record 27-year sentence in 2017 for selling stolen card numbers tied to over $170M in losses.
First-order effects
- Hieupc's identity theft service — which touched some 200 million Americans — is decapitated, cutting off its buyer base from a proven supply of stolen personal data.
- The 200 million affected Americans remain exposed regardless of the conviction, since the stolen identities were already sold and monetized through the service.
Second-order effects
- Demand does not disappear with the vendor: buyers migrate to rival underground markets, consolidating traffic around whoever can match the reliability that made the service worth $125K a month.
- For prosecutors, the escalating benchmark matters: Seleznev's 27 years and now this 13-year term give federal judges a rising reference range for cross-border data theft prosecutions.
Third-order effects
- If the sentencing trajectory holds — months-long terms for single-target hackers giving way to decade-plus terms for service operators — prison exposure itself becomes a priced-in cost of running large-scale identity theft platforms, pushing operators further toward jurisdictional arbitrage.
- The case reinforces a structural split in enforcement reach: US-based defendants like former NSA employee Nghia Hoang Pho serve shorter terms for classified-data leaks, while foreign-run theft services draw the harshest sentences, shaping where large-scale operations choose to locate.
The trend: US sentencing for foreign-run cybercrime services is escalating from single-digit to decade-plus prison terms, turning punishment severity into the main deterrent lever against cross-border identity theft operations.