Story of Vietnamese hacker “Hieupc”, who was earning $125K/month running a bustling identity theft service, and was recently released from prison
At the height of his cybercriminal career, the hacker known as “Hieupc” was earning $125,000 a month running a bustling identity theft service … Tweets: @reybango , @briankrebs , @mattotcha , @dstrom , @briankrebs , @rogeragrimes , @secrecon , and @hocsinc Tweets: Rey Bango / @reybango : “When I was running the service, I didn't really care because I didn't know my customers and I didn't know much about what they were doing with it” I feel like this is how most cybercriminals think. They're only hurting big corps or rich people. 🙄 https://krebsonsecurity.com/ ... @briankrebs : Confessions of an ID Theft Kingpin, Part II. In re: customers: “Buying identities is so much better than stolen payment card data, which can be used once or twice before they're no good anymore. But identities can be used over and over for years.” https://krebsonsecurity.com/ ... Matt Willemsen / @mattotcha : 26 Confessions of an ID Theft Kingpin, Part I - At the height of his cybercriminal career, the hacker known as “Hieupc” was earning $125,000 a month running a bustling identity theft service https://krebsonsecurity.com/ ... @dstrom : The backstory of jailed Vietnamese hacker Hieu Minh Ngo, who has caused more financial harm to more Americans, and recently released from prison, tells his story to Krebs: https://krebsonsecurity.com/ ... @briankrebs : “I don't know of any other cybercriminal who has caused more material financial harm to more Americans than Ngo,” the Secret Service's Matt O'Neill said of Hieu Min Ngo, just released after 7 years in prison. Confessions of an ID Theft Kingpin, Part I: https://krebsonsecurity.com/ ... Roger A. Grimes / @rogeragrimes : Great part I story of a Vietnamese identity hacker who at one time had 99% of everyone in the US's identity in just one of his many databases. He charged $1 for anyone to find any record. https://krebsonsecurity.com/ ... ReconSecureComputing / @secrecon : Confessions of an ID Theft Kingpin, Part I: after more than seven years in prison, “Hieupc” (Hieu Minh Ngo), is back in his home country & hoping to convince other would-be cybercrooks to use their computer skills for good. Krebs on Security https://krebsonsecurity.com/ ... @hocsinc : https://krebsonsecurity.com/ ... Fascinating look at the activities of a not famous but very effective hacker. Personally identifiable information (PII0 NEEDS to be protected with multi-layer security #CyberSecurity #ITInfrastructure
Context & Ripple Effects
In 2015, Hieu Minh Ngo drew a 13-year US sentence for running an identity theft service that touched some 200 million Americans — the case that made him the Secret Service's benchmark for financial harm. This piece is Brian Krebs' retrospective on that operation and its aftermath, part of the long arc of Krebs' two decades profiling the worst cybercriminals documented in the recent WSJ profile.
What makes the story durable is the business model: a database covering roughly 99% of US residents, sold one record at a time for $1. Ngo has now been released after serving about seven years, closing the loop on the case while the service model he pioneered lives on elsewhere.
First-order effects
- Ngo walks free having served roughly half his sentence, while the Secret Service still credits him with more material financial harm to Americans than any other cybercriminal it tracks.
- His own account — that he never knew what customers did with the data he sold — now stands as a first-person confession about how little visibility even top-tier data brokers have into downstream abuse.
Second-order effects
- The $1-per-lookup resale model he ran is recognizably the ancestor of today's access-broker scene, where groups like The Com feed stolen credentials into extortion operations such as those linked to Scattered Spider.
- The case shows the same supply chain recurring in newer prosecutions: Jesse Kipf sold access to systems he broke into, and Lin Rui-siang allegedly ran a $100M+ dark-web market — each monetizing intrusion the way Ngo monetized identity records.
Third-order effects
- When operators sit outside US jurisdiction, sentences function mainly as deterrence theater: a 13-year term cut to about seven years did not dismantle the market for stolen identities, only removed one seller.
- If the pattern holds, enforcement pressure shifts from prosecuting individual brokers to attacking the underlying trade in personal data itself — the boundary between 'public' records and sellable identity is where regulators keep arriving late.
The trend: Cybercrime keeps consolidating into offshore, as-a-service marketplaces that resell personal data and system access at retail prices, outpacing the reach of US prosecution.