A Russian hacker was sentenced Thursday to 12 years in prisonafter pleading guilty breaches data consumer U.S., stealing data from more than a dozen U.S. companies and information on more than 100 million American consumers.

The hacker is named Andrei Tyurin, he is 37 years old and was sentenced in Manhattan federal court after pleading guilty to hacking , bank fraud and illegal online gambling.
Prosecutors say the Russian hacker is involved in the theft of the personal data of about 80 million JP Morgan Chase customers.
In addition, it is said to have targeted financial institutions, brokerage firms , and financial news publishers, including the Wall Street Journal in the United States, from 2012 to mid-2015. attacks resulted in the theft of personal information of approximately 100 million customers of the targeted companies.
According to authorities, Tyurin operated from his home in Moscow, amassing over $19 million from his businesses. His infrastructure spanned five continents, allowing him to carry out successful attacks in many locations.
A US government spokesman said the Russian hacker “played a significant role in orchestrating and facilitating an international hacking campaign that led to one of the largest thefts of US customer data from a single financial institution.”
In court documents, Tyurin's lawyer, Florian Miedel, wrote that Tyurin only received $5 million, as promised to him by another "associate" who relied on Tyurin to get names and information to find customers for his illegal online gambling business.

The lawyer asked for leniency for his client, saying the Russian hacker never stole money through hacking.
In a letter to the judge, Tyurin said he “felt great shame” for the personal information he stole online and that he recognized that he “chose the wrong path in life.” He also wrote that he has changed since the birth of his daughter (four years ago), whom he now cannot see.
On the other hand, prosecutors argue that both the Russian hacker and his partner in the illegal gambling operation were primarily concerned with being detected rather than morally responsible for the use of the stolen data.
Prosecutors proposed a stiff sentence, citing the difficulty of arresting someone operating from such a distance.
Source: Securityweek
