Justin Sean Johnson, a 30-year-old from Detroit, Michigan, pleaded guilty to stealing the personally identifiable information (PII) of 65,000 employees of the University of Pittsburgh Medical Center (UPMC)and selling it on the dark web.
UPMC is Pennsylvania's largest healthcare provider , employing more than 90,000 employees, across 40 hospitals and 700 practices.
Read also: Deep and Dark Web: How will you dive into the dark parts of the web?

Johnson ( also known on the dark web as "TheDearthStar" or "Dearthy Star") is accused of conspiracy, wire fraud, and identity theft, and faces 43 charges filed in May 2020.
Scott Brady, U.S. Attorney, said in a press release issued in June 2020, following Johnson’s arrest, the following: “Justin Johnson is accused of stealing the names, Social Security numbers, addresses, and payroll information of every employee of Pennsylvania’s largest healthcare system. Following his breach, Johnson sold the PII of UPMC employees to buyers around the world on “dark” online marketplaces, who in turn engaged in a massive campaign of further fraud and theft.”
Johnson initially breached UPMC's HR database network in early December 2013 , hacking into the company's Oracle PeopleSoft human resources management system. On the same day, he gained access to the PII of approximately 23,500 UPMC employees after running a test query on the compromised HR database.

Between January 21 and February 14, 2014, he continued to access the database multiple times a day remotely, to infiltrate the PII of tens of thousands of UPMC employees.
See also: FBI analyst charged with stealing counterterrorism documents
The 30-year-old sold the stolen data on "dark" Internet marketplaces, such as Evolution and AlphaBay Market.
In addition to selling the PII of approximately 65,000 employees from UPMC's compromised HR databases, Johnson also stole and sold nearly 90,000 additional sets of PII (outside of UPMC) between 2014 and 2017, which were likely used by the buyers to commit identity theft and bank fraud.
Johnson faces a maximum sentence of five years in prison and a fine of up to $250,000 for conspiracy to defraud the U.S., as well as a mandatory sentence of two years in prison and a fine of up to $250,000 for each count of identity theft.

According to a press release from the U.S. Department of Justice (DoJ), the investigation that led to Johnson's prosecution was conducted by agents from the Internal Revenue Service-Criminal Investigation, the U.S. Secret Service, the U.S. Postal Inspection Service, and the Homeland Security Investigations (HSI).
Proposal: Police arrested eight suspects for smishing scams!
Johnson remains in custody awaiting trial.
"Hackers like Johnson should know that our office will relentlessly pursue you until you are taken into custody and held accountable for your crimes," U.S. Attorney Brady said last year.
Finally, Timothy Burke, a U.S. Secret Service agent, said: “The healthcare sector has become an attractive target for cybercriminals looking to steal personal information to use in fraud. The Secret Service is committed to identifying and apprehending those involved in crimes against our Nation’s critical systems for their own profit.”
Information source: bleepingcomputer.com
