Max Butler
Max Ray Vision (formerly Max Ray Butler, alias Iceman) is a former computer security consultant[1] and hacker who served a 13-year prison sentence, the longest sentence ever given at the time for hacking charges in the United States.[2] He was convicted of two counts of wire fraud, including stealing nearly 2 million credit card numbers and running up about $86 million in fraudulent charges.[3]
Early life
[edit]Butler was born on 10 July 1972,[4][5][6] and grew up in Meridian, Idaho with a younger sibling; his parents divorced when he was 14.[5] His father was a Vietnam War veteran and computer store owner who married a daughter of Ukrainian immigrants.[7] As a teenager, Max Butler became interested in bulletin board systems and hacking.[5] After a parent reported a theft of chemicals from a lab room at Meridian High School, Butler pleaded guilty to malicious injury to property, first-degree burglary, and grand theft. Butler ultimately received probation for his crimes. He was sent to live with his father and he transferred to Bishop Kelly High School.[8]
First offense
[edit]Butler attended Boise State University for a year.[9] In 1991, Butler was convicted of assault during his first year of college.[5] His appeal was unsuccessful on procedural grounds, as a judge ruled that Butler's defense attorney did not raise the issue in an earlier appeal. The Idaho State Penitentiary paroled Butler on 26 April 1995.[10]
Professional and personal life
[edit]Butler moved with his father near Seattle and worked in part-time technical support positions in various companies. He discovered Internet Relay Chat and frequently downloaded warez, or illegally downloaded software or media. After an Internet service provider in Littleton, Colorado traced Butler's uploads of warez to an unprotected file transfer protocol server –the uploads were consuming excessive bandwidth–to the CompuServe corporate offices in Bellevue, Washington, CompuServe fired Butler.[11]
After moving to Half Moon Bay, California, he changed his last name to Vision and lived in a rented mansion "Hungry Manor" with a group of other computer enthusiasts.[12] Butler became a system administrator at computer gaming start-up MPath Interactive.[13] The Software Publishers Association filed a $300,000 lawsuit against Butler for engaging in unauthorized distribution of software from CompuServe's office and later settled the case for $3,500 and free computer consulting.
After marrying Kimi Winters, he moved to Berkeley, California, and worked as a freelance pentester and security consultant. During this time, he developed 'an online community resource called the "advanced reference archive of current heuristics for network intrusion detection systems," or arachNIDS.'[14]
FBI investigation, guilty plea, and sentencing
[edit]In the spring of 1998, Butler installed a backdoor onto American federal government websites while trying to fix a security hole in the BIND server daemon. However, an investigator with the United States Air Force found Butler via pop-up notifications.[15] He hired attorney Jennifer Granick for legal representation after hearing Granick speak at DEF CON. On 25 September 2000, Butler pleaded guilty to gaining unauthorized access to Defense Department computers.[4] Starting in May 2001, Butler served an 18-month federal prison sentence handed down by US District Judge James Ware.[16]
After his release from prison in 2003 on supervised release, Butler exploited Wi-Fi technology to commit cyberattacks anonymously along with Chris Aragon from San Francisco.[17] He advanced to programming malware, such as allowing the Bifrost Trojan horse to evade virus scanner programs and exploited the HTML Application feature of Internet Explorer to steal American Express credit card information.[18] Butler also targeted Citibank by using a Trojan horse towards a credit card identity thief and began distributing PINs to Aragon, who would have others withdraw the maximum daily amount of cash from ATMs until the compromised account was empty.[19]
Arrested in 2007, Butler was accused of operating CardersMarket, a forum where cyber criminals bought and sold sensitive data such as credit card numbers. After pleading guilty to two counts of wire fraud, stealing nearly 2 million credit card numbers, which were used for $86 million in fraudulent purchases, Butler was sentenced to 13 years in prison, which was the longest sentence ever given for hacking charges in the United States of America at the time.[20] After prison, Butler will also face 5 years of supervised release and is ordered to pay $27.5 million in restitution to his victims.[3][21]
Aftermath
[edit]In 2018 Butler was charged with running drone-smuggling ring from jail. The indictment states that in October 2014 he obtained an illicit cell phone and allegedly used it to obtain stolen debit card numbers from the internet, through which he stole money that he paid out to fellow inmates.[22]
Prosecutors say that a former cellmate named Jason Dane Tidwell stayed in touch with Butler via an encrypted messaging app and that, in the spring of 2016, Butler allegedly told Tidwell to buy a remotely piloted drone with some of the debit card scam proceeds to delivery contraband by airdrop. An inmate informed on the scheme, but guards never managed to find the contraband. One inmate, Phillip Tyler Hammons, confessed to retrieving airdrops, and he fingered Butler as the mastermind behind the plan. Butler claims that it was Hammons who behind the whole scheme.[22]
Butler was released from FCI Victorville Medium 2 on 14 April 2021.
Butler's story was featured in an episode of the CNBC television program American Greed in 2010.[23]
References
[edit]- ^ "Case File: Cybercrime: Max Butler". CNBC. Retrieved 28 October 2010.
- ^ ""Iceman" Computer Hacker Receives 13-Year Prison Sentence". FBI. Retrieved 28 September 2017.
- ^ a b Mills, Elinor. "'Iceman' pleads guilty in credit card theft case". CNET News. Retrieved 25 September 2010.
- ^ a b Evans, Will (27 September 2000). "Berkeley Hacker Admits To Government Infiltration". The Daily Californian. Retrieved 4 March 2011.
- ^ a b c d Poulsen, Kevin (22 December 2008). "One Hacker's Audacious Plan to Rule the Black Market in Stolen Credit Cards". Wired. Retrieved 4 March 2011.
- ^ U.S. Public Records Index Vol 1 (Provo, UT: Ancestry.com Operations, Inc.), 2010.
- ^ Poulsen, Kevin (2011). Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground. Crown Publishers. p. 2. ISBN 978-0-307-58868-5.
- ^ Poulsen, pp. 4–5.
- ^ "Computer Hacker Masterminds". American Greed. CNBC. 5 May 2010.
- ^ Poulsen 2011, p. 15.
- ^ Poulsen 2011, p. 16.
- ^ Poulsen 2011, pp. 14, 16.
- ^ Poulsen 2011, p. 17.
- ^ "McGraw Hill – Intrusion Detection and Prevention". Intrusion Detection and Prevention. McGraw Hill/intrusion-detect.com. Archived from the original on 13 July 2011. Retrieved 16 March 2011.
- ^ Kevin Poulsen (9 May 2001). "Whitehat hacker made FBI patsy Sleep with dogs, wake with fleas..." The Register. Retrieved 11 December 2018.
- ^ Delio, Michelle (22 May 2001). "A 'White Hat' Goes to Jail". Wired. Retrieved 16 March 2011.
- ^ Poulsen 2011, pp. 68–71.
- ^ Poulsen 2011, pp. 80–84.
- ^ Poulsen, pp. 101–104.
- ^ "Record 13-Year Sentence for Hacker Max Vision". Wired. ISSN 1059-1028. Retrieved 4 January 2021.
- ^ McMillan, Robert. "Hacker Iceman gets record 13 year sentence". Retrieved 28 October 2010.
- ^ a b Poulsen, Kevin (1 December 2018). "Feds Say Imprisoned Hacker Ran a Drone Smuggling Ring". The Daily Beast. Retrieved 5 June 2024.
- ^ American Greed: Cybercrime: Max Butler. Cnbc.com (3 May 2010). Retrieved on 2013-09-27.
Further reading
[edit]- Kevin Poulsen, Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground, 2011, publisher: Crown. ISBN 0-307-58868-8
- Misha Glenny, DarkMarket: How Hackers Became the New Mafia, 2012, publisher: Vintage. ISBN 0307476448