Darket Diaries
Darket Diaries

162: Hieu

All Hieu Minh Ngo wanted was to make money online. But when he stumbled into the dark web, he found more than just opportunity, he found a global dark market. What started as a side hustle turned into an international crime spree. Find Hieu on X: https://x.com/HHieupc.Sponsors Support for this show

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: The episode traces Vietnamese hacker Hyu Mingo’s path from teenage curiosity and credit-card theft to building a lucrative identity-search business by abusing U.S. data brokers and reselling access to criminal customers. It examines the blurry line between illegal hacking, data brokerage, and surveillance, while arguing the CFAA was used to punish access-rule violations more than the downstream harms. The story ends with his prison sentence, release, and later shift to cybercrime prevention.

Main Topics: Early hacking and first offenses (Priority: 5/5): Hyu describes growing up in Vietnam, discovering computers through curiosity, then stealing dial-up internet accounts as a teen because internet access was expensive. This led to his first legal trouble and pushed him toward deeper hacking. Underground forums and escalation into credit-card theft (Priority: 5/5): He learned from hacker forums, used tools like Google dorks, SQL injection, and default-password attacks, then moved into stealing credit card data from vulnerable e-commerce sites and laundering funds through online poker chip dumping. Transition from card theft to identity brokerage (Priority: 5/5): After moving to New Zealand and then back to Vietnam, he pivoted from credit cards to U.S. personal data, motivated by easier sales and lower perceived risk. He targeted data brokers like Locate Plus, MicroBuild, and Court Ventures. Data broker access, impersonation, and monetization (Priority: 5/5): Hyu used phishing, stolen logins, and impersonation to gain access to private-investigator tools and APIs, then built websites that sold identity lookups to criminals. The episode emphasizes that he was effectively reselling access to already-collected data. Legal case, CFAA, and what counts as harm (Priority: 4/5): The host argues the prosecution focused on CFAA-based unauthorized access and terms-of-service violations, not the actual downstream tax-refund fraud. The episode questions whether data brokers, not Hyu, were the larger privacy violators. Arrest, prison, and rehabilitation (Priority: 4/5): Hyu was lured to Guam, arrested by U.S. authorities, extradited through multiple prisons, pleaded guilty in 2015, and was sentenced to 13 years. He was released in 2020, later worked in Vietnamese cyber defense, and now helps fight cybercrime.

Key Arguments: Hyu’s early hacking was driven by curiosity and access barriers, not initially by profit; the expensive, slow internet in Vietnam helped trigger his first thefts. Once he realized vulnerable websites and stored card data were abundant, he could industrialize theft using scanners, SQL injection, and automated tooling. Online poker sites enabled chip-dumping laundering, turning stolen card data into cash with relatively low friction in the late 2000s. Data brokers aggregate highly sensitive personal information and sell it under restricted access models, creating a surveillance ecosystem that is legal but deeply invasive. The episode argues that the real victims are often the data brokers and the people whose information is exposed, but the prosecution charged Hyu mainly for unauthorized access under the CFAA. The host criticizes the CFAA for turning website terms-of-service violations into federal crimes, citing broader concerns about overcriminalization and the Aaron Swartz precedent. Hyu’s business worked because he was effectively a reseller of data broker queries, not the direct perpetrator of every downstream identity-fraud abuse. His later remorse and work with law enforcement suggest partial rehabilitation and an attempt to undo harm by helping victims and hunting cybercriminals.

Data Points: Age of first hacking activity: 14–15 years old - Hyu says he began hacking as a teenager out of curiosity about the internet. Year of first major internet theft: Around 2004 - He stole dial-up ISP accounts when 56K modems and metered internet were common. Reported damage from stolen internet accounts: $5,000 - The paperwork sent to his home stated he caused $5,000 in damage. Age during e-commerce card theft: 17–18 years old - He and a collaborator hacked e-commerce sites while still in high school. Daily stolen card volume: 50 to 100 credit cards per day - He described a website supplying a constant stream of stolen cards. Card resale price: Visa/MasterCard: $0.50; American Express/Discover: $1–$3 - He sold bulk card data on underground forums at very low prices because supply was huge. Weekly/monthly search pricing: $1 per search on his site; $0.14 per search to Court Ventures - He resold data broker lookups at a markup through his own website. First week revenue from identity-search site: $5,000 - His site generated immediate revenue after launch. Monthly revenue peak: More than $120,000 per month - He says the identity-search business produced this amount at its peak. Monthly payment to Court Ventures: $20,000 to $35,000 per month - He paid the broker for API-based lookups while reselling them at a markup. Total profit from identity sales: More than $3 million - He claims to have made this over roughly two years, 2010–2012. Identity volume sold: More than 3 million U.S. identities - He says this was the scale of searches/resales through his website. Data broker account count: More than 5,000 accounts - He cycled through many stolen or impersonated accounts on MicroBuild alone. Size of API-accessed identity pool: Almost 200 million U.S. identities - He says Court Ventures gave him access to a very large database via API. Reported damage in prosecution: Over $60 million - The prosecutors alleged he caused this amount in damage. Potential prison exposure: Up to 45 years - His lawyers warned him he could face this if convicted at trial across combined charges. Sentence: 13 years in prison - He pleaded guilty in 2015 and was sentenced to 13 years. Actual time served: 7 years - He was released in 2020 for good behavior after serving about seven years. Amount lost when Liberty Reserve was seized: Over $300,000 - He says funds he had saved there were lost when the service was taken down. Money remaining on return to Vietnam: A little more than $50,000 and one apartment - He says this was what he had left after release. Number of cybercriminals arrested with his help: More than 200 - He says he has assisted Vietnamese and other law enforcement agencies since returning home.

Pivotal Quotes: "I was started to be a hacker when I was very young, maybe around fourteen, fifteen years old." — Hyu Mingo: He explains the origin of his interest in hacking and how it began with curiosity. "I feel like, you know, I owe a lot to the people, especially the people in the U.S. I kind of hurt and harm so many people's lives." — Hyu Mingo: He reflects on remorse after prison and his view of the harm caused by his actions. "If you violate a website’s terms of use should not be a federal crime." — Jack Rhysider: The host’s critique of the CFAA and how the case was prosecuted.

Implications: The episode highlights how surveillance-driven data markets can be abused, while exposing how broad computer-crime laws can criminalize access-rule violations more than real-world harm. It suggests privacy erosion, data broker opacity, and weak security are systemic risks, not just one hacker’s story.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries