CASE FILE
INC-20070905-ICEMAN
2005 – SEP 2007
TLP:CLEAR
// Cyber Incident Case File — eCrime Carding Forum Consolidation & Mass Financial Data Theft (Subject of Kevin Poulsen's "Kingpin")

ICEMAN CARDING EMPIRE

COMPILED: 2026-08-29  |  INCIDENT DATE: 2005 (CardersMarket founded) to 2007-09-05 (arrest); sentenced 2010-02-12  |  SOURCES: U.S. DOJ · U.S. Secret Service · Kevin Poulsen's "Kingpin" (2011) · Wikipedia · The Register · NPR · Network World · 6+ additional press sources
Incident Type: eCrime — Carding Forum Consolidation / Mass Financial Data Theft
Attribution: MAX RAY BUTLER ("ICEMAN" / "MAX VISION") [HIGH — CONVICTED]
Severity: CRITICAL (Historical)
Era: Pre-ATT&CK / Early Organized Carding Era
ATT&CK Framework: Enterprise (Retrospective)
~2,000,000
Stolen Credit/Debit Card Records Trafficked
$86.4M
Estimated Fraudulent Charges Resulting From Stolen Data
13 Years
Prison Sentence — Longest-Ever US Hacking Sentence at the Time
6,000
Carding-Forum Members Absorbed in a Single-Night Takeover (Aug 2006)
00
Case File Overview
Attributed Actor → No companion actor card on file — single-perpetrator historical eCrime case; convicted individual (Max Ray Butler, aka "Iceman"), not a tracked MITRE G-ID or ongoing threat cluster
Incident NameThe Iceman Carding Empire (CardersMarket Consolidation & Mass Card Theft)
Date Range2005 (CardersMarket founded) – 2007-09-05 (arrest); pled guilty 2009; sentenced 2010-02-12
Incident TypeeCrime — Carding Forum Consolidation / Financial Data Theft
Primary ActorMax Ray Butler, legally Max Ray Vision ("Iceman," "Digital," "Aphex") — individual perpetrator, San Francisco, CA
Attribution ConfidenceHIGH — pled guilty; convicted on two counts of wire fraud
Primary TargetRival carding forums (DarkMarket, TalkCash, ScandinavianCarding, TheVouched); business/retail wireless networks; payment processors and financial institutions nationwide
Victim Count~2 million compromised card accounts across roughly 100+ US financial institutions; 6,000+ carding-forum members absorbed into CardersMarket
Initial DiscoverySecret Service and FBI separately investigated carding-forum activity through 2006–2007; "Iceman" was unmasked via an undercover investigation using a cooperating associate
Discovered ByU.S. Secret Service (lead), with FBI cooperation; informant/cooperating witness within Butler's own criminal network
Dwell TimeApproximately 2+ years of sustained criminal operation (2005 forum founding to Sept 2007 arrest) before law enforcement disruption
Primary ImpactConsolidation of the English-language carding underground into a single Butler-controlled marketplace; ~$86.4M in fraudulent charges; landmark 13-year sentence and $27.5M restitution order
ATT&CK FrameworkEnterprise (Retrospective) — predates ATT&CK's 2013 introduction; applied loosely given the fraud/marketplace nature of the case
MITRE Campaign IDNot catalogued — individual criminal prosecution, not a tracked APT group or campaign
Historical IOCsCardersMarket and the forums it absorbed have been offline since 2007; techniques are of historical/educational interest only
01
Situation Overview

Between 2005 and his arrest in September 2007, Max Ray Butler — a former "white hat" security researcher who had once served as an FBI informant — built and forcibly consolidated what became the largest stolen-credit-card marketplace on the internet, trafficking in roughly 2 million compromised card accounts and enabling an estimated $86.4 million in fraudulent charges. Operating under the alias "Iceman," Butler's story, later chronicled in journalist Kevin Poulsen's 2011 book Kingpin, remains one of the defining case studies of the transition from scattered, amateur "carding" forums to organized, monopolistic cybercrime marketplaces.

Butler's path to cybercrime was unusual: in the late 1990s he was a respected security researcher and, controversially, a confidential FBI informant, before a 1998 conviction for hacking U.S. Air Force and other federal networks — ironically, while attempting to "patch" a vulnerability he had found — sent him to federal prison for 18 months. Released in 2002 and unable to rebuild a legitimate career, Butler turned fully to the criminal underground, adopting the "Iceman" persona and, in June 2005, launching a carding forum called CardersMarket.

Butler's defining and most notorious act came on the night of August 16, 2006: rather than compete with rival carding forums, he simultaneously hacked into four of them — DarkMarket, TalkCash, ScandinavianCarding, and TheVouched — extracted their combined membership databases and years of private conversation histories, rendered the original sites inaccessible, and migrated everything into CardersMarket. Overnight, Butler's forum absorbed roughly 4,500 additional members, quadrupling to around 6,000 users and making him the de facto monopolist of the English-language carding underground — an act of criminal empire-building unprecedented in scale at the time.

Butler paired this technical dominance with a real-world cashing-out operation run in partnership with Christopher Aragon, a former bank robber, and was ultimately identified and arrested by the U.S. Secret Service in San Francisco on September 5, 2007. He pled guilty in 2009 and was sentenced in February 2010 to 13 years in federal prison — at the time the longest sentence ever imposed for hacking-related offenses in United States history — along with $27.5 million in restitution.

02
Background & Context

By the mid-2000s, "carding" — the trafficking of stolen payment-card data — had matured from informal IRC channels into structured web forums with reputation systems, escrow services, and vendor rankings, mirroring legitimate e-commerce. Competing forums frequently attacked one another in what participants called "hacking wars," attempting to steal rivals' member databases and reputational standing rather than cooperating, a dynamic Butler exploited more decisively and completely than any predecessor.

Widespread, poorly secured retail and small-business WiFi networks made wardriving-based intrusion — physically locating and exploiting open or weakly secured wireless networks to reach point-of-sale and payment systems — a viable technique for stealing card data at scale; Butler and his associates rented hotel rooms and used high-powered antennas to reach target networks from a discreet distance. Contemporaneous law-enforcement capability for tracking anonymized, forum-based criminal marketplaces was still developing, and payment-card issuers had not yet widely adopted the fraud-detection and network-segmentation practices that later became standard following high-profile breaches like TJX (2007) and Heartland Payment Systems (2008).

Butler's own history was itself a warning sign in hindsight — his 1998 conviction demonstrated both his technical skill and willingness to cross legal lines, and his difficulty finding legitimate work after release is described in retrospective accounts as a direct contributing factor in his return to crime. No specific law-enforcement intervention interrupted his 2005–2006 build-up of CardersMarket before it reached dominant scale.

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Post-Release Return to the Underground (2002–2005) BLIND
Following his 2002 release from federal prison, Butler struggled to find legitimate security work under his history, and by 2005 had fully adopted the "Iceman" persona, launching the CardersMarket forum in June 2005 as a venue for trading stolen card data.
Because this was a low-profile forum launch rather than an intrusion, it drew no law-enforcement attention at the time and gave Butler roughly a year to build initial infrastructure and reputation.
Mass Data Theft via Wireless Network Intrusion BLIND
In parallel with growing CardersMarket, Butler and associates conducted wardriving operations — renting hotel rooms near target businesses and using high-powered antennas to locate and exploit vulnerable WiFi networks — to breach point-of-sale systems and payment processors, harvesting card data that fed directly into his and his network's carding operations.
These intrusions targeted a broad, opportunistic set of small and mid-sized businesses rather than a single high-value target, making the campaign's true scope difficult for any single victim organization to detect or report.
Hostile Takeover of Rival Carding Forums (Aug 16, 2006) BLIND
In a single coordinated operation, Butler exploited security flaws in four rival carding forums — DarkMarket, TalkCash, ScandinavianCarding, and TheVouched — extracting their member databases and years of conversation archives, taking the original sites offline, and merging everything into CardersMarket. Membership quadrupled overnight from roughly 1,500 to 6,000, and Butler became the dominant hub of English-language carding.
This hostile takeover was highly visible within the criminal underground itself — the "hacking war" it triggered is documented as a contributing factor that later helped FBI Special Agent Keith Mularski establish trust and undercover access on the rebuilding DarkMarket community as "Master Splyntr," a separate FBI sting operation that took root later in 2006.
Cash-Out Operation With Christopher Aragon BLIND
Butler partnered with Christopher Aragon, a former bank robber and drug smuggler, to convert stolen card data into cash through counterfeit cards, gift-card purchases, and other real-world fraud schemes, extending the operation's impact from data theft into direct financial harm.
The real-world cash-out network created physical evidence and human intermediaries that were ultimately more vulnerable to traditional law-enforcement investigative techniques than Butler's technical operations alone.
Undercover Investigation & Identification VISIBLE — UNREVIEWED
The U.S. Secret Service, with FBI cooperation, built a case against Butler using a cooperating witness/informant within his own network, gradually connecting the "Iceman" persona to Max Butler's real identity and documenting the scale of stolen data and forum activity.
This investigative approach — infiltrating the human network around a technically sophisticated actor rather than attempting to out-hack him — proved decisive.
Arrest, Prosecution & Sentencing DETECTED
U.S. Secret Service agents arrested Butler in San Francisco on September 5, 2007. He pled guilty in 2009 to two counts of wire fraud, and on February 12, 2010, was sentenced to 13 years in federal prison plus five years of supervised release and $27.5 million in restitution — at the time the longest sentence ever handed down for hacking-related crimes in US history.
04
TTPs — MITRE ATT&CK Mapping Pre-ATT&CK incident (2005–2007); techniques are retrospective and adapted from a fraud/marketplace case, not a standard intrusion campaign
[RETROSPECTIVE]
Resource Development
T1583.001
Acquire Infrastructure: Domains
[HIGH] Registered and operated CardersMarket as consolidated criminal-marketplace infrastructure to host absorbed forum communities.
[RETROSPECTIVE]
Reconnaissance
T1595.002
Active Scanning: Vulnerability Scanning
[MEDIUM] Physically located and probed poorly secured retail/business WiFi networks (wardriving) to identify exploitable access points.
[RETROSPECTIVE]
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Exploited unpatched vulnerabilities in rival carding forums' web software to gain administrative access to their databases.
[RETROSPECTIVE]
Initial Access
T1078
Valid Accounts
[MEDIUM] Leveraged compromised or weakly secured wireless network access as a foothold into retail/business point-of-sale environments.
[RETROSPECTIVE]
Collection
T1005
Data from Local System
[HIGH] Extracted complete member databases, private-message archives, and forum content from four rival carding sites in a single operation.
[RETROSPECTIVE]
Collection
T1213
Data from Information Repositories
[HIGH] Harvested payment-card data from compromised payment-processing and point-of-sale systems reached via wireless intrusion.
[RETROSPECTIVE]
Exfiltration
T1041
Exfiltration Over C2 Channel
[MEDIUM] Removed stolen databases and card data from victim networks for consolidation into CardersMarket infrastructure.
[RETROSPECTIVE]
Impact
T1489
Service Stop
[HIGH] Rendered four competing carding forums permanently inaccessible to their original members as part of the takeover, effectively destroying rival platforms' operational continuity.
[RETROSPECTIVE]
Impact
T1657
Financial Theft
[HIGH] Monetized stolen card data through a real-world cash-out network, contributing to an estimated $86.4 million in fraudulent charges.
[RETROSPECTIVE]
Command & Control
T1102
Web Service
[LOW] Operated CardersMarket as an open web-forum marketplace rather than covert C2, facilitating ongoing data trading among a large criminal user base.
05
Defender Post-Mortem What was missed, when, and why
FORUM SECURITY &
WIRELESS EXPLOITATION
MISSED
Neither the rival carding forums nor the retail/small-business networks Butler wardrove into detected the underlying vulnerabilities before exploitation; the carding underground's forums were run by other criminals with limited security investment, and retail wireless networks of the era commonly used weak or default encryption.
HOSTILE TAKEOVER
PARTIALLY DETECTED
(WITHIN CRIMINAL COMMUNITY)
The August 2006 takeover was immediately obvious to the carding community itself — forums went offline and members found themselves migrated to CardersMarket — but this visibility existed entirely outside conventional law-enforcement or victim-organization detection channels, delaying any formal investigative response.
POST-INCIDENT
LESSON ADOPTED
The case became a template for subsequent U.S. Secret Service and FBI carding investigations (including the DarkMarket sting), demonstrating that infiltrating the human trust networks and cooperating-witness relationships around a criminal marketplace was more effective than attempting to technically out-hack a skilled individual operator.
SENTENCING PRECEDENT
LESSON ADOPTED
Butler's 13-year sentence — the longest hacking-related sentence in US history at the time — established a strong sentencing precedent for large-scale identity-theft and carding prosecutions, directly informing charging and sentencing strategy in subsequent major cases such as Albert Gonzalez's TJX/Heartland prosecutions.
06
Technical Artifacts Malware, tools, CVEs, IOCs
Wardriving Intrusion Methodology
Wireless Network Exploitation Technique [HISTORICAL — Limited detection utility]
Combination of physical reconnaissance (renting hotel rooms near targets) and high-powered directional antennas to locate and exploit inadequately secured business WiFi networks, providing a foothold into point-of-sale and payment-processing systems without requiring direct physical premises access.
CardersMarket Forum Platform
Criminal Marketplace Infrastructure [HISTORICAL — Offline since 2007]
Web forum launched June 2005 that, following the August 2006 consolidation, became the dominant English-language carding marketplace with roughly 6,000 members, functioning as an open trading venue for stolen card data, tutorials, and vendor reputation — a structural precursor to later, more operationally secure dark-web marketplaces.
Rival-Forum Database Extraction Toolset
Web Application Exploitation [HISTORICAL — Specific exploits undisclosed]
Exploited security flaws (specific vulnerabilities not fully disclosed in public reporting) in the web software running DarkMarket, TalkCash, ScandinavianCarding, and TheVouched to extract complete user databases and private-message archives in a single, simultaneous operation on August 16, 2006.
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling.
⚠ HISTORICAL IOCs — These artifacts are archival. Infrastructure has long since been dismantled. Use for research and retrospective analysis only.
TypeValue / DescriptionSourceDate
STAT~2,000,000 stolen credit/debit card records traffickedUS DOJ sentencing press release2010-02-12
STAT$86.4 million in estimated fraudulent chargesUS DOJ; press reporting2010-02
INFRACardersMarket[.]com (forum, offline since 2007)Wikipedia; contemporaneous press2005–2007
NOTEThis is a historical criminal-marketplace case rather than a technical intrusion campaign with preserved malware samples; no public malware hashes, C2 domains, or IP indicators have been published, since the operation centered on forum infrastructure and wireless network exploitation rather than deployed malicious code. Consult the US DOJ press releases and Kevin Poulsen's "Kingpin" (2011) for the fullest public accounting of the case's technical and investigative details.
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
Not a geopolitical incident, but the case is frequently cited in US law-enforcement and policy discussions of organized cybercrime as an early, clear demonstration that a single skilled individual could achieve marketplace-level dominance over a criminal financial ecosystem, informing later interagency task-force approaches (Secret Service Electronic Crimes Task Forces, FBI cyber squads) to carding and payment-fraud investigations.
⬡ Technical / Capability
Directly informed subsequent law-enforcement investigative technique, particularly the value of long-term undercover infiltration of criminal marketplaces — exemplified by the FBI's own DarkMarket sting under Special Agent Keith Mularski, which took root on the same forum ecosystem Butler had destabilized — over purely technical counter-hacking approaches.
⬡ Legal / Regulatory
Established a significant sentencing precedent — Butler's 13-year term was, at the time, the longest ever imposed in the US for hacking-related offenses — shaping prosecutorial and sentencing expectations in subsequent major identity-theft and carding cases, including the prosecution of Albert Gonzalez for the TJX and Heartland Payment Systems breaches.
08
Attribution
ATTRIBUTION CONFIDENCE: HIGH
Attributed ToMax Ray Butler, legally known as Max Ray Vision, aka "Iceman," "Digital," "Aphex"
SponsorNone — independent individual criminal actor; no state or organizational sponsorship
Formal AttributionFormally and conclusively established through guilty plea and federal conviction; not a disputed or inferred attribution
IndictmentsIndicted 2007 on wire fraud and identity theft charges; pled guilty 2009; sentenced 2010-02-12 to 13 years federal prison, 5 years supervised release, and $27.5 million restitution
Companion Actor CardNone on file — individual criminal case, not a tracked ongoing threat actor or MITRE Group
Primary EvidenceDirect forensic evidence recovered from Butler's own systems and CardersMarket infrastructure; cooperation/testimony from associates within his cash-out network; guilty plea removing any need for contested attribution
Competing HypothesesNone — this is one of the rare cases in this library with fully resolved, court-confirmed attribution rather than analytical inference
What Would Change AssessmentNot applicable — attribution is legally conclusive

Unlike most entries in this library, attribution for the Iceman/CardersMarket case is not an analytical judgment but a matter of public legal record: Max Ray Butler was identified, indicted, pled guilty, and was sentenced by a US federal court, with the underlying evidence — including his own systems, forum infrastructure, and cooperating-witness testimony — never seriously disputed. The case is included here not because attribution is uncertain, but because its investigative, technical, and legal legacy shaped how law enforcement and the security industry have approached organized cybercrime and carding-marketplace prosecutions ever since.

09
Historical Significance

The Iceman case is a foundational example in the study of organized cybercrime economics: Max Butler did not simply steal data, he forcibly consolidated a fragmented, competitive criminal ecosystem into a single dominant marketplace through technical force — a dynamic later echoed, in less violent forms, by the rise and fall of major dark-web marketplaces. It remains a core teaching case for understanding how criminal marketplaces achieve, and lose, market power.

The case's investigative resolution — infiltrating the human and financial network around a technically superior individual actor rather than attempting to counter-hack him — became a template subsequently used in larger operations, including the FBI's own DarkMarket sting (itself entangled with the same forum ecosystem Butler had destabilized) and numerous later carding-marketplace takedowns. It demonstrated that even highly capable technical adversaries typically retain real-world, human-network vulnerabilities that patient undercover investigation can exploit.

Legally, Butler's 13-year sentence — the longest ever imposed for hacking-related crimes in the US at the time — recalibrated expectations for how severely large-scale identity-theft and carding operations would be punished, directly informing the prosecutorial approach used against subsequent major carding figures like Albert Gonzalez. Chronicled in Kevin Poulsen's widely read 2011 book Kingpin, the case remains one of the most detailed publicly documented accounts of how an individual hacker's technical skill, criminal ambition, and personal history intersected to create outsized real-world financial harm — and how that harm was ultimately unwound.

10
References URLs are NOT defanged — navigate directly
Wikipedia
Accessed: 2026-08-29
US Secret Service
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2007-09
The Register
Accessed: 2026-08-29
The Register
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2001
The Register
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2001
The Register
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2000
Network World
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2009
Network World
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2010
ABC News
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2000
Wikipedia
Accessed: 2026-08-29
Wikipedia
Accessed: 2026-08-29
IPMall / DOJ
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2010