How a 16 year old hacked a bank & got €500K
How a 16 year old hacked a bank & got €500K
What where you doing when you were at the age of 15/16? Hanging out with friends? Discovering your identity? Maybe you was dedicated for your study, learning for your next exams. Most probably, you were doing something that kids are supposed to be doing (stereotyped) around that age. I wasn’t, however. I was in my room at my parents place hacking my way banks.
Why should I try to hack into banks and not just work at McDonalds like any other ‘normal’ kid would do? Simply because I could. At that time I had zero to none experience and no extended knowledge of what I was doing. I just did it and tried to figure out along the way how to perfect my hacking skills. Working at McDonalds doesn’t make you special and I had the urge to create a key position where people would want to work with me in the near future instead of standing in a line of people with your hopes up that someone would see that you are qualified enough in what you do.
If you follow the crowd, you will likely get no further than the crowd. If you walk alone, you’re likely to end up in places no one has ever been before. Being an achiever is really not without its difficulties, for peculiarity breeds contempt.
My computer became my best friend spending at least 10 to 18 hours a day with it trying to crack the systems. For weeks I barely left the house and even ‘forgot’ to eat. I became extremely obsessed, but I failed time after time. Computer systems are created to be smarter than you so when you try to get access the system automatically will close the gaps. But then, after 9 weeks of struggling and physical suffering, I suddenly had a big break through. I was overthinking the problems that I was facing so I couldn’t see the solutions that I needed. We tent to be set in various ways, bound by our perspectives and stuck in our thinking. When you manage to let that go, you can once again see the world (and the challenge you are facing) once again from a bright and sunny perspective.
There is a saying: “If the Mountain won’t go to Mohammed, then Mohammed must come to the Mountain”
I was stuck because I didn’t knew how to locate the right servers that they were using. The systems always managed to re-routed my traces to the the public servers, but I needed the servers where the ABN Amro stored their client information. I created a fairly simpel virus which would ping information to me once it connects to any PC with an active internet connection. I placed the virus on a USB drive and I placed a sticker on the USB with the letters ‘XXX‘. Assuming that there could be pornography stored on the drive. At 06:00 AM in the morning I went to the head office of the ABN Amro in Amsterdam and I threw the USB drive in front of the entrance of the (employee) parking garage. From that moment it was within 3 hours that I already received a ping (signal) back. Someone actually fell for my trick and plugged the bugged USB drive in their work computer. With just one simple trick I had access to their systems which allowed me to proceed.
When I got access to the client mainframe I almost immediately found several bugs and possible exploits. When any payment was processed by this bank, there was a millisecond where there was a data transaction from one server to another which was processed by, what they call, an ‘open port’. Knowing and understanding how the payments are handled by the systems of the ABN Amro, and knowing that there was an open port and where to find it, I was able to intercept any payment quite easily and reroute them to a bank account of my own. (Which I didn’t, just to be clear 🤓)
After I found these flaws, I started to write a full report of my findings and all possible errors of the bank.
I wrote about the employee concerning the USB Drive and the systems with their open ports and possible damage it could cause and I stepped on the first train and went to the head office of the ABN Amro in Amsterdam. I walked to the reception and demanded, with my first slamming on their desk, that I could speak with someone from the managing board. I choose for this ‘bad-ass’ approach, which was far away from my comfort zone, because otherwise I was afraid that they would just send me away, laughing at me, since they would see me as some random whipster just making a fuss about something that they really didn’t understand.
After a while they figured that which direction I wanted to go and I was able to speak with someone from their IT department. When I explained what I did and why I was there this guy became to the realisation that it would become an responsibility issue, since he was working for their IT department, It was within less than 30 minutes to place me at a table with someone of the managing board. I told my story and what I actually did with there systems, sweating my ass off since I knew that they could work with me or they would have me arrested by the police since I had no authorization to do what I did.
Fortunately for me they choose for the easy way and the same day they offered me a very generous contract of €500.000,00 to fix all the problems that I found and to make an similar inventarisation of the major parts of their systems. They also made me sign an NDA so I can’t really tell more juicy facts about this.
That was the moment that the Nouveau Riche Group ‘was born’. Now already more than 10 years ago. Since than I became a dedicated full time hacker offering solutions to companies and individuals. Until this day I still love what I am doing and I have the same passion to succeed in every project that I work on like it’s my first day on the job.
