How A Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist
nytimes.comOne question, how did they know which specific servers to take? That would've required some interesting research / espionage ahead of time, but the article didn't mention that part of the job.
Yes, I was wondering exactly that. Would the mysterious bankers who tasked 'Ray' with this job even know the physical location of the servers in the data centre? I'd like more information about these 'technicians' as well. Splitting 250k four ways does not seem like a huge payoff for something that could have gone so wrong in so many ways.
It’s kind of a fun story but it doesn’t make sense. Was that the only data in a data center in the world that’s not backed up elsewhere? Did I miss that part?
Your confusion doesn't make any sense. The point was to steal a copy of the data, not prevent the original owners from having the data any more.
> The bankers “were involved in prime mortgages” and had “circumnavigated” certain regulations.
> Ellis’s assignment was to break into the data center and steal around 80 servers that hosted the incriminating files
The hit was contracted by the bankers who broke the law. Why would they need a copy of the evidence?
If the goal was to know what the prosecution has on them they took the worst route. Hiring petty criminals to steal the damn servers and giving them more details than they need to know is a stupid idea. Instead of hacking the data out of the servers (which would have been even easier in 2007), you now have a trail of inconvenient witnesses who can't wait to spill the secrets for a lighter sentence. He might have been just a decoy for something bigger.
The story smells like a book promotion and a petty criminal further bolstering a high profile (but stupid) robbery.
As noted by others, it is indeed a book promotion [1] The "petty criminal" has himself published a series of books [2]
However I take issue with your argument with "hacking would have been easier". DCs in the 2000s were (and to a large extent, still are) extremely easy to access. If the data at stake were actual "banking" data, in the 00s, it could have been still largely "air-gapped" (in the loose sense) from the internet. Hacking would have required a lot of lateral movement. And experts.
Hence, a large trail. Arguably larger than "hey bobby, here's a wad of cash, go in that building, steal these boxes in corridor A"
I also take issue with the "physical locations of DCs are still secrets" angle of the article.
Anyone working in a DC-adjacent industry and is curious enough can locate the back-entrance to any DC they have some business with. If it is a secret, it's not a well kept one (for good, operational reasons!)
Sites like DC Map give you the exact physical location, for instance.
The story is entertaining but it has clearly been romanticized.
[1]https://us.macmillan.com/books/9780374619794/cloudthief/ [2]https://www.amazon.com/gp/product/B0C9YVP3X2
Ok good point.
Certainly not the only data center that is not backed up in the past 12 months..
858TB gone forever: South Korea's data center fire shows the cost of no ... Oct 9, 2025 The National Information Resources Service (NIRS) in South Korea, however, recently lost 858TB of government data after a fire broke out in the building - and there were no backups.
Nope. THe story doesn't make any sense at all.
They stole about 5 milion dollars worth of computer equipment, which depending on how it's purchased is either a single cabinet of storage or a few cabinets of compute, which is largely worthless on the resale market, or if you believe the criminals, they were stealing evidence of illegal activities of the "bankers".
The story is way too sexed up and hollywood'd
Sounds like a really awful attempt at writing a Mr Robot sequel.
And we are to believe they don't have FDE on their application servers?
Bit dubious about how some of this hangs together. One detail that stood out to me:
> They removed mounting screws, disconnected the servers and put them in laundry bags — 20 bags in all, each large enough to hold four or five servers.
That's like 100kg or more of servers in each bag? I guess that is not totally impossible but it doesn't seem like a particularly easy way to move them around. It's not like putting five laptops in a bag and walking out with it over your shoulder.
Maybe they mean the rolling laundry carts that one puts such bags in. Not sure what one's excuse for pushing a bunch of them around a data center would be though.
I agree the details don't smell right though.
Anyone who has ever seen or handled a simple 1U server knows this is absolute bullshit. And laundry bags have to be absolutely the worst possible way to transport something like this.
And they stole 80 of them? So basically a truckload? Sure.
Data centers are huge and barely staffed. It's a really rich target for thieves in terms of IT hardware and scrap metal. There are literally tons of copper in there per acre. All the cameras in the world won't save you if you only have 4 guys in a 20 acre building.
That’s why they are often armed, some with rifles
Not, I trust, in the UK
> Nathaniel Rich. I am a novelist, […]
See Cloudthief here https://nathanielrich.com/books/
I was hoping for a story where they took all the bank loan data and the backups.
That is part of the plot of the TV show "Mr. Robot". Not just the loans, but balances too!
This story is making my bullshit detector go haywire. I’m guessing it was more mundane than what they claim. How much does it cost to buy one or several security guards? It’s a hell of a lot more likely than the movie script story the article contains.
Did this guy sign a book or movie deal? The only fact I believe is that they stole stuff from the data center.