The data centre heist that nobody saw coming

Fake police, real access cards, and 80 servers gone.

Share
The data centre heist that nobody saw coming
Photo Credit: Paul Mah. AI illustrated.

24/7 camera surveillance. 11 security guards. None of it counted for anything against a brazen attack that saw 80 servers removed from a data centre in broad daylight.

The New York Times recently published an in-depth account of the King's Cross data centre heist in central London, pulled off Ocean's Eleven style.

Only two were ever caught

The heist happened in 2007, a few years before I started writing about data centres. I found it riveting, not least because I've always considered these facilities immune to physical intrusion.

I guess someone forgot to tell the crooks that.

Of the 10 people involved, just two were eventually identified and arrested, and only by chance. An unrelated attempted burglary led to the data centre guards being shown mug shots of a suspect's known associates. The guards recognised two of them: Terry Ellis, the ringleader, and Denis Carr, his lieutenant. The rest were never caught.

Ocean's Ten

According to the Times, Ellis was approached by a fixer who promised £1.5 million, roughly US$4.8 million today, to steal 80 servers from a Verizon data centre. This was allegedly to remove evidence of certain bankers' involvement in subprime mortgages, and the gang was given specific information about which servers to target.

To handle that part of the job, they recruited four computer technicians, bringing the team to 10 people. They then spent three weeks surveilling the data centre.

On the day itself, they arrived in a fake police van and two other cars positioned to block the view from the road. Wearing police uniforms, they barged in.

Fake authority

The entire break-in hinged on deception: a mix of fake authority, confusion, and a bit of intimidation. No weapons.

The gang claimed someone was on the roof, which was enough to persuade the head of security to go upstairs. The remaining guards were handcuffed "for safety", and guards posted elsewhere in the building were called down. With the site under control, the live CCTV feed to an independent security company was cut. When the company called to check, Ellis pretended to be from Verizon security and said there was a fault with repairs already underway.

That bought them 40 minutes. Using access cards taken from the guards, the gang entered the data hall and removed the 80 servers they had come for, which I'm inclined to think were 1U units. The servers were never recovered.

Could this happen today?

The same playbook would not succeed today. From the data centres I've visited in Singapore and the region in recent years, the scheme would literally not get through the door.

Just a handful of blockers: badges paired with biometrics, high fencing with locked gates, security offices separated from the network operations centre, and IP-based cameras running over diverse network paths. Each one breaks a different link in the 2007 chain.

Which leaves the harder question. The controls have moved on, but so has the value of what sits in the racks. Could a sufficiently organised gang still pull off a physical data centre heist today?