Anonymous and The AEGIS Alliance NewsNoticias anónimasHacker NewsInternational NewsNoticiasOtros vídeosVideos

Anonymous-Linked Prisoner Hacked Romania’s Inmate System, Cut Sentences, and Exposed a Password Nobody Rotated

Hackers breach system responsible for New Orleans bond transactions, jail releases

Un hacker afiliado al colectivo anónimo recientemente sorprendió al mundo de la ciberseguridad violando el sistema de gestión penitenciaria de Rumania y reduciendo las condenas por sí mismo y 15 Compañeros en el centro correccional Târgu jiu. Este incidente único no es sólo un testamento de vulnerabilidad en los sistemas penitenciarios digitales, sino también una llamada de atención a la infraestructura mundial de TI de justicia.

The Anonymous Prison Hack: Unraveling the Incident

What Happened in Romania?

En agosto de 2025, un ciberdelincuente condenado, alegando vínculos con el grupo anónimo, explotó debilidades técnicas en el sistema de gestión de reclusos de Rumania, conocido como IMSweb, un millón de euros proyecto lanzado hace apenas dos años. Utilizando credenciales de acceso anticuado en un quiosco de prisión, el hacker obtuvo acceso administrativo completo y modificó sus propios y otros registros de los reclusos. Cambios incluidos:

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Reducing his sentence via “earning days.”

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Transferring funds between prisoner accounts.

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Granting inmates “improved conditions,” including altered records of intimate encounters.​

The exploit lasted three months y no fue detectado a pesar de un gasto anormalmente alto en cuentas de prisioneros y múltiples señales de advertencia. Un empleado financiero expuso la brecha cuando los saldos no disminuyeron después de las transacciones. Un examen interno reveló al menos 300 horas de acceso no autorizado. La Administración Penitenciaria Nacional llamó al episodio "isolado", pero el sindicato y la prensa local registraron fallos sistémicos más amplios.

How the Hack Unfolded

This saga started in Dej, un hospital penitenciario en Transilvania, donde un recluso dotado técnicamente descubrió cómo abusar de las tabletas de quiosco que permitieron a los presos acceder a la PNB (penitenciaria nacional) Association) aplicación de gestión de reclusos. Mediante la manipulación de las ventanas del sistema y la observación de la actividad de inicio de sesión, el hacker adquirió credenciales de un (antiguo) director del hospital, credenciales válidas en toda la red carcelaria nacional.

El hacker entonces enseñó a otros este exploit, incluyendo Aurel Z., que, al transferir a Târgu Jiu, aplicó el mismo método a esa instalación. Con el acceso a nivel de administración, los reclusos podrían añadir "días iniciales", modificar los saldos de cuentas e incluso acceder a contenidos restringidos. Notablemente, la cuenta de un recluso mostró un gasto mensual tres veces el salario mínimo rumano, un alumbramiento que impulsó la investigación.

Direct Quotes from Sources

"Un ciberdelincuente condenado obtuvo acceso al sistema IMSweb, que contiene una base de datos completa de todos los presos del país. Para ello, utilizó el quiosco de información en la colonia y el login de uno de los agentes de policía, que no había cambiado su contraseña durante años. Esto resultó ser suficiente para obtener derechos de administrador."
— Hi-Tech.uaInvestigación​

"El sindicato afirma que el hacker de Târgu Jiu solo pasó más de 300 horas conectado al sistema con acceso administrativo sin detección... They have also accused the ANP Director of gross negligencia por no detectar la violación después de dos supervisores y un gerente de turno informó de rumores que habían oído de reclusos".
— Risky.biz reporting on union statements​

Systemic Vulnerabilities in Prison Technology

IMSweb: A Project Rushed to Market

IMSweb fue financiado con el apoyo de la Unión Europea y "hastily put into operation so as not to lose funding", según el sindicato de oficiales de prisiones de Rumania. Los críticos argumentan que faltaban protocolos de supervisión y ciberseguridad adecuados. El despliegue apresurado y la reutilización rutinaria de las credenciales abrió la puerta para tal incumplimiento.

Gastos técnicos

El hack consistía en manipular los sistemas operativos del dispositivo (utilizando atajos del desarrollador y acceso al navegador) y explotar la reutilización de contraseña. Los registros de acceso web, el hackeo F12 DevMode y las credenciales copiadas en dispositivos fueron herramientas centrales. Esto demuestra cómo el acceso interno y físico a la infraestructura de TI amplifica enormemente el riesgo cuando se combina con la mala higiene de seguridad.

Ethical and Societal Dimensions

Cybercriminals Inside the System

El incidente desafía las suposiciones tradicionales sobre el control de los reclusos y la seguridad de los sistemas de justicia digital. Que un prisionero no sólo podría reducir su sentencia, sino que también mejorar la vida para otros puede ser visto a través de varias lentes éticas —algunos viendo un aspecto de Robin Hood, otros condenando la violación de la confianza y la ley.

Responsabilidad institucional

El personal penitenciario rumano no actualizó las credenciales y respondió adecuadamente a las señales de alerta. Se siguieron las investigaciones disciplinarias, dirigidas a los que encontraron negligencia. El episodio ha generado un debate público más amplio sobre la transparencia, la supervisión y los peligros de la "transformación digital" perseguidos sin salvaguardias sólidas.

Global Context: Hackers in Prisons, the Anonymous Legacy

Not an Isolated Event

Hacking collectives like Anonymous have a storied history with prison, from both sides of the barsJeremy Hammond, que es parte de Anónimo y Antiseg, sirvió 10 años en Estados Unidos prisión por hackear la firma de análisis de seguridad Stratfor, extrayendo información confidencial de entidades militares y corporativas.

“For each of these hacks, I knew what I was doing was against the law. I considered myself a ‘hacktivist’ who fights for causes he believes in, but never for profit.”
—Jeremy Hammond, Anonymous hacktivist, in court​

The pattern of hackers exploiting weaknesses inside prison computer systems is an emerging concern. The New Orleans Parish Sheriff’s Office was breached in a ransomware attack recently, affecting jail release and transfer systems and exposing contracts and inmate intake data. (CBS/YouTube)​

Prison IT and Ransomware

Jail systems are prime targets for ransomware and cyber exploits, as they deal with highly sensitive personal data and affect fundamental rights. In New Orleans, a Russian-speaking group extracted 842GB of data, targeting the jail’s docket, master system, and release management—all potentially affecting when and how inmates are freed. (CBS/YouTube)​

Anonymous and Digital Protest

Anonymous, though decentralized, continues to challenge power using technical skills. Their collective and affiliate hackers, whether or not directly involved in the Romanian breach, style themselves as digital activists as well as criminals.​

Impact and Repercussions

Immediate Reforms

Romania has isolated the affected inmate management system for inspection and announced disciplinary proceedings for negligent staff. Measures include removing physical access points (keyboards, tablets), increasing surveillance, and tightening password policies.​

No names of the hackers have yet been officially released. However, one named hacker, Aurel Z., was reportedly five months from finishing a nearly ten-year sentence for laundering money for the Italian mob when caught applying the hack at Târgu Jiu.​

A Precedent in Digital Justice

Romanian cybersecurity experts warn that this is the “first time a Romanian prisoner has managed to hack a state system of this level,” raising red flags for prison systems worldwide. It is a cautionary tale for countries investing in digitized prison management without adequate investment in cybersecurity and staff training.​

Lessons for Digital Correctional Management

Key Weaknesses Identified

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Password hygiene and infrequent update

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Physical access, paired with digital vulnerabilities

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Poor response to early warning indicators from inmates and informants

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    Lack of independent penetration testing before going live with new IT systems ​

Software and Network Safeguards

Experts advocate timely patching, credential rotation, two-factor authentication, and regular independent security audits as essential. Hardware should not allow multitasking or developer tools access for routine users. Staff need comprehensive training—cybersecurity is as much a human problem as a technical one.​

Larger Implications: The Future of Prison Cybersecurity

Cyber-Physical Borders

The incident challenges the illusion of separation between physical and digital prison boundaries. Inmates with computer knowledge, given minimal digital privileges, can still potentially escalate access unless robust containment and monitoring are in place.

Policy and Oversight

Governments must balance digitization with rigorous oversight, factoring in unique threats posed by placing potentially high-skilled individuals in controlled digital environments. Systems must be hardened and regularly red-teamed, and feedback—from inmates as well as staff—taken seriously.​

Conclusion: A New Era of Prison Cyber Risk

This unprecedented hack—driven by an Anonymous-linked prisoner in Romania—should provoke intense scrutiny of correctional technology worldwide. As digital systems become integral to management and record-keeping, the threat landscape morphs: insider risks join external hackers as a major force. The responsibility for digital justice rests not only with system architects but also with staff, administrators, and political oversight bodies.

Actualización: lo que siguió Târgu Jiu Breach

The original video embed at the top of this post stays in place. Reporting after the first wave of coverage filled in names and a second failure mode that the early write-up only sketched.

Romania Insider, citing local prison coverage, said the Târgu Jiu inmate who used the stolen Dej credentials was helped by a prison officer who logged him into the national IMSweb console. The officers’ union said the same method later showed up at two more complexes — Timișoara and Pelendava, near Craiova — and that the Târgu Jiu account alone sat in the system for more than 300 hours. The inmate publicly tied to the Târgu Jiu run is Aurel Z., then serving nine years and ten months for laundering money for the Italian mob and, at the time of the breach, about five months from a scheduled January 2026 release. Changing his own «earned days» put that date in doubt. (Romania Insider, Risky Bulletin)

No public 2026 verdict against Aurel Z., the unnamed Dej hospital inmate who first lifted the director’s password, or the officer accused of handing over the login has been posted in English-language court records reviewed for this update. The National Penitentiary Administration still called the episode isolated. The union still called that a dodge.

What later recaps added without a verdict

English-language recaps through early 2026 kept repeating the same core timeline: an inmate first learned the kiosk trick at the Dej prison hospital, Aurel Z. carried the method to Târgu Jiu after a July transfer, and admin access on IMSweb lasted long enough for sentence credits, commissary balances, visit schedules, and records at other facilities to move. Project Nightfall and security shops restated the 300-hour figure and the stale director login. They did not produce a published criminal judgment against Aurel Z. or against the officer whose password never rotated.

That silence is the story now. A national inmate database that accepted a retired director’s credentials from a prisoner kiosk is not a one-off curiosity. It is a design that treated physical bars as if they cancelled the need for basic access control. Readers tracking hacktivist name-use should keep the original video embed at the top of this file and treat later social posts that slap an Anonymous logo on the breach as commentary, not as a charging document. For how Anonymous treats paid front groups and name-hijackers, see Attempting to Clear up Misconceptions about Anonymous y The YouTube Channel «Anonymous Official» Exposed.

Key Quotes Recap

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    “A prisoner hacker associated with the Anonymous group managed to hack the prison’s internal computer network and change the data about his own sentence, as well as help 15 other prisoners.”  ​

  • p]:pt-0 [cliente]:mb-2 [cliente]:my-0′′

    “The union claims the Târgu Jiu hacker alone spent more than 300 hours logged into the system with admin access without being detected.”​​

A union president puts a full name on the kiosk login

English-language recaps kept calling the Târgu Jiu inmate Aurel Z. Romanian union officials went further. Cosmin Dorobanțu, president of the Federation of Unions in the National Penitentiary Administration, told Fanatik in October 2025 that investigators had identified a single prisoner: Cristic Nicu Aurel Z., then 29, tied to an Italian cybercrime group. Dorobanțu said the man was serving 9 years, 10 months, and 10 days for fraudulent financial operations under Article 250 of the criminal code. Fanatik reported a separate description of the underlying case as a counterfeit-money operation for an Italian group known as Napoli, with judges imposing a 10-year term that began in 2016, and said the prisoner had been weeks away from a conditional-release commission when the breach became public. Changing earned days in the software, the union argued, sabotaged the very hearing that might have sent him home.

Dorobanțu also undercut the idea that a database edit was a door key. He said that when a prisoner is actually released, staff pull the paper penitentiary file, and a commission would have seen a mismatch between the application and the paper. The software, in his account, only alerts the inmate-records service that someone looks eligible. That is a narrower failure than a fantasy of inmates walking out on a forged sentence, and it is a larger one: a national system let a prisoner sit in an administrator session for hundreds of hours, move money, and alter records that staff were supposed to trust until a human compared them to a folder.

The same Fanatik reporting said that in 2024, while he was at Timișoara, Cristic Nicu Aurel Z. filed nine complaints against decisions of the prison director, and that a court told him to stop an almost obsessive habit of contesting every restriction of detention. The National Penitentiary Administration’s technical control of the access logs, Dorobanțu said, ran from September 16, 2025 through October 3, 2025. The officers’ union said keyboards were pulled from prisoner info-kiosks at Târgu Jiu on September 18, 2025, after the illicit activity was confirmed. The inmate had presented himself as part of Anonymous. The AEGIS Alliance has long treated that name as a banner people adopt, not as a membership card. The video embedded at the top of this report stays. Later posts that paste an Anonymous logo on the breach are commentary, not a charging document.

Europa Liberă reported that the first use of the access, on August 8, 2025, from a terminal prisoners could reach at Târgu Jiu, included opening adult sites for other inmates before the financial edits began in earnest on August 14. Fifteen prisoners were identified as beneficiaries: reduced sentence calculations, purchases, account balances, compensatory-appeal days, and visits. The union said the intruders also reached security data and intervention recordings and talked about cloning the application. No English-language criminal judgment against Cristic Nicu Aurel Z., the Dej hospital prisoner who first lifted the stale director password, or the officer accused of handing over a login has appeared in the court reporting reviewed with these union statements. The administration still called the episode isolated. The union still called that a dodge.

That second silence is the part that should travel. A kiosk, a password nobody rotated, and a paper file that might have caught a bad release date are not a Romanian curiosity. They are a design used anywhere a jail puts a browser in front of people who already know how browsers break. Readers who want the longer argument about who gets to wear the Anonymous name can read Attempting to Clear up Misconceptions about Anonymous and the newsroom’s hacker news file. The original YouTube embed on this page is unchanged.

The AEGIS Alliance U.K.
Bringing you news from the United Kingdom and greater Europe! Journalist, editor, activist, social media management, content creator. Based in the U.K.

Publicaciones relacionadas

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

Botón volver arriba