Anonymous-Linked Prisoner Hacked Romania’s Inmate System, Cut Sentences, and Exposed a Password Nobody Rotated

Un hacker affilié au collectif anonyme a récemment choqué le monde de la cybersécurité en violant le système de gestion pénitentiaire de la Roumanie et en réduisant les peines pour lui-même et 15 Détenus au centre pénitentiaire de Târgu Jiu. Cet incident unique témoigne non seulement de la vulnérabilité des systèmes pénitentiaires numériques, mais aussi d'un appel à la justice mondiale.
The Anonymous Prison Hack: Unraveling the Incident
What Happened in Romania?
En août 2025, un cybercriminel condamné, qui revendique des liens avec le groupe anonyme, a exploité des faiblesses techniques dans le système de gestion des détenus en Roumanie, connu sous le nom d'IMSweb. projet lancé deux ans plus tôt. En utilisant des identifiants de connexion périmés sur un kiosque de prison, le pirate a obtenu un accès administratif complet et modifié ses propres dossiers et ceux des autres détenus. Voici les changements apportés :
- [&>p]:mb-2 [&>p]:my-0′′>
Reducing his sentence via “earning days.”
- [&>p]:mb-2 [&>p]:my-0′′>
Transferring funds between prisoner accounts.
- [&>p]:mb-2 [&>p]:my-0′′>
Granting inmates “improved conditions,” including altered records of intimate encounters.
The exploit lasted three months et n'a pas été détecté malgré des dépenses anormalement élevées dans les comptes de prisonniers et des signes d'avertissement multiples. Un employé financier a révélé la violation lorsque les soldes n'ont pas diminué après les transactions. Un examen interne a révélé au moins 300 heures d'accès non autorisé. L'Administration pénitentiaire nationale a appelé l'épisode « isolé », mais le syndicat et la presse locale ont signalé des échecs systémiques plus larges.
How the Hack Unfolded
This saga started in Dej, un hôpital pénitentiaire de Transilvanie, où un détenu techniquement doué a découvert comment abuser des tablettes de kiosque qui ont permis aux détenus d'accéder à l'ANP (Pénitencier national Association) application de gestion des détenus. En manipulant les fenêtres du système et en observant l'activité de connexion, le hacker a acquis des titres de compétence d'un (ancien) directeur d'hôpital, des titres de créance valables dans tout le réseau pénitentiaire national.
Le hacker a ensuite enseigné à d'autres cet exploit, y compris Aurel Z., qui, après avoir transféré à Târgu Jiu, a appliqué la même méthode à cette installation. Avec l'accès au niveau de l'administration, les détenus pourraient ajouter des « jours de récupération », modifier les soldes de compte, et même accéder au contenu restreint. Notamment, le compte d'un détenu montrait une dépense mensuelle de trois fois le salaire minimum roumain, un écart flagrant qui a motivé l'enquête.
Direct Quotes from Sources
"Un cybercriminel condamné a accès au système IMSweb, qui contient une base de données complète de tous les prisonniers du pays. Pour ce faire, il a utilisé le kiosque d'information de la colonie et la connexion d'un des policiers, qui n'avait pas changé son mot de passe depuis des années. Cela s'est avéré suffisant pour obtenir des droits d'administrateur."
— Bonjour.L'enquête
"Le syndicat prétend que le hacker Târgu Jiu seul a passé plus de 300 heures connecté au système avec accès admin sans détection... Ils ont également accusé le directeur de l'ANP de la négligence pour ne pas avoir détecté la brèche après que deux superviseurs et un gestionnaire de quart ont signalé des rumeurs qu'ils avaient entendues de détenus."
— Risquey.biz reporting on union statements
Systemic Vulnerabilities in Prison Technology
IMSweb: A Project Rushed to Market
IMSweb a été financé avec le soutien de l'Union européenne et « rapidement mis en œuvre afin de ne pas perdre de financement », selon le syndicat roumain des agents pénitentiaires. Les critiques affirment que les protocoles de surveillance et de cybersécurité ne sont pas appropriés. Le déploiement précipité et la réutilisation routinière des pouvoirs ont ouvert la porte à une telle brèche.
Exploitations techniques
Le hack comprenait la manipulation des systèmes d'exploitation de l'appareil (en utilisant des raccourcis de développeur et l'accès au navigateur) et l'exploitation de la réutilisation de mot de passe. Les journaux d'accès Web, le piratage F12 DevMode et les identifiants copiés sur les appareils étaient des outils centraux. Cela démontre comment l'accès interne et physique à l'infrastructure informatique amplifie considérablement le risque lorsqu'il est associé à une mauvaise hygiène de sécurité.
Ethical and Societal Dimensions
Cybercriminals Inside the System
Cet incident remet en question les hypothèses traditionnelles concernant le contrôle des détenus et la sécurité des systèmes de justice numérique. Qu'un détenu puisse non seulement réduire sa peine, mais aussi améliorer la vie des autres peut être vu à travers différents objectifs éthiques — certains voyant un aspect Robin des Bois, d'autres condamnant la violation de la confiance et de la loi.
Responsabilité institutionnelle
Le personnel pénitentiaire roumain n'a pas mis à jour ses pouvoirs et n'a pas répondu adéquatement aux avertissements. Des enquêtes disciplinaires ont suivi, ciblant les personnes jugées négligentes. L'épisode a suscité un débat public plus large sur la transparence, la surveillance et les dangers de la « transformation numérique » menée sans garanties solides.
Global Context: Hackers in Prisons, the Anonymous Legacy
Not an Isolated Event
Hacking collectives like Anonymous have a storied history with prison, from both sides of the bars. Jeremy Hammond, qui fait partie d'Anonymous et d'Antisec, a servi 10 ans aux États-Unis prison pour avoir piraté l'entreprise d'analyse de sécurité Stratfor, en extrayant des informations confidentielles à des entités militaires et corporatives.
“For each of these hacks, I knew what I was doing was against the law. I considered myself a ‘hacktivist’ who fights for causes he believes in, but never for profit.”
—Jeremy Hammond, Anonymous hacktivist, in court
The pattern of hackers exploiting weaknesses inside prison computer systems is an emerging concern. The New Orleans Parish Sheriff’s Office was breached in a ransomware attack recently, affecting jail release and transfer systems and exposing contracts and inmate intake data. (CBS/YouTube)
Prison IT and Ransomware
Jail systems are prime targets for ransomware and cyber exploits, as they deal with highly sensitive personal data and affect fundamental rights. In New Orleans, a Russian-speaking group extracted 842GB of data, targeting the jail’s docket, master system, and release management—all potentially affecting when and how inmates are freed. (CBS/YouTube)
Anonymous and Digital Protest
Anonymous, though decentralized, continues to challenge power using technical skills. Their collective and affiliate hackers, whether or not directly involved in the Romanian breach, style themselves as digital activists as well as criminals.
Impact and Repercussions
Immediate Reforms
Romania has isolated the affected inmate management system for inspection and announced disciplinary proceedings for negligent staff. Measures include removing physical access points (keyboards, tablets), increasing surveillance, and tightening password policies.
Legal Proceedings
Aucun nom des hackers n'a encore été officiellement publié. Cependant, un dénommé hacker, Aurel Z., A été cinq mois après avoir terminé une peine de près de dix ans pour blanchiment d'argent pour la mafia italienne lors de l'application du piratage Târgu Jiu.
A Precedent in Digital Justice
Romanian cybersecurity experts warn that this is the “first time a Romanian prisoner has managed to hack a state system of this level,” raising red flags for prison systems worldwide. It is a cautionary tale for countries investing in digitized prison management without adequate investment in cybersecurity and staff training.
Lessons for Digital Correctional Management
Key Weaknesses Identified
- [&>p]:mb-2 [&>p]:my-0′′>
Password hygiene and infrequent update
- [&>p]:mb-2 [&>p]:my-0′′>
Physical access, paired with digital vulnerabilities
- [&>p]:mb-2 [&>p]:my-0′′>
Poor response to early warning indicators from inmates and informants
- [&>p]:mb-2 [&>p]:my-0′′>
Lack of independent penetration testing before going live with new IT systems
Software and Network Safeguards
Experts advocate timely patching, credential rotation, two-factor authentication, and regular independent security audits as essential. Hardware should not allow multitasking or developer tools access for routine users. Staff need comprehensive training—cybersecurity is as much a human problem as a technical one.
Larger Implications: The Future of Prison Cybersecurity
Cyber-Physical Borders
The incident challenges the illusion of separation between physical and digital prison boundaries. Inmates with computer knowledge, given minimal digital privileges, can still potentially escalate access unless robust containment and monitoring are in place.
Policy and Oversight
Governments must balance digitization with rigorous oversight, factoring in unique threats posed by placing potentially high-skilled individuals in controlled digital environments. Systems must be hardened and regularly red-teamed, and feedback—from inmates as well as staff—taken seriously.
Conclusion: A New Era of Prison Cyber Risk
This unprecedented hack—driven by an Anonymous-linked prisoner in Romania—should provoke intense scrutiny of correctional technology worldwide. As digital systems become integral to management and record-keeping, the threat landscape morphs: insider risks join external hackers as a major force. The responsibility for digital justice rests not only with system architects but also with staff, administrators, and political oversight bodies.
Mise à jour : ce qui a suivi Târgu Jiu Violation
The original video embed at the top of this post stays in place. Reporting after the first wave of coverage filled in names and a second failure mode that the early write-up only sketched.
Romania Insider, citing local prison coverage, said the Târgu Jiu inmate who used the stolen Dej credentials was helped by a prison officer who logged him into the national IMSweb console. The officers’ union said the same method later showed up at two more complexes — Timișoara and Pelendava, near Craiova — and that the Târgu Jiu account alone sat in the system for more than 300 hours. The inmate publicly tied to the Târgu Jiu run is Aurel Z., then serving nine years and ten months for laundering money for the Italian mob and, at the time of the breach, about five months from a scheduled January 2026 release. Changing his own « earned days » put that date in doubt. (Romania Insider, Risky Bulletin)
No public 2026 verdict against Aurel Z., the unnamed Dej hospital inmate who first lifted the director’s password, or the officer accused of handing over the login has been posted in English-language court records reviewed for this update. The National Penitentiary Administration still called the episode isolated. The union still called that a dodge.
What later recaps added without a verdict
English-language recaps through early 2026 kept repeating the same core timeline: an inmate first learned the kiosk trick at the Dej prison hospital, Aurel Z. carried the method to Târgu Jiu after a July transfer, and admin access on IMSweb lasted long enough for sentence credits, commissary balances, visit schedules, and records at other facilities to move. Project Nightfall and security shops restated the 300-hour figure and the stale director login. They did not produce a published criminal judgment against Aurel Z. or against the officer whose password never rotated.
That silence is the story now. A national inmate database that accepted a retired director’s credentials from a prisoner kiosk is not a one-off curiosity. It is a design that treated physical bars as if they cancelled the need for basic access control. Readers tracking hacktivist name-use should keep the original video embed at the top of this file and treat later social posts that slap an Anonymous logo on the breach as commentary, not as a charging document. For how Anonymous treats paid front groups and name-hijackers, see Attempting to Clear up Misconceptions about Anonymous et The YouTube Channel « Anonymous Official » Exposed.
Key Quotes Recap
- [&>p]:mb-2 [&>p]:my-0′′>
“A prisoner hacker associated with the Anonymous group managed to hack the prison’s internal computer network and change the data about his own sentence, as well as help 15 other prisoners.”
- [&>p]:mb-2 [&>p]:my-0′′>
“The union claims the Târgu Jiu hacker alone spent more than 300 hours logged into the system with admin access without being detected.”
A union president puts a full name on the kiosk login
English-language recaps kept calling the Târgu Jiu inmate Aurel Z. Romanian union officials went further. Cosmin Dorobanțu, president of the Federation of Unions in the National Penitentiary Administration, told Fanatik in October 2025 that investigators had identified a single prisoner: Cristic Nicu Aurel Z., then 29, tied to an Italian cybercrime group. Dorobanțu said the man was serving 9 years, 10 months, and 10 days for fraudulent financial operations under Article 250 of the criminal code. Fanatik reported a separate description of the underlying case as a counterfeit-money operation for an Italian group known as Napoli, with judges imposing a 10-year term that began in 2016, and said the prisoner had been weeks away from a conditional-release commission when the breach became public. Changing earned days in the software, the union argued, sabotaged the very hearing that might have sent him home.
Dorobanțu also undercut the idea that a database edit was a door key. He said that when a prisoner is actually released, staff pull the paper penitentiary file, and a commission would have seen a mismatch between the application and the paper. The software, in his account, only alerts the inmate-records service that someone looks eligible. That is a narrower failure than a fantasy of inmates walking out on a forged sentence, and it is a larger one: a national system let a prisoner sit in an administrator session for hundreds of hours, move money, and alter records that staff were supposed to trust until a human compared them to a folder.
The same Fanatik reporting said that in 2024, while he was at Timișoara, Cristic Nicu Aurel Z. filed nine complaints against decisions of the prison director, and that a court told him to stop an almost obsessive habit of contesting every restriction of detention. The National Penitentiary Administration’s technical control of the access logs, Dorobanțu said, ran from September 16, 2025 through October 3, 2025. The officers’ union said keyboards were pulled from prisoner info-kiosks at Târgu Jiu on September 18, 2025, after the illicit activity was confirmed. The inmate had presented himself as part of Anonymous. The AEGIS Alliance has long treated that name as a banner people adopt, not as a membership card. The video embedded at the top of this report stays. Later posts that paste an Anonymous logo on the breach are commentary, not a charging document.
Europa Liberă reported that the first use of the access, on August 8, 2025, from a terminal prisoners could reach at Târgu Jiu, included opening adult sites for other inmates before the financial edits began in earnest on August 14. Fifteen prisoners were identified as beneficiaries: reduced sentence calculations, purchases, account balances, compensatory-appeal days, and visits. The union said the intruders also reached security data and intervention recordings and talked about cloning the application. No English-language criminal judgment against Cristic Nicu Aurel Z., the Dej hospital prisoner who first lifted the stale director password, or the officer accused of handing over a login has appeared in the court reporting reviewed with these union statements. The administration still called the episode isolated. The union still called that a dodge.
That second silence is the part that should travel. A kiosk, a password nobody rotated, and a paper file that might have caught a bad release date are not a Romanian curiosity. They are a design used anywhere a jail puts a browser in front of people who already know how browsers break. Readers who want the longer argument about who gets to wear the Anonymous name can read Attempting to Clear up Misconceptions about Anonymous and the newsroom’s hacker news file. The original YouTube embed on this page is unchanged.









