20 July 2026

How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist

The New York Times  |  Nathaniel Rich

Heistman Terry Ellis and a professional criminal crew targeted a Verizon-operated data center in King's Cross, London, to steal approximately 80 servers containing incriminating financial records. Commissioned by American bankers seeking to destroy evidence of regulatory violations, the high-stakes operation required bypassing advanced physical security systems to retrieve intact digital data.

The targeted facility housed critical server infrastructure for multiple global financial institutions following a series of rapid corporate mergers. To execute the heist without destroying the underlying files, the criminal syndicate expanded its traditional five-man tactical team to include four specialized computer technicians. An additional client representative joined the ten-man infiltration team to ensure the precise extraction of the specific hardware hosting the subprime mortgage data. This physical breach highlights the critical vulnerability of centralized digital storage facilities to coordinated, non-cyber tactical exploitation by sophisticated hostile actors seeking to compromise sensitive corporate assets.

Comment
Physical security remains the weakest link in critical information infrastructure protection. Most cyber security frameworks focus heavily on logical access controls. The ISO/IEC 27001 standard mandates strict physical perimeter controls for server rooms. Tactical red teaming must integrate physical breach scenarios to test data centre resilience.

No comments: