14-year-olds use online manual to hack ATM

Forgoing a kick around in the playground, a couple of teenage boys spent one school lunch break last week hacking into a Bank of Montreal cash machine.

  12 3 comments

14-year-olds use online manual to hack ATM

Editorial

This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.

After finding an old ATM service manual online, Matthew Hewlett and Caleb Turon decided to head to their nearest BMO machine at a Safeway store in their hometown of Winnipeg.

When the boys tried to get into the system they were asked for a password. Taking a punt on a commonly used default, they were shocked to see their attempt work.

Instead of trying to clear the machine out, the pair made their way to the nearest BMO branch to flag the security risk but, Hewlett told the Winnipeg Sun, staff did not believe them.

"So we both went back to the ATM and I got into the operator mode again. Then I started printing off documentation like how much money is currently in the machine, how many withdrawals have happened that day, how much it's made off surcharges," Hewlett says.

The teenagers even changed the machine's greeting screen from 'Welcome to the BMO ATM' to 'Go away. This ATM has been hacked.'

When they returned to the BMO branch with documentation of their hack, the branch manager vowed to contact security. The bank has since taken steps to prevent a repeat but insists that customer data was never at risk.

Meanwhile, caught up in their adventure, the boys were late for lessons and asked bank staff to write a note.

"Please excuse Mr Caleb Turon and Matthew Hewlett for being late during their lunch hour due to assisting BMO with security," the letter presented to the school secretary began.

Sponsored [On-Demand Webinar] Global Workforce Payments: Mastering a world of complexity

Comments: (3)

James Piggot

James Piggot Product Analyst at Finastra

This is both very funny and serious at the same time! I love the ending where the bank write a note excusing the boys for being late due to them assisting the bank with security. But why on earth did this happen and how come this bank is still operating if their security is so lax? I guess the answer is they don't employ any 14 year olds?

A Finextra member 

I think BMO security and audit should give you two boys a summer job ...well done ..... Shake the tree and fruit will fall ...... LOL

A Finextra member 

One more lesson about security ..... Just because the door is closed, does not mean it's locked...

[New Report] Managing Fraud Risks with Synthetic Data: A Practical Approach for Businesses ServicesFinextra Promoted[New Report] Managing Fraud Risks with Synthetic Data: A Practical Approach for Businesses Services Industry