# Inmate Hacks Prison: Watches P***, Prints Money, Reduces Sentence

Source: https://www.youtube.com/watch?v=-xCp7nag3GM
Recap page: https://rapidrecap.app/video/-xCp7nag3GM
Generated: 2025-12-08T21:04:40.597+00:00

---
## Quick Overview

An inmate named Aurel in a Romanian prison hacked the Ministry of Justice's prison management system, gaining admin access, reducing his sentence from 9 years and 10 months to 67 days, depositing 5,000,000 RON into his account, and later giving fellow inmates access to adult websites before the incident was discovered and resolved, leading to embarrassment for the Romanian Ministry of Justice.

**Key Points:**
- A Romanian inmate named Aurel, serving a 9-year, 10-month sentence for counterfeiting, gained admin access to the prison's IT system.
- Using admin privileges, Aurel reduced his sentence from 9 years and 10 months down to 67 days and deposited 5,000,000 RON (over a million dollars) into his account.
- Aurel initially used his access to give fellow inmates access to adult websites, including pornography and a hub resembling Pornhub, before moving to more serious data alterations.
- The system was vulnerable due to unverified admin accounts initially provided to staff, which Aurel exploited by spamming the Windows Start menu to escape the kiosk software.
- The Romanian National Administration of Penitentiaries confirmed the incident involved thousands of data alterations, including reducing sentences, but claimed it was a temporary impairment of confidentiality, not a full database breach.
- The subsequent national backlash included reports of other radio station hacks using compromised Barix studio-to-transmitter links (STLs) and India's government backtracking on mandatory pre-installation of a cybersecurity app called Sanchar Saathi due to privacy concerns.

![Screenshot at 00:04: 392:A screenshot showing the inmate Aurel's prisoner ID \(628392\) being modified on the 'Modify Prison Sentence' interface from an unknown number of days to just 67 days.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-00-04.png)

**Context:** The video recounts a significant security breach within the Romanian prison system, centered around an inmate named Aurel who managed to exploit vulnerabilities in the internal IT platform managed by the Ministry of Justice. This platform provided kiosks for inmates to manage basic functions like viewing sentence details and topping up accounts. The narrative juxtaposes this Romanian prison hack with recent cybersecurity issues in India concerning a mandatory government security app, illustrating a broader theme of governmental technology failures and security vulnerabilities.

## Detailed Analysis

The video details a major security breach within a Romanian prison orchestrated by an inmate named Aurel, who was serving 9 years and 10 months for counterfeiting. Aurel managed to gain admin access to the prison's IT system, which inmates used for basic functions. He exploited a flaw by spamming the Windows Start menu to escape the kiosk interface, gaining access to the underlying Windows XP operating system. Once logged in as 'admin' with full access, Aurel reduced his own sentence to 67 days and illegally deposited 5,000,000 RON (equivalent to over a million dollars) into his account. He then extended this access to his fellow inmates, initially allowing them to browse adult websites before engaging in thousands of data alterations across the system, including modifying others' sentences. The Romanian National Administration of Penitentiaries later issued a statement confirming the incident, attributing it to unverified admin accounts initially provided to staff, but downplayed the severity, claiming it was only a 'temporary impairment of the confidentiality and integrity of certain data sets' rather than a full database breach. The video then pivots to discuss two related cybersecurity issues: first, the Indian government's controversial order to mandate the installation of the Sanchar Saathi cyber safety app on all new phones, which was later reversed due to public outcry over privacy; and second, recent radio station hacks in the US where attackers compromised poorly secured Barix Studio-to-Transmitter Link (STL) equipment to broadcast obscene content and misuse the Emergency Alert System (EAS) tone.

### Romanian Prison Hack

- Aurel, an inmate, gained admin access to the prison's IT system
- reduced his sentence from 9 years/10 months to 67 days
- deposited 5,000,000 RON into his account
- gave other inmates access to adult content.

### Exploitation Method

- Aurel bypassed the kiosk software by spamming the Windows Start menu to access the underlying Windows XP OS
- accessed admin credentials that were initially provided to staff but never verified.

### Official Response (Romania)

- The National Administration of Penitentiaries confirmed thousands of data alterations over 300 logged hours
- claimed it was not a database breach but a 'temporary impairment of confidentiality and integrity'.

### Indian Cyber Security App Controversy

- The Indian government ordered smartphone makers to preload the Sanchar Saathi app, which was reportedly unremovable
- faced backlash over privacy concerns
- government later reversed the mandatory pre-installation order.

### Radio Station Hacking Trend

- The video cites previous hacks where attackers compromised Barix Studio-to-Transmitter Link (STL) equipment
- broadcasted obscene material and misused the Emergency Alert System (EAS) signal.

![Screenshot at 00:02: 50:The initial screen showing the 'Modify Prison Sentence' interface where the inmate's days are being changed from an unknown value to 67 days.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-00-02.png)
![Screenshot at 00:05: 29:The Sanchar Saathi app interface showing options like 'Block Your Lost/Stolen Mobile Handset' and 'Easy Reporting of Suspected Fraud Communication'.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-00-05.png)
![Screenshot at 00:18: 36:A map of Romania showing the locations of Timișoara, Târgu Jiu, and Pelendava, highlighting where the incarcerated individuals were held.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-00-18.png)
![Screenshot at 07:31: 00:The FCC Public Notice explaining that the hacks resulted from compromised studio-transmitter link \(STL\) equipment, often due to default passwords.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-07-31.png)
![Screenshot at 07:51: 00:A news headline stating 'Jimmy Kimmel, Walking Dead part of $600,000 penalties for false emergency alerts', referencing illegal EAS signal misuse.](https://ss.rapidrecap.app/screens/-xCp7nag3GM/00-07-51.png)
