Hacked in 20 Minutes: What a Live Bank Breach Tells Us About Cyber Risk

Hacked in 20 Minutes: What a Live Bank Breach Tells Us About Cyber Risk

22 Jun 2026

Hacked in 20 Minutes: What a Live Bank Breach Tells Us About Cyber Risk

Hacked in 20 Minutes: What a Live Bank Breach Tells Us About Cyber Risk

Bueno Bank does not exist. The laptop belonged to Glenn Wilkinson, a professional ethical hacker. The customer data extracted live on stage during Transform Finance’s 4th Annual Leaders Summit Europe, Amsterdam, was fabricated. The database password found in a plaintext spreadsheet on a network share was planted.

Everything else was real.

The tools used were freely downloadable. The technique employed was a phishing email exploiting publicly available LinkedIn data. The time taken to go from initial access to full database control was under twenty minutes. The audience watching: two hundred senior financial crime practitioners, many of them responsible for the security of institutions considerably larger than Bueno Bank.

The silence when the account balance updated to €1,000,000 said more than the demonstration needed to.

The Human is Still the Door

The demonstration, led by Wilkinson, and the wider session on cybersecurity risk made one point clear: the decisive vulnerability is not technical, but human. The entry point to Bueno Bank was not a software vulnerability, an unpatched server, or a misconfigured firewall. It was a pressured employee who opened an email attachment that appeared to come from her manager, in a context specifically engineered to make not opening it feel professionally riskier than opening it.

The email was constructed using information gathered entirely from open sources. A support interaction with the bank’s customer service team yielded a name. A LinkedIn search yielded a photograph, a surname, a title, a set of colleagues and a professional network. The message that landed in the employee’s inbox was not a generic phishing attempt. It was a hyper-personalised piece of social engineering: an accidentally carbon-copied internal document about restructuring and redundancy, addressed to people the employee would recognise, referencing a concern she would have good reason to take seriously.

“In twenty years of doing this,” Wilkinson said, “it consistently works.”

What followed was methodical rather than dramatic. A compromised laptop provided the initial access point, allowing attackers to pivot into the organisation’s internal network. Credentials found in a password file on the machine opened further systems. A database configuration file left in a network share provided the connection string for the core banking database. The command to retrieve customer records was four lines long.

The lesson is not that the bank’s defences were uniquely inadequate. Most of the vulnerabilities exploited in the demonstration, including password reuse, credentials stored in plaintext, configuration files accessible on shared drives, and a culture in which urgent communications from authority figures are acted upon without verification, exist to some degree in almost every organisation.

The breach was not a sophisticated operation. It was a methodical application of publicly known techniques to universally present weaknesses.

 

Glenn Wilkinson speaking at the 4th Annual FinCrime Leaders Summit Europe, Amsterdam

 

The Ransomware Economy

The attack on Bueno Bank did not stop at data exfiltration. It concluded with the deployment of ransomware: every file on every accessible system encrypted, every customer record locked, every operational process halted pending payment of a cryptocurrency ransom.

This is not a scenario that belongs to the future. The Dutch Data Protection Authority recorded 178 successful cyber breaches in the Netherlands last year. Average ransom demands in the Netherlands slightly exceed €5 million. Globally, major retailers, manufacturers and professional services firms have been hit in recent months alone, using ransomware developed by organised criminal groups operating franchise models: one group creates the malware; affiliates license it for a few hundred dollars; the ransom proceeds are split between franchisor and franchisee.

The parallel with the industrialisation of fraud is not coincidental. The same dark web infrastructure that sells phishing kits targeting specific banks also markets initial access to compromised corporate networks. These pre-positioned footholds allow a would-be attacker to skip the reconnaissance and initial compromise phases entirely. Criminal specialisation has reached the point where the division of labour within a cyberattack mirrors the division of labour in a legitimate technology business.

The average time between a criminal’s initial access to a network and the detonation of ransomware is 197 days. During that period, the attacker is quiet: assessing the network, mapping the backup infrastructure, identifying cyber insurance coverage, disabling protections, and waiting for the optimal moment to strike.

Getting the Basics Right

Wilkinson’s prescription was, in his own framing, deliberately unglamorous: resilience over perfection, every day, one improvement at a time.

The largest breaches, across every sector and every year, are traceable to failures of basic cyber hygiene rather than the defeat of sophisticated defences. Password reuse remains among the most exploited vulnerabilities in existence, despite the wide availability of password managers and the broad consensus that they should be used. Multi-factor authentication, deployed consistently, defeats the majority of credential-based attacks. Patch management, the process of applying software updates that organisations often defer, closes the vulnerabilities that exploit tools are designed to target.

Beyond these fundamentals, Wilkinson highlighted a category of detection tool that requires no specialist knowledge to deploy and costs nothing: canary tokens. A document is created with a tracking token embedded invisibly within it. It is left in a location a legitimate employee would have no reason to access. If the document is opened, the security team receives an immediate alert.

The same principle also extends beyond individual files. Thinkst Canaries, for example, operate as honeypots that imitate systems, services or credentials inside an environment. Their purpose is simple: create realistic assets that legitimate users should not touch, but that an attacker moving through a network may be tempted to investigate. When they do, the organisation receives a high-confidence signal that something is wrong.

In the demonstration, Wilkinson explained how he had been caught on a real engagement in exactly this way. He had gained domain administrator access to an internal server and found what appeared to be a staff password document. Opening it triggered a notification that someone with elevated access was browsing a restricted drive. The engagement was over.

The point is not that canary tokens or honeypots solve the problem. It is that the gap between a breach going undetected for 197 days and a breach being detected in minutes is sometimes a free tool and a twenty-minute setup process.

At the final stage of the attack chain, Wilkinson also pointed to Agger Labs, his own company, as an example of last-line ransomware defence. The logic is not to assume every intrusion can be prevented. It is to recognise that when ransomware does appear inside an environment, organisations need the ability to detect and kill the attack before encryption can begin or spread.

Resilience is a Practice, Not a Project

The closing argument was framed as a rejection of perfectionism. Cybersecurity investment is often conceptualised as a programme with an end state: the point at which the organisation is secure. That end state does not exist. The threat evolves continuously; the attack surface expands with every new system, every new employee and every new business relationship; and the attackers are, structurally, more agile than the defenders.

What organisations can build is resilience: the capacity to detect intrusions early, contain their impact, recover from them quickly, and learn from them systematically. Each incremental improvement, from a stronger password policy to a patched vulnerability to a simulated phishing exercise that prompts a genuine conversation, moves the needle in the right direction. None of them, individually, is sufficient. All of them, consistently practised, are the closest thing to security that exists.

For the financial crime professionals in the room, the message was pointed. The adversary who steals a billion dollars through a sophisticated social engineering campaign and the adversary who encrypts your core banking systems and demands €5 million to restore them are operating on different parts of the same infrastructure.

Understanding how both think, and deploying the same systematic, intelligence-led approach to both, is no longer a luxury.

It is the job.


This article is part of Transform Finance's coverage of the 4th Annual FinCrime Leaders Summit Europe, Amsterdam 2026.

Loading