London24NEWS

Astonishing inside story of the £100million heist of the century: How a infamous gang of robbers – dressed as cops and with their pet alsatian Buster in tow – infiltrated a fortress-like knowledge centre to hold out the ‘prison Mount Everest’…

Like all self-respecting career criminals, Terry Ellis started stealing during his childhood, when he and his friends in working-class Camden Town would jump on to slow-moving freight trains and loot their radio sets.

Later, he graduated to robbing post offices with a sawn-off shotgun, smuggling cannabis across Spain and selling cocaine to north London celebrities.

However, Ellis, whose father was also an armed robber, always hankered for a greater challenge – ‘to take the art of robbery to the next level’ as the cockney bandit so poetically put it.

And in 2007, after several spells in prison, he fulfilled that ambition with a job he’d later modestly call his ‘criminal Mount Everest’.

It involved getting in (and out of) a huge, fortress-like data centre operated by international telecoms giant Verizon in King’s Cross and stealing Pentium computer chips worth £5 million. However, the data stored on those chips was worth far more – £100 million, says Ellis – as it contained immensely sensitive banking information, wanted by the shady ‘banking syndicate’ that commissioned the robbery.

It was a challenge that certainly deserved comparison to scaling the world’s highest mountain, involving as it did getting past eight levels of security.

The brains-over-brawn heist that Ellis and his fellow robbers pulled off involved fake police uniforms, cars and dogs, not to mention shocking amounts of bravado and sang-froid.

No wonder it was dubbed the Ocean’s Eleven robbery by a gobsmacked media after the star-studded 2001 caper film about an ingenious $160million (£120million) casino heist.

Terry Ellis started stealing during his childhood before he went on to fulfil his ambition with a job he¿d later call his ¿criminal Mount Everest¿ ¿ robbing telecoms giant Verizon

Terry Ellis started stealing during his childhood before he went on to fulfil his ambition with a job he’d later call his ‘criminal Mount Everest’ – robbing telecoms giant Verizon

The heist involved getting in (and out of) a data centre operated by international telecoms giant Verizon in King¿s Cross ¿ a site that backed on to Regent's Canal

The heist involved getting in (and out of) a data centre operated by international telecoms giant Verizon in King’s Cross – a site that backed on to Regent’s Canal

Now, the real story of the elaborate King’s Cross crime has inspired a novel, Cloudthief, by award-winning US writer Nathaniel Rich, which revolves around an unlikely duo who team up to steal data of immense value from a huge and inadequately-protected data centre in Tulsa, Oklahoma.

In the 19 years since the Verizon heist, data centres have become perhaps the biggest single engine of growth in the global economy, not only storing everything on the internet but also powering the vast computations of the artificial intelligence industry.

Everybody knows about them today, but in December 2007 data centres were largely a mystery to the general public, who knew little about these huge, anonymous buildings beyond the obvious fact that they had an awful lot of security.

And the three-floor, two-acre Verizon complex, which backed on to Regent’s Canal along St Pancras Way, needed to be especially secure. Unlike other data centres even at that time, it stored data that wasn’t backed up anywhere else, as is the standard security protocol these days. Perhaps its owners assumed that nobody could possibly get past its daunting defences. This was certainly the conclusion initially reached by the swaggering Ellis and his cronies, as he admitted in a 2023 memoir.

Ellis is now a reformed character after a stint at Britain’s only therapeutic prison, HMP Grendon in Buckinghamshire, which offers group therapy sessions.

He revealed in the book how he was approached by a ‘fixer’ acting on behalf of a group of dodgy bankers in the US who wanted to erase evidence of their illegal involvement in funding construction projects in Ireland. Ellis believes the group was linked to the so-called subprime mortgage disaster that sparked the world financial crisis less than a year later.

The heist – which Ellis and the syndicate’s fixer ‘Ray’ discussed over coffee and cakes in a cafe overlooking Hampstead Heath – necessitated getting ten people into the building. Ellis and his four criminal confederates knew very little about computers, so four shady technicians had to join them. Their paymasters insisted that a tenth man, who knew how to find and extract the data they were targeting, should go along too.

Their task was to remove 80 servers that held the data, disable them without destroying the contents and then spirit them away to safety. They would be paid a total of £1.5million (the equivalent of £3.6million today) for a night’s work, which sounded less generous when they learned that three previous attempts to get hold of the data had failed.

The elaborate King¿s Cross heist inspired the novel Cloudthief by US writer Nathaniel Rich

The elaborate King’s Cross heist inspired the novel Cloudthief by US writer Nathaniel Rich

The information contained on the chips ‘can’t fall into the hands of the FBI or ever see the light of day’, the fixer told Ellis, according to his memoir, as the consequences would be ‘catastrophic not just to my people but the banking industry in general’. And it needed to look ‘like just another opportunist robbery’, he added.

That last proviso seemed faintly ludicrous given all the security that they’d have to get past. First, there was the building’s outer perimeter, which was patrolled around the clock by security guards, ringed by security cameras and regularly checked by police. Every 20 minutes, the front entrance would automatically light up ‘like a Belisha beacon on a zebra crossing’.

Every door was reinforced with steel, opening outwards to make it harder to force it open. All the exit doors only opened from the outside and each was monitored by cameras. The exterior windows were sealed shut. All the glass – inside and out – was bullet-proof.

First, visitors had to get past a swipe-card entry system, which also conducted a biometric hand scan, before they could get inside.

The next hurdle was a ‘thermostatic pressurised airlock vestibule’ 13ft long by 8ft wide, in which the reinforced door at one end couldn’t be opened until the other had closed – effectively trapping any intruder.

After that was another turnstile which opened into a foyer, with a uniformed guard stationed there continuously behind bullet-proof glass. He buzzed approved visitors through a third turnstile to another door, which was monitored by a CCTV suite operated by three more guards in what was the security control room. Each of them had a panic button that could summon help from any one of three police stations within a mile radius. A six-strong team of guards patrolled the hundred or so rooms in the rest of the building.

Even if the intruders got past all that, CCTV in the computer data rooms was remotely monitored by an external private security company. Discovering this last snippet of information in advance, Ellis admits, proved crucial.

He and his associates didn’t believe in carrying guns as this would significantly increase their prison time if they were caught. If they needed to resort to violence, they would rely instead on their kickboxing expertise. Either way, trying to muscle their way in seemed like a recipe for disaster.

From inside a British Telecom van they had bought at auction and parked outside, they spent weeks surreptitiously watching the building. But after logging the movements of security guards and cleaners in and out of the building and assessing the field of view of the battery of CCTV cameras, they despaired of finding a weak point in the defences.

One of them did manage to get on to the roof after swimming across Regent’s Canal and exploiting the cameras’ single blind spot, but was unable to get any further.

Ellis was on the point of calling it all off when, one weekend, he was at a friend’s flat and the street outside was suddenly blocked off by police. They had spotted a man on the roof of a library and were worried he was going to jump. The incident gave Ellis an idea.

The gang duly obtained five sets of brand new police uniforms and radios, as well as a fluorescent dog-handler’s jacket for the team member who would handle Buster, an alsatian they borrowed who was ‘as big as a barn door’ and whose bark was ‘menacingly loud’. They also bought a police van and car from a film-props company.

A court heard that the robbers had attacked several members of staff, some of whom needed treatment for shock after being threatened with the snarling dog

A court heard that the robbers had attacked several members of staff, some of whom needed treatment for shock after being threatened with the snarling dog

Given that the Verizon security guards had to clock on at certain points as they patrolled the building or else an automatic alarm would go off, the thieves calculated that they should try to get into the data centre and out again within an hour.

Just after 9pm on December 6, 2007, they sprang into action. Their police vehicles skidded to a halt outside the Verizon front entrance as another car – containing the computer technicians – pulled up behind, helping to hide the other vehicles from real police passing on the main road. Five uniformed ‘police officers’ – Ellis and his crew – and their dog Buster jumped out.

Spotting four security guards through the glass, Ellis buzzed the intercom and ordered them to open the door. The chief guard asked what was going on. ‘We have had a report that someone is up on the roof. We’re a fast-response robbery squad and we need to get access to the building,’ he said, holding his police ID to the camera.

As the guards continued to hesitate, he banged on the window, angrily demanding that they ‘open the f***ing door’. This had the desired effect and they were allowed in.

When they got as far as the security control room, where three guards sat behind the camera monitors, Ellis asked if any of them had been on the roof in the past hour. After they all denied they’d done so, Ellis said he had to go up there immediately but first he insisted on handcuffing the guards as police had been told that the intruder was dressed as a security guard. He had to be sure who everyone was before they could be released, he explained.

The guards obliged, even agreeing to call down three guards patrolling the second floor so they could be handcuffed, too. ‘They – like the other guards – looked perplexed but they all reluctantly complied,’ writes Ellis. ‘But not before I had to threaten them all with the dog, which thankfully did the trick.’ Leaving the handcuffed guards in a stairwell, the gang then let the computer technicians and the tenth team member into the building while Ellis and a confederate headed to the top floor where they knew two more security guards lurked.

They rapidly cuffed them, too, Ellis ‘whacking’ one of them against a wall and pushing him to the floor after turning a corner and almost bumping into him.

He then returned to the front desk and cut the live feed from the CCTV cameras. Just seconds later, the private security company monitoring the feed called the data centre to ask what had happened. There’d been a power surge in the computer system which had knocked out all their monitors, Ellis – pretending to be Verizon security – told the caller.

Their technicians were already working on it and the system would be up and running again within the next 40 minutes, Ellis assured him.

The caller appeared to accept the explanation, although a sweating Ellis – who’d considered this moment about the riskiest part of the heist because he didn’t know whether he was supposed to give the caller a code to prove his credentials – was aware the man to whom he’d been speaking could have called the police.

I know why Jack the Ripper was protected for so long

 

Hi, I’m Alex Matthews, Editor of The Crime Desk.

In 2014, we revealed the bombshell evidence identifying Aaron Kosminski as the fabled Jack the Ripper. Now, we can reveal his astonishing connection to the Freemasons and claims this motivated his killings and protected him from life in prison. 

Sign up here to get our exclusive piece for free.

But they pressed on, the technicians using the security guards’ ID cards to access the top-floor data room – room 992 – where, using battery-operated screwdrivers, they disconnected the targeted computer servers and stored them in 20 large laundry bags they’d brought with them.

Meanwhile, the others swept the complex for any remaining staff, handcuffing two technicians and four cleaners they found – bringing the grand total of subdued occupants to 16.

Suddenly, the team member at reception radioed to say that two men had come to the front entrance. But they were only technicians coming in to work and they didn’t spot anything amiss as they headed to a third-floor room – which was fortunate for the thieves as they’d run out of handcuffs and would have had to tie the newcomers’ hands with shoelaces.

They were out of the building at 10pm and, just as they passed a nearby police station, ‘all hell broke loose’ as a convoy of a dozen police vehicles, sirens blaring, hurtled off in the direction of the data centre, alerted automatically – the thieves assumed – by the alarm system.

‘Blue lights were flashing all down Kentish Town Road and for a second I thought they were on to us,’ Ellis recalls in his book, The Art Of Robbery. ‘My stomach was doing somersaults, I could hear the dog barking in the back.’

In fact, they were home and dry. Unfortunately for Ellis and his second-in-command Denis Carr, their celebrations were short-lived. The Verizon security guards identified them from photos shown to them by police investigating another robbery.

Ellis, who’d had the nerve to rent a canal boat and live for three weeks on the Regent’s Canal right behind the data centre as police searched for them, was arrested in September 2008, surrounded by police on the street as, armed with a new passport, he headed towards Luton airport to fly to a hideaway in Thailand.

He served nearly eight and a half years in prison for the Verizon heist and three other robberies. The court heard the robbers had attacked several members of staff and some needed treatment for shock after being threatened with the snarling dog.

Ellis claims MI5 twice visited him in prison, offering to have his sentence reduced to three years if he identified who had recruited him to steal what they called ‘highly sensitive banking data’ and reeling off a string of US and UK banks to him as possibilities.

The data centre’s owners at the time underplayed the robbery because, say Ellis and others, they were reluctant to admit that the data was vulnerable to determined criminals. Experts say that, as data centres have spread across the world, the issue of how secure they are has never been more relevant.

None of the Verizon computer servers have ever been recovered, nor has anyone but Ellis and Carr ever been prosecuted.

‘I’m not going to defend what I did,’ said Ellis in a 2023 interview in which he couldn’t hide his pride that they pulled it off. ‘There’s always victims in this. I’m not going to say that the banks steal millions off of people and that justifies me doing it. It was just a job, and my job was crime.’

  • To read about Jack the Ripper’s astonishing link to the Freemasons and a chilling cover up sign up to The Crime Desk newsletter HERE 
  • What kind of cases do you want to read more about? Let us know at: [email protected]