What is Motivating the Hacker Cracking Pakistan’s Biggest Banks? (INTERVIEW)
A couple weeks ago, a Pakistani hacker named “Xploiter” hacked several of the databases of HBL, Pakistan’s largest bank. Last week, he and another hacker defaced the website of Allied Bank, another major banker in the region.
I was interested in what would inspire a person to do this sort of thing. I know many hackers claim they’re just pointing out security flaws, and in fact Xploiter claimed as much in the Allied Bank website defacement, where he or his cohort wrote:
We were focusing on Security Leaks to make Pak Banks Secure But some kids said our leaks are fake So we Defaced!
But I wasn’t convinced that was the full story, so I went looking for Xploiter shortly after news of the first hack broke. He was not difficult to find, and it turns out the second half of the statement above might be more revealing in terms of his motivations than any explanations about his desire to promote Pakistan’s web security.
Xploiter told me quite directly that the reason he hacked HBL — the second hack hadn’t yet happened when we spoke — was that a member of the bank’s IT team was antagonizing him on Facebook, implying that he didn’t have the skills to penetrate the bank’s servers and saying “I am in 2030.” You can read a snippet of that conversation here, though I have no way of knowing if it has been edited or what was said before this section as Xploiter’s Facebook appears to have since been taken down. In this conversation, Xploiter is using the pseudonym “Escobar Pablo”.
In fact, that sort of challenge is also what got Xploiter into hacking in the first place. He told me that when he was younger he got into a disagreement with a website admin who then banned him from chatting on the site. Xploiter promised to hack his computer as revenge, and though it took him seven months, he eventually did.
If anything, then, the lesson behind these hacks is probably “don’t antagonize hackers” rather than anything else. If HBL learned anything specific about the vulnerabilities of its website it seems to have been only tangential to Xploiter’s main goal of humiliating his adversary on HBL’s IT team and proving his own skills. His motivations are certainly juvenile, but you have to wonder why any IT security professional would be dumb enough to get pulled into a pissing contest with a hacker. So in case anyone needed a reminder: don’t touch fire unless you want to get burned.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




