Jayson Street, a 54-year-old American, exposes cyberspace vulnerabilities. Antonie Robertson / The National
Jayson Street, a 54-year-old American, exposes cyberspace vulnerabilities. Antonie Robertson / The National
Jayson Street, a 54-year-old American, exposes cyberspace vulnerabilities. Antonie Robertson / The National
Jayson Street, a 54-year-old American, exposes cyberspace vulnerabilities. Antonie Robertson / The National

Gisec 2022: Meet Jayson E Street, the ethical hacker paid to breach bank security


Sarwat Nasir
  • English
  • Arabic

Not only has Jayson E Street gotten away with breaching banks' databases, he has even hacked into the US Department of Treasury, all the while getting paid to do it.

The American, 54, is an ethical hacker, meaning he gets paid by companies to hack into their systems and expose their vulnerabilities in cyberspace.

Speaking to The National on the first day of the Gulf Intelligence and Security Expo Conference (Gisec), being held at the Dubai World Trade Centre until March 23, Mr Street told of some of his most notorious hacking jobs over the past two decades.

What I do with hacking, and what most of my fellow hackers do, is that we look to discover vulnerabilities or try to make things do something that they weren't supposed to do
Jayson E Street

“I have the luxury to be able to choose which kind of engagement I'm going to get,” he said.

“I don't usually get the boring ones. I try to go for something that is unusual or exciting, or something that I'll be able to travel and see things.”

Mr Street started hacking into banks' databases in 2010 when he was asked to help secure sensitive data on behalf of the financial institution for which he worked. Since then, he has breached bank security around the world, including in Beirut, Jordan, Jamaica and the US.

With no intention of stealing any money, Mr Street hacks into the “victim’s” system, with a message on a notepad that pops up once it is done, to show the bank their data has been compromised.

One of his most intense hacking jobs was in Kingston, Jamaica, where he pretended to be a TV producer and duped a charity organisation.

“Another company had hired me and I had a whole team of people already working on it,” said Mr Street.

“I came in to help with the security awareness side of it. I assumed the identity of a TV producer and instead of going after the main company, I went after a charity organisation that were on the same network.

“They were on the same scope as the financial institution.”

Mr Street carries out penetration tests, social engineering experiments where he walks into banks, pretends to be a customer and plugs in USBs into their computer.

This operates a code that comprises their machines, exposing just how vulnerable their digital infrastructure is.

Mr Street shows up in usual style – baggy jeans, black t-shirt and a jacket – to test if he will get caught.

But during most bank jobs, he has walked out effortlessly, carrying extremely sensitive data in his pocket.

“What I do with hacking, and what most of my fellow hackers do, is that we look to discover vulnerabilities or try to make things do something that they weren't supposed to do,” he said.

“And I always tell people – a hacker has never created a vulnerability. What they’ve done is they discovered the vulnerabilities that were there and they have reported it, so people can get it fixed.

“The criminals aren't going to report it, they're just going to exploit it.”

Mr Street said his most notorious job was when he accidentally targeted the wrong bank in Beirut.

He said he laughs about it now but it was “horrifying” at the time.

“I did rob the wrong bank. I keep trying to tell people it’s a cool story. They weren’t expecting it at all and it was like a real robbery,” he said.

“I didn’t see what bank I was going into and I did manage to 'rob' it.”

One of his most successful hacking jobs, he says, came when he went back to a company that he had hacked before to see if they had taken his advice on how to protect their data.

He rehacked the company in 2020 to see if their digital infrastructure was still vulnerable a year after “stealing” their intelligence.

“I had 'robbed' them the year before and we went through educational process. The upper management was so shocked by what I did, they took it seriously,” he said.

“They educated their employees and the CEO talked about it in their yearly meeting.

“I came back next year and I did compromise them but not as successfully as I did before.

“I did get into every department but at some point, I did get caught.”

Tips to keep your car cool
  • Place a sun reflector in your windshield when not driving
  • Park in shaded or covered areas
  • Add tint to windows
  • Wrap your car to change the exterior colour
  • Pick light interiors - choose colours such as beige and cream for seats and dashboard furniture
  • Avoid leather interiors as these absorb more heat
French business

France has organised a delegation of leading businesses to travel to Syria. The group was led by French shipping giant CMA CGM, which struck a 30-year contract in May with the Syrian government to develop and run Latakia port. Also present were water and waste management company Suez, defence multinational Thales, and Ellipse Group, which is currently looking into rehabilitating Syrian hospitals.

Closing the loophole on sugary drinks

As The National reported last year, non-fizzy sugared drinks were not covered when the original tax was introduced in 2017. Sports drinks sold in supermarkets were found to contain, on average, 20 grams of sugar per 500ml bottle.

The non-fizzy drink AriZona Iced Tea contains 65 grams of sugar – about 16 teaspoons – per 680ml can. The average can costs about Dh6, which would rise to Dh9.

Drinks such as Starbucks Bottled Mocha Frappuccino contain 31g of sugar in 270ml, while Nescafe Mocha in a can contains 15.6g of sugar in a 240ml can.

Flavoured water, long-life fruit juice concentrates, pre-packaged sweetened coffee drinks fall under the ‘sweetened drink’ category
 

Not taxed:

Freshly squeezed fruit juices, ground coffee beans, tea leaves and pre-prepared flavoured milkshakes do not come under the ‘sweetened drink’ band.

UPI facts

More than 2.2 million Indian tourists arrived in UAE in 2023
More than 3.5 million Indians reside in UAE
Indian tourists can make purchases in UAE using rupee accounts in India through QR-code-based UPI real-time payment systems
Indian residents in UAE can use their non-resident NRO and NRE accounts held in Indian banks linked to a UAE mobile number for UPI transactions

THE BIO

Ms Davison came to Dubai from Kerala after her marriage in 1996 when she was 21-years-old

Since 2001, Ms Davison has worked at many affordable schools such as Our Own English High School in Sharjah, and The Apple International School and Amled School in Dubai

Favourite Book: The Alchemist

Favourite quote: Failing to prepare is preparing to fail

Favourite place to Travel to: Vienna

Favourite cuisine: Italian food

Favourite Movie : Scent of a Woman

 

 

How does ToTok work?

The calling app is available to download on Google Play and Apple App Store

To successfully install ToTok, users are asked to enter their phone number and then create a nickname.

The app then gives users the option add their existing phone contacts, allowing them to immediately contact people also using the application by video or voice call or via message.

Users can also invite other contacts to download ToTok to allow them to make contact through the app.

 

TICKETS

Tickets start at Dh100 for adults, while children can enter free on the opening day. For more information, visit www.mubadalawtc.com.

Updated: March 21, 2022, 4:19 PM