In the United States (and in other countries too), it's very common to see certain prisons with special programs aimed at "rehabilitating" inmates, but at the Marion Correctional Institution in Ohio, it backfired. Five convicts were part of an operation that led to the assembly of two hidden computers in the facilities, and the laying of a significant amount of cables that allowed them to connect to the prison's local network using stolen credentials.

Inmates Built Two Hidden PCs and Connected to the Prison Network
Prison

Imagine a group of inmates carrying computer parts more than 300 meters inside a prison without any security check. Now imagine them reassembling those computers and installing enough cabling to connect to the prison's local network. It sounds like something out of a TV show, but that's exactly what happened at Marion Correctional Institution in Ohio. The five inmates involved were part of the so-called "Green Initiative" within the institution, and one of their activities was the complete recycling and dismantling of obsolete computers.

Inmates Built Two Hidden PCs and Connected to the Prison Network
Part of the installed cables. Someone was busy...

The Investigation

According to the official report published by the Ohio Inspector General's Office (50 pages, but worth reading entirely), the investigation began in August 2015. The inmates managed to access the local network using stolen credentials from one of the guards, and while connected, they didn't sit idle. Forensic analysis of the hard drives detected activities such as credit card scams, identity theft, and several forms that were supposedly to be used in tax fraud. Add to that adult content, an email spammer, passes to restricted areas of the prison, instructions for making drugs and homemade explosives, access to the Tor network, proxies, VPN, VirtualBox with a Kali Linux image, TrueCrypt, and a copy of Wireshark.

Inmates Built Two Hidden PCs and Connected to the Prison Network
Nothing better than a "web" to hide a couple of computers... right?

How They Were Caught

The inmates were caught because they didn't know when to stop, and they didn't hide their tracks well either. The IT department noticed that one of the terminals was exceeding the daily access limit by a huge margin, and after analyzing logs they discovered that the affected guard's credentials were used even on days when he wasn't working. This automatically expanded the investigation, leading to the discovery of the two hidden computers in the ceiling of a training room. What most surprised Inspector General Randall Meyer is the way all safety protocols failed, especially in not tracking the movement of parts through the prison. The inmates have already been transferred to other facilities.

Source: