In a world of digitization, hackers are the new bank robbers
Published at | Updated at
IDAHO FALLS (Courtroom Insider) — The early 20th century is often depicted as the height of kidnappings and bank robberies — and rightfully so. The era is ripe with stories of notorious criminals like John Dillinger and Machine Gun Kelly.
Dillinger, a bank robber from Indiana, proved so hard to catch that he, in part, prompted the evolution of the Bureau of Investigation into the FBI we know today. And Machine Gun Kelly, a man from Houston best known for kidnapping and ransoming an oil tycoon, got his nickname from his liberal use of a “Tommy Gun.”
Both men are still listed on the FBI’s website today, showing how their stories live on even decades after their crime sprees were put to an end.
These mega criminals might seem like characters of the past. However, as the world around us has digitized, criminal trends have followed suit. Instead of bank robbers, we have hackers today. Instead of millionaires being kidnapped and ransomed, cybercriminals are stealing millions of people’s personal data and holding it for ransom.
It was technology that helped end the golden age of bank robbery — with surveillance cameras, alarms and the shift from physical currency to digital currency combining to make bank robbing a high-risk endeavor with relatively low reward.
Now, however, the rise of the digital world has spawned a new era of digital criminals.
According to a 2025 report from the Identity Theft Resource Center, the frequency of data breaches and other incidents of cybercrime is sharply increasing and is expected to become more prevalent with the introduction of artificial intelligence.
A report by Axis Intelligence found that in 2025, there were over 297 million victim notices of data breaches. By August of this year, there had already been 471 million victim notices — nearly twice the amount in nearly half the time.
It’s all in a name
The largest contributor to those 471 million victim notices was the Canvas data breach on May 12 of this year. Personal data belonging to an estimated 275 million students, teachers, and other staff was stolen in a breach conducted by a group that calls itself “ShinyHunters.” The breach reportedly involved approximately 9,000 schools and colleges.
Many modern hacker groups have given themselves names and identities, the most famous likely being “Anonymous.” This group is known for using the Guy Fawkes mask as its symbol. In many ways, this labeling is similar to that of criminals in the past who created personas to elevate their fame.

Look at Machine Gun Kelly, for example. According to Biography, it was Kelly’s wife who got him the Tommy Gun and gave him the nickname. She even went so far as to hand out bullet casings to people as souvenirs — and it worked. Everyone knows Kelly’s nickname, but no one knows his real name anymore (it’s George Kelly Barnes, btw.)
The name ShinyHunters itself is directly tied to Pokémon culture. In the card game, special, rare cards are referred to as “shiny.” Collectors looking for those rare cards, specifically, are “shiny hunters.” The hacker group took the name and the obsession normally reserved for card collectors and applied it to seeking out targets to extort, according to Secure.
Playing ‘cat and mouse’
The ShinyHunters hacker group is also known for finding a target, stealing its personal data, and then ransoming that data back to the target. But even when ransom is paid, the group is known to publish the stolen data anyway.
Secure says multiple organizations targeted by ShinyHunters in the past have paid the demanded ransom only to have their data leaked, regardless. These acts have given the hacker group a reputation for noncompliance with even the group’s own terms.
When ShinyHunters breached Canvas in May, it adhered to its established methodology. According to Cyber Magazine, on May 7, the Canvas login page had a new message, straight from ShinyHunters, which read: “ShinyHunters has breached Instructure (again). Instead of contacting us to resolve it, they ignored us and did some ‘security patches.’”
That’s right, this latest breach was the second time Canvas’ parent company had been hacked by ShinyHunters.
This kind of overt, almost teasing messaging — ala the idiom “a game of cat and mouse” — is not far off from the actions of some of history’s most infamous criminals and their taunts directed at law enforcement.

The Indiana State Police website includes some examples of taunts Dillinger aimed at Capt. Matt Leach. In one instance, Dillinger reportedly called Leach, saying, “You almost surprised me in Gary (Indiana), gumshoe.” In another instance, Dillinger reportedly sent a book titled “How to be a Detective” to Leach in the mail, and postcards that said, “Wish you were here.”
According to Tech Insider, Canvas’ parent company, Instructure, paid the ransom. No amount was officially disclosed, but the outlet says rumors circulated that it was as much as $10 million.
ShinyHunters reportedly returned the data they’d stolen, but the hacker group likely recorded it and made alternate copies.
Tech Insider also reports that the FBI specifically advises victims of data breaches not to pay ransoms, as doing so encourages future data breaches.
A Robin Hood-like motive
Not every hacker group is perusing the internet looking for the next opportunity to steal your personal data and sell it back to you. Some cite ethical or moral reasons as the cause for their actions.
Cyberleek, for example, claims it has been stealing and leaking footage of Rockstar’s upcoming Grand Theft Auto 6 as a response to the gaming industry’s “degradation through monetization,” Dexerto reports.
There were bank robbers who also took an ethical angle to justify their crimes (or at least make themselves popular with the public). According to Biography, Pretty Boy Floyd — whose actual name was Charles Arthor Floyd — is rumored to have burned the mortgage papers of banks he robbed, in theory freeing the debtors from their debts.

Floyd was also known for sharing the money he stole with locals, which in 1930’s America, still reeling from the Great Depression, made him a very popular man. Oklahoma locals reportedly dubbed him “The Robin Hood of Crooked Point.”
Likewise, CyberLeek sees itself as an organization sticking up for the little guy. However, while Floyd made it seem like he was looking out for the forgotten lower class, Cyberleek says it’s fighting against paid DLC (extra video game content locked behind a paywall, for you non-gamers) that should be available in the base game.
It’s an issue that gamers have been complaining about for years. Ask any one of them, and they’ll tell you the frequency of DLC being released and the price of DLC have both steadily increased over the years. (To any gaming CEO out there reading this, toss this poor game-loving journalist a bone and hook me up with some free stuff. Thanks in advance.)
According to Dexerto, it is unknown whether Cyberleek is a single person or a group. Unlike ShinyHunters, it’s not seeking any sort of ransom or other compensation.
Cyberleek also vows to target companies it perceives as damaging to the gaming industry as a whole. This sets it apart from both bank robbers and hacker groups like ShinyHunters, whose primary goal is personal profit. Even Pretty Boy Floyd was ultimately just in the game (is that a pun? wordplay?) for the money.
The ‘golden age’ of getting away with it
The 1920s and 1930s are widely known as the golden age of bank robberies and kidnappings for ransom, but it’s hard to say whether we’ve entered a golden age of cybercrime.
The bank robbers of the past were largely able to get away with their crimes because, as long as they weren’t still at the bank when police arrived, it was difficult for law enforcement to track these criminals down.
Tracking down today’s hacker groups is just as difficult, if not more so. Remember, authorities still haven’t been able to determine whether Cyberleek is a single person or a collective, let alone identify the perpetrator(s).
The cybercriminals involved in these international groups are good at masking their identities. Hackers can use VPNs (virtual private networks) and proxy servers to hide their locations and identities. By utilizing multiple VPNs and chains of these proxy servers, Security Investigation reports hackers are able to remain anonymous.
Investigators trying to identify hackers have to focus on more abstract means, such as pattern recognition. For example, if a user logs on to a server from multiple countries within a short time period, investigators can conclude that the hacker is likely using VPN or proxy services to “bounce” their IP address around, making them more difficult to track.
Hiding one’s identity by bouncing one’s IP address around the world is like a more abstract version of how 1930’s bank robbers avoided police. For example, Dillinger (I know, I’ve talked about him a lot, but he was kind of a big deal) fled across the country. According to Britannica, he moved frequently to avoid police — from as far north as Wisconsin to as far south as Florida. At one point, he’d left Indiana and ended up all the way over in Tucson, Arizona.
Hackers are able to do essentially the same thing in the digital world, moving their IP addresses faster than police can keep up. But they have one major advantage compared to the bank robbers of the past: a bank robber had to physically be at a bank to hold the place up (obvious, I know). Hackers, on the other hand, can strike from anywhere they can get a connection.
So, if the golden age of bank robberies largely stemmed from law enforcement’s inability to stop them, the idea that we are already in a golden age of cybercrime doesn’t seem too far off.
Differences, and where do we go from here?
While there are many similarities between early 20th-century criminals and today’s cybercriminals, it is important to note at least one stark difference between the two groups.
The vast majority of 1930s bank robbers were exceptionally violent. All three of the bank robbers referenced in the article were known killers. (I mean, you don’t get a name like “Machine Gun Kelly” by handing out cupcakes at your local grocery store.) All three of the men named also met violent fates, and they took a lot of innocent people down with them.
Hackers, by contrast, rarely get caught. But when they do, it doesn’t typically end in a shootout with federal agents.
That said, while hacker groups aren’t shooting people in the streets, the economic cost of their actions can be massive when you take into account ransom payments and the costs of maintaining and developing security networks. Not to mention, hackers could cause real, tangible damage if they targeted health care networks or the power grid.
This article is not meant to minimize the damage caused by men like Kelly, Dillinger and Lloyd. But if you take anything from this reading, I hope it’s this: Cybersecurity is a big deal, and with how rapidly our lives are moving into the digital space, it’s only going to become an even bigger issue.
According to the Federal Trade Commission, there are a few things the average consumer can do to protect his or her data.
First, the FTC advises keeping your software up to date. Software updates frequently include security patches that help counter the latest cyber threats. The agency also recommends securing your home Wi-Fi network, using two-factor authentication whenever possible, and staying aware of phishing attempts. Taking these steps can help ensure your data remains safe.
In March, President Donald Trump signed Executive Order 14390, which focuses on combatting cybercrime. The federal government works with various private companies to help detect and combat cybercrime, with efforts under the umbrella of the National Coordination Center.
The Department of Justice also has a section of the Criminal Division specifically focused on cybercrime, called the Computer Crime and Intellectual Property Section. By combining the efforts of local, state and federal agencies with private companies, the government is able to better identify, track and eventually prosecute cases of cybercrime.
To learn more about what the U.S. government is doing to identify and catch cybercriminals, visit the FBI’s cyber webpage. You can also find educational materials to keep yourself and your loved ones safe from cybercriminals at fbi.gov/how-we-can-help-you.

