How Teenage Hackers Targeted the CIA and Exposed U.S. Officials

A group of young hackers turned online activism into a campaign against senior U.S. intelligence officials, eventually leading to arrests, prison sentences and a massive public debate over cybersecurity and surveillance.
In 2015, John Brennan was serving as director of the CIA when his private information became the target of teenage hackers.
What followed was not a conventional cyberattack by a sophisticated criminal organization. According to the documentary account, the operation involved young hackers who used publicly available information, social engineering and access to compromised accounts to reach some of the most powerful figures in the U.S. intelligence community.
The story began several years earlier, with a teenager known online as “Default.”
From Teenager to Hacker
Around 2008, Default was described as a typical American teenager interested in soccer, video games and computers.
His interest in hacking developed gradually. He began experimenting with computers and became interested in Anonymous, the decentralized online activist movement that was particularly prominent at the time.
Anonymous attracted hackers from around the world and became associated with both political activism and disruptive online attacks. But the group was also difficult to control because of its decentralized structure, making it difficult to determine who could be trusted.
Default eventually became involved with another hacker group, described in the documentary as AnonSec.
His activities reportedly moved beyond simple experimentation.
A $9.4 Million Student Debt Database
One of the most striking incidents described in the documentary involved a compromised server belonging to a Canadian university.
Default reportedly discovered that the server provided access to financial records containing information about students who owed the university money.
The total amount listed was approximately $9.4 million.
According to his own account, he found an option that could delete the records and decided to use it. He later described accessing a PHP shell and removing the information.
The documentary notes that it was unclear whether the records remained permanently deleted, because universities typically maintain multiple backups and offline records.
The incident nevertheless demonstrated how a relatively young hacker could potentially gain access to sensitive institutional systems.
From Hacking for Fun to Political Activism
Default’s motivations reportedly changed over time.
Instead of hacking simply for the challenge, some of his later activities were politically motivated.
One campaign focused on Denmark’s laws concerning sexual abuse of animals. The hackers reportedly targeted government websites and websites connected to the practice, using cyberattacks to draw public attention to the issue.
The documentary presents the campaign as an example of how hackers could use technical skills to push an issue into the public spotlight.
But this approach also crossed a legal line: the hackers were accessing and disrupting systems without authorization.
Edward Snowden Changes the Picture
Another major influence was Edward Snowden, the former U.S. intelligence contractor whose 2013 disclosures revealed extensive details about U.S. surveillance programs.
The documentary describes Default as deeply influenced by Snowden’s revelations and the debate over government surveillance.
Snowden’s disclosures became part of a wider international discussion about privacy, government power and national security. For young hackers such as Default, the revelations also raised questions about whether governments were themselves operating beyond the limits they publicly described.
That political anger eventually brought Default into contact with another young hacker known as Kraka.
The Attack on U.S. Intelligence Officials
Kraka was a teenager in England who was reportedly angry about U.S. foreign policy and surveillance.
The hackers began targeting senior U.S. intelligence officials.
One early target was James Clapper, then the U.S. director of national intelligence.
According to the documentary, information about Clapper was gathered from publicly available sources and was then used to gain access to his communications. The hackers subsequently turned their attention to John Brennan, then CIA director.
The Brennan attack reportedly relied heavily on social engineering.
Rather than breaking through an advanced technical security system, the attacker allegedly contacted a telecommunications company’s support operation while pretending to be an employee.
The documentary says the hacker eventually obtained account information associated with Brennan and used it to gain access to Brennan’s personal email account.
The episode highlighted a basic cybersecurity problem: even strong organizations can be vulnerable when attackers exploit people and information rather than software alone.
Brennan’s Personal Information Was Leaked
Once inside Brennan’s email account, the hackers reportedly obtained his private phone number and other information.
The account was then used to obtain sensitive documents.
Among the material later published was Brennan’s SF-86 security-clearance application, a lengthy form containing highly sensitive personal information.
The documentary says the leaked material included information about Brennan’s personal history and other confidential details. It also describes the publication of government documents concerning U.S. policy and interrogation practices.
The breach became a major embarrassment for the U.S. intelligence community.
It also demonstrated that access to one personal account could potentially expose information far beyond the original target.
The Investigation Closes In
The hackers continued releasing information.
According to the documentary, they obtained access to accounts belonging to other U.S. officials and eventually gained access to databases containing personal information relating to thousands of Department of Justice and FBI employees.
But the operation eventually began to unravel.
Default had taken extensive precautions to hide his identity. However, the documentary says he eventually discussed the hacking operation with a friend while drinking and inadvertently revealed information that could identify him.
That mistake reportedly helped investigators connect him to the attacks.
When the FBI eventually raided his home, agents seized his computer equipment and hard drives.
One of those drives reportedly contained nearly 1,000 Bitcoin, according to the documentary account.
Arrests and Prison Sentences
The crackdown did not stop with Default.
Kraka was also arrested by British authorities, while other members of the group were arrested in the United States and United Kingdom.
Because Kraka was a minor, he received a juvenile sentence and spent two years in a detention facility, according to the documentary.
Default received a substantially longer sentence: five years in federal prison, along with approximately $145,000 in restitution.
The consequences demonstrated the difference between online activism and lawful political protest.
Regardless of the hackers’ stated motivations, unauthorized access to private accounts and government systems can result in serious criminal penalties.
The Bigger Question: Activism or Cybercrime?
The story raises a difficult question about where political activism ends and cybercrime begins.
The hackers described their actions as attempts to expose government surveillance, foreign policy and powerful institutions.
But the methods involved unauthorized access, theft of private information, disruption of computer systems and publication of sensitive data.
That distinction matters.
A political objective does not automatically make a cyberattack legal, just as a government security objective does not automatically resolve debates about privacy and surveillance.
The Snowden disclosures had already triggered a major public debate about government surveillance. The hacker campaign added another dimension by demonstrating how vulnerable powerful officials could become when their personal information was exposed.
A Lesson in Human Security
Perhaps the most important lesson from the story is that cybersecurity is not only about sophisticated software.
The attacks described in the documentary often depended on ordinary pieces of information: names, phone numbers, addresses, account details and information available online.
Attackers were able to combine those pieces of information and use them against their targets.
That technique is commonly known as social engineering.
It can be difficult to defend against because the weakest point may not be a computer system at all. It may be a person who receives a convincing phone call or email.
The story of Default and Kraka therefore became more than a story about teenage hackers.
It became an example of how personal information, political anger and relatively simple manipulation could combine to create consequences far beyond the internet.
And for the young hackers involved, the consequences lasted long after the attacks themselves ended.
As the documentary recounts, Default later acknowledged in court that he had believed his actions were justified politically, but eventually concluded that he had been wrong.











