Phineas Fisher: The Hacker Who Took Down Spyware Firms
28 Jul 2026
The hacker who humiliated spyware makers and was never caught
Since August 2014, a hacktivist known only as Phineas Fisher has repeatedly breached companies and organizations tied to surveillance, policing, and political power — and has never been identified.
How it started
Phineas Fisher first surfaced in August 2014, announcing a hack of Gamma Group, the maker of FinFisher spyware, via a Twitter account called @GammaGroupPR. That breach set the pattern for what followed: a string of politically charged hacks targeting organizations Phineas Fisher viewed as complicit in surveillance or authoritarian abuse.
The Hacking Team breach
The most damaging hack targeted Hacking Team, an Italian startup that built spyware tools. Phineas Fisher stole more than 400 gigabytes of data from the company. Italian authorities investigated the breach but their probe ended without identifying the hacker. Years later, Hacking Team's CEO, David Vincenzetti, was forced to sell the company — a consequence the report links directly to the breach's fallout.
A pattern of targets
According to the report, Phineas Fisher also hacked:
- The union representing the Mossos d'Esquadra, Catalonia's police force
- The ruling party of Turkish president Recep Tayyip Erdoğan
- Cayman National Bank's Isle of Man branch, in 2016
Proceeds from these actions weren't kept quiet either — Phineas Fisher donated at least $10,000 in Bitcoin to Rojava, though the report notes it's unclear how or why that recipient was chosen.
A bounty for hacktivists
Phineas Fisher went on to announce a "Hacktivist Bug Bounty Program," designed to reward other hacktivists for exposing companies engaged in illegal or unethical activity. In their own words: "I look for illegal ways to make money in order to free my time so I can do something useful with it."
On the question of identity, Phineas Fisher has been deliberately evasive, saying: "Everything I say that contains clues about my identity is half trolling. I'm in the habit of saying misinformation." Whether Phineas Fisher is one person or a group remains unknown.
Why founders should care
For early-stage founders — especially those building in security, data, fintech, or gov-tech — this case carries several probabilistic warnings:
- Companies handling sensitive surveillance, policing, or citizen data may be more likely to become targets for politically motivated breaches, particularly if their products or business model are seen as ethically contentious.
- The fact that Italian authorities' investigation into the Hacking Team hack ended without identifying the perpetrator suggests that law enforcement may have real limits in tracing sophisticated, motivated attackers — meaning founders likely can't rely on eventual prosecution as a deterrent.
- A large breach can trigger lasting business damage well beyond the initial incident: Hacking Team's CEO was reportedly forced to sell the company years after the hack, suggesting reputational fallout from a breach may compound over time rather than fade.
- The existence of a "Hacktivist Bug Bounty Program" signals a possible emerging trend of activist-driven security scrutiny — startups in ethically sensitive spaces may increasingly need to anticipate scrutiny not just from regulators or competitors, but from ideologically motivated hackers.
The bigger picture
The report offers no details on how the bug bounty program is funded or administered, nor any confirmation of legal or financial consequences Phineas Fisher may have faced. What is clear: a decade after the first breach, the hacker's identity remains unknown, and the operational and reputational risks illustrated by these cases remain instructive for any founder building in sensitive data or surveillance-adjacent spaces.