The hacker who humiliated spyware makers and was never caught

Some hackers get caught. Some get famous. Phineas Fisher managed both, without ever being identified. A decade after their most consequential hack, the person behind that name is still out there, still in contact with journalists, and still completely unknown to law enforcement.

According to TechCrunch, Phineas Fisher is the subject of renewed attention as part of a series on cybersecurity’s biggest unsolved mysteries. And this particular mystery matters beyond the drama of an anonymous hacker on the run. Their targets were spyware companies that sold surveillance tools to authoritarian governments, and the damage Phineas did to at least one of them was permanent.

The biggest hit came in 2015. Phineas hacked Hacking Team, an Italian firm that had essentially commercialized government spyware and helped turn it into a global industry. The breach pulled out more than 400 gigabytes of material: source code, tens of thousands of internal emails, customer lists, and confidential contracts. Journalists used the leaked data to expose surveillance scandals in Ecuador, Mexico, and Panama. Years after the breach, Hacking Team’s CEO David Vincenzetti was forced to sell the company for one euro. One euro. The firm that helped pioneer the market that eventually produced NSO Group and its Pegasus spyware effectively collapsed because of a single hacker.

Before Hacking Team, Phineas first appeared in August 2014, hacking Gamma Group, the company behind FinFisher spyware. They created a fake Twitter account called @GammaGroupPR and dumped stolen files, including mobile spyware code, product manuals, and pricing. It was cheeky and pointed. Then they published a postmortem that read as much like a leftist political manifesto as a technical write-up, and disappeared.

The targets that followed were consistent with a clear ideological pattern. Phineas hacked the union of the Mossos d’Esquadra, Catalonia’s police force, and posted a 39-minute tutorial video explaining how they did it. They also hit the ruling party of Turkish president Recep Tayyip Erdogan, motivated, they said, by solidarity with Rojava, the autonomous leftist region in northern Syria that Turkey was attacking. Their last known hack was against Cayman National Bank’s Isle of Man branch. Phineas stayed quiet about it for three years, then announced a “Hacktivist Bug Bounty Program” to reward people who expose corporate wrongdoing. They also confirmed they had been hacking multiple banks for years and had donated at least $10,000 in Bitcoin to Rojava.

That was the last public appearance. Both their Twitter and Reddit accounts are gone. Italian authorities investigated the Hacking Team breach and found nothing linking it to a real identity. FinFisher, according to a former employee, never even contacted law enforcement.

So what do we actually know about who Phineas Fisher is? Not much that can be verified. They have referenced Spanish-speaking anarchists, wrote the Hacking Team postmortem in Spanish, and followed Latin American leftist accounts online. But they have also told journalists directly that their first language is neither English nor Spanish, and that they deliberately sprinkle their public statements with misinformation. “Everything I say that contains clues about my identity is half trolling,” Phineas said. That is not a person making the investigator’s job easy.

Some have speculated the persona could be a cover for a state actor, possibly Russia, which has a history of using hacktivist fronts to obscure its own operations. But the targets don’t fit that theory well. Russia has no obvious motive to destroy Hacking Team or expose surveillance abuses in Latin America. Phineas has denied the Russian connection, for whatever that denial is worth.

It’s also possible the persona was passed between different individuals over the years. But there is no evidence for that either. What is confirmed is that Phineas is still alive and reachable. The journalist behind this reporting has been in contact with them within the last two years.

The deeper story here isn’t really about one mysterious hacker. It’s about what the spyware industry looked like before Phineas tore into it, and what followed. Hacking Team’s customer list showed that repressive governments around the world were buying tools to spy on journalists, activists, and dissidents. The leak created real accountability, briefly. The industry then regrouped, got bigger, and kept selling. NSO Group eventually became the name everyone knows. So while Phineas may have ended one company, the market they helped build carried on just fine.

That’s the uncomfortable truth sitting underneath the legend of Phineas Fisher. The hacks were real, the impact was real, and the person behind them is still free. But the surveillance industry they targeted is also still very much operational.