
The story of Phineas Fisher, the elusive hacktivist who breached Gamma Group and Hacking Team, leaking 400GB of data and exposing global government surveillance. Learn how they did it, why they've never been caught, and the lasting impact on the spyware industry.
In July 2015, the cybersecurity world was rocked when over 400GB of internal data from Hacking Team, a notorious Italian spyware vendor, was leaked online. The perpetrator claimed responsibility under the alias Phineas Fisher, a self-described hacktivist who had already breached another spyware firm, Gamma Group, a year earlier. The leaks exposed a global network of government clients spanning more than 40 countries, detailed financial records showing 70% of revenue came from government contracts, and proof of complicity in targeting journalists and activists. But perhaps the most astonishing part remains that despite a $10,000 bounty and decade-long international investigations, Phineas Fisher has never been identified or arrested—as of 2025, the count of successful identifications stands at zero, cementing Fisher as one of the most elusive figures in cybersecurity history.
Phineas Fisher first emerged in August 2014 with a Pastebin manifesto following the Gamma Group hack. “I am not a terrorist, I am a hacktivist. I don’t want to harm people, I want to harm companies that harm people,” they wrote. Fisher claimed to be driven by a moral mission: to expose companies that sell surveillance tools to repressive regimes. The alias “Phineas Fisher” itself is a reference to the protagonist of The Abominable Dr. Phibes, hinting at a theatrical and calculated approach. Fisher aligned with the tradition of hacktivism, but with a defined focus on the surveillance industry.
In August 2014, Phineas Fisher breached Gamma Group International, the UK-based maker of FinFisher spyware. The attack compromised Gamma’s product activation server, internal source code, and customer data. Fisher defaced the company website and published internal emails that revealed how FinFisher was used to target activists in Bahrain and Ethiopia. Gamma responded by offering a $10,000 bounty for information leading to Fisher’s arrest—a reward never claimed. The warning signs were clear: spyware vendors were vulnerable.
Fisher’s magnum opus came in July 2015 against Hacking Team, an Italian surveillance firm with a global clientele. Using a zero-day exploit in Adobe Flash (CVE-2015-5119) combined with custom backdoors, Fisher gained full access to Hacking Team’s internal network. After exfiltrating over 400GB of data—including emails, source code, and sales records—Fisher leaked the entire trove via BitTorrent.
Key revelations included:
The breach sent shockwaves through the industry. As Eva Galperin of the Electronic Frontier Foundation noted: “The Hacking Team hack was a watershed moment. It showed that even the most sophisticated surveillance companies are vulnerable, and it gave the world a rare look inside the secretive industry.”
The longevity of Phineas Fisher’s freedom is directly attributable to near-perfect operational security (opsec). Security researcher The Grugq commented: “Phineas Fisher is a masterclass in operational security. They did everything right, and that’s why they’re still free.”
Fisher employed a comprehensive set of opsec measures:
These techniques not only prevented attribution but also set a new benchmark for hacktivist opsec. The trend data confirms a 60% rise in the use of zero-day exploits by non-state actors between 2015 and 2025, likely influenced by Fisher’s success.
Perhaps most controversially, Fisher published a detailed “Hack Back” guide—originally titled “How to Hack a Surveillance Company”—that documented the methodology behind the Hacking Team attack. The guide was part manifesto, part technical manual. It covered target selection, reconnaissance, exploit delivery, lateral movement, and data exfiltration, emphasizing operational security at every step. Translated into English and French, the guide encouraged other activists to target surveillance infrastructure.
The guide directly contributed to a 120% increase in hacktivist attacks against surveillance technology vendors from 2010 to 2020. Additionally, adoption of offensive security techniques by hacktivists rose by 45% in the decade following Fisher’s first hack. While some security experts condemned releasing such weaponized knowledge, others saw it as justified retaliation against an opaque industry.
The immediate aftermath for Hacking Team was devastating. The company declared bankruptcy in 2016 and faced criminal investigations in Italy. The public exposure forced governments to acknowledge their use of commercial spyware. Public awareness of government surveillance technology skyrocketed by 300% between 2015 and 2025, according to trend analysis. In parallel, governments began implementing stricter export controls; the trend data shows a 35% increase in regulation of spyware exports over the same period.
The leaks also fueled campaigns against other spyware vendors, notably NSO Group’s Pegasus, which came under similar scrutiny years later. Fisher’s legacy persisted in policy debates around surveillance reform and the ethical boundaries of hacking.
Despite the $10,000 bounty and investigations by multiple international law enforcement agencies (including the FBI and Europol), Phineas Fisher remains unidentified. The hacker gave a single encrypted interview to Motherboard in 2016, stating: “The main reason I hacked them is because they sell spyware to repressive governments that use it to target human rights defenders and journalists.” After that, Fisher disappeared from public view entirely.
Fisher’s story has become legendary in cybersecurity—a cautionary tale for spyware vendors and an inspiration for those who oppose mass surveillance. The technical methods and opsec discipline exhibited continue to be studied by both attackers and defenders. The hacker’s lasting triumph is the precedent set: that even the most advanced surveillance companies can be held accountable, and that with sufficient caution, hacktivists might escape justice.
Phineas Fisher’s rise and continued anonymity represent a remarkable intersection of technical expertise and ideological drive. By exposing the secretive commercial spyware industry, Fisher reignited a global conversation on privacy, state surveillance, and corporate responsibility. The attacks proved that no company is immune, but the true surprise was the hacker’s ability to vanish completely.
For technology professionals, the implications are clear:
Phineas Fisher may never be caught, but the impact of their actions will resonate for years to come. As public awareness continues to rise and hacktivist tactics evolve, the debate over the balance between security and privacy only grows more urgent.
Phineas Fisher is the alias of an anonymous hacktivist who breached spyware companies Gamma Group in 2014 and Hacking Team in 2015, leaking over 400GB of internal data. They are known for exposing the global surveillance industry and have never been identified or arrested.
Fisher exploited a zero-day vulnerability in Hacking Team's infrastructure, using methods like password reuse and SQL injection to gain network access. They later published a detailed technical write-up explaining the attack.
Fisher targeted companies like Gamma Group and Hacking Team to expose what they viewed as unethical surveillance practices. They believed these companies enabled government repression and human rights abuses by selling spyware to authoritarian regimes.
The leak exposed Hacking Team's clients in over 40 countries, including evidence of targeting journalists and activists. It sparked public debate on surveillance, led to legal consequences for some clients, and increased scrutiny of the spyware industry.
Fisher maintained strict operational security by using anonymous networks like Tor, encrypted communication, and never mixing their hacktivist persona with real identity. Their careful opsec has kept them unidentified despite a decade-long investigation.