Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous hack, Phineas remains, by most accounts, the most prolific and public hacker never to have been caught. As part of our series on the biggest cybersecurity mysteries of all time, we are delving into the enigma of Phineas, the hacktivist who hacked controversial spyware makers FinFisher and Hacking Team. The latter, an Italian startup, was among the first to turn government spyware into a viable global business, paving the way for spyware makers such as the Israeli NSO Group. Phineas’ hack against Hacking Team eventually led to the startup’s demise years later.
Apart from Anonymous, an amorphous amalgam of hacktivists with a mixed track record of mostly stunt hacks designed to gather publicity rather than have real impact, Phineas is perhaps the most well-known hacktivist in history. Their story is made of impressive hacks and endless unanswered questions.
The Vigilante Who Turned Spyware Makers Inside Out
Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There is even a song about them.
Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a post-mortem that doubled as a leftist manifesto, then vanished.
A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end.
Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a post-mortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against.
The Phineas Fisher “Hacktivist Bug Bounty Program”
Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. Phineas donated at least $10,000 in Bitcoin to Rojava.
Phineas kept the hack — which happened in 2016 — quiet for three years later before announcing the “Hacktivist Bug Bounty Program,” an initiative to reward hacktivists who expose companies’ illegal and unethical activities. When Cayman National Bank confirmed the hack, it claimed it “was amongst a number of banks targeted.” Phineas confirmed they had been hacking several banks for years.
Why Phineas Fisher Has Never Been Caught
That was their last public appearance. Their Twitter and Reddit accounts have long since been deleted, leaving no online trail. FinFisher never contacted law enforcement, according to a former company employee. The Italian authorities’ investigation into the Hacking Team hack ended without finding any evidence pointing to Phineas’ real identity. What can be said, from my own reporting, is that Phineas is alive and well — they have been in contact with me within the last couple of years.
So who is Phineas Fisher? Taking their claims at face value, they are a hacktivist with anarchist ideals, but also a cybercriminal. Could they instead be a fabricated persona controlled by a spy agency — Russia, say, which has a history of inventing hacktivists to muddy the waters after its own hacks? Phineas has denied being a Russian spy, and it is unclear why Moscow would go after all of Phineas’ chosen targets.
Their origins are equally murky. Phineas has name-dropped Spanish-speaking anarchists, wrote the Hacking Team post-mortem in Spanish, and followed numerous Latin American leftist accounts on Twitter. They told me their first language is neither English nor Spanish, though they have acknowledged living in a Spanish-speaking country. It is all worth taking with a grain of salt. “Everything I say that contains clues about my identity is half trolling,” Phineas once told me. “I’m in the habit of saying misinformation.”
It is also possible that the Phineas persona was passed around between 2014 and 2019 and used by different individuals. But there is no evidence of that, and after 10 years of conversations, my gut says Phineas truly is the hacktivist they claim to be.
What Is the Impact of Phineas Fisher’s Hacks on the Spyware Industry?
The most direct impact was the crippling of Hacking Team. The leak of its source code and internal communications exposed how the company sold surveillance tools to repressive governments, stripping away the veneer of legitimacy that the nascent spyware industry relied upon. For years after, the company struggled to regain trust, ultimately leading to its sale for a nominal fee. The hack set a precedent: no spyware vendor was safe from exposure, and the cost of doing business with morally questionable clients could be total ruin.
FinFisher, by contrast, weathered its breach largely intact. The company did not report the incident to law enforcement, suggesting a desire to avoid scrutiny. This divergence highlights how the impact of a hack often depends on the resilience and transparency of the target. Hacking Team’s collapse sent a chilling signal through the industry, while FinFisher’s survival demonstrated that not all breaches are equally fatal.
Ten Years of Unanswered Questions About Phineas Fisher
After a decade, the central question remains: how has Phineas Fisher avoided capture? The answer lies in a combination of operational security, luck, and the nature of the targets. Phineas often used multiple layers of encryption and anonymous communication channels. The hacks were carefully timed and executed with a clear understanding of legal boundaries — Hacking Team, for instance, was left in a position where pursuing the hacker publicly would have drawn attention to its own dubious client list.
Phineas also benefited from the reluctance of victims to cooperate with law enforcement. Spyware companies, by their nature, operate in a gray area of international law and prefer to avoid the spotlight. A full-scale investigation into a hack might reveal more about their own business practices than they care to disclose. This created a perverse incentive: the best way to catch Phineas would have required transparency that many targets were unwilling to provide.
The hacker’s ability to maintain a consistent persona across multiple operations while leaving no digital trace is exceptional. Even when communicating with journalists, Phineas used encrypted channels and rigorous counter-surveillance tactics. This has led some to speculate that Phineas may have been a group or a state-sponsored actor, but the evidence for either theory remains circumstantial.
The Technical Details of Phineas Fisher’s Most Famous Hacks
The Hacking Team hack, in particular, demonstrated a sophisticated understanding of the target’s infrastructure. Phineas gained initial access through a spear-phishing email, but quickly moved laterally through the network, exploiting weak internal security practices. The hacker exfiltrated data over a period of weeks, using encrypted channels to avoid detection. The resulting leak of over 400 gigabytes included not only source code and emails but also exploit kits and zero-day vulnerabilities that Hacking Team had developed or purchased.
The FinFisher hack was similarly methodical. Phineas targeted the company’s public-facing servers and used SQL injection to extract databases. The stolen data included customer lists, pricing models, and software updates. Both hacks were followed by detailed post-mortems that explained the technical steps taken, providing a blueprint for other hacktivists and embarrassing the spyware makers by demonstrating how easily they had been compromised.
The Future of the Phineas Fisher Mythos
A decade on, Phineas Fisher has become a symbol of what one skilled individual can achieve against a well-funded but complacent industry. The hacker’s legacy is not just in the data leaks but in the fear they instilled in spyware vendors worldwide. The hacktivist bug bounty program, while short-lived, represented a novel attempt to institutionalize vigilante hacking — rewarding others for exposing corporate misconduct rather than hoarding the glory.
Yet the silence since 2019 raises the question of whether Phineas is still active. The hacker may have retired, moved on to other identities, or simply chosen to remain quiet in the face of increased surveillance. The disappearance of their online accounts suggests a deliberate step back from the public eye. But given the hacker’s history of reappearing after prolonged absences, it would be unwise to assume the story is over.
The mystery of Phineas Fisher endures not just because of the technical prowess demonstrated, but because of the moral questions raised. In an era where governments and corporations routinely deploy spyware against dissidents and journalists, the figure of a lone hacker turning the tables on surveillance vendors holds a powerful appeal. Whether Phineas is a hero, a criminal, or an agent of chaos, the lack of capture after a decade speaks to a fundamental tension in the cybersecurity world: the people who build surveillance tools are often the least equipped to defend themselves against the very techniques they sell.