Shadow Brokers Leak Remains Unsolved 10 Years After NSA Tool Heist

Ten years after the Shadow Brokers leak, the identity of the perpetrators remains a mystery, and the stolen NSA tools continue to cause damage worldwide.

By Central
New malware fast16, designed to sabotage nuclear simulations, discovered in the Shadow Brokers data dump a decade later.
Highlights
  • Ten years after the Shadow Brokers leak, the perpetrators have not been identified.
  • The leaked EternalBlue exploit enabled the WannaCry and NotPetya attacks, causing billions in damage.
  • In April 2026, a new malware called fast16 was discovered in the same data dump, targeting nuclear simulations.

Ten years after a mysterious group calling itself the Shadow Brokers burst onto the scene and claimed to have stolen the most powerful hacking tools ever created by the United States National Security Agency, the identity of the perpetrators remains unknown. The damage caused by the leaked tools is estimated to exceed $10 billion. And in April 2026, researchers discovered yet another previously unknown weapon buried inside the same decade-old data dump — a piece of malware designed to sabotage nuclear weapons simulations, built years before the world ever heard of Stuxnet.

When a Ghost Appeared: The Summer of 2016

In August 2016, a group calling itself the Shadow Brokers sent encrypted messages to multiple news organizations, claiming to have breached the NSA’s elite hacking unit, the Equation Group. They offered what they said were the agency’s most dangerous cyber weapons for auction. The asking price: 100 million Bitcoin — a sum so absurd even at the time that it immediately raised questions about whether the group had any genuine intention to sell.

Security researchers who analyzed the leaked samples quickly confirmed their authenticity. The tools contained project names that matched those found in documents leaked by NSA whistleblower Edward Snowden. These were real. They belonged to the most sophisticated cyber offensive unit in the world.

But the Shadow Brokers themselves were a riddle. Their English was awkward and inconsistent — deliberately broken or genuinely non-native, no one could decide. The group granted exactly one interview, then vanished back into the noise. The auction never closed. Months later, the group released the bulk of the tools for free, with no explanation and no demand met. Every move they made was irrational, which made them impossible to read — and that, perhaps, was the point.

The Suspect Who Wasn’t the Culprit

Only one serious suspect has ever been named publicly: Harold T. Martin III, a former NSA contractor. In 2016, federal agents searched his home and seized more than 50 terabytes of classified documents — one of the largest breaches of classified information in U.S. history. In 2019, Martin was sentenced to nine years in prison for willful retention of national defense information.

But Martin was never charged with leaking the Shadow Brokers tools. And after his arrest, the Shadow Brokers continued their online activity, releasing more data. The prevailing theory among investigators and security analysts is that the Shadow Brokers were a persona — a front created by Russian intelligence for deniability and propaganda purposes. But no definitive proof has ever emerged. Ten years later, the number of arrests directly tied to the theft: zero.

EternalBlue: The Most Destructive Leak in History

Among the tools the Shadow Brokers released was one that would change the world: EternalBlue. It exploited a zero-day vulnerability in Windows, allowing an attacker to spread malware across a network without any user interaction. When it was dumped online in April 2017, Microsoft had already released an emergency patch — but countless organizations had not applied it, and many could not.

In May 2017, North Korean hackers used EternalBlue to launch the WannaCry ransomware attack. It crippled the UK’s National Health Service, shut down factories, and infected organizations in more than 150 countries. The chaos was enormous, though the ransom payments themselves were small.

The following month, Russian military hackers deployed NotPetya, using EternalBlue as one of its primary propagation vectors. NotPetya was disguised as ransomware but was actually a wiper — designed to destroy data, not extract payment. It began by targeting Ukraine but spiraled out of control, hitting multinational corporations including the shipping giant Maersk, which had to rebuild its entire global IT infrastructure, and the pharmaceutical company Merck, whose production lines ground to a halt. Total damages: estimates exceed $10 billion.

The cost of the Shadow Brokers leak was not paid by the NSA. It was paid by private companies, public hospitals, and ordinary citizens caught in the blast radius of weapons their own government had built and hidden.

A Fresh Discovery a Decade Later: The fast16 Malware

The Shadow Brokers data dump is still giving up secrets. In April 2026, the cybersecurity firm SentinelOne revealed that it had identified and analyzed a previously unknown piece of malware buried in the leaked files, referenced under the project name “fast16.” The file was labeled with a single dismissive note: “NOTHING TO SEE HERE — CARRY ON.”

What SentinelOne found was anything but nothing. fast16 was a highly specialized piece of software sabotage, built around 2005 — two years before the earliest known version of Stuxnet. It was designed to tamper with software used to simulate nuclear weapons detonations. Specifically, it only activated when the simulated material density exceeded 30 g/cm³ — a threshold reached only in the compression stage of a nuclear warhead. The precision of its targeting was extraordinary.

The world first became aware of state-sponsored cyber sabotage in 2010, when Stuxnet was discovered targeting Iran’s nuclear enrichment centrifuges. fast16 pushes that timeline back by at least five years. It shows that the United States was conducting sophisticated, targeted digital sabotage against nuclear programs long before Stuxnet became public knowledge.

The Vulnerability Equity Process: Reform After the Damage

The NSA had known about the Windows vulnerability that EternalBlue exploited for at least five years. It did not disclose it to Microsoft. No patch was developed. When the tools leaked, Microsoft rushed out a fix, but the damage was already inevitable — too many systems could not be patched in time.

After the leak, the U.S. government’s Vulnerabilities Equities Process (VEP), which governs whether intelligence agencies disclose vulnerabilities or retain them for offensive use, came under scrutiny. Reforms were introduced to increase transparency and accountability. But critics argue the process remains opaque and insufficient. The central question has never been resolved: When an intelligence agency hoards a vulnerability for offensive operations, who bears the responsibility when that weapon escapes into the wild?

The Lesson That Wasn’t Learned

What the Shadow Brokers left behind was not just a collection of hacking tools. It was a demonstration of a fundamental truth about cyber weapons: secrets cannot be kept forever. The tools that intelligence agencies build have a lifespan far longer than their creators intend. They escape. They are repurposed. They come back to harm the very people they were supposed to protect.

The perpetrator of the Shadow Brokers leak has not been caught. But that question, ten years on, matters less than the one that remains unanswered: What happens when it happens again? Because it will. And the next leak may be larger, more destructive, and even harder to contain.

The data dump from 2016 is still yielding new discoveries. fast16 is unlikely to be the last. Somewhere in that archive, other dormant weapons may be waiting — built by the world’s most powerful intelligence agency, lost to the internet, and still undiscovered.

Share This Article