PHINEAS FISHER▊
Someone read a Citizen Lab report on the spyware sold to hunt journalists and dissidents, decided — in their words — "that's fucked up," and hacked the companies that made it. In 2014 they gutted Gamma International, maker of the FinFisher spyware, and trolled the leak from a Twitter account named after the firm's PR. In July 2015 they did it to Hacking Team, the Italian "lawful intercept" vendor, dumping roughly 400 gigabytes — internal email, the client list of repressive-government customers, and the source code — onto the open internet in an afternoon. The surveillance industry's most feared adversary turned out to be one anonymous person with a manifesto. Nobody knows who. Nobody ever caught them.
I would characterize myself as an anarchist revolutionary, not as a vigilante.
— "Phineas Fisher," in an encrypted-chat interview after the Hacking Team breach, to Motherboard / VICE
- WHO
- "Phineas Fisher" — also "Phineas Phisher," "Hack Back!" An anonymous hacktivist; real identity unknown FACT
- SCENE
- Solo hacktivism against the commercial-spyware trade — the person who turned surveillance vendors into the surveilled (see Disclosure Wars)
- THE DRAMA
- Breached FinFisher-maker Gamma (2014) and spyware vendor Hacking Team (2015), publishing the receipts; later hit a Catalan police union and, per their own communiqué, gave stolen bank funds to Kurdish/Rojava causes
- RECORD
- Gamma breach Aug 2014; Hacking Team breach ~400GB, Jul 2015; Sindicat de Mossos (SPME) breach May 2016. Published "HackBack" accounts claiming responsibility FACT
- STATUS
- AT LARGE — never identified, never charged; a 2017 Spanish arrest claim was disputed and unconfirmed
This file documents what was published and what it did — not how it was done. The breaches are settled fact: the companies confirmed them, journalists mirrored the dumps, researchers combed the emails for years. What stays contested is the frame. To supporters and to the hacker's own account, this was direct action against an industry that sells the tools of repression. To critics, it was crime dressed as conscience — a self-appointed vigilante who stole from banks and exposed thousands of rank-and-file police by home address. The archive keeps both, and the one fact neither side disputes: it worked, and no one was ever caught.
the drama timeline
ACT I — GAMMA GOES DOWN (2014)
A watchdog report names the spyware sold to authoritarian governments. Someone reads it, gets angry, and hacks the vendor — then runs the leak as a comedy account.
-
2012–14
The receipts that started it
Citizen Lab and others document that FinFisher — the intrusion suite sold by Anglo-German firm Gamma International — is turning up on the devices of activists and journalists, including a Bahraini dissident's laptop. Phineas Fisher later says reading this research is what set the whole thing off: they read it and thought "that's fucked up."
-
AUG 2014
Gamma breached, trolled in public
Phineas Fisher announces a breach of Gamma, leaking a trove of internal material — product manuals, a customer price list, and details of the FinFisher toolset — and narrates the whole thing from a Twitter account named @GammaGroupPR, live-tweeting the humiliation of a surveillance company as if it were its own comms team. The leak is accompanied by a published account, "HackBack!," claiming responsibility.
ACT II — 400 GIGABYTES (JULY 2015)
The main event. An entire "lawful intercept" company is turned inside out overnight — and the company's own Twitter feed becomes the megaphone for the leak.
-
JUL 5–6, 2015
Hacking Team, publicly gutted
Phineas Fisher breaches Hacking Team, the Milan firm that sold its "Remote Control System" intrusion suite to governments, and dumps roughly 400GB to the open internet: internal emails, the customer list, invoices, and source code. The company's own hijacked Twitter account announces it. Overnight the industry can read exactly who Hacking Team sold to — a landmark exposure of the commercial-spyware trade.
-
2015–16
The fallout
The leaked files confirm sales to governments with grim human-rights records, name the zero-days Hacking Team stockpiled, and become years of source material for reporters and researchers. Italian export authorities move against the firm's global license. Phineas Fisher tells Motherboard the goal was never to expect one leak to end the company — only to set it back and buy "breathing room" for the people its software targeted.
ACT III — ROBBING THE BANK, RECORDING THE HIT (2016)
The politics get explicit: a police union, a bank, and a donation to Rojava — and a published account daring others to do the same.
-
MAY 2016
The Catalan police union (SPME)
Phineas Fisher breaches the Sindicat de Mossos d'Esquadra — a union of Catalonia's regional police — defacing its site, taking its Twitter, and leaking personal data on thousands of officers. Phineas cites the police-brutality documentary Ciutat Morta as the trigger, and publishes an account of the operation as a manifesto meant to "inform and inspire" others. The exposure of ordinary officers' private data is the line critics point to.
-
2016
Rojava — the Robin Hood claim
Per Phineas Fisher's own communiqué and later interviews, funds obtained illegally from a bank were donated — in bitcoin — to Kurdish/Rojava causes. This is the clearest statement of the Robin Hood self-framing: money taken from institutions the hacker regards as complicit, redirected to a cause the hacker supports. It is also, as critics note, self-reported bank theft.
ACT IV — THE ONE WHO GOT AWAY (2017–)
Arrests are announced, then walked back. A decade on, the surveillance industry's most effective attacker is still a name and nothing else.
-
2017
The arrest that wasn't
Spanish authorities, investigating the Catalan police-union breach, arrest several people — and reporting floats that one may be Phineas Fisher. The claim is quickly disputed; no charge sticks to the persona, and Phineas Fisher's channels keep operating. The identity behind the handle is never confirmed.
-
2018–26
A template, and a ghost
The published "HackBack" writeups circulate as a hacktivist creed, and Phineas Fisher becomes the model everyone cites for going after the spyware trade directly. Years later, retrospectives still open the same way: the hacker who humiliated the spyware makers and was never caught. Even Phineas Fisher, asked about the campaign's effectiveness, hedged — "considering I'm still free, I have doubts about its effectiveness."
both sides, on the record
The case for the hero: Phineas Fisher attacked companies whose products were documented, by Citizen Lab and others, on the devices of journalists and dissidents. The Hacking Team dump did what years of polite advocacy hadn't — it put the client list, the invoices, and the source of a "lawful intercept" vendor in front of the whole world, and gave the people that software targeted, in the hacker's phrase, a little breathing room [2].
By results: the surveillance industry's most feared adversary was one anonymous person with a manifesto, and the receipts fed reporting and export-control action for years. The asymmetry, in Phineas Fisher's own framing, is the point: hacking gives the underdog a chance to fight and win [3].
The case for the criminal: strip the politics and this is unauthorized intrusion, destruction of data, self-reported bank theft, and the mass exposure of thousands of rank-and-file police by home address and bank details — ordinary people, not executives. Good intentions do not make that lawful, and critics classify it plainly as vigilante cybercrime [7].
Who decides the target? A self-appointed anarchist picking which companies deserve to be destroyed and which banks deserve to be robbed is the same discretionary power, unaccountable, that the surveillance industry is condemned for. Even the hacker conceded doubt about whether any of it changed the outcome [6].
YOU DECIDE
The breaches are not in dispute: Gamma and Hacking Team were opened up, the receipts were real, and the spyware trade has been reading its own laundry ever since. What you make of the person depends on whether "anarchist revolutionary" or "vigilante" is the truer word — and Phineas Fisher volunteered the first while critics insist on the second. The exposed officers didn't sell spyware. The dissidents didn't ask to be surveilled. Both things are on the record.
The archive does not deputize. The archive keeps the leaked client list — and the leaked badge numbers.
evidence locker
PRIMARY / FIRST-PARTY & RESEARCH
Motherboard / VICE — "The Vigilante Who Hacked Hacking Team Explains How He Did It" ATTRIBUTED — the text interview; source of the "anarchist revolutionary, not vigilante" line and the "breathing room" motive.
vice.com — the vigilante interview
CrimethInc. — "HackBack! Talking with Phineas Fisher" ATTRIBUTED — long first-party interview on hacking as direct action; the Rojava donation and the "underdog" framing.
crimethinc.com — HackBack interview
REPORTING & REFERENCE
WIRED — "Hacking Team Breach Shows a Global Spying Firm Run Amok" FACT — contemporaneous account of the July 2015 breach and the ~400GB dump.
wired.com — Hacking Team breach
The Intercept — "Leaked Documents Confirm Hacking Team Sells Spyware to Repressive Countries" ATTRIBUTED — analysis of the leaked client list.
theintercept.com — the client list
TechCrunch — "The hacker who humiliated spyware makers and was never caught" ATTRIBUTED — 2026 retrospective on the Gamma and Hacking Team breaches and the unresolved manhunt.
techcrunch.com — never caught
Help Net Security / HackRead — Catalan police union (SPME) breach FACT — the May 2016 SPME intrusion, defacement, and leak of officers' personal data.
helpnetsecurity.com — the SPME hit
CONTEXT & CROSS-LINKS
The standard. "Phineas Fisher" is an anonymous persona; no real-world identity is asserted here, and the 2017 arrest claim is reported as disputed and unconfirmed. The breaches of Gamma, Hacking Team, and the Catalan police union are stated as fact because they are documented and were confirmed by the victims and by reporting. The Robin Hood self-framing — anarchist revolutionary, breathing room for the surveilled, funds redirected to Rojava — is attributed to Phineas Fisher's own interviews and writeups. The opposing view, that this is vigilante crime including bank theft and the exposure of ordinary officers' data, is given at full strength. This file documents the disclosures and their impact; it reproduces no operational content from the published guides. If a line here couldn't survive scrutiny, it wouldn't be on the page.