Connect with us

News

The hacker who humiliated spyware makers and was never caught

info

Published

on

Anonymous hacktivist mask.jpg

Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous hack, Phineas remains, by most accounts, the most prolific and public hacker never to have been caught

As part of our series on the biggest cybersecurity mysteries of all time,  we’re delving into the enigma of Phineas, the hacktivist who hacked controversial spyware makers FinFisher and Hacking Team. The latter, an Italian startup, was among the first to turn government spyware into a viable global business, paving the way for spyware makers such as the Israeli NSO Group. Phineas’ hack against Hacking Team eventually led to the startup’s demise years later.

Apart from Anonymous, an amorphous amalgam of hacktivists with a mixed track record of mostly stunt hacks designed to gather publicity rather than have real impact, Phineas is perhaps the most well-known hacktivist in history. Their story is made of impressive hacks and endless unanswered questions.  

Who is Phineas Fisher? 

Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. 

The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them

Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a post-mortem that doubled as a leftist manifesto, then vanished. 

A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end. 

Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a post-mortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against. 

Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. (Phineas donated at least $10,000 in Bitcoin to Rojava.) 

Phineas kept the hack — which happened in 2016 — quiet for three years later before announcing the “Hacktivist Bug Bounty Program,” an initiative to reward hacktivists who expose companies’ illegal and unethical activities. When Cayman National Bank confirmed the hack, it claimed it “was amongst a number of banks targeted.” Phineas confirmed they had been hacking several banks for years. 

That was their last public appearance. Their Twitter and Reddit accounts have long since been deleted, leaving no online trail. FinFisher never contacted law enforcement, according to a former company employee. The Italian authorities’ investigation into the Hacking Team hack ended without finding any evidence pointing to Phineas’ real identity. What I can say, from my own reporting, is that Phineas is alive and well — they have been in contact with me within the last couple of years. 

So who is Phineas Fisher? Taking their claims at face value, they’re a hacktivist with anarchist ideals, but also a cybercriminal. Could they instead be a fabricated persona controlled by a spy agency — Russia, say, which has a history of inventing hacktivists to muddy the waters after its own hacks? Phineas has denied being a Russian spy, and it’s unclear why Moscow would go after all of Phineas’ chosen targets. 

Their origins are equally murky. Phineas has name-dropped Spanish-speaking anarchists, wrote the Hacking Team post-mortem in Spanish, and followed numerous Latin American leftist accounts on Twitter. They told me their first language is neither English nor Spanish, though they have acknowledged living in a Spanish-speaking country. It’s all worth taking with a grain of salt. “Everything I say that contains clues about my identity is half trolling,” Phineas once told me. “I’m in the habit of saying misinformation.” 

It’s also possible that the Phineas persona was passed around between 2014 and 2019 and used by different individuals. But there is no evidence of that, and after 10 years of conversations, my gut says Phineas truly is the hacktivist they claim to be. 

A awe-inspiring hacktivist that hacked two controversial government spyware startups, and more, may be the most prolific hacker to have never gotten caught.
ASCII art from Phineas’ Hacking Team breach post-mortem. (Image: TechCrunch)Image Credits:TechCrunch /

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

OpenAI says it slowed Astra model development over security concerns

info

Published

on

By

OpenAI logo in Seoul.jpg

OpenAI said Friday it has suspended work on some aspects of its upcoming model Astra after an internal review found it had made significant advancements in agentic coding and cybersecurity — enough to warrant concern over its capabilities.

OpenAI said in a blog post Friday that this model, which is still in development, reached its “critical cybersecurity threshold,” meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems. Under the company’s “Preparedness Framework,” which it created in 2023, this triggered additional safeguards.

“While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time,” OpenAI wrote. “Astra is an upcoming model, and was not involved in exploiting Hugging Face.”

The disclosure highlights an unusual moment in the topsy-turvy and still nascent frontier AI labs sector. Companies across every industry hold back products over potential risks, including for safety and cybersecurity concerns. But they rarely announce those decisions publicly when it’s a product that is still under development.

In this case, OpenAI is already under scrutiny after a different unreleased model breached Hugging Face’s systems during internal testing — the first verifiable incident of an AI lab losing control of its model. Since then, OpenAI and AI labs such as Anthropic have disclosed other incidents in which AI models breached their sandboxes and posed threats during cybersecurity tests.

The string of cases — seems like a new disclosure every day now — has triggered varying reactions from cybersecurity experts, lawmakers, and the AI labs themselves. Some express fear and call for stricter oversight. But there’s also a bit of flexing. In certain circles, any AI lab with a model that has that kind of capability will be seen as an impressive advancement.

OpenAI said it was sharing this information because it believes “it’s important to be transparent with the public and the safety and security communities about this potential shift in capabilities.”

The AI lab said it’s also taking action, including enacting stricter security controls and pausing internal activities involving Astra that don’t meet these beefed guardrails. OpenAI said it is working with relevant government agencies and “select AI safety organizations” to test the capabilities for this model.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading

News

Nigeria now full authoritarian state under Tinubu— PDP 

info

Published

on

By

Pdp.jpg

The Peoples Democratic Party, PDP, has accused the administration of President Bola Tinubu of turning Nigeria into a “full authoritarian state,” citing alleged erosion of democratic institutions, suppression of dissent and weakening of checks and balances.

The PDP made the allegation in a statement signed by its National Publicity Secretary, Interim National Working Committee, Ini Ememobong, on Saturday.

The statement reads in full, “The report by the Human Rights Foundation, in its latest global assessment, classifying Nigeria as a fully authoritarian regime is a mere global confirmation of the local reality that Nigerians have been facing under the APC-led Federal Government. The report confirms the faulty electoral process, absence of protection for dissent, erosion of democratic safeguards and the obvious collapse of checks and balances on the executive by critical national institutions.

“The report published on the foundation’s Tyranny Tracker platform, tyrannytracker.org, shows that the country performed abysmally low on all the critical pillars of its assessment, indicating a full descent into authoritarianism, which is incompatible with democratic tenets.

“It is worthy of note that the assessment parameters of the foundation align with the theoretical frameworks that have identified, analysed and condemned authoritarian regimes-being the rule by a dictator and a small group, or a single party; the absence of institutional checks and balances; loss or apprehension of freedom of speech; opposition targeting; and weak and fake elections. 

“It does not take any high degree of intelligence for anybody to agree with the report, because all the indicators of authoritarianism are present in Nigeria, under this Tinubu regime.

“A few examples from the numerous anomalies experienced by Nigerians will suffice here-the recent deployment of uncivilised and uncouth media attacks by officials of the administration to attack Cardinal Onaiyekan, the Catholic Bishops Conference of Nigeria, the Catholic Church and Christianity generally.

“This incident is one of many which eloquently attest to the absence of freedom of speech under this administration. What did the cleric say that is not the lived experience of Nigerians, except, of course, the few who are isolated from reality and their paid human megaphones? 

“The complete failure of the National Assembly to offer any form of meaningful checks to the executive is not a secret-else how could an administration fail to execute the Appropriation Act for three years, and yet that administration gets commendation, instead of condemnation, from the legislature? A parliament that ignores or blatantly disrespects the country’s constitution and its own standing rules during critical legislative activities cannot offer credible oversight of the executive. 

“What is left, which the administration has doubled down on, is the fact that the 2027 elections are designed as a mere formality, far from reflecting the people’s wishes through the ballot.

“We call on the Tinubu APC administration to immediately take critical steps to de-escalate the political tensions emanating from actions traceable to their officials and their proxies, in the interest of the survival of democracy. 

“The continuous asphyxiation of the opposition, clear weaponisation of security agencies against real and perceived opponents, increasing signs of partisanship by the electoral umpire, and reckless deployment of combustible political rhetoric by the President and his handlers should cease. 

“The President must realise that there are two contests embedded in the 2027 Presidential elections-the presidency and the country. An attempt to focus on winning the former at all costs may result in the loss of the latter; and only a free, fair, credible and peaceful contest can guarantee a win for both coveted prizes.

“We urge Nigerians to continue to demand accountability from their leaders at all levels, as this is the irreducible minimum that democracy provides.”

Continue Reading

Trending