Phineas Fisher is a hacktivist persona known for high-profile intrusions against commercial surveillance vendors, political organizations, police-associated targets, and financial institutions. The actor has remained publicly unidentified and is widely recognized for operations framed as ideologically motivated opposition to spyware vendors, policing, and state repression. Phineas Fisher first gained prominence through the 2014 compromise of Gamma Group, the maker of FinFisher spyware, which resulted in the public release of internal materials about the company’s surveillance products. In 2015, the actor conducted a major breach of the Italian spyware vendor Hacking Team, leaking a large volume of internal emails, source code, contracts, and customer information. That operation is notable both for its strategic impact on Hacking Team and for the actor’s later publication of a detailed intrusion narrative describing exploitation of an embedded device for initial access, use of a backdoored firmware for persistence, internal reconnaissance, credential harvesting, privilege escalation to domain administration, and eventual access to source-code repositories and large-scale data exfiltration. Additional operations attributed to Phineas Fisher include attacks against the union of the Mossos d'Esquadra in Catalonia, Turkey’s ruling AKP party, and Cayman National Bank’s Isle of Man branch. Public statements associated with the persona linked some activity to solidarity with Rojava and to funding hacktivist causes. The actor also promoted a so-called Hacktivist Bug Bounty Program intended to reward intrusions exposing allegedly unethical corporate conduct. Known tradecraft directly associated with Phineas Fisher includes initial access via exploitation, internal network scanning and reconnaissance, credential theft, privilege escalation, persistence, post-exploitation, and exfiltration. The actor has also publicly documented aspects of operations through post-mortems and tutorial material, contributing to the persona’s influence within hacktivist circles. No high-confidence public attribution to a nation-state exists.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist intrusion activity targeting spyware vendors, government-related entities, a police union, a political party, and later a bank; known for major data leaks including Gamma Group and Hacking Team.
Hacktivist persona known for high-profile intrusions and data leaks against spyware vendors, police-affiliated organizations, a Turkish ruling party target, and a bank, motivated in the article by anarchist and anti-police ideals and support for Rojava.
Conducted an intrusion against Turkey's ruling party (AKP) and exfiltrated approximately 300,000 emails, which were later published by WikiLeaks.
Hacktivist-style intrusion and data theft activity, including acquiring and passing along stolen data and previously breaching Hacking Team to dump private files and emails.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.