Phineas Fisher is the pseudonym of an unidentified hacktivist known for politically motivated intrusions against commercial surveillance vendors, political organizations, police-associated entities, and financial institutions. The persona is most widely associated with high-profile breaches of Gamma International, the maker of FinFisher, and the Italian spyware vendor Hacking Team, as well as later operations targeting a Catalan police union, Turkey’s ruling AKP party, and Cayman National Bank’s Isle of Man branch. Phineas Fisher has also been referred to as “Phisher.” Phineas Fisher is generally characterized as an anti-surveillance, anti-police, and anti-authoritarian actor rather than a conventional financially motivated cybercriminal or state-directed espionage group. Public statements attributed to the persona frame operations as retaliation against companies and institutions seen as enabling repression, surveillance, or abuse. The actor has claimed solidarity with causes including Rojava and has publicly promoted a “Hacktivist Bug Bounty Program” intended to reward intrusions exposing illegal or unethical corporate activity. The actor’s most consequential operation was the 2015 compromise of Hacking Team, which resulted in the public release of more than 400 GB of internal data, including emails, contracts, customer information, and source code. That breach materially increased public scrutiny of the commercial spyware industry and enabled reporting on Hacking Team’s relationships with government customers and its role in surveillance abuses. Phineas Fisher had previously claimed responsibility for the 2014 breach of Gamma International, which exposed internal material related to the FinFisher surveillance suite, including product documentation, pricing information, exploit-related material, and source code components. The Gamma intrusion was significant for malware analysis and for exposing the capabilities and business practices of a major commercial spyware vendor, although the company continued operating afterward. Phineas Fisher has also been linked to the compromise of the Mossos d'Esquadra police union, an operation consistent with the persona’s anti-police ideology, and to the 2016 intrusion into Turkey’s ruling Justice and Development Party (AKP), in which roughly 300,000 emails were reportedly obtained. The actor later claimed responsibility for hacking Cayman National Bank’s Isle of Man branch and stated that illegal intrusions against banks had been used to generate funds for activist causes. Publicly attributed donations tied to the persona reinforced the image of an ideologically motivated hacktivist willing to combine data theft, public leaking, and theft for political ends. Tradecraft publicly attributed to Phineas Fisher includes opportunistic exploitation of exposed services and weak internal security controls, as well as more advanced intrusion techniques. In the Hacking Team operation, the actor claimed initial access via an unpatched zero-day vulnerability in an embedded device, followed by installation of a backdoored firmware for persistence, internal reconnaissance, credential harvesting, abuse of poorly secured backups and unauthenticated databases, escalation to domain-level privileges, and compromise of source-code repositories and email systems. The actor has also published post-mortems and tutorial material describing operational methods, indicating an intent not only to embarrass targets but also to disseminate offensive knowledge to other hacktivists. Despite extensive public attention, Phineas Fisher has never been publicly identified with confidence. Investigations into the Hacking Team breach reportedly failed to uncover evidence sufficient to determine the actor’s identity. Speculation has ranged from a lone operator to a collective or fabricated persona, but there is no high-confidence public evidence resolving that question. The most defensible assessment is that Phineas Fisher is an enduring pseudonymous hacktivist identity associated with anti-surveillance and anti-establishment cyber operations that had outsized impact on public understanding of the commercial spyware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist persona known for high-profile intrusions and data leaks against spyware vendors, police-affiliated organizations, a Turkish ruling party target, and a bank, motivated in the article by anarchist and anti-police ideals and support for Rojava.
Conducted an intrusion against Turkey's ruling party (AKP) and exfiltrated approximately 300,000 emails, which were later published by WikiLeaks.
Hacktivist-style intrusion and data theft activity, including acquiring and passing along stolen data and previously breaching Hacking Team to dump private files and emails.
Individual hacktivist-style operator who breached and exfiltrated internal emails, files, and source code from Hacking Team, later describing use of a zero-day in an embedded device, a backdoored firmware for persistence, internal network sniffing/scanning, credential discovery (including Domain Admin), email server access, and Git server account takeover via password reset to obtain source code. Previously compromised Gamma International.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.