Italian surveillance vendor Hacking Team was breached and roughly 400GB of internal data was dumped online, exposing source code, emails, customer records, and exploit details tied to its Remote Control System (RCS) spyware platform. Researchers reviewing the leak found multiple offensive capabilities, including an unpatched Adobe Flash remote code execution flaw later tracked as a major zero-day risk, alongside other exploits targeting Flash and Windows. The leaked material also showed Hacking Team had developed techniques to compromise targets using tools such as the Tor Browser, while the company told customers it expected their surveillance operations to resume soon despite the breach.
The documents triggered broad scrutiny of Hacking Team’s business with government agencies worldwide, including reported sales or support tied to Sudan, Ethiopia, Russia, Mexico, South Korea, and Serbia, as well as numerous other police, intelligence, and security bodies. Reporting on the leak linked the company to clients accused of domestic spying, election-related surveillance, and monitoring journalists and dissidents, including South Korea’s NIS and multiple Mexican agencies. The fallout reached Hacking Team’s Western customers as well, with the DEA canceling its contract, while critics argued the records showed the company had supplied intrusive spyware to agencies associated with repression and possible export-control violations.

Trace attribution and downstream blast radius.
14 events from the most recent confirmed update back to the earliest known activity.
The South Korean controversy deepened when an NIS agent linked to the spyware operation was found dead after deleting files related to the hacking programs, prompting calls for investigation.
Leaked material indicated South Korea's National Intelligence Service purchased multiple RCS licenses in 2012, including 35 additional lines shortly before the country's presidential election.
Vice reported that the U.S. Drug Enforcement Administration terminated its contract with Hacking Team in the aftermath of the company's breach and disclosures.
Reporting based on the leaked materials described how Hacking Team developed spyware that enabled monitoring of Tor Browser users, including use in an FBI-linked operation.
After the breach, Hacking Team informed customers that it expected them to be able to resume surveillance operations soon despite the disruption caused by the data dump.
Documents from the breach showed numerous Mexican government bodies had purchased Hacking Team's RCS spyware, with reporting describing Mexico as the company's top customer.
Leaked emails showed Hacking Team renewed a license with Ethiopia's Information Network Security Agency after reports that the agency had used the software against journalists.
Leaked emails cited in the coverage showed Hacking Team sold its surveillance software to Sudan, a deal that drew scrutiny because of UN sanctions and Sudan's human rights record.
Reporting on the leaked emails highlighted Hacking Team's defense of selling intrusive spyware to governments accused of abuses, especially Sudan and Ethiopia, and amplified backlash over its customer vetting.
Security researchers analyzing the leaked data identified an Adobe Flash Player zero-day and verified a proof-of-concept exploit against a fully patched version, warning that public disclosure increased the risk of weaponization.
Analysis of the dumped documents revealed Hacking Team had sold surveillance tools to governments and agencies in countries such as Sudan, Bahrain, Kazakhstan, Ethiopia, Mexico, and Russia-linked entities, prompting broad criticism.
Attackers compromised Italian surveillance vendor Hacking Team and released roughly 400GB of internal data, exposing emails, source code, and customer information.
Leaked emails indicated the NIS tested Hacking Team's Tactical Network Injection capability in 2014 ahead of regional elections, expanding the South Korean spyware scandal.
According to leaked correspondence described in the reporting, Hacking Team stopped selling to Sudan in 2014 after pressure from a UN panel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
24 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourceweb.archive.org
Open sourcevice.com
Open sourcewikileaks.org
Open sourcewikileaks.org
Open sourcewikileaks.org
Open sourcewikileaks.org
Open sourcewikileaks.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.