In recent decades, a number of elusive hackers have captivated the public’s attention, but none as much as Phineas Fisher. A decade after their most notable breach, Phineas continues to be regarded, by many, as the most active and visible hacker who has never been apprehended.
As part of our exploration into the most significant cybersecurity enigmas of all time, we are investigating the mystery surrounding Phineas, the hacktivist known for targeting controversial spyware developers FinFisher and Hacking Team. The latter, an Italian startup, was among the pioneers in transforming government spyware into a thriving global enterprise, setting a precedent for other spyware firms like the Israeli NSO Group. Phineas’ incursion into Hacking Team eventually contributed to the startup’s downfall years later.
Aside from Anonymous, a vague collective of hacktivists known for a patchy history of primarily attention-seeking hacks rather than impactful actions, Phineas is arguably the most famous hacktivist ever. Their narrative is filled with remarkable breaches and endless inquiries that remain unresolved.
Who is Phineas Fisher?
Described variously as an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has stated that they “utilize numerous aliases” for different hacking endeavors.
The hacks that are known have been substantial enough to elevate Phineas to legendary status among hackers. “I would love to meet Phineas Fisher so that I could take them out for a seven-course, three-Michelin-star meal somewhere and hear them explain how they turned Hacking Team inside out like a gym sock,” a prominent security researcher famously tweeted. There’s even a song dedicated to them.
Phineas first surfaced in August 2014, claiming they had breached Gamma Group, the creators of the FinFisher spyware — which is the origin of the nickname. They announced the breach through a Twitter handle playfully called @GammaGroupPR, leaking compromised data that included mobile spyware, product manuals, and a pricing list. The impact was minimal, and FinFisher continued to operate. Phineas published a post-mortem that also served as a leftist manifesto, then disappeared.
A year later, they returned with a vengeance, breaching Hacking Team, another spyware producer. They obtained nearly everything: over 400 gigabytes comprising source code, tens of thousands of internal emails, confidential agreements, and client databases. This leak enabled journalists to uncover scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was coerced into selling his company for one euro. For some ex-employees, Phineas’ hack marked the start of the company’s decline.
Phineas proceeded to hack the union of the Mossos d’Esquadra, the police force in Catalonia, releasing a post-mortem and a 39-minute tutorial video — consistent with their declared anti-police beliefs. Their following target was the ruling party of Turkey’s authoritarian leader Recep Tayyip Erdoğan, a hack driven by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was battling against.
The last known target of Phineas was Cayman National Bank’s branch in the Isle of Man, a self-governing island located between England and Ireland. This breach revealed a different dimension of Phineas. “I look for illegal methods to earn money, allowing me to liberate my time for more worthwhile pursuits. Once I figured that out, I began to scale it up and accumulate more than I need, donating the surplus,” Phineas stated during an interview with activist Freddy Martinez. (Phineas contributed at least $10,000 in Bitcoin to Rojava.)
Phineas kept the breach — which occurred in 2016 — under wraps for three years before unveiling the “Hacktivist Bug Bounty Program,” an initiative to reward hacktivists who expose unethical and illegal behaviors of corporations. When Cayman National Bank acknowledged the breach, it asserted it “was one of several banks targeted.” Phineas verified that they had been penetrating multiple banks for years.
That was their last public engagement. Their Twitter and Reddit profiles have long been eradicated, leaving no digital footprint. According to a former employee, FinFisher never reached out to law enforcement. The investigation by Italian authorities into the Hacking Team breach concluded without any leads pointing to Phineas’ true identity. Based on my own findings, I can assert that Phineas is alive and well — they have communicated with me within the last few years.
So who is Phineas Fisher? If we take their statements at face value, they are a hacktivist with anarchist principles, but also a cybercriminal. Could they instead be an invented persona managed by a spy agency — Russia, perhaps, which has historically created hacktivists to obscure the truth after their own cyber operations? Phineas has refuted being a Russian operative, and it remains unclear why Moscow would target all of Phineas’ chosen victims.
Their origins are equally obscure. Phineas has referred to Spanish-speaking anarchists, composed the Hacking Team post-mortem in Spanish, and followed numerous leftist Latin American accounts on Twitter. They informed me that their first language is neither English nor Spanish, although they have admitted to residing in a Spanish-speaking nation. It’s all important to approach with skepticism. “Everything I disclose that provides hints about my identity is partly meant to mislead,” Phineas once shared with me. “I’m accustomed to sharing disinformation.”
It’s also feasible that the Phineas identity was shared among different individuals between 2014 and 2019. However, there is no proof of this, and after a decade of discussions, my instinct suggests Phineas is indeed the hacktivist they claim to be.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

