:

PHANTOM HACKER EXPOSES SPYWARE MAKERS, REMAINS FREE

SECURITY DESK1 MIN READ
SAT, JUL 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A mysterious hacktivist known as Phineas Fisher has compromised multiple government spyware firms without ever being apprehended, potentially making them the most prolific uncaught hacker in recent history.

Phineas Fisher has claimed responsibility for breaching controversial spyware makers that develop surveillance tools for governments. The hacker's targets have included companies selling intrusive monitoring software to authoritarian regimes and law enforcement agencies. Fisher has released sensitive data from these firms, exposing internal documents and operations. The releases have embarrassed the spyware industry and triggered investigations into their practices. Despite sustained law enforcement attention, Fisher's identity remains unknown. The hacker operates with operational security that has successfully evaded capture across multiple jurisdictions. Fisher's actions align with hacktivist principles, framing the breaches as exposing surveillance infrastructure used against civilians. The hacker has maintained an active presence online while remaining unidentified, making them a notable figure in hacking history for sustained activity without arrest.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cisco's President Jeetu Patel joined executives from OpenAI, Anthropic, and others in signing an open letter warning that AI-enabled cyberattacks will likely become more widespread and sophisticated. The same AI capabilities that boost productivity can be weaponized by malicious actors.

1H AGOAI Desk

Anthropic has warned users about unauthorized token theft after discovering hackers accessing Claude accounts. The breach prompted the AI company to alert subscribers about potential account compromises.

1H AGOAI Desk

Attackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit capable of injecting malicious code directly into memory. The attack bypasses disk-based detection by intercepting PHP file loading.

2H AGODev Desk

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, requiring software vendors to disclose actively exploited flaws within 24 hours. Vendors must now prove exactly what shipped and when vulnerabilities were discovered.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.