CSIDB logo
Threat actor

Phineas Fisher

Attribution profile

Type
Activist
Location
United States of America
Known incidents
4 incidents
First seen
2014-08-02
Last seen
2016-05-20
Updated
2026-08-01 05:35
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Phineas Fisher is the alias used by a hacker who has claimed responsibility for a series of high‑profile data breaches and leaks. The individual is known to operate from the United States of America, as indicated in the available background information. Public statements attributed to Phineas Fisher describe the activity as a form of activism aimed at fighting economic inequality and promoting social change, with the hacker emphasizing that personal profit is not a motive. The actor has repeatedly framed intrusions as cybercrime that serves a broader political purpose, such as returning stolen wealth to the public or exposing alleged misconduct by institutions. This self‑portrayal as a hacktivist has been consistent across multiple manifestos and interviews.

Targets have included law‑enforcement related organizations, financial institutions, and companies that develop surveillance technology. In 2016 the hacker defaced the website of the Sindicat de Mossos d’Esquadra, a Catalan police union, compromised its web server, hijacked its Twitter account and leaked personal details of officers, citing protest against alleged law‑enforcement misconduct. The same year Phineas Fisher claimed to have stolen funds and internal documents from Cayman National Bank on the Isle of Man, distributing the material through the Distributed Denial of Secrets platform while asserting the act was aimed at economic elites. In early 2016 the actor also breached an external web server belonging to the Israeli mobile forensics firm Cellebrite, extracting approximately 900 GB of technical specifications, customer data and legacy system credentials. Additional operations have focused on firms that produce intrusion tools, notably the 2015 breach of Italian surveillance company Hacking Team, from which a 400 GB torrent of source code, emails and internal documents was released, and the 2014 leak of Gamma Group’s FinFisher suite, for which a Reddit user using the PhineasFisher handle claimed responsibility.

The actor’s tactics frequently involve website defacement, unauthorized access to web servers, and takeover of associated social‑media accounts to amplify the impact of a breach. After gaining entry, Phineas Fisher typically exfiltrates large volumes of data and publishes the material through public leaking sites or torrent files to ensure wide distribution. In several incidents the hacker has recorded and shared walkthrough videos of the exploits, presenting them as tutorials intended to inspire other individuals to conduct similar hacks. The use of legacy backups as an entry point was noted in the Cellebrite intrusion, where outdated authentication material was harvested from a superseded system. When targeting financial actors, the actor has described stealing money and documents and then redistributing the proceeds, a pattern seen in the Cayman National Bank incident. Throughout these operations the hacker has relied on publicly available leaking platforms such as Distributed Denial of Secrets and torrent distribution channels rather than developing custom malware families.

Attribution to Phineas Fisher rests primarily on the actor’s own claims, including Reddit posts, Twitter handles and manifestos that accompany the released data; no governmental or state sponsorship has been demonstrated in the open sources. The hacker has not been linked to any known criminal consortium or organized cybercrime group, operating instead as an individual or loosely affiliated collective using a consistent pseudonym. Law‑enforcement investigations have been noted in the statements of victims such as Cayman National Bank, which confirmed cooperation with authorities while the actor’s identity remains unverified publicly. The available information places the operator’s geographic base in the United States of America, though no further detail on infrastructure or support networks is provided. Consequently, the profile of Phineas Fisher is built on the actor’s public declarations and the technical details of the breaches they have claimed.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB