The Hacking Team Leak and a Very Bad Week to Sell Spyware

The Hacking Team Leak and a Very Bad Week to Sell Spyware

Tech News flash hacking-team privacy security surveillance

I was going to write about something else today but then Sunday night the Hacking Team thing broke and I've had about six tabs of leaked internal emails open since yesterday morning, so that's what we're doing instead.

Quick catch-up if you somehow missed it: Hacking Team is an Italian company that's spent years selling surveillance and intrusion software to governments and law enforcement agencies - the kind of stuff that can remotely flip on a target's webcam, pull their Skype logs, or lift files off a laptop without the owner ever noticing. Sunday night somebody broke into their systems and walked off with something like 400 gigabytes of internal data. Instead of quietly reselling it or sitting on it, whoever did this dumped the whole thing as a torrent and posted the link from Hacking Team's own Twitter account, which they'd also taken over and renamed to "Hacked Team." That detail alone is what turns this from a grim security story into one people actually want to read.

The 400GB is emails going back years, source code for their exploit tools, invoices, contracts, internal chat logs, basically the entire company laid bare for anyone with a BitTorrent client. And people are combing through it. Researchers have been going file by file since yesterday, finding client lists (some governments you'd expect, a few you'd hope wouldn't be shopping for this kind of thing), pricing sheets, and some genuinely rough internal password habits - one exec's passwords turning up in the dump are the sort of thing that would get you laughed out of a first-year security class. I'm not going to paste them here, mostly because half the fun of a leak like this is watching everyone else find it themselves, but if you go looking you won't have to look far.

Here's my actual take, which I know isn't the popular one in every corner of the internet: I don't feel bad for them, but I don't think this is purely funny either. A company whose entire business is breaking into other people's computers getting broken into is objectively a little satisfying, sure. But the tools themselves are still out there now, documented and shared with the rest of the internet, and some of Hacking Team's customers were reportedly using this software against journalists and activists rather than the terrorism-and-organized-crime pitch in their marketing decks. Leaking a surveillance vendor's client list is a genuinely different thing than leaking a retailer's customer database. There's a real argument this is a public service. There's also a real argument that whoever did this now has working exploit code sitting in a torrent that anybody can grab, and that part isn't nothing.

Selfishly, as someone still running a couple of client sites with Flash-based video embeds because switching them over hasn't been worth the fight yet, I'm bracing a little. Companies like this sit on unpatched vulnerabilities specifically because they're valuable while nobody else knows about them, and a dump this size out of a company whose whole job was finding those holes feels like the kind of thing where the real fallout shows up over the next week or two, not in the first day. I'd put money on us not having seen the worst of what's buried in those 400 gigs yet.

If you want to spend an afternoon the way I did yesterday, the archive is trivially easy to find and reading the internal emails is a genuinely strange experience - a company arguing about expense reports and vacation requests in between contract negotiations for spyware. Ordinary and unsettling at the same time. I made coffee twice and completely lost track of the afternoon both times.

One last thing, unrelated but I don't have anywhere else to put it: does anyone else's "Get Windows 10" reservation icon keep disappearing from the taskbar and coming back a day later like it's checking to see if you've changed your mind? Mine's done it four times this week. I have not changed my mind. I also haven't clicked it, out of pure stubbornness at this point.