The Italian surveillance technology company Hacking Team, which sold spyware to governments and law enforcement agencies, was itself hacked. On the night of Sunday 5 July 2015 an attacker used the company’s own Twitter account to publish links to around 400GB of internal data.
What happened
- The leak included internal emails, source code for the company’s surveillance software, passwords, and invoices and client records.
- Documents appeared to show sales to governments in countries including Sudan, Ethiopia, Egypt, Saudi Arabia, Kazakhstan, and Azerbaijan; the company said it had procedures to address human rights concerns.
- Researchers found several previously unknown zero-day exploits in the data, including flaws in Adobe Flash Player, which Adobe patched within days.
- Some of the leaked exploits were quickly adopted by criminal exploit kits before fixes were widely applied.
Why it mattered
The breach exposed the commercial market for government spyware and showed how stockpiled vulnerabilities can put ordinary users at risk once they escape.
Lessons for organisations
Keep patch processes fast enough to respond to newly disclosed exploits within days, and protect social media and administrative accounts with strong, unique credentials and multi-factor authentication.
Sources: The Washington Post, The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.