Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Hm. There are several reasons for this I can come up assuming good intent. You could shuffle this data towards security researchers or the police to identify and notify affected people. It could also contain information which enables or simplifies secondary attacks against the service. Or it could contain data allowing to attack other related groups.

All of these are too big to decide and analyze in the moment the attack goes active and visible in the infrastructure. You'd just dump it and then wipe it and figure it out later.

It's certainly a sensitive dataset and it doesn't feel any kind of "good" for literally anyone to have it. But to me it's not slam-dunk just evil.



I'm not saying this is morally right or anything, but the other reason is to cause the spyware company's current and potential clients to lose faith in their reliability as a partner.

It's one thing to pop one of these companies and dump their tooling -- they'll just get a new set of 0-days if that's part of their MO and keep selling the tools, maybe changing them a bit to evade AV detection if that's a concern.

It is another thing entirely for their client list and the identities of their client's targets to get leaked. That's the sort of thing potential customers of these companies want to avoid at all costs.

All that said, I think they could have achieved much the same effect by just dumping their client list and maybe quietly (and privately) notifying the victims.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: