Hacking Team goes to war against former employees, suspects some helped hackers
As surveillance startup's sales grew, so did internal strife at Hacking Team. — Italian prosecutors have begun a criminal investigation of six former employees of the embattled company Hacking Team …
Context & Ripple Effects
Two weeks after attackers dumped 400GB of Hacking Team's source code, documents, and emails, the surveillance vendor is turning on its own ranks: Italian prosecutors have opened a criminal investigation into six former employees the company suspects helped the hackers. The accusation lands on a company already bleeding commercially — the CEO has said it lost 20% of its customers after the breach while signing four new contracts.
The breach had already exposed the client base that defines Hacking Team's business — Mexico and Italy topped the list revealed in the leaked files, with 11 Mexican customers including local police — and the fallout has been escalating since, culminating in Italy later revoking the company's license to sell software outside Europe. Now the insider angle adds a legal front to a commercial and diplomatic one.
First-order effects
- Six named former employees move from alumni to criminal suspects under Italian prosecution, while Hacking Team's leadership deflects blame for the breach away from its own security posture.
- Government customers weighing renewal decisions now have two reasons to walk — exposed tooling and a firm whose own staff allegedly turned — pressing harder on the 20% customer attrition the CEO already acknowledged.
Second-order effects
- Rival intrusion vendors inherit skeptical buyers: every claim Hacking Team makes about insider betrayal invites questions about whether their own ex-employees hold exploit code and client lists too, an industry-wide trust problem Phineas Fisher's targeting of both Hacking Team and FinFisher made explicit.
- The Italian government's regulatory response gains justification — a vendor that cannot secure or police its own people strengthens the case for the export-license crackdown that followed.
Third-order effects
- If insider-assistance allegations become the standard post-breach narrative, spyware vendors will respond the way other IP-driven firms do — litigation against departing staff — turning talent disputes into a structural feature of the surveillance market.
- The pattern points toward state supervision of the exploit trade hardening: breaches exposing authoritarian client lists, followed by national license revocations, suggest governments will treat these firms as regulated exporters rather than ordinary software companies.
The trend: Commercial spyware vendors are entering a compounding-failure cycle where each breach exposes clients and code, triggering customer flight, regulatory revocation, and legal retaliation against insiders.