Researcher details how hacker-for-hire group RocketHack infiltrated the email and Telegram accounts of ~3,500 individuals, including politicians and journalists
An unprecedented peek inside an underground hacker-for-hire operation reveals 3,500 targets, including Belarusian presidential candidates … Tweets: @rondeibert , @iblametom , and @martijn_grooten Tweets: Profdeibert / @rondeibert : NSO Group is a more polished version of the type of cyber mercenary firm operating in grey zones, like that reported on below. But the outcome is the same: dictators, kleptocrats, and even corrupt businesses are driving a new type of despotism-as-a-service. https://twitter.com/... Thomas Brewster / @iblametom : One of the domains owned by one of the apparent hackers here is inṣtagṛam[.]com. Pretty smart phishing domain. https://twitter.com/... Martijn Grooten / @martijn_grooten : Hacker-for-hire groups aren't getting the attention their actions deserve. Their targets often include civil society and this case is no exception. Important work by @FeikeHacquebord and good write-up by Tom. https://twitter.com/... Expand More For Next Unexpand More For Next
Context & Ripple Effects
The mercenary-hacking beat has been building for years: Latin American governments bought Hacking Team exploits to spy on political opposition back in 2016, and India emerged as a hack-for-hire hub targeting politicians, companies, and activists in 2020. What makes this Forbes report different is access — an inside view of RocketHack's own operation rather than inference from victims or leaked customer lists.
The target list is the story: roughly 3,500 individuals, including Belarusian presidential candidates and journalists, had email and Telegram accounts infiltrated. Citizen Lab's Ron Deibert frames RocketHack alongside NSO Group as the same grey-zone business model at different price points — despotism-as-a-service available to any buyer.
First-order effects
- Belarusian opposition figures, politicians, and journalists must treat email and Telegram as compromised channels, since account infiltration exposes sources, contacts, and private coordination.
- Telegram faces a specific reputational problem: its accounts were among the attack surface for a mass-targeting operation, not just a bystander platform.
Second-order effects
- Commercial spyware firms like NSO Group get pulled into the same scrutiny cycle — Deibert explicitly casts them as a more polished version of the same trade, so every new operator exposed raises questions about the whole supplier ecosystem.
- Demand-side evidence accumulates for governments considering export controls or sanctions on spyware brokers, following the pattern where Hacking Team's client list became the basis for public accountability.
Third-order effects
- If the pattern holds, state-aligned hacking keeps blurring into a contractor market — echoing how Russian hacking evolved from criminal schemes into joint criminal-government teams — with repression outsourced to firms whose customers are dictators, kleptocrats, and corrupt businesses.
- Messaging platforms become structural targets: as political organizing consolidates on apps like Telegram, credential theft against those platforms becomes standard tradecraft, pushing platforms toward hardened authentication as a baseline expectation.
The trend: Hacker-for-hire operations are maturing into an off-the-shelf surveillance industry serving authoritarian buyers, with each exposed operator normalizing the model NSO Group made famous.