Lorenzo Franceschi-Bicchierai

Lorenzo Franceschi-Bicchierai

@lorenzofb.bsky.social

Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies. Also writing a book about Hacking Team and the history of government spyware. ☎️ Signal: +1 917 257 1382

18,491 Followers 2,528 Following 792 Posts Joined Apr 2023
4 hours ago

I’m not sure I understand what’s the public interest in knowing the real identity behind an artist, no matter how influential and rich they are.

5 0 1 0
4 hours ago

If you have to ask yourself: to dox, or not to dox? Then you already have the answer.

5 0 0 0
11 hours ago
Post image

Infosec right now:

27 9 3 1
1 day ago
Post image

Tal Dilian, asked by 🇬🇷TV network Mega who #Intellexa’s clients were in Greece & whether he had worked with state services, Greek authorities, private actors or any Greek official:

➡️“We provide technology only to governments & law enforcement agencies.”

[Full statement below translated from Greek]

2 2 0 0
12 hours ago
Preview
The FBI is investigating malware hidden inside games hosted on Steam | TechCrunch The FBI believes a series of video games published on Steam in the last two years were embedded with malware by the same hacker.

NEW: The FBI is looking for a hacker who published several video games on Steam that were laced with malware in the last two years.

The bureau is aslo looking for gamers who fell victim and installed these games on their computers.

11 5 0 0
1 day ago
Preview
Law enforcement shuts down botnet made of tens of thousands of hacked routers | TechCrunch An international law enforcement operation shut down a service called SocksEscort, which allegedly helped cybercriminals all over the world launch ransomware and DDoS attacks, as well as distribute ch...

NEW: A global law enforcement operation took down a botnet allegedly used to facilitate ransomware, DDoS attacks, the distribution of child sexual abuse material (CSAM), and other cybercrimes.

The botnet was made of more than 369,000 hacked routers and IoT devices, according to Europol.

17 6 0 0
1 day ago
Preview
Pro-Iran hacktivist group says it is behind attack on medical tech giant Stryker | TechCrunch The hacktivist group claimed the attack was in retaliation for a U.S. strike on a Tehran school that killed more than 175 people, most of them children.

In a statement, CISA's acting director Nick Andersen said the agency is investigating the attack. "We are working shoulder-to-shoulder with our public and private sector partners as we continue to uncover relevant information and provide technical assistance."

techcrunch.com/2026/03/11/s...

3 0 1 0
1 day ago
Preview
Operation Triangulation: iOS devices targeted with previously unknown malware While monitoring the traffic of our own corporate Wi-Fi network, we noticed suspicious activity that originated from several iOS-based phones. Since it is impossible to inspect modern iOS devices from...

FWIW, Triangulation report is from June 2023, Hexacon was October of that year.

securelist.com/operation-tr...

2023.hexacon.fr/conference/a...

4 1 0 0
2 days ago
Preview
Exclusive: Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show The hack occurred after a server at the Child Exploitation Forensic Lab in the FBI’s New York Field Office was inadvertently left vulnerable by a special agent.

Scoop: Here’s the bonkers story of how a foreign hacker inadvertently (?) broke into an evidence server holding FBI Epstein material in 2023 and then threatened to call in law enforcement when they found it was full of CSAM.
www.reuters.com/world/us/for...

314 145 14 10
2 days ago
Preview
Pro-Iran hacktivist group says it is behind attack on medical tech giant Stryker | TechCrunch The hacktivist group claimed the attack was in retaliation for a U.S. strike on a Tehran school that killed more than 175 people, most of them children.

NEW: The pro-Iran hacktivists Handala claim to have hacked U.S. medical tech giant Stryker. Some company systems have been wiped, causing disruptions and outages worldwide.

The hakctivists said the attack was "in retaliation for the brutal attack on the Minab school," which killed dozens of kids.

24 7 1 0
2 days ago
Preview
Hacker broke into FBI and compromised Epstein files, report says | TechCrunch According to a Reuters report, a foreign hacker broke into a server that was part of the FBI’s investigation into Jeffrey Epstein — without realizing they had hacked an FBI server.

NEW: A hacker broke into a server at the Child Exploitation Forensic Lab in the FBI’s New York Field Office in 2023 and compromised files related to the Epstein investigation, as first reported by Reuters.

“The FBI contained the affected network,” the FBI said in a statement.

24 12 0 0
2 days ago
Preview
From Flock to ICE, Here’s a Breakdown of How You’re Being Watched To better understand what exactly we’re looking at in this dystopian surveillance hellscape, 404 Media’s Jason Koebler and Joseph Cox joined Reddit's r/technology for an Ask Me Anything session.

From Flock's nationwide surveillance to ICE tools, we are being watched. Is there anyway to go back now?

"Police love telling each other about the new capabilities and tools that they've acquired, so this tech can spread from city to city very quickly."

A 404 Media guide to surveillance in 2026:

435 226 8 6
2 days ago
Post image

Also great joke here by @thegrugq.bsky.social.

1 0 0 0
2 days ago
Post image

I see some people are speculating that this was Trenchant winking that they were the ones behind Operation Triangulation, or at least pretending to be (as @patrick.risky.biz said in the latest pod episode.)

3 0 3 0
3 days ago
Preview
DOGE employee stole Social Security data and put it on a thumb drive, report says | TechCrunch A whistleblower is accusing a former DOGE member of stealing a large number of Americans’ personal data while he was working at the Social Security Administration, with the plan of using it at his new...

NEW: A former DOGE employee allegedly stole Americans' personal data from two large databases at the Social Security Administration, according to a new report.

The former employee allegedly put the databases on a thumb drive and wanted to use them at their new contractor job.

33 10 1 3
3 days ago
Post image

I forgot to point out that Trenchant's own logo is two triangles.

x.com/TrenchantARC

2 0 0 0
3 days ago

Thank you 🙏

2 0 0 0
3 days ago

Looks like John predicted pretty much what happens with L3Harris and Coruna.

25 11 0 0
3 days ago

Thank you!

1 0 0 0
4 days ago
Post image

As per its stated policy, Kaspersky did not attribute Operation Triangulation.

Instead the company winked that it knew who made the tools when it chose the name and logo of the hacking campaign.

techcrunch.com/2026/03/09/a...

25 4 2 0
4 days ago
Preview
The mystery of a globetrotting iPhone-hacking toolkit Tools used in a series of hacking campaigns by hackers in Russia, Ukraine, and China may have originated inside U.S. government contractor L3Harris, TechCrunch has learned.

There's been a lot of speculation about this, and all signs pointed in this direction. But we now have former L3Harris Trenchant employees telling us that they recongnized some of the artifacts and codenames published by Google.

One of them also told us Coruna was used in Operation Triangulation.

34 7 1 1
4 days ago
Preview
The mystery of a globetrotting iPhone-hacking toolkit Tools used in a series of hacking campaigns by hackers in Russia, Ukraine, and China may have originated inside U.S. government contractor L3Harris, TechCrunch has learned.

SCOOP: The iPhone mass hacking toolkit used by Russian spies was developed at U.S. military contractor L3Harris, former employees said.

The Coruna toolkit was used against Ukrainians and by Chinese cybercriminals, according to Google. But the toolkit was initially developed for Western governments.

219 123 7 14
4 days ago

I just learned that Trend Micro re-branded to TrendAI...uhm, OK.

13 1 3 1
4 days ago

If anyone is wondering, I will not be at RSA. And god willing I won't be at RSA next year either, nor the year after that, nor the year after that, nor the year after that, nor the year after that, nor the year after that, nor the year after that, nor the year after that, nor the year after that, no

26 4 1 3
4 days ago
Preview
Russian government hackers targeting Signal and WhatsApp users, Dutch spies warn | TechCrunch Dutch intelligence is accusing Russia-backed hackers of running a “large-scale global” hacking campaign against Signal and WhatsApp users.

NEW: Dutch intelligence services are warning of new hacking campaigns against Signal and WhatsApp users, including government and military officials, and journalists worldwide.

The social engineering techniques used are not new, but the fact that the Dutch are warning against them means they work.

19 19 2 1
1 week ago

AI companies are more worried about their chatbot’s mental health than that of their users, who can actually have psychosis induced by those chatbots, leading some of them to take their own lives.

I love this future.

23 8 0 0
1 week ago

Thank you so much

0 0 0 0
1 week ago
Preview
FBI investigating hack on its wiretap and surveillance systems: report | TechCrunch Hackers allegedly broke into the FBI’s networks, according to a report by CNN.

NEW: The FBI said it is investigating a hack on its networks.

The breach affected the FBI's systems to manage wiretaps and surveillace requests, according to CNN.

techcrunch.com/2026/03/05/f...

23 10 0 4
1 week ago
Preview
Italian prosecutors confirm journalist was hacked with Paragon spyware | TechCrunch Italian authorities are making progress in their investigation into a wide-ranging spyware scandal in Italy involving Paragon spyware. But the mystery of who hacked two Italian journalists with Parago...

NEW: Italian prosecutors confirm that the phone of journalist Francesco Cancellato was hacked with Paragon spyware at the same time as the phones of two immigration activists.

The Italian government admitted the hack on the activists, but said it wasn't behind Cancellato's hack. So who was?

21 11 1 0
1 week ago
Preview
Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech | TechCrunch Enterprise software was a major focus of zero-day activity during 2025, with security and networking devices, like firewalls, VPNs, and virtualization platforms among the most targeted by malicious ha...

NEW: Google said that last year, and for the first time, it found more zero-days used by spyware makers (15) rather than government-backed espionage groups (12) in the wild.

The shift demonstrated “a slow but sure movement in the landscape” of how governments hack targets, the company said.

13 11 0 0