Tech
Ghost hackers: the cybersecurity mystery that nobody has solved
In the long history of hacking, there have been numerous data breaches that, years or even decades later, remain unsolved. Countless hackers and hacking groups behind them have never been unmasked.
But prolific hacking groups do get caught. This is true whether they’re cybercriminals such as LAPSUS$, a notorious extortion gang that compromised companies such as Microsoft and Nvidia and that have had multiple members arrested, or sophisticated government hacking groups from Russia and China, whose members have been named, indicted, and placed on most-wanted lists.
Still, some of the most fascinating cases in cybersecurity history remain wide open — no culprits, no answers, and in some cases, not even a clear motive. We decided to revisit several of them in a series of articles, starting with one of the strangest episodes in the history of intelligence leaks.
The first installment centers on the Shadow Brokers — an enigmatic group that surfaced online, dumped a trove of hacking tools believed to belong to the NSA, and then vanished.
In the summer of 2016, in the midst of the Russian hacks related to the U.S. presidential elections, the group appeared on Twitter. They linked to a Pastebin post and @-mentioned several news outlets — a strange, ineffective strategy that meant most of those outlets likely never saw the tweets.
But if anyone had clicked on the link, they would have seen a document titled “Equation Group Cyber Weapons Auction — Invitation” — a reference to the shadowy hacking operation widely believed to be run by the NSA.
“!!! Attention government sponsors of cyber warfare and those who profit from it !!!! How much you pay for enemies’ cyber weapons?” the hackers wrote, claiming to have hacked the Equation Group.

The document included links to download some hacking tools, as well as a link to download an encrypted file that interested buyers could decrypt by making a bid. “Auction files better than Stuxnet,” they wrote, referring to the famous malware used against Iranian nuclear facilities in a U.S.-Israeli cyberattack in 2007. They asked for at least 1 million Bitcoin.
The leak quickly attracted press coverage. Once security researchers analyzed the tools, they realized these were exceptionally sophisticated cyberweapons, very likely stolen from the NSA — a suspicion bolstered by the fact that some shared names with programs revealed by NSA whistleblower Edward Snowden.
The auction was likely a ruse, since the group eventually dumped many of the tools publicly months later. Much about the Shadow Brokers made little sense. Their broken English was almost comical, as if they were either trying too hard or deliberately signaling the artifice. Despite clearly seeking attention — and getting plenty of press coverage — the group only spoke to a journalist once, giving a brief interview to 404 Media’s Joseph Cox, then a reporter at VICE Motherboard.
Ten years later, we know literally nothing about who was behind the Shadow Brokers persona. Cox and I interviewed former NSA staffers at the time, who said an NSA insider or former insider could be involved. But nobody has ever been arrested and charged — extraordinary, given this was arguably one of the worst leaks of U.S. intelligence hacking tools ever.
One potential suspect was Harold T. Martin III, an NSA contractor arrested for stealing classified information from the agency. But the theory has a problem: While Martin was in custody, the Shadow Brokers remained active online. He has never been formally charged in connection with the leaks. The most widely credited theory is that the Shadow Brokers were created by a Russian government spy group as a propaganda tool.
The impact was massive. Among the tools released, the Shadow Brokers published EternalBlue — a family of zero-day vulnerabilities targeting Windows that allowed hackers to break into computers on a hacked network, rapidly expand their access, and deploy self-propagating worms. (Zero-day vulnerabilities are flaws unknown to the software maker, meaning no patch yet exists.) North Korean hackers used EternalBlue to unleash the WannaCry ransomware worm. Russian hackers later built it into NotPetya, which spiraled beyond its initial Ukrainian targets and caused an estimated $10 billion in damages globally. For businesses, the lesson was stark: Vulnerabilities hoarded by intelligence agencies don’t stay secret forever — and when they leak, the private sector pays the price.
The trove is still yielding discoveries. Among the leaked tools was one containing a list of project names — including one called Fast16, flagged only with the label “NOTHING TO SEE HERE — CARRY ON.” Last month, researchers announced they had located and examined it, finding malware dating to 2005, designed to tamper with software allegedly used by Iranian nuclear scientists.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers
Ellis AI announced Thursday its emergence from stealth with $10 million in seed funding from investors including First Round Capital, 645 Ventures, Harlem Capital, Khosla Ventures, Thrive Capital, Slow Capital, Kearny Jackson, and Ariel Alternatives CEO Mellody Hobson.
Ellis uses AI agents to tackle the fragmented workflow private credit managers deal with, including managing documents, spreadsheets, and correspondence. The company was founded by Ryan Williams, best known for co-creating the real estate investment platform Cadre alongside Josh and Jared Kushner back in 2014. That company raised more than $160 million in funding and, at its peak, was valued at $800 million before being sold for an undisclosed sum to the alternative investment company Yieldstreet in 2024.
“At Cadre, I saw the next major constraint,” Williams said. “Even as the front end of private markets became more modern and accessible, the operating infrastructure underneath it remained fragmented.”
He started working on Ellis last year. The company seeks to connect and centralize all the scattered software, accounting information, and documents a private credit firm would use into one easily accessible platform. The system can flag discrepancies in the data and uses AI agents to help perform tasks like portfolio monitoring and preparing reports.
For example, Williams promises the agents can help close a fund’s books at the end of the month.
“A team may have to download files from several systems, reformat the data, compare balances, investigate discrepancies, and re-enter information by hand. In many firms, Excel becomes the operating system,” he continued. “Ellis connects to the systems and documents a firm already uses rather than forcing it to rip everything out and start over.”
It keeps a human in the loop, too, he says. “Material decisions and actions remain with the human experts,” he said.
“I expect the human loop to become narrower, but not disappear,” he continued, when asked if he sees a day when the AI works fully autonomously. “Our goal is not to replace human judgment; it’s to help people cut through the noise and make educated decisions faster.”
This piece was updated to add an investor.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Tesla reportedly might sell its China business ahead of a SpaceX merger
Tesla is reportedly considering cleaving off its entire business in China to grease the wheels of a merger with SpaceX, according to the Wall Street Journal.
The newspaper reports that “some Tesla executives have been told to prepare for a separation of the China business,” which could include a “spinoff, sale or closure,” citing unnamed sources. The company reportedly would be able to do this fairly quickly because CEO Elon Musk had already tasked executives to prepare for a split in the event that Beijing invades Taiwan.
Separating China from Tesla’s global operations could make it easier to integrate the company into SpaceX, which is a defense contractor that has to follow strict rules around citizenship and national security. That would also be a major concession. China has grown to dominate Tesla’s business, not only as a market for its vehicles, but as a production hub that serves Asia more broadly, and also Europe.
Tech
WhatsApp is testing a new folder for messages from large businesses
During Meta’s Q2 2026 earnings call, Mark Zuckerberg said that other revenue in the family of apps segment crossed $1 billion, largely thanks to WhatsApp paid messaging and subscriptions.
As more businesses use WhatsApp to reach consumers, users’ inboxes often get cluttered, making it hard to find personal and group messages. Meta is now trying out a new feature where it will place messages from larger businesses like banks or airlines in a separate folder, TechCrunch has learned exclusively.
When a user receives a message from a large business, WhatsApp will automatically move that message to a new “Offers & Updates” folder after a set number of hours. The company said it is testing different durations, up to 24 hours, to move messages to a new folder.
Users who prefer their messages to be on the timeline can turn this setting off. However, they don’t control when messages are moved automatically.
Meta said that with this feature, messages like discount codes and delivery updates are out of the inbox in a few hours, and the main chat timeline feels less cluttered. For businesses, this means that users can look for their messages in a specific folder rather than getting lost in all chats.
WhatsApp is starting to test this feature with select partners using its WhatsApp Business Platform, and will look to expand based on observations. At the moment, small businesses and individual accounts using WhatsApp Business are exempt from this feature. WhatsApp said it could explore moving business messages from small businesses to the new “Offers & Updates” folder in the future.
In the last few years, WhatsApp has taken steps to reduce business message spam. In 2024, it started allowing users to unsubscribe from marketing messages from brands. Last year, it put a curb on the number of broadcast messages businesses and individuals can send in a time frame. In October 2025, it went one step further and limited the number of messages businesses could send without getting a response from users. The company has fully rolled out the first two features while it is still iterating on the third feature.
Despite these steps, the WhatsApp inbox can feel chaotic. From my own experience, there have been days when I have cleared unread messages at the start of the day only to end with more than 30-40 unread messages. Even at the time of writing, more than half of my unread messages were business communications. I am not alone in feeling this.
The new feature might reduce the clutter a little, but it won’t be effective until users have control over filtering out messages from the main inbox.
WhatsApp made its AI business agents available globally in June, with more than 1 million businesses already using them. During the earnings call, Zuckerberg mentioned Brazil’s car rental company Movida and said that it has seen an uptick in conversions and customer support issue handling through AI agents. In the coming months, we could see more businesses use AI within WhatsApp for sales, marketing, and support use cases. A chat app with over 3 billion users must strike a balance between personal and business messages before it becomes a vehicle for AI spam.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
