For the Record
In light of ongoing public reporting and the landmark ruling in the Alhathloul v. DarkMatter Group case, my name has occasionally been raised in media coverage surrounding DarkMatter. Given the serious nature of the allegations in that case, which involve cyber-surveillance, zero-click exploits, and the targeting of human rights activists, I am writing this to set the record straight regarding my actual role, my departure from DarkMatter, and why I was not named as a defendant in this lawsuit.
Media reports have sometimes broadly labeled former employees under generic terms like “ex-hacker”. My actual background and work tell a very different story. I served as a threat intelligence analyst. My work focused on helping to advise and build national threat intelligence capabilities, assessing cybersecurity threats, and providing training on lawful collection. I was not an offensive operator, a developer of zero-click exploits, or a direct executor of surveillance campaigns against dissidents or journalists. As I have maintained publicly in the past, I never condone illegal activity, nor do I participate in targeting U.S. citizens or activists.
The federal court opinion in Alhathloul v. DarkMatter Group details specific allegations regarding Project Raven and the deployment of a zero-click hacking platform known as Karma. There are clear legal and factual reasons why I was not named as a party to this litigation. My brief tenure at DarkMatter ended well before the primary events at issue in the lawsuit occurred. The core exfiltration and targeting of activist Loujain Alhathloul took place in late 2017 while she was in the United States. I was no longer employed by or working with DarkMatter during those operations.
Furthermore, the lawsuit centers on specific executive decisions, zero-click exploit acquisitions, and operational deployment against designated targets, such as Purple Sword. I had no involvement in acquiring those exploits, managing that infrastructure, or selecting those targets. The three individual defendants in the lawsuit, were senior executives who entered into a 2021 Deferred Prosecution Agreement with the U.S. Department of Justice, admitting to specific roles in deploying offensive cyber tools. I was not part of that agreement because I did not participate in those actions.
The U.S. District Court allowed civil claims under the Computer Fraud and Abuse Act to move forward against DarkMatter and top executive leadership precisely because those individuals were named in the agreement. Courts and federal prosecutors distinguish between executive decision-makers who oversaw unauthorized computer intrusions and short-term analysts who worked on defensive capabilities. My position was strictly limited to advisory threat intelligence, far removed from the offensive hacking operations detailed in the court's opinion.
Guilt by association is an easy narrative in headline-driven, click-bait media, but legal accountability relies on facts, actions, and evidence. The court records and federal investigations make clear who was responsible for those actions. My commitment has always been to integrity, intelligence, and adherence to the law. Lastly, the distinction between offensive and defensive operations is essential to understanding why my name does not, and will not, appear on that court docket.