FinePrint

Surveillance Vendors

FinFisher Collapsed. One of Its Managers Kept Selling.

By Shawn Segal·August 30, 2026·3 min read

FinFisher was the Munich company that sold the FinSpy trojan to governments for over a decade. Citizen Lab caught it targeting Bahraini activists in 2012 and mapped its command servers in as many as 36 countries. German prosecutors raided 15 properties in 2020, seized the company's accounts in 2022, and charged four of its former managing directors in 2023 with intentionally evading EU export controls to sell spyware to Turkey's intelligence service through a Bulgarian shell company. The company filed for insolvency and let all 22 employees go. Civil society groups, reasonably, celebrated: the criminal complaint they filed in 2019 had killed a spyware firm.

So where did everybody go?

At least one answer sits in Pullach, the quiet Munich suburb best known as the longtime home of Germany's foreign intelligence service. In June 2020, with the Munich investigation already underway, a company called AdSum UG was registered there. A UG is the German legal form you can stand up with one euro of capital. AdSum's website says it creates "the best technology partnerships in the cybersecurity arena," connects "institutions and best-in-class vendors," and helps clients "keep your countries safe against organized crime." Countries, plural. This is a company that sells to governments.

Its founder and managing director is Carlos Gandini, formerly a managing director of FinFisher.

In February, the Portuguese weekly Expresso reported on a document leaked from Intellexa, the spyware conglomerate the US Treasury sanctioned in 2024. The document is dated April 2021 and identifies Gandini as the person responsible for representing Intellexa in Angola. Angola's intelligence service, SINSE, bought a license for Predator, Intellexa's phone-hacking spyware. We know how that capability got used: this February, Amnesty International and Reporters Without Borders forensically confirmed that Teixeira Cândido, one of Angola's most prominent journalists, was hacked with Predator.

Line up the timeline and the problem is plain. A manager of a spyware company under criminal investigation for illegal exports founds a broker firm. Within a year, per the leaked document, that broker is moving a competitor's spyware to an authoritarian intelligence service. The manufacturer gets sanctioned. The client government points the product at a journalist. And the broker in Pullach keeps its one-page website up, offering to keep your countries safe.

This is the accountability gap FinePrint keeps finding in the surveillance trade. Prosecutors can kill a company. Sanctions can hit a manufacturer. Neither touches the connective tissue: the individual dealmakers who carry client relationships from one venture to the next. The broker layer also adds distance on paper. Angola did not buy from a sanctioned conglomerate; it dealt with a small German cybersecurity partner. Every intermediary makes the chain harder to see and harder to police.

Gandini did not respond to questions from netzpolitik.org, which covered the Expresso findings in March. Reporters Without Borders said that if the reporting holds, people from a company that demonstrably operated illegally are again brokering this technology, and called that an alarming sign of continuing impunity in the sector.

We have added AdSum to the CSV Tracker as a Tier 3 watchlist entry, alongside a people record for Gandini and the sourced incident trail. The open questions are the ones German export authorities should be asking: what else has AdSum brokered, to whom, and under what license? If you have documents, we read the fine print. Send them.

Newsletter

Findings and features, in your inbox.

New findings and monthly features from the FinePrint newsroom. Free, no spam, unsubscribe anytime.

Delivered by Substack.