Hacktakes · Edition 17
Hacktakes · Edition 17 · August 3, 2026

The Economics of Corporate Cyberstalking

Because trivial fines make cyberstalking a rational business expense, only personal criminal liability for executives can stop corporate shadow agencies.

By Victor Hale

Sparked by 'Crush this lady': how eBay harassment campaign led to $56M payout · discussion

I can approve the live spiders and the burner phones, but accounting is going to need a receipt for this pig mask.
I can approve the live spiders and the burner phones, but accounting is going to need a receipt for this pig mask.

Corporations are exceptionally efficient machines for externalizing risk. We are used to seeing this dynamic play out in environmental policy, where profits are privatized and catastrophic losses are shifted to the public ledger. The exact same mathematical incentives apply to corporate security. We generally think of enterprise security departments as protectors of physical assets, guarding warehouses and data centers from external intrusion. We imagine them managing badge access, or deploying network firewalls against anonymous international hackers. In reality, they frequently evolve into organizational structures economically optimized to insulate the C-suite from legal liability.

The Department of Justice recently celebrated what it called the "maximum statutory fine of $3 million" against eBay for an extensive corporate cyberstalking campaign targeting public critics. The media immediately seized upon the true-crime drama of rogue employees mailing live spiders, bloody pig masks, and funeral wreaths to a pair of newsletter writers. The prevailing institutional narrative frames this prosecution as a catastrophic failure of corporate oversight and workplace culture.

We need to look past the true-crime hysteria and examine the operational arithmetic. The company generates roughly $27 million in revenue every single day, meaning a three-million-dollar penalty equates to just over two and a half hours of corporate income. The Financial Times coverage dryly documented the financial absurdity of the settlement, contrasting the minor statutory limit with the billions the company clears in annual net income. Technologists participating in a recent Hacker News discussion accurately zeroed in on how a penalty of this size provides absolutely zero deterrent to a modern multinational corporation. They noted the obvious math: for a company of this scale, a penalty of three million dollars is roughly equivalent to a pocket-change parking ticket for an affluent professional. It is just the cost of doing business. Our entire economy is built on this premise. When the financial cost of silencing a vocal critic is mathematically lower than the projected shareholder cost of enduring a sustained public relations crisis, rational market actors will simply purchase the silence.

To understand how this system actually functions, we have to borrow a structural concept from Cold War espionage: the cut-out. In covert intelligence operations, leaders never issue direct, recorded orders to commit illegal acts. The paper trail is a vulnerability. Instead, they express a generalized desire to solve a specific problem. An isolated operational unit—the cut-out—interprets that desire and executes the messy reality on the ground. The entire purpose of the cut-out is to serve as an organizational airlock. If the operation succeeds, the leadership reaps the strategic benefit. And if the operation is exposed, the cut-out absorbs all the legal and public blowback, granting the leadership legally bulletproof plausible deniability. It is a brilliant, highly evolved survival mechanism for large bureaucracies.

We should analyze the eBay security team exactly through this lens, rather than treating their actions as random instances of retail harassment. This was an internal group heavily staffed by former law enforcement officers deploying standard CIA-style tradecraft. They utilized GPS trackers placed on vehicles, coordinated complex cross-country surveillance via burner phones, and set up fake online personas to obfuscate their digital footprints. They operated entirely as an intelligence cut-out designed to protect the C-suite from the friction of bad publicity by any means necessary. The executives simply expressed deep, aggressive frustration with the newsletter writers, heavily implying that the problem needed to be resolved. The cut-out translated that vague executive fury into a kinetic psychological warfare campaign, successfully shielding the leadership from the unsavory mechanics of the execution. We watch a handful of ex-cops get marched into federal court, and we view the resulting federal prosecution of these lower-level security operatives as proof that the corporate governance structure catastrophically failed. It worked perfectly.

The sheer effectiveness of this organizational airlock is evident in the executives' lucrative landing pads. The systemic insulation held flawlessly against federal scrutiny. Former CEO Devin Wenig departed the company with a massive $57 million severance package and subsequently took a comfortable seat on the General Motors board. Former Chief Communications Officer Steve Wymer seamlessly transitioned to a role as a Silicon Valley non-profit CEO. Neither man faced personal criminal charges for the corporate terror campaign launched on their behalf. The cut-out successfully absorbed the blast radius.

When legal penalties are levied strictly against a corporate entity rather than its individual leadership, they fundamentally cease to function as punishments. For a multi-billion-dollar enterprise, a three-million-dollar statutory maximum fine serves strictly as a risk-adjusted licensing fee for operating a privatized intelligence agency. It poses absolutely no existential threat to the business. Psychologically, this shifts corporate crime from a moral boundary into a simple line item on a spreadsheet.

So we continuously hear empty calls for better internal corporate culture, enhanced ethics training, and stricter compliance dashboards. None of these mechanisms alter the underlying mathematics of the threat, because the financial incentives of the market overwhelmingly favor maintaining plausible deniability through outsourced operational units. We need to stop pretending this is a human resources problem. We need to stop asking corporations to police their own shadow agencies. We need to acknowledge that the current legal framework treats targeted harassment as a minor operational tax. The only way to stop corporations from weaponizing their security departments against public critics is through federal regulation that holds executives personally and criminally liable for the operations conducted on their behalf. As long as the ultimate punishment remains a negligible corporate fine, the practice will continue unchecked as a standard business expense. Either we impose actual individual liability, or we accept corporate espionage against citizens as a perfectly rational market strategy.

← Back to Edition 17