B1 first appeared on a dark web forum called /void/chat, posting a decrypted copy of a pharmaceutical company’s internal safety report — not to extort them, but to expose that a faulty batch of insulin had been quietly buried. No ransom note. No manifesto. Just the data, timestamped, with a PGP signature reading B1 .
No ransom. No threat. Just a warning — delivered illegally, but undeniably useful. hacker b1
When reached for comment, the firm’s lead author backtracked slightly: “We’re not sure. That’s the honest answer. B1 leaves no metadata, no reusable infrastructure, no behavioral patterns longer than 48 hours. It’s like chasing fog.” Law enforcement has come close twice. In November 2024, the FBI seized a server in Luxembourg that B1 had used as a jump point — but found only a single file left behind: a high-resolution scan of a 1980s-era photo showing a crowded internet cafe, with one face circled in red ink. B1 first appeared on a dark web forum
For three years, B1 has been the most elusive, contradictory, and oddly principled operator in the global cyber underground. Not quite a black hat. Not quite a white hat. Something else entirely. “B1 isn’t a person. It’s a role,” says Dina Kaur, a former NSA cyber threat analyst who has tracked the entity since 2023. “The name comes from chess — the B1 square. It’s the starting position of a knight. That piece doesn’t move in straight lines. It jumps.” Just the data, timestamped, with a PGP signature reading B1