10 Most Influential Ethical Hackers to follow in 2026
In 2018, a researcher scanning Magento-powered online stores noticed something odd: the same few lines of malicious JavaScript kept turning up, siphoning payment card numbers straight out of checkout pages before the data ever reached a payment processor. They kept pulling the thread. By the time the findings went public, the same skimmer, later nicknamed MagentoCore, turned out to be sitting inside more than 7,300 live stores, undetected by the store owners, their hosting providers, and their security tools alike.
Nobody paid that researcher to find it. No company had commissioned an audit. Someone noticed something that didn’t look right, kept digging, and told the world before criminals could keep quietly draining card numbers from unsuspecting shoppers. That’s the pattern behind almost every meaningful advance in web security over the last two decades: not a vendor’s roadmap, but an independent hacker who went looking for trouble no one else was watching for.
Keep that story in mind because Willem de Groot is the first one on the list.
That’s also, not coincidentally, the exact blind spot this list is about. Traditional perimeter defenses (firewalls, WAFs, endpoint tools) are built to watch the front door. The researchers on this list built their reputations finding what happens after the front door: inside the browser, inside a third-party script, inside a payment page, inside a consent banner nobody reads. It’s the same territory Reflectiz exists to monitor, which is exactly why the people who do this work in public, for free, in front of an audience, deserve to be followed.
This list publishes on October 1, International Ethical Hackers Day and the opening day of Cybersecurity Awareness Month, as the next entry in a series that’s already covered the men and the women shaping cybersecurity conversation, and the CISOs setting enterprise risk strategy. This one is about the people doing the finding: the hands-on researchers, bounty hunters, and builders whose work routinely becomes next year’s supply chain attack retrospective if nobody catches it first.
How this list was built
No one here bought their way onto this list, and no one was ranked by follower count. Every name below has a documented, verifiable body of hands-on work: disclosed vulnerabilities, tracked malware campaigns, published research, or tools the community actually uses. Where two researchers were equally accomplished, we leaned toward the one more active in public, because a list of people “to follow” should be led by people who are actually easy to follow.
10. Willem de Groot
Netherlands · LinkedIn · X (@gwillem)
Focus areas: Magecart, e-commerce malware, Magento/Adobe Commerce security
His name is Willem de Groot, and he’s the researcher behind the MagentoCore story that opened this list. For more than a decade, he has done more than almost anyone alive to make Magecart a household name in security circles. His research (MagentoCore, the “Shopper Approved” plugin compromise, and a long string of other skimmer campaigns) has been covered by BleepingComputer, TechCrunch, and Security Affairs so many times that his name has become shorthand for “someone actually checked.” He runs ongoing, largely unfunded scans of the e-commerce web looking for exactly the kind of client-side skimming code that PCI DSS 4.0’s newer script-inventory requirements were written to catch.
Why his voice matters: De Groot represents the purest version of independent security research: no employer mandate, no bounty program paying him per find, just a researcher who decided someone needed to keep counting the infected stores everyone else stopped looking at.
What makes him influential: He’s arguably done more to document the actual scale of the Magecart problem, in numbers, than any single vendor report, which is exactly the kind of client-side visibility gap tools like WAFs are structurally blind to.
9. STÖK (Fredrik Alexandersson)
Sweden · LinkedIn · X (@stokfredrik)
Focus areas: Bug bounty, live hacking events, security education/content
STÖK built one of the most recognizable personal brands in offensive security by doing something unusual for the field: filming it. His YouTube hacking vlogs turned invite-only live-hacking events into something a much wider audience could watch and learn from, and his reputation has grown to the point that Google invited him to a closed-door red-teaming session against its own flagship AI products, a level of trust that isn’t handed out for follower counts alone.
Why his voice matters: He’s proof that teaching in public and doing serious technical work aren’t in tension: his content has pulled a large number of newcomers into bug bounty who might never have found the field otherwise.
What makes him influential: Continuous, adversarial probing (the exact discipline STÖK has built his career and his content around) is precisely the mindset behind Reflectiz’s own approach to ongoing penetration testing, rather than the once-a-year scan-and-forget model.
8. Zach Edwards
United States · LinkedIn · X (@thezedwards)
Focus areas: Ad-tech, tracking/consent research, digital privacy investigations
Zach Edwards occupies a specialty most “top hacker” lists skip entirely: the invisible layer of trackers, pixels, and SDKs that quietly collect data on nearly every website, often in ways that violate the very consent banners sitting on top of them. His research is regularly cited in security and privacy journalism, including KrebsOnSecurity’s 2026 coverage of consumer tracking exposure, and he maintains an active HackerOne profile alongside his work as a threat researcher.
Why his voice matters: Most security conversations still treat privacy as a legal checkbox rather than a technical attack surface. Edwards treats it as exactly that: something you investigate, not just something you certify.
What makes him influential: This is the layer most security tooling ignores completely: a tracker that fires before consent, or keeps running after a user opts out, is invisible to a WAF, but very visible to a regulator, which is exactly the gap Privacy Hub-style monitoring exists to close.
7. Anand Prakash
India · LinkedIn · X (@anandpraka_sh)
Focus areas: Web application security, bug bounty, cloud security
Anand Prakash built his reputation the traditional bug-bounty way (high-profile, high-severity finds at Facebook, Uber, and Twitter, among others), then did something less traditional with it: he built a company. AppSecure grew into PingSafe, a cloud security startup that SentinelOne acquired for more than $100 million in 2024. Few researchers on any “top hacker” list have taken a personal bug-hunting reputation and turned it into an outcome that large.
Why his voice matters: Prakash is a rare example of a bounty hunter’s technical instincts scaling into an entire company’s product thesis, rather than staying a side hustle alongside a day job.
What makes him influential: His path from single vulnerability reports to founding an acquired security company is a genuine hacker-to-builder story, at a scale most bounty hunters only aspire to.
6. Ben Sadeghipour (NahamSec)
United States · LinkedIn · X (@nahamsec)
Focus areas: Bug bounty, live-hacking streams, security education
Ben Sadeghipour, better known in the community as NahamSec, is one of the most consistently visible bug bounty hunters working today, not because he chases headlines, but because he live-streams the actual work. His recon streams, YouTube tutorials, and interview series have turned into one of the more reliable on-ramps for people trying to break into bug bounty from scratch, and his own hunting record backs up the teaching. That teaching instinct has since scaled into HackingHub, a hands-on hacking education platform he co-founded and now runs as CEO.
Why his voice matters: A huge amount of what makes bug bounty intimidating to newcomers is that the process is usually invisible; Sadeghipour made it watchable, in real time, mistakes included.
What makes him influential: Like STÖK, his career is a standing argument that a website’s real exposure isn’t what an annual scan finds; it’s what a motivated, continuously probing researcher finds today, live, on camera.
5. Obadare Peter Adewale
Nigeria · LinkedIn · X (@ObadareAdewale)
Focus areas: Penetration testing, PCI compliance assessment, security governance
Obadare Peter Adewale holds a distinction that’s easy to state and hard to overstate: he’s recognized as the first EC-Council Licensed Penetration Tester in Africa. He co-founded Digital Encode in 2003 (a two-decade run in hands-on security assessment) and holds a PCI Qualified Security Assessor (QSA) credential alongside a lifetime OWASP membership. In 2024 he became Nigeria’s first Professor of Practice in Cybersecurity, at Miva Open University, and he sits on Lagos State’s Cybersecurity Advisory Board.
Why his voice matters: He’s spent more than twenty years doing the unglamorous, technical, hands-on work of penetration testing and compliance assessment in a market most global “top hacker” lists never look at.
What makes him influential: As a working PCI QSA, he sits at the exact intersection this list keeps returning to: the point where hands-on penetration testing and payment-card compliance are, in practice, the same job.
4. Farah Hawa
Focus areas: Application security, bug bounty, security education/content
Farah Hawa built her reputation the way bug bounty rewards actual work: methodically, in public. She started documenting her bug bounty journey on YouTube early in her career, a decision that turned into one of the more genuinely useful on-ramps for newcomers trying to understand what hunting for vulnerabilities actually looks like day to day. Bugcrowd featured her in its own Community Spotlight series, and her career has since carried her from full-time penetration testing roles into her current position as a Security Analyst at Meta, with a large and active Instagram and YouTube following built entirely around her hacking content.
Why her voice matters: Most bug bounty content is either too technical for beginners or too shallow to be useful. Hawa’s has stayed genuinely instructional as her own career has grown more senior.
What makes her influential: Her path, from documenting her first bugs on camera to a security analyst role at one of the world’s largest platforms, is a real demonstration that public, hands-on learning compounds into a serious career.
3. Rachel Tobac
United States · LinkedIn · X (@RachelTobac)
Focus areas: Social engineering, human-layer security, security awareness
Rachel Tobac, CEO of SocialProof Security, has spent her career proving a point most technical security conversations conveniently skip: a lot of the most damaging breaches never touch a line of vulnerable code. Bugcrowd’s own “Hacker Spotlight” series has featured her work, and her live social-engineering demonstrations (for national press, for congressional audiences, for CNN’s cameras) have made the abstract idea of social engineering concrete for people who’d otherwise assume “hacking” only means typing.
Why her voice matters: Not every risk is a line of code. Some of it is a phone call, a convincing voice, and thirty seconds of someone’s trust, and no scanner on earth catches that.
What makes her influential: She’s one of the clearest public reminders that a fully patched, perfectly monitored system can still be walked straight through the front door by a good enough conversation.
2. HD Moore
United States · LinkedIn · X (@hdmoore)
Focus areas: Penetration testing tools, attack surface management, exposure discovery
HD Moore earns a spot on this list for a body of work that quietly underpins an enormous share of offensive security today: he created the Metasploit Framework, the tool that turned exploit development and penetration testing from a scattered, ad-hoc craft into something with shared infrastructure the whole industry could build on. He later founded Rumble, now runZero, focused on a problem that should sound familiar by now: attack surface visibility, and specifically all the assets and exposures that traditional tools never get around to finding.
Why his voice matters: Almost every other researcher on this list has, at some point, used a tool Moore built or a framework he influenced. Few people’s fingerprints are on more of the field’s actual tooling.
What makes him influential: His current focus (finding what an organization doesn’t know it’s running) is, almost word for word, the exposure management problem this entire list keeps circling back to.
1. Ysrael Gurt
Focus areas: Client-side security, Magecart research, exposure management
Ysrael Gurt is someone Google has publicly recognized as one of the top researchers in its Vulnerability Reward Program. His path into the field, detailed in Forbes’ 30 Under 30 coverage and in interviews with the Israeli tech press, has been an unusual one even by hacker standards, and it’s fed directly into the Magecart and client-side threat research he’s spoken about publicly for years, including deep dives into how skimming campaigns have targeted Shopify stores. Today, he is Reflectiz’s co-founder and CTO.
Why his voice matters: He’s spent years staring specifically at the layer traditional security tools miss: the browser, the third-party script, the checkout page, which is precisely the terrain the rest of this list operates in.
What makes him influential: He built a company around the exact blind spot his own bug-hunting career kept running into, which is a more honest test of conviction than most “visionary founder” narratives can claim.
Why These Voices Keep the Web Honest
Ten different specialties, ten different countries, and one thread running through all of them: none of this research happened because a scanner ran on schedule. It happened because a person went looking (at a checkout page, a tracking pixel, a login flow, a phone call) for the thing that wasn’t supposed to be there. That’s the same posture behind continuous exposure management: not a once-a-year audit, but an assumption that something is probably already wrong, and the only question is who finds it first.
FAQs
How do I start a career in ethical hacking or bug bounty?
Most researchers on this list point to the same on-ramps: platforms like HackerOne and Bugcrowd, structured courses (several featured here teach exactly this), and hands-on practice environments like Hack The Box or TryHackMe, followed by building a public track record of disclosed findings.
How does this connect to what Reflectiz does?
Every specialty on this list (client-side threats, continuous penetration testing, tracking/privacy exposure, and payment-page compliance) maps to a real gap traditional security tools leave open. That’s the same gap Reflectiz’s platform is built to close.
What is an ethical hacker?
A white hat hacker is a security researcher who finds vulnerabilities and discloses them responsibly, to the affected company, a bug bounty program, or the public, rather than exploiting them for personal gain.
What is International Ethical Hackers Day?
Observed on October 1st, it’s a day recognizing the contributions of ethical hackers and security researchers to global cybersecurity, and it falls at the start of Cybersecurity Awareness Month.
What is Magecart, and why does it come up so often on this list?
Magecart refers to a family of criminal groups that inject skimming code into e-commerce checkout pages to steal payment card data directly from shoppers’ browsers, a client-side attack that traditional server-side security tools typically can’t see.
What’s the difference between white hat, grey hat, and black hat hackers?
White hats operate with permission or through responsible disclosure; black hats exploit vulnerabilities maliciously for profit or harm; grey hats sit in between, sometimes finding and disclosing issues without explicit authorization but without malicious intent.
Subscribe to our newsletter
Stay updated with the latest news, articles, and insights from Reflectiz.
AI Has Changed The Web.
Are You Ready for What’s Next?
Third-party code shifts by the hour. Supply-chain compromises strike without warning. AI-driven web attacks now evolve faster than traditional security can ever keep up.
Reflectiz delivers the continuous, real-time visibility needed to expose the risks traditional tools miss entirely.
Zero code changes. Zero access to your data. Ultimate peace of mind.