From GhostExodus to OSINT: Jesse McGraw’s pivot

Jesse McGraw, convicted in 2011 as the hacker GhostExodus, now uses open-source intelligence to find online predators and advise on lawful cybersecurity.

Jesse McGraw, once known online as GhostExodus and sentenced in 2011 to 110 months in prison, now works with open-source intelligence to identify online predators and promote legal cybersecurity practices.

In 2009 McGraw and members of the Electronik Tribulation Army planned a retaliatory attack against rival groups. While working nights as a security guard at the North Central Medical Plaza in Dallas, he accessed more than a dozen computers, including the building’s HVAC control system. He recorded a video that showed his face and the control equipment in the background. A researcher who studies industrial control systems used publicly available information from the footage to locate the facility and notified federal authorities. McGraw was arrested days before a planned July 4 action and later received a roughly 11-year sentence, reflecting the potential risk to patients and clinic operations.

After serving his sentence, McGraw says he stopped illegal intrusion and redirected his skills. He now leads a team that uses only open-source intelligence to find and report online predators, support child victims and create educational materials for parents and schools. He described this role as a form of ‘red hat’ work, applying adversary thinking without breaking the law. ‘The victim impact is now central to what I do today,’ McGraw wrote.

McGraw traces his earlier actions to social isolation and to discovering hacking in high school. He recalled a friend writing a tool in a math class and using it to move through the school network. In his teens he relied on social engineering and sought the technical challenge rather than financial gain. He identifies as neurodivergent and says episodes of intense focus helped him find technical flaws, which he combined with rising risk taking as earlier thrills faded.

He now concentrates on the sectors his group once targeted, including healthcare, education and industrial control systems. He reports findings to law enforcement, advises activists on legal limits for online campaigns, and works with security professionals to reduce harm to critical services. McGraw has taken part in podcasts and a feature-length documentary on cyber conflict. He wrote that he has no desire to return to his former activities and that he uses his knowledge to help victims and prevent attacks.

Articles by this author