<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Industry of Anonymity]]></title><description><![CDATA[A newsletter that goes inside the business of cybercrime]]></description><link>https://industryofanonymity.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png</url><title>Industry of Anonymity</title><link>https://industryofanonymity.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 02 Sep 2026 07:17:06 GMT</lastBuildDate><atom:link href="/__u/industryofanonymity.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jonathan Lusthaus]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[industryofanonymity@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[industryofanonymity@substack.com]]></itunes:email><itunes:name><![CDATA[Jonathan Lusthaus]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jonathan Lusthaus]]></itunes:author><googleplay:owner><![CDATA[industryofanonymity@substack.com]]></googleplay:owner><googleplay:email><![CDATA[industryofanonymity@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jonathan Lusthaus]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Pirate vs Privateer]]></title><description><![CDATA[This guest post was written by Dr Miranda Bruce, a researcher who specialises in the geography of cybercrime.]]></description><link>https://industryofanonymity.substack.com/p/pirate-vs-privateer</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/pirate-vs-privateer</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Mon, 31 Aug 2026 11:03:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Naval analogies have long been a mainstay in cybersecurity discourse. This month, one that&#8217;s been floating around for at least a decade has jumped back into the spotlight: the cyber privateer. Privateers were private naval companies given &#8216;letters of marque&#8217; to attack enemy ships on behalf of the State. Although privateering was a relatively short-lived arrangement &#8212; climaxing in the UK with the execution of infamous privateer-turned-pirate Sir Walter Raleigh &#8212; it provided a critical stop-gap measure for countries under siege and running out of public resources.</p><p>This is precisely the fix proposed by the Trump Administration&#8217;s Presidential Memo from a few weeks ago: &#8220;<a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/">Expanding Capabilities to Combat Transnational Cyber-Enabled Crime</a>&#8221;. The Memo announces a program that will allow vetted private companies to conduct &#8220;surveillance and cyber effects operations&#8221; against individuals and groups conducting &#8220;cyber-enabled crime&#8221;. The target is &#8220;transnational criminal organizations&#8221; and the &#8220;cybe&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/pirate-vs-privateer">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Revenge of the (cyber) nerds?]]></title><description><![CDATA[The subject of this month&#8217;s post is the sentencing of two young, but serious, cybercriminals.]]></description><link>https://industryofanonymity.substack.com/p/revenge-of-the-cyber-nerds</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/revenge-of-the-cyber-nerds</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Fri, 31 Jul 2026 20:42:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>The subject of this month&#8217;s post is the </span><a href="https://www.cps.gov.uk/national-news/news/cyberhackers-who-targeted-tfl-jailed-more-five-years-each"><span>sentencing</span></a><span> of two young, but serious, cybercriminals. Owen Flowers and Thalha Jubair, both based in the UK, were teenagers when they carried out their attacks on Transport for London (and, of course, other targets). They have been linked to the highly visible network known as Scattered Spider, responsible for </span><a href="/__u/industryofanonymity.substack.com/p/cybercrime-and-the-mundane"><span>high profile attacks</span></a><span> on MGM Resorts, Harrods, M&amp;S and Co-op. Jubair has also been linked to the </span><a href="https://www.bbc.co.uk/news/articles/c4gyg0y6yg2o"><span>overlapping collectives</span></a><span> of The Com and Lapsus$.</span></p><p><span>When the arrest, prosecution and sentencing of cybercriminals takes place we get a rare opportunity to examine these seemingly faceless offenders. The recent activities of Scattered Spider have created fear for its victims, the cybersecurity community and, with increased media reporting, the general public as well. The immediate realisation on reviewing the published information on these offenders is that they are young and also nerds (I say this as a proud nerd myself). They were both known to spend&#8230;</span></p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/revenge-of-the-cyber-nerds">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Apr - Jun 2026)]]></title><description><![CDATA[This edition of the Cybercrime Research Quarterly continues the discussion on AI and cybercrime.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-c60</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-c60</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Tue, 30 Jun 2026 21:15:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>This edition of the Cybercrime Research Quarterly continues the discussion on AI and cybercrime. In my April post, I examined the news of Anthropic&#8217;s Claude </span><a href="/__u/industryofanonymity.substack.com/p/mythical-threats"><span>Mythos</span></a><span> model, and the likelihood (or not) that it would reshape the world of cyber threats. Following on from this, I now profile an academic paper presented at the Workshop on the Economics of Information Security (WEIS), held earlier this month in Berkeley. Co-authored by Jack Hughes, Ben Collier, and Daniel Thomas, the paper is called </span><a href="https://weis2026.econinfosec.org/wp-content/uploads/sites/13/2026/05/WEIS2026_paper_12.pdf"><span>&#8220;Stand-Alone Complex or Vibercrime? Exploring the adoption and innovation of GenAI tools, coding assistants, and agents within cybercrime ecosystems&#8221;</span></a><span>. This paper addresses the issue, which is a worry to some, of whether AI is being widely adopted by cybercriminals and enhancing the threat they pose.</span></p><p><span>The paper is a long and winding read, so here I provide some key highlights and reflections. The authors adopt an exploratory approach, seeking to answer three key research questions:</span></p><p><span>1. How much interest is the underground cybercrime ecosystem showing in these tools and what effects are they having on cybercrime subcultures?</span></p><p><span>2. Are these communities adopting these tools, and if so, how?</span></p><p><span>3. What are the economic effects of GenAI innovations on cybercrime?</span></p><p><span>In terms of data, the paper draws on </span><a href="https://www.cl.cam.ac.uk/~sp849/files/2018-crimebb.pdf"><span>CrimeBB</span></a><span>, an archive managed by the Cambridge Cybercrime Centre, which provides many millions of posts for research on a range of underground forums. The authors curated a sample of 97,895 relevant threads across these forums, spanning from late 2022 until late 2025. This period captures the point at which ChatGPT was released up to the point that the researchers undertook the analysis. In terms of methods, the paper makes use of a m&#233;lange of computational and human components, with intersecting quantitative and qualitative elements.</span></p><p><span>What are the key conclusions from this paper? The authors find, in line with existing literature on cybercrime and technical innovation, that AI adoption among users of underground forums is far from hype worthy. While there is some evidence for its use, no major disruptions to the cybercriminal ecosystem have been observed. Instead, the authors argue that, prior to the AI flood, cybercrime was already increasingly automated and specialised. Low level actors already had access to off-the-shelf tools and scripts, and AI does not significantly lower the barriers to entry any further. For more elite actors, AI aids software development, but in a more incremental way, by supplanting existing means for checking errors and other basic coding tasks.</span></p><p><span>A key feature of the article&#8217;s set up is to test for both maximal and minimal cases of AI adoption by the cybercriminal community. The maximal case would be the development of &#8220;autonomous or semi-autonomous crime-gang-in-a-box infrastructure&#8221; leading to a &#8220;full-scale industrial transformation of the cybercrime ecosystem&#8221;. The minimal case is where AI is taken on by actors in unstructured and ad hoc ways with no significant impact seen in the organisation of cybercrime or its key business models. But by the end of this paper, this distinction is almost forgotten, as the cybercriminal use of AI appears so minimal it may even fall short of the hypothesised minimal case. In fact, in their conclusion, the authors editorialise: &#8220;In some ways this all suggests a more mature response from the cybercrime ecosystem than we see in industry (possibly because of the lack of a CEO and venture capital class). Many of the broader economic effects reflect patterns also observed in legitimate content and tech economies &#8211; for saturation of overproduced low-quality content in particular&#8221;.</span></p><p><span>Throughout the qualitative analysis, there are a number of points at which cybercriminal actors express very ambivalent attitudes towards this new tool and worry it degrades values within their community along with the central place of skill. One poster opines that &#8220;AI for code causes a very fast negative degradation of your skills&#8221;. Another champions the importance of human critical thinking and problem solving.</span></p><p><span>In considering cybercrime and AI adoption, we could take Hughes, Collier and Thomas&#8217; work as support for the maxim </span><em><span>evolution not revolution</span></em><span>. But we do need to be aware of the limitations of this study, many of which are noted by the authors. The CrimeBB database is constituted of open forums that often attract lower-level offenders. More serious and professional cybercriminals from around the globe, who congregate and communicate in closed channels and even offline, may have a different approach to AI. Additionally, like almost all academic studies, this paper cannot speak to the world of today or the future. It is possible novel AI developments, or the way the cybercriminal community engage with them, may shift going forward and we see a major change. But, for the moment and with the information we have, this research supports a more sober assessment of actual use of AI by cybercriminals, rather than speculating on a range of possible uses.</span></p>]]></content:encoded></item><item><title><![CDATA[Blank Canvas]]></title><description><![CDATA[This month&#8217;s post concerns the extortion of Instructure, the company that owns the online learning platform Canvas.]]></description><link>https://industryofanonymity.substack.com/p/blank-canvas</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/blank-canvas</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sun, 31 May 2026 21:44:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This month&#8217;s post concerns the extortion of Instructure, the company that owns the online learning platform Canvas. Canvas is used by thousands of universities and other educational institutions around the world, and provides multiple functions, including for sharing course materials like lecture slides and communicating with students. It can also be used to publish assessments, receive submissions and facilitate marking.</p><p>While it is likely that Canvas was breached over a longer period of time, on May 7 the attackers defaced the login page with a public extortion demand and Instructure disabled the platform in response. ShinyHunters, a shadowy network of (probably) young offenders well-known for similar extortions, claimed responsibility. On May 11, a ransom payment was made in exchange for data return, the destruction of stolen data and a promise to cease extortion attempts against Instructure and its customers. For more details on this episode see <a href="https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/">here</a>, <a href="https://www.bbc.co.uk/news/articles/cdepzg83x87o">here</a> and <a href="https://www.wired.com/story/canvas-hack-shinyhunters-ransomware-instructure/">here</a>.</p><p>Many likely did not take notice of this attack. Canvas is not a big brand that would attract the same level of media attention as more famous entities, such as <a href="/__u/industryofanonymity.substack.com/p/cybercrime-and-the-mundane">Harrods</a> or <a href="/__u/industryofanonymity.substack.com/p/the-cybercrime-quarterly-jul-sep-0f3?utm_source=publication-search">MGM</a>. It is so niche to the education sector, that even some working in cyber threat intelligence may not have paid much attention to the news. But if you work in the education sector, as I do, the episode was immediately noteworthy as it had a direct impact on day-to-day operations. This speaks to the scale and breadth of modern-day cybercrime: beyond the headlines, many victims remain hidden below the surface.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/blank-canvas">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Mythical Threats]]></title><description><![CDATA[Whenever the topic of AI comes up in public (and private) discussions, there are two clear camps that consistently emerge.]]></description><link>https://industryofanonymity.substack.com/p/mythical-threats</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/mythical-threats</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Thu, 30 Apr 2026 21:07:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Whenever the topic of AI comes up in public (and private) discussions, there are two clear camps that consistently emerge. On one side are the hype merchants who speak of the groundbreaking revolutions that AI will bring to many facets of human life. Naturally, some in this camp are AI companies and their advocates, but there are also independents who are genuinely impressed by this innovation. On the other side are the sceptics. Those within this latter group argue that AI does not come close to delivering what the hype merchants say it does, or there are major concerns with its use.</p><p>This AI debate is found within the cybersecurity discourse as well. A good example is the release this month of Anthropic&#8217;s Claude Mythos model. Early reporting on the release speculated on the power of this model and the sophisticated hacking threat it could pose. For instance, the <a href="https://www.bbc.com/news/articles/c2ev24yx4rmo">BBC reported</a> that &#8220;[f]inance ministers, central bankers and financiers have expressed serious concerns about a powerful new AI model they fear could undermine the security of financial systems&#8221;. Due to its supposed power, Mythos was only released to a small number of companies and organisations to test, further enhancing the mystique and concerns around the model. In response to these reports, sceptic experts kicked into gear questioning the capacity and importance of the Mythos release, with claims along the lines that the news was a &#8220;<a href="https://www.theregister.com/2026/04/22/anthropic_mythos_hype_nothingburger/?utm_medium=share&amp;utm_content=article&amp;utm_source=linkedin">nothingburger</a>&#8221;.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/mythical-threats">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Jan - Mar 2026)]]></title><description><![CDATA[For the first edition of the Cybercrime Research Quarterly 2026 I engage with an article published this month in the The British Journal of Criminology, titled &#8220;Violence, Conflicts and Weapons in the World of Financial&#8211;Economic Cybercrime&#8221;.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-75f</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-75f</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Tue, 31 Mar 2026 11:15:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For the first edition of the Cybercrime Research Quarterly 2026 I engage with an article published this month in the <em>The British Journal of</em> <em>Criminology,</em> titled &#8220;<a href="https://academic.oup.com/bjc/article/66/2/331/8161387">Violence, Conflicts and Weapons in the World of Financial&#8211;Economic Cybercrime</a>&#8221;. Co-authored by Luuk Bekkers and Rutger Leukfeldt, the article examines an important, but not widely studied, topic: how embedded is violence in the world of cybercrime?</p><p>Cybercrime is often regarded as a somewhat &#8220;nerdy&#8221; endeavour where threats are chiefly digital rather than physical. But cybercriminals are not just some intangible threat. They exist in the offline world, with some even knowing each other in person. In these cases, physical violence between them is possible, even if it is not the norm. Perhaps the most famous example comes from Turkey in the mid 2000s when a leading fraudster, operating under the nickname Cha0, <a href="https://www.wired.com/2008/09/turkish-police/">kidnapped a hacker</a> called Kier and posted pictures of him online, alongside a note branding him as an informant.</p><p>Using more recent police data from the Netherlands, Bekkers and Leukfeldt conduct a rare academic study of cybercriminal violence. They analyse 15 closed investigations of cybercriminal networks, with a focus on fraud cases: &#8220;phishing, bank helpdesk fraud, online consumer fraud and/or friend-in-need fraud&#8221;. This paper is part of a broader project focussed on money mule linked networks. By directly accessing police files and interviewing investigators, the article follows the approach of the Dutch Organised Crime Monitor, which involves direct support from the authorities. Similar approaches are not always possible in other jurisdictions where academic-police cooperation is less developed.</p><p>Bekkers and Leukfeldt identify violence or the threat of violence in 10 out of their 15 cases, finding that there is a range of manifestations of violence within financial cybercrime. In sum:</p><p>&#8220;This primarily involves relatively minor forms, such as threats made to invoke fear and to ensure cooperation from co-offenders. However, while not all suspects were associated with violent behaviours, a number of core members were demonstrably willing and capable of using physical violence. Some already had a history of violent offences, e.g. armed robbery, and introduce these tools in the online crime sphere; not only for direct financial purposes, but also as a more expressive reaction related to conflict, betrayal and status. This reflects the concept of &#8216;cafeteria-style offending&#8217;: some of the offenders involved in offline financially driven crime commit similar offences online, opportunistically looking for different ways to earn money. Other cybercrime suspects were engaged in violent behaviours without a known criminal history&#8221;.</p><p>They then apply an existing framework of violence to the case studies. Each of the five categories of this framework find some support:</p><p>&#183; Violence as part of the modus operandi (1 case)</p><p>&#183; Violence as a way of keeping co-offenders in line (8 cases)</p><p>&#183; Violence to hide illegal activities from authorities (5 cases)</p><p>&#183; Violence as a way of settling disputes (6 cases)</p><p>&#183; Violence as a reaction to betrayal (5 cases)</p><p>Despite many of these cases involving violence or the threat of violence, it did not appear to be an important part of each cybercriminal business model. That is, perhaps not unexpectedly, because the frauds take place online and victims are duped and digitally victimised (which is what makes these cases cybercrime). There was only one investigation where violence was connected to the modus operandi: a threat that a motorcycle gang would pay a visit to victims if they did not provide their bank account details. The rest of the instances of violence concerned the internal dynamics of the cybercriminal networks. Of the remaining overlapping categories, keeping co-offenders in line was dominant, appearing in eight cases.</p><p>While this paper demonstrates the ways in which violence might be embedded within cybercriminal networks, it does not provide evidence that it is widely used. As the authors note, the sample of investigations is not representative of all cybercrime cases. First, the cases are only Dutch and there may be differences in other jurisdictions. Second, the cases are only those that have been prosecuted and there may be differences between these cases and those of cybercriminals who were never caught.</p><p>Finally, the cases are not representative even of Dutch prosecutions. There is no sampling frame (complete list) of all relevant prosecutions to choose from, and the selected investigations are intentionally focussed on fraud and money laundering networks. Given that these kind of offences are less technical and often involve offenders who have connections to forms of conventional crime, it would not be surprising if these offenders are linked to violence in ways that criminal hackers and coders are unlikely to be. Money mules, who have access to the proceeds of cybercrimes, are relatively low-level actors who make for unreliable collaborators that need to be kept in line. In this paper, the offenders doing this &#8220;keeping in line&#8221; owned firearms and had past histories of violent offences, including robbery and assault. It is far more likely that beatings, shootings, or the threat of beatings and shootings, will emanate from these kinds of &#8220;thugs&#8221; rather than the &#8220;nerds&#8221; that may be associated with more technical offences.</p>]]></content:encoded></item><item><title><![CDATA[Navigating Shadowlands]]></title><description><![CDATA[This month&#8217;s post is inspired by Kim Zetter&#8217;s profile of Allison Nixon, published on February 16 in the MIT Technology Review. Nixon is the Chief Research Officer at the cyber threat intelligence company Unit 221B, and has garnered increasing amounts of attention in recent times as a key figure investigating the Com, a loose network of largely young Western offenders engaged in a range of offending from ransomware to sextortion. While Zetter&#8217;s profile highlights many interesting aspects of the cat and mouse game being played out between Nixon and these offenders, the key element that drew my attention was the discussion of the personal threats Nixon has faced.]]></description><link>https://industryofanonymity.substack.com/p/navigating-shadowlands</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/navigating-shadowlands</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sat, 28 Feb 2026 19:00:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This month&#8217;s post is inspired by Kim Zetter&#8217;s <a href="https://www.technologyreview.com/2026/02/16/1132526/allison-nixon-hackers-security-researcher/">profile of Allison Nixon</a>, published on February 16 in the <em>MIT Technology Review</em>. Nixon is the Chief Research Officer at the cyber threat intelligence company Unit 221B, and has garnered increasing amounts of attention in recent times as a key figure investigating the Com, a loose network of largely young Western offenders engaged in a range of offending from ransomware to sextortion. While Zetter&#8217;s profile highlights many interesting aspects of the cat and mouse game being played out between Nixon and these offenders, the key element that drew my attention was the discussion of the personal threats Nixon has faced.</p><p>The article includes examples of public and graphic death threats made online against Nixon, as well as the sharing of AI generated nudes based on her likeness. In line with the Com&#8217;s reputation for nastiness, Zetter also makes mention of potential offline threats, including &#8220;bricking&#8221; (throwing a brick through a victim&#8217;s window)&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/navigating-shadowlands">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Black Axe]]></title><description><![CDATA[Each month, when I write these posts, I spend some time thinking of an appropriate title that captures the essence of the news I am reflecting on.]]></description><link>https://industryofanonymity.substack.com/p/the-black-axe</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-black-axe</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sat, 31 Jan 2026 14:02:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Each month, when I write these posts, I spend some time thinking of an appropriate title that captures the essence of the news I am reflecting on. My intention is for the title to be both evocative and accurate. This month, part of my effort was saved by a story that provides its own title. In early January, <a href="https://www.europol.europa.eu/media-press/newsroom/news/34-arrests-in-spain-during-action-against-black-axe-criminal-organisation">Europol</a> and the <a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16763">Spanish National Police</a> both announced an operation against the &#8216;Black Axe&#8217; criminal organisation, which resulted in 34 arrests in Seville, as well as in Madrid, M&#225;laga and Barcelona.</p><p>Black Axe has its origins in Nigeria but now operates globally. Europol provides a worrying overview:</p><p>&#8220;The criminal network is known for its involvement in a wide range of criminal activities, including cyber-enabled fraud, drug trafficking, human trafficking and prostitution, kidnapping, armed robbery and fraudulent spiritual practices. The group&#8217;s annual criminal proceeds are estimated to be in the billions of euros, generated through many small-scale operations that collectively have&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/the-black-axe">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Oct - Dec 2025)]]></title><description><![CDATA[The final 2025 edition of the Cybercrime Research Quarterly summarises my law review article &#8220;The Cybercrime Industry&#8221;, which was recently published in the Harvard National Security Journal. The article examines the emergence of cybercrime as a highly specialised and professional industry.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-0fb</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-0fb</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Wed, 31 Dec 2025 16:11:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The final 2025 edition of the Cybercrime Research Quarterly summarises my law review article <a href="https://journals.law.harvard.edu/nsj/wp-content/uploads/sites/82/2025/11/Lusthaus_16-Harvard-Natl-Security-J.-2-2025.pdf">&#8220;The Cybercrime Industry&#8221;,</a> which was recently published in the <em>Harvard National Security Journal.</em> The article examines the emergence of cybercrime as a highly specialised and professional industry. It focusses on the puzzle of how cybercriminals industrialised on this scale despite operating in a highly distrustful environment where true identities are shrouded and physical enforcement is curtailed. There are famous works by legal scholars, such as <a href="https://www.hup.harvard.edu/books/9780674641693">Robert Ellickson</a> and <a href="https://www.journals.uchicago.edu/doi/abs/10.1086/467902">Lisa Bernstein</a>, which examine private ordering and the ways in which people informally govern themselves in contexts where the state fails to do so efficiently &#8211; from cattle ranchers to the diamond industry. This article focusses on criminal settings which the state cannot legitimately regulate, leaving these cybercriminals to govern themselves beyond the law. Three key data sources underpin this study: hundreds of interviews with law enforcement, security professionals and former cybercriminals, carried out across 20 countries; legal documents from the United States and elsewhere; and archives of cybercriminal marketplaces, particularly Darkode, which was the major English language forum for technical goods and services, like malware, before it was shut down by law enforcement in 2015.</p><p>The solution to the puzzle identified above is encapsulated in the paper like this:</p><p>&#8220;Rather than developing new methods to enhance cooperation, it appears that cybercriminals have leveraged existing mechanisms that have worked in many other aspects of human life. In particular, reputation and enforcement have been widely employed in the governance of cybercrime. Online forums and marketplaces have developed a number of institutions which provide order and considerably scale up trade, along with other forms of cooperation, to much larger networks of cybercriminals. These components blur the boundary between self-governance and private governance. Marketplaces extend the reputation mechanism by employing tools like quantitative rating systems and allowing for qualitative reviews and information to be published on users. Administrators also create and enforce rules to prevent scams and other negative behaviours&#8221;.</p><p>An intriguing theme across the article&#8217;s findings is that there appear to be limits to the success of cybercriminal governance. Despite their best attempts to vet membership, enforce rules or resolve disputes, misbehaviour remains a key challenge for these communities. This is not surprising given we are talking about criminal communities, many of whom specialise in forms of online fraud. But it should also be remembered that the application of the law is far from perfect in more legitimate settings. For instance, many crimes are never reported to the police, and, of those that are, only a fraction are investigated and prosecuted to completion. In short, extra-legal governance is &#8220;likely to reduce risks involved in cooperation, but it cannot solve them entirely&#8221;.</p><p>Some of these broad findings may be familiar to readers of <em><a href="https://jonathanlusthaus.com/industry-of-anonymity/">Industry of Anonymity</a></em>. But one of the key points of interest in this new article is that there are &#8220;layers of order within the underground, and cybercriminals may not necessarily choose to operate in the most structured and visibly regulated settings&#8221;. This is perhaps a natural extension of the idea of private ordering itself. While all cybercriminal governance is informal by virtue of being unofficial and beyond the state, there remain more and less structured forms of this informal governance. Large marketplaces have clearly stated rules, but small groups may operate on mutual understandings and norms. Yet, as the Darkode analysis shows, even when forums have a relatively strict governance system, a shadow system may still prevail: &#8220;Examples of this include administrators allowing new members in, like J.P. Morgan, against the standard rules for introduction, as well as disputes where administrators refuse to take a central arbitrator role and instead leave users to engage in their own conflict resolution, or simply allow the information to serve as a potential warning to the community&#8221;. For context, J.P. Morgan was the nickname of an elite Russian-speaking actor, who joined the site and was swiftly promoted without having to follow the normal protocols (much to the chagrin of some existing Darkode members).</p><p>To sum up the key takeaway from this article:</p><p>&#8220;For extra-legal governance, and the example of cybercrime, we can see that some rules are relatively formal, even if they are not derived from the state. But even in this type of setting, individuals may develop their own more informal systems of order to aid cooperation. There are layers of extra-legal governance and informal order. It would be a mistake to assume that modes of governance beyond the state&#8217;s authority are monolithic, and that users would have universal preferences which can be met by one system alone&#8221;.</p><p>Read the original article <a href="https://journals.law.harvard.edu/nsj/wp-content/uploads/sites/82/2025/11/Lusthaus_16-Harvard-Natl-Security-J.-2-2025.pdf">here</a>.</p>]]></content:encoded></item><item><title><![CDATA[Gamekeepers Turned Poachers]]></title><description><![CDATA[This month was a busy one for cybercrime news.]]></description><link>https://industryofanonymity.substack.com/p/gamekeepers-turned-poachers</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/gamekeepers-turned-poachers</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sun, 30 Nov 2025 22:46:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This month was a busy one for cybercrime news. Two well-known cybercriminals gave interviews on their operations to journalists, providing rare insider insights. One was a major figure in the history of Eastern European cybercrime, known online as <a href="https://www.bbc.co.uk/news/articles/cm2w0pvg4wko">Tank</a>. The other is a younger, more contemporary player in the form of <a href="https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/">Rey</a>, an administrator tied to the Scattered LAPSUS$ Hunters network which has carried out a series of recent high profile attacks. On the cyber-fraud side, a Chinese court sentenced five leading members of the <a href="https://www.bbc.com/news/articles/cy9pyljl009o">Bai family</a> to death for their role in extensive scam operations in Southeast Asia, while Trend Micro released a report on <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/reimagining-fraud-operations-the-rise-of-ai-powered-scam-assembly-lines">AI-powered scams</a>.</p><p>Despite there being a wealth of choices for this month&#8217;s newsletter post, I choose not to highlight any of these major events but, instead, to focus on a story which has captured less interest, yet offers an important opportunity for reflection. On November 2, <a href="https://chicago.suntimes.com/the-watchdogs/2025/11/02/crytpo-cryptocurrency-crime-chicago-digital-mint-ransom-ransomware-hack">news broke</a> that two individuals were indicted for carrying out ransomware attacks against US companies using ALPHV/BlackCat ransomware, with a third unindicted and unnamed co-conspirator listed (a copy of the indictment can be found <a href="https://regmedia.co.uk/2025/11/03/ryancliffordgoldberg_kevintylermartin_indictment.pdf">here</a>). While we know that the leaders/authors of these kinds of malware are based in Eastern Europe, what&#8217;s interesting about this case is that the two named individuals were based in the US states of Georgia and Texas, while the third, unnamed actor was from Florida. But what&#8217;s particularly intriguing about this case is that these three individuals were employees of cybersecurity firms. One worked as an incident response manager for Sygnia Cybersecurity Services and the other two worked for DigitalMint, a company that specialises in ransomware negotiations. All three have been fired.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/gamekeepers-turned-poachers">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Phish in a Barrel ]]></title><description><![CDATA[For quite some time the narrative around cybercrime has been that the key threats originate from outside the West.]]></description><link>https://industryofanonymity.substack.com/p/phish-in-a-barrel</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/phish-in-a-barrel</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Fri, 31 Oct 2025 21:58:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For quite some time the narrative around cybercrime has been that the key threats originate from outside the West. As such, policing cybercrime faces a fundamental challenge: carrying out investigations across borders. This challenge can be broken into numerous related obstacles: time and resources; divergent procedures; differing agendas; a lack of capacity; local corruption and so on. In many cases, the likelihood of arresting offenders has seemed low.</p><p>This narrative may soon need to change. Earlier this month we saw the <a href="https://www.theguardian.com/uk-news/2025/oct/07/man-teenage-boy-arrested-kido-nurseries-cyber-attack-london#:~:text=The%20two%20boys%2C%20both%20aged,from%20the%20Kido%20nursery%20chain.">arrest</a> of two people &#8220;on suspicion of computer misuse and blackmail&#8221;, both of whom were 17 years old. These arrests were in connection to a cyberattack on Kido International, a childcare company operating nurseries in London. Data related to over 8,000 children were stolen. As part of their <a href="https://www.bbc.co.uk/news/articles/cpvlgzk0xvpo">extortion attempt</a>, the ransomware group behind the attack published some of the names, photos and other information from a small number of child victims, and called parents to pre&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/phish-in-a-barrel">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Jul - Sep 2025)]]></title><description><![CDATA[This edition of the CRQ focusses on two issues within cybercrime that are understudied.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-008</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-008</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Tue, 30 Sep 2025 21:04:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This edition of the CRQ focusses on two issues within cybercrime that are understudied. One is Chinese cybercrime and the increasingly famous <a href="/__u/industryofanonymity.substack.com/p/the-cybercrime-quarterly-oct-dec-f72">&#8220;pig butchering&#8221;</a> scams - swindles that require building a long term relationship with the victim before the fraud attempt is made. The other is the role of the &#8220;unwitting&#8221; within cybercrime operations, whereby non-criminals are unknowingly drawn into criminal activities. I have chosen to focus this post on Qiaoyu Luo&#8217;s recent article (co-authored with Yun Zhao), which is titled &#8220;<a href="https://link.springer.com/article/10.1007/s12117-025-09568-2">Butcher or be butchered: understanding the unwitting recruitment by cybercrime groups in China</a>&#8221;. The article, published in the journal <em>Trends in Organized Crime</em>, seeks to solve a puzzle around why cybercriminal networks would recruit unwitting workers when these people are likely to lack criminal skillsets and are also more likely to report the criminal activity to the police.</p><p>The research is based on multi-year fieldwork carried out by Luo in China, where he conducted over 60 interviews with participants from a range of backgrounds, including law enforcement agents, cybersecurity practitioners and former cybercriminals. These participants came from a range of locations across China, from major cities to rural areas. Most of these interviews were conducted in person.</p><p>So, what are the key takeaways from this research? First, much like in other parts of the world, Chinese cybercrime has become highly specialised. The relevance of this to unwitting workers is that some roles within the cybercrime industry, such as participating in online chats or making bank transfers, don&#8217;t require specialist criminal (or technical) knowledge. This means almost anyone can play a role within cybercrime. As one of the study participants put it: &#8220;As long as they are a person who can communicate in Mandarin or a dialect, they basically meet these criminal groups&#8217; requirements for capability&#8221;. The paper also finds that these cybercriminal enterprises also engage in &#8220;compartmentation&#8221; so that various components of the business are separated, and it might not always be obvious that some functions are connected to an illicit enterprise.</p><p>The second finding takes this line of thinking further: &#8220;the division of labour obscures the illegality of many business segments within the cybercrime industry, making it difficult for recruits to recognise whether their activities are criminal&#8221;. One example provided by the authors is a cyber-fraud operation in Fujian Province, which used fake identities and stories to manipulate people into buying overpriced tea. The police officer who uncovered this scam argued that it was often difficult for those involved to determine their connection to criminality:</p><p>&#8220;Most people in the technical and promotion departments didn&#8217;t know they were involved in cyber fraud; they only knew that the company hired them for promotion and maintenance work. What&#8217;s more, the group even appeared to be a legitimate company, with ties to schools, and schools even sent interns to work there&#8221;.</p><p>Luo also located some of those who had participated unwittingly in cybercriminal enterprises. One former member of a cybercriminal organisation, who was a recent university graduate, described only realising the truth on being arrested:</p><p>&#8220;In the beginning, everything was good, I thought I was doing an ordinary job, and at the end of the year, I was already thinking about the year-end bonus and the year-end party, until one day, the police broke into our office &#8211; I thought they went to the wrong door at first&#8221;.</p><p>From a Western perspective, often we can be quite suspicious of unwitting participants in crime, and wonder whether they either knew of the truth, or should have known. In the context of China, Luo&#8217;s data provides good support for the view that, despite these suspicions, there do appear to be a large number of individuals participating in Chinese cybercrime, who genuinely believe they are involved in legitimate work. This support comes from a range of viewpoints, including law enforcement sources.</p><p>With that said, the final takeaway from this study indicates that some individuals may eventually become &#8220;witting&#8221; cybercriminals. As Luo and Zhao put it:</p><p>&#8220;Some members, upon realising they are involved in criminal activities, choose to leave quietly, not wanting to implicate their colleagues and friends with whom they have established bonds, and wanting to avoid trouble. Meanwhile, other members gradually change their views on criminal involvement through continuous participation and interaction, transitioning from being &#8216;victims&#8217; caught up in crime to becoming active participants in the ongoing criminal enterprise&#8221;.</p><p>This idea is clearly the inspiration for the article&#8217;s title. At some point, as individuals learn more about the criminality they are part of, they move from being the &#8220;butchered&#8221; to the &#8220;butcher&#8221;. As this evolution takes place, the study suggests that the cybercriminal groups use a combination of social bonding, normalisation and threats to keep these workers inside their illicit enterprises.</p><p>In sum, a solution to the puzzle of why cybercriminal networks in China choose to draw on unwitting workers, when these people are neither criminally skilled or trustworthy, is provided by this article. The work is not always highly skilled, specialisation means that more criminal elements can be hidden from workers, and, when they do find out, the process is managed to encourage either their continued involvement or their silence.</p><p>Read the original article <a href="https://link.springer.com/article/10.1007/s12117-025-09568-2">here</a>.</p>]]></content:encoded></item><item><title><![CDATA[Convening with Electronic Ghosts]]></title><description><![CDATA[With August coming to an end, this month&#8217;s post highlights some intriguing content coming from the major cybersecurity conference DEF CON 33.]]></description><link>https://industryofanonymity.substack.com/p/convening-with-electronic-ghosts</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/convening-with-electronic-ghosts</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sun, 31 Aug 2025 22:40:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>With August coming to an end, this month&#8217;s post highlights some intriguing content coming from the major cybersecurity conference DEF CON 33. In particular, I&#8217;m interested in discussing <a href="https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60359">&#8220;Ghosts of REvil: An Inside Look with the Hacker Behind the Kaseya Ransomware Attack&#8221;</a>. This presentation was delivered by Jon DiMaggio and John Fokker, two former government agents now working in the private sector. As the title suggests, the talk provides a detailed analysis of the infamous Kaseya episode, whereby the REvil network carried out an &#8220;upstream&#8221; supply chain attack, compromising a virtual system administrator to deploy ransomware against numerous &#8220;downstream&#8221; victims.</p><p>For those interested in the details of the talk, the slides can be found <a href="https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Jon%20DiMaggio%20John%20Fokker%20-%20Ghosts%20of%20REvil%20An%20Inside%20Look%20with%20the%20Hacker%20Behind%20the%20Kaseya%20Ransomware%20Attack.pdf">here</a>, and a media report summarising the talk can be found <a href="https://www.darkreading.com/cyberattacks-data-breaches/revil-actor-russia-planning-2021-kaseya-attack">here</a>. In this post I&#8217;m focussing on the story of Yaroslav Vasinskyi, aka Rabotnik, a key figure in the Kaseya attack. His account underpins the DEF CON talk and has been contemporaneously publishe&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/convening-with-electronic-ghosts">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[A Remote Threat]]></title><description><![CDATA[This newsletter focusses on profit-driven cybercrime, which means that nation state threats fall at its edges.]]></description><link>https://industryofanonymity.substack.com/p/a-remote-threat</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/a-remote-threat</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Thu, 31 Jul 2025 22:15:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This newsletter focusses on profit-driven cybercrime, which means that nation state threats fall at its edges. In odd cases, these state actors may be more central. The oddest cases often involve North Korea. One of my <a href="/__u/industryofanonymity.substack.com/p/the-cybercrime-quarterly-apr-jun-1ef">previous posts</a> examined the unusual financial motivation behind some of this state&#8217;s cyber-attacks, with a clear focus on monetary gain rather than conventional political, or even economic, espionage. In particular, North Korea has been linked to a series of major cryptocurrency heists. This month&#8217;s post examines something even stranger.</p><p>On July 24, an Arizona woman was sentenced to 102 months prison time for supporting an intriguing kind of North Korean scheme. As the US Department of Justice <a href="https://www.justice.gov/opa/pr/arizona-woman-sentenced-17m-information-technology-worker-fraud-scheme-generated-revenue">press release</a> explained, Christina Marie Chapman was part of a &#8220;fraudulent scheme that assisted North Korean Information Technology (IT) workers posing as U.S. citizens and residents with obtaining remote IT positions at more than 300 U.S. companies. The scheme generated more than $17 million in illicit revenue for Chapman and for the Democratic People&#8217;s Republic of Korea&#8221;.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/a-remote-threat">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Apr - Jun 2025)]]></title><description><![CDATA[Within the hierarchy of cybercrimes, there has been a tendency to view technical offences, such as malware or hacking, as being &#8220;purer&#8221; or more important than so-called cyber-enabled fraud.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-871</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-871</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Mon, 30 Jun 2025 21:52:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eNOz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Within the hierarchy of cybercrimes, there has been a tendency to view technical offences, such as malware or hacking, as being &#8220;purer&#8221; or more important than so-called cyber-enabled fraud. In this line of thinking, the former is clearly more sophisticated. This edition of The Cybercrime Research Quarterly challenges these kinds of assumptions. It captures the key findings from the study &#8220;<a href="https://journals.sagepub.com/doi/full/10.1177/14773708251329695">The Evolution of Nigerian Cybercrime: Two Case Studies of UK-based Offender Networks</a>&#8221;, published in the <em>European Journal of Criminology</em>, which I co-authored with Tom Holt, Mike Levi, Edward Kleemans and Rutger Leukfeldt.</p><p>This paper is a qualitative comparison of two (anonymised) historical cybercriminal networks, largely comprised of Nigerian offenders who were resident in the UK. These case studies drew on interviews with key investigators, access to police/legal files, as well as an analysis of relevant open sources. We also conducted a comparative analysis of more recent US investigations of Nigerian cybercriminal networks operating around the world. Our key research questions were: &#8220;(1) How have Nigerian cybercriminal networks evolved over time? (2) How do Nigerian cybercriminal networks operate abroad, particularly within a European context?&#8221; (p. 2).</p><p>Case 1 centred on a particular form of &#8220;advance fee fraud&#8221; (AFF), where the offenders contacted victims in the US to inform them they had won a prize and needed to contact an &#8220;agent&#8221; to redeem it. In order to access the &#8220;winnings&#8221;, an initial fee needed to be paid of around $300. Despite the victims being American, many of the key offenders were based in the UK. Case 2 involved &#8220;business email compromise&#8221; (BEC), whereby the fraudsters impersonated a figure of authority within an organisation (e.g. CEO/CFO) or a supplier to it, directing the transfer of funds into an account the offenders controlled. In many instances, banks will not cover the losses from these fraudulent transactions, in the same way losses from credit card fraud might be restored. The legal files in this case, describe this scam as &#8220;sophisticated, well-organised, technologically-aware&#8221; (p. 10). Both cases involved losses of at least hundreds of thousands, if not millions of dollars/pounds.</p><p>There are several important findings that have come out of the comparison of these cases. First, Nigerian cybercriminals have advanced to incorporate new business models, such as BEC, in addition to the classic advance fee fraud. Second, &#8220;while Nigerian offenders are focussed on fraud, they are increasingly engaging with some of the more technical components of cybercrime&#8221; (p. 15). They make use of illicit online markets to obtain malware, tools and data to increase the efficiency of their operations. Third, the offenders in these cases were operating in the UK, suggesting a transnational dimension to cybercrime based on migration and not just the transnationalism of the Internet. Following on from this, while there is a growing literature on Nigerian scammers based within Nigeria, there is little information on how such offenders operate abroad. These cases indicate that offenders had considerable offline interactions and were embedded in social networks, linked to friendships, shared residences, and attendance at restaurants and churches connected to the broader diaspora community. The final key finding on these cybercriminal networks is:</p><p>&#8220;Despite the innovations described in this paper, in human terms, these structures are stable and consistent. This suggests comparable cybercriminal networks can support different business models, ranging from Advanced Fee Fraud to BEC. While we do not have direct evidence in these cases, it is also possible that groups may have evolved from carrying out AFF into carrying out BEC. There are already suggestions within Case 1 of some members of the network engaging with activities beyond conventional AFF&#8221; (p. 15).</p><p>This figure captures the similar and relatively egalitarian network structures across the two cases. The spiral line indicates the challenges in making clear links to a &#8220;boss&#8221; based on the information contained in the legal files and interviews (a challenge that was more pronounced in Case 2).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!eNOz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_424, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_webp, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 424w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_848, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_webp, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 848w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_1272, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_webp, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_1456, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_webp, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!eNOz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png" width="708" height="486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:486,&quot;width&quot;:708,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A diagram of a company's collective\n\nAI-generated content may be incorrect.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A diagram of a company's collective

AI-generated content may be incorrect." title="A diagram of a company's collective

AI-generated content may be incorrect." srcset="/__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_424, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_auto, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 424w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_848, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_auto, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 848w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_1272, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_auto, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eNOz!, /__u/industryofanonymity.substack.com/w_1456, /__u/industryofanonymity.substack.com/c_limit, /__u/industryofanonymity.substack.com/f_auto, /__u/industryofanonymity.substack.com/q_auto:good, /__u/industryofanonymity.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc746de6-40b5-49a3-a583-a660abd7eefb_708x486.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The US cases we examined provided good support for our core case findings. In particular, most of these additional cases involved Nigerian fraudsters operating abroad, across a range of jurisdictions: US, South Africa, Ghana, Malaysia, Canada, and UAE. These cases also support the view that Nigerian cybercriminals have been carrying out increasingly sophisticated offending, and have been engaging with technical tools and services to enhance their operations.</p><p>So what is the key takeaway from this research? Cyber-enabled fraud is no less important, or worthy of attention, than more technical forms of cybercrime. In fact, the case studies in this paper indicate that there is not a hard boundary between these categories. While Nigerian cybercriminals are less technical than some other actors, they are innovative and sophisticated in their own way. If we focus only on malware and hacking, the serious threat presented by these other kinds of groups will be ignored. It should not be. After all, even something as seemingly simple as BEC is having great success against organisations of all sizes.</p><p>Read the original article <a href="https://journals.sagepub.com/doi/full/10.1177/14773708251329695">here</a>.</p>]]></content:encoded></item><item><title><![CDATA[Cybercrime and the Mundane]]></title><description><![CDATA[The episode featured in this month&#8217;s post began late last month and will likely continue at least into the next: the ransomware attack on Marks & Spencer (M&S) and the reported associated attacks on Co-op and Harrods. While cyber-attacks can often seem abstract and ethereal, for those living in the UK this campaign might have had direct impact on day-to day-lives. While some may have had personal data compromised or been unable to make online purchases, the most obvious evidence of the attack on M&S could be observed by any UK resident simply by walking into one of the stores and noting the half-empty shelves. The impact was as mundane as day-to-day grocery shopping.]]></description><link>https://industryofanonymity.substack.com/p/cybercrime-and-the-mundane</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/cybercrime-and-the-mundane</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Sat, 31 May 2025 20:38:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The episode featured in this month&#8217;s post began late last month and will likely continue at least into the next: the ransomware attack on <a href="https://www.bbc.co.uk/news/articles/c0el31nqnpvo">Marks &amp; Spencer</a> (M&amp;S) and the reported associated attacks on <a href="https://www.bbc.co.uk/news/articles/c3wx092exlzo">Co-op</a> and <a href="https://www.theguardian.com/business/2025/may/01/harrods-latest-retailer-hit-cyber-attack-website-shops">Harrods</a>. While cyber-attacks can often seem abstract and ethereal, for those living in the UK this campaign might have had direct impact on day-to day-lives. While some may have had personal data compromised or been unable to make online purchases, the most obvious evidence of the attack on M&amp;S could be observed by any UK resident simply by walking into one of the stores and noting the half-empty shelves. The impact was as mundane as day-to-day grocery shopping.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/cybercrime-and-the-mundane">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[No post this month...]]></title><description><![CDATA[Due to paternity leave, there will be no post this month.]]></description><link>https://industryofanonymity.substack.com/p/no-post-this-month-a0c</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/no-post-this-month-a0c</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Wed, 30 Apr 2025 20:06:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Due to paternity leave, there will be no post this month. We will be back on the regular schedule with the next new post at the end of May. Subscriptions will be extended to account for this.</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/no-post-this-month-a0c">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Cybercrime Research Quarterly (Jan - Mar 2025)]]></title><description><![CDATA[Each year cybersecurity books grow in number.]]></description><link>https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-858</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-cybercrime-research-quarterly-858</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Mon, 31 Mar 2025 19:30:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Each year cybersecurity books grow in number. Of course, while the quantity of these books is noteworthy, we have to be mindful of the quality, as well. Books range from dull to sensationalist, while others are derivative and don&#8217;t offer much in the way of new information or analysis. Alongside thought-provoking academic papers, it is the rarer books &#8211; those that strike a balance and offer readable, original and insightful analyses &#8211; that I seek to profile as part of the Cybercrime Research Quarterly posts. This edition focusses on the recently released <em><a href="https://www.hurstpublishers.com/book/ransom-war/">Ransom War: How Cyber Crime Became a Threat to National Security</a> </em>by Max Smeets.</p><p>The title of this book is derived from its opening example: the major ransomware campaign carried out by the ransomware group Conti against Costa Rican public sector organisations, and the subsequent declaration by the country&#8217;s president on May 8th 2022 that they were in a &#8220;state of war&#8221;. This series of attacks, which significantly impacted tax filing and customs operations, caused major real-world harm well beyond the immediate targets. This kind of damage and disruption is now familiar to us, having witnessed attacks on <a href="https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf">hospitals</a>, <a href="https://www.nytimes.com/2021/05/14/business/darkside-pipeline-hack.html">energy providers</a> and other forms of critical infrastructure across many countries. In short, Smeets&#8217; key argument is that these ransomware groups, over time, have evolved into a national security threat.</p><p>This book offers a sober, scholarly and non-technical analysis of ransomware. It seeks to move beyond media accounts of the impact of such attacks, as well as practitioner reports on their more technical components, and instead offers a &#8220;deeper comprehension of the organisational dynamics behind ransomware&#8221;. <em>Ransom War </em>has a clear focus on how these groups function like &#8220;legitimate businesses, employing increasingly specialised processes&#8221;. In focussing on both the social and economic, Smeets is aligned with a maturing line of research within both broader <a href="https://www.annualreviews.org/content/journals/10.1146/annurev-lawsocsci-041822-044042">cybercrime</a> and <a href="https://federicovarese.com/wp-content/uploads/2019/07/varese-2017-redefining-organised-crime-03.pdf">organised crime</a> research. To operationalise this approach, he develops and applies the MOB framework: &#8220;Modus Operandi, Organizational Structure, and Branding and Reputation&#8221;. Another intriguing dimension of this book, which is tied to this perspective, is the discussion of the &#8220;Ransomware Trust Paradox&#8221;. This examines the tension between ransomware actors breaking into a victim&#8217;s systems and compromising their data, while also requiring that this victim will then trust them not to release the data and to decrypt their systems, if payment is made.</p><p>Although it makes broader contributions, in essence, <em>Ransom War</em> could be considered a detailed case study of a single group: Conti, one of the major ransomware operations of recent years. The key reason for this choice is likely the unparalleled public database of the group&#8217;s chatlogs that was leaked in 2022. There have been some <a href="https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/">preliminary analyses </a>shedding light on the group&#8217;s internal dynamics, and a number of academic studies have continued to trickle out with different <a href="https://www.tandfonline.com/doi/full/10.1080/01639625.2024.2419905">foci</a> and <a href="https://ieeexplore.ieee.org/abstract/document/10142119">methods</a>. But, in order to provide a comprehensive analysis of the Conti business model and to come to terms with the huge scale of the dataset, a significant book length treatment is certainly warranted. This is Smeets&#8217; main contribution.</p><p>As part of this detailed case study, Smeets offers a range of important takeaways on the Conti operation. First, the study finds that, along with a constellation of collaborators, the group had over a hundred individuals in their core network, with over fifty kept on salary. Other malware operations have been compared to startups, but Conti appears more corporatised than these past examples. And while the group was clearly criminal, it also operated across legal boundaries, including by recruiting some workers through conventional job sites, many of whom, at least at first, may not have understood the true nature of their employer. Although some within Conti may have earned significant sums, perhaps USD$100,000s or more, the majority of &#8220;Conti&#8217;s workforce is on a base salary that aligns with the standard pay scales in Russia's industry&#8221;.</p><p>Second, despite adopting such a corporate model, Conti still suffered from a number of failures, including, at times, limited innovation. Smeets identifies that the group might have focussed too much on expanding into new business areas and underinvested in their core offering. He even speculates that, like Silicon Valley entrepreneurs, Stern, the leader of Conti, may have become somewhat bored with the day-to-day ransomware business and sought new challenges.</p><p>Finally, the book sheds light on the question of how much a major cybercriminal group might work with/for the state. Despite widespread speculation, based on the data, Smeets argues that Conti operates &#8220;autonomously and is not directly controlled by Russian state entities like the FSB&#8221;, but the group does &#8220;occasional collaborations with the government&#8221;.</p><p>For all the book&#8217;s positives, its policy discussion is one of the least impactful components. <em>Ransom War </em>does cover some key topics, for example debates around legislating against victim payments to extortionists, and offers some more novel suggestions, for instance having a code of ethics and training for journalists to reduce ways the media amplify ransomware branding. But the challenge is a major one, and it is not reasonable to expect one scholar and one book to resolve it. Smeets&#8217; policy discussion reinforces that the book&#8217;s real payoff is the detailed socio-economic depiction of a leading ransomware group that it provides. Many can benefit from a better understanding of the historical evolution of this threat. Decision-makers might be interested to know that some ransomware groups assess cyber insurance policy holders as more likely to pay out and are therefore seen as a better target. CTI professionals may find some useful analytical tools for engaging with the social and economic, rather than technical, aspects of these groups. Finally, policymakers can gain a deeper understanding of what can lead to the success, and failure, of these groups and develop their own counter-strategies accordingly.</p><p>Find <em>Ransom War</em> and its publisher information <a href="https://www.hurstpublishers.com/book/ransom-war/">here</a>.</p>]]></content:encoded></item><item><title><![CDATA[The Silent Threat]]></title><description><![CDATA[It might be tempting to use this month&#8217;s post to write another analysis of the latest news regarding the Trump administration and cybersecurity.]]></description><link>https://industryofanonymity.substack.com/p/the-silent-threat</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/the-silent-threat</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Fri, 28 Feb 2025 22:47:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It might be tempting to use this month&#8217;s post to write another analysis of the latest news regarding the Trump administration and cybersecurity. The obvious choice of story would be DOGE, and the fierce debates that have been generated within the cybersecurity community around what Elon Musk and his team are doing within U.S. government systems, and how these actions may clash with existing protocols, access privileges and procedures. There is, as well, a line of discussion around whether such rapid changes may create opportunities for a variety of threat actors. I might also have expanded this analysis to engage with a philosophical point around the classic trade-off between &#8216;security&#8217; and &#8216;efficiency&#8217;.</p><p>But as last month's post was on the Trump administration, I do not want to continue too much of a trend, for fear of missing out on numerous other important stories within the cyber world. The risk is that Trump news trumps all other news. The focus of this month&#8217;s post is on this very&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/the-silent-threat">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Staring into Trump’s Crypto Ball]]></title><description><![CDATA[We're probably all suffering from Trump news fatigue already.]]></description><link>https://industryofanonymity.substack.com/p/staring-into-trumps-crypto-ball</link><guid isPermaLink="false">https://industryofanonymity.substack.com/p/staring-into-trumps-crypto-ball</guid><dc:creator><![CDATA[Jonathan Lusthaus]]></dc:creator><pubDate>Fri, 31 Jan 2025 21:33:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9E3v!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71b9405f-42d4-4a0d-87b3-062af8bc6e8b_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We're probably all suffering from Trump news fatigue already. The seemingly endless stream of reports on the newly inaugurated president and his administration is unavoidable to anyone with an Internet connection. While I don't want to add another piece to this already overwhelming amount of content, and I often try to focus on stories of interest that have escaped mainstream attention, this event is perhaps too big to ignore. Part of the value of analysis also lies in making sense of, and through, large volumes of information.</p><p>The subject of this month&#8217;s post is a form of futurism: how might the Trump presidency affect cybercrime trends? By engaging in this futurism, I also break another rule of this newsletter, which is to avoid making long term predictions that risk misinterpreting the noise or being contradicted by the truly unexpected. Given that Trump is an unpredictable figure, these risks are heightened even more. But as we are living through an age of norm-breaking, it seems f&#8230;</p>
      <p>
          <a href="/__u/industryofanonymity.substack.com/p/staring-into-trumps-crypto-ball">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>