- What: Analysis of coordination challenges between law enforcement and cybercriminals
- Impact: Highlights growing sophistication of threat actors
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES CYBER RISK THREAT INTELLIGENCE NEWS The Coordination Gap: How Attackers Are Outpacing Law Enforcement The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos. Arielle Waldman,Features Writer,Dark Reading August 6, 2026 4 Min Read SOURCE: WSF AL VIA ALAMY Black Hat USA 2026 – Las Vegas – Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt. Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations. At Black Hat USA 2026, Carole House, CEO of Penumbra Strategies and senior fellow at the Atlantic Council, led a session titled "Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone" that examined these trends. She emphasized that "no single actor controls enough to be deterred by law enforcement actions" and called for a shift in strategy to close the gap between the coordination of attackers and the lack of coordination on behalf of law enforcement agencies. Related:CSS: The Hidden Threat Lurking in Your Inbox House recommended a coordinated national strategy to dismantle cybercrime operations, and she demonstrated how following military frameworks she learned from her time in the US Army and as an intelligence officer could aid in the response. "The nature of the problem [is that] we are fighting a very coordinated, very sophisticated adversary with a very untimely response," House said. "That gap between their coordination and ours leads to failures." Fighting Cybercrime: One Step Forward, Two Steps Back Law enforcement did conduct some successful actions and takedowns over the past few years, but they mainly acted as a temporary disruption as threat actors just set up new networks and infrastructure. Franchise models were also made to make operators replaceable, House warned. Threat actors now demonstrate increased coordination in how they set up their operations. They have franchises, divisions of labor, human resources departments, and customer support channels through the messaging platform Telegram. However, law enforcement agencies' response remains the same: investigate, attribute, indict, and hope for attribution, explained House. "They're defending against a threat that's being continuously regenerated," she said. Sanctions have been a go-to deterrent method because they can be applied quickly and are useful for attribution and public shaming, she said. However, sanctions are not perfect for every context, she added. Related:Angola's Largest Telco Breached Hours Before IPO In March, the Trump administration released an executive order (EO) titled "Combatting Cybercrime, Fraud, and Predatory Schemes Against American Citizens." While it acknowledged state support and had the right framing, House spotted some holes and called on everyone working in and engaging with agencies to weigh in with improvements. For example, frameworks that law enforcement put together to coordinate on anti-ransomware measures could be applied to fight cybercrime as a whole. "That concept of putting multiple organizations against the most high-value network simultaneously — that is a really valuable tool," she said. "The new EO action plan should leverage that." House has worked in various government roles, including a special adviser on cybersecurity and critical infrastructure policy at the White House National Security Council. But unfortunately, she's seen some efforts rolled back recently. "The [Trump] admin rescinded all the measures we put in place to fight fraud, which has been tough seeing that," she said. 'Failures Teach Us More Than Wins' Americans don't care if their hospital or gas station goes down because another nation- or non-state actor was behind it; they care about the impact, House said. To that end, law enforcement actions should look at priority networks and organize efforts based on the breach, its impact, and threat actors across ecosystems, focusing on safe haven jurisdictions that protect threat actors. Related:Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook She called for international partnerships and new ways to impose operational friction. But a notable obstacle is information sharing, which is a critical component of coordination. For example, when agencies don't share their priority lists, they end up prioritizing for their own metrics, House warned. "We made a real paradigm shift in 2021 and I believe it had generally good results," she said. "However, there remains structural failures that we are facing, and we have to be honest about that because those failures teach us more than the wins." How the Security Community Can Help Jamie Levy, senior director of adversary tactics at Huntress, says effectiveness of takedowns to curb ransomware has waned. Before AI and vibe coding emerged, when law enforcement took a network down, there would be a void. Other ransomware actors would fill the void as they fought for their top position, but it wouldn't stop the threat and only hindered it for a time, she tells Dark Reading. Now, she wonders if takedowns really do much at all, because threat actors can spin up infrastructure with AI, vibe coding, and other advanced tools. They're basically up and running moments later. "We need to start thinking more long term," Levy says. "The big solution here is where the security community comes together as a whole to fight this problem. I know we're businesses and we have to compete, but I'm hoping at some point we can all be a little more collaborative." Efforts have already begun. Huntress has relationships with various companies, and researchers converse in Slack channels to feed each other threat intelligence. For example, if they know for sure another company's software is being used in a campaign, they can warn them. "I feel like this is the only way forward," she says. Read more about: Black Hat News About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Black Hat USA Coverage СLOUD SECURITY Researcher Claims Control of ChatGPT Secure Sandbox byAlexander Culafi AUG 6, 2026 5 MIN READ CYBERSECURITY OPERATIONS From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture byArielle Waldman AUG 6, 2026 4 MIN READ THREAT INTELLIGENCE AI Sends Global Crime Syndicates Into Fraud Nirvana byTara Seals AUG 5, 2026 9 MIN READ CYBER RISK AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking byJai Vijayan AUG 5, 2026 4 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s regist