Black Hat USA 2026 – Las Vegas – Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt.
Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations.
At Black Hat USA 2026, Carole House, CEO of Penumbra Strategies and senior fellow at the Atlantic Council, led a session titled "Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone" that examined these trends. She emphasized that "no single actor controls enough to be deterred by law enforcement actions" and called for a shift in strategy to close the gap between the coordination of attackers and the lack of coordination on behalf of law enforcement agencies.
Related:CSS: The Hidden Threat Lurking in Your Inbox
House recommended a coordinated national strategy to dismantle cybercrime operations, and she demonstrated how following military frameworks she learned from her time in the US Army and as an intelligence officer could aid in the response.
"The nature of the problem [is that] we are fighting a very coordinated, very sophisticated adversary with a very untimely response," House said. "That gap between their coordination and ours leads to failures."
Fighting Cybercrime: One Step Forward, Two Steps Back
Law enforcement did conduct some successful actions and takedowns over the past few years, but they mainly acted as a temporary disruption as threat actors just set up new networks and infrastructure. Franchise models were also made to make operators replaceable, House warned.
Threat actors now demonstrate increased coordination in how they set up their operations. They have franchises, divisions of labor, human resources departments, and customer support channels through the messaging platform Telegram. However, law enforcement agencies' response remains the same: investigate, attribute, indict, and hope for attribution, explained House.
"They're defending against a threat that's being continuously regenerated," she said.
Sanctions have been a go-to deterrent method because they can be applied quickly and are useful for attribution and public shaming, she said. However, sanctions are not perfect for every context, she added.
Related:Angola's Largest Telco Breached Hours Before IPO
In March, the Trump administration released an executive order (EO) titled "Combatting Cybercrime, Fraud, and Predatory Schemes Against American Citizens." While it acknowledged state support and had the right framing, House spotted some holes and called on everyone working in and engaging with agencies to weigh in with improvements.
For example, frameworks that law enforcement put together to coordinate on anti-ransomware measures could be applied to fight cybercrime as a whole. "That concept of putting multiple organizations against the most high-value network simultaneously — that is a really valuable tool," she said. "The new EO action plan should leverage that."
House has worked in various government roles, including a special adviser on cybersecurity and critical infrastructure policy at the White House National Security Council. But unfortunately, she's seen some efforts rolled back recently.
"The [Trump] admin rescinded all the measures we put in place to fight fraud, which has been tough seeing that," she said.
'Failures Teach Us More Than Wins'
Americans don't care if their hospital or gas station goes down because another nation- or non-state actor was behind it; they care about the impact, House said. To that end, law enforcement actions should look at priority networks and organize efforts based on the breach, its impact, and threat actors across ecosystems, focusing on safe haven jurisdictions that protect threat actors.
Related:Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
She called for international partnerships and new ways to impose operational friction. But a notable obstacle is information sharing, which is a critical component of coordination. For example, when agencies don't share their priority lists, they end up prioritizing for their own metrics, House warned.
"We made a real paradigm shift in 2021 and I believe it had generally good results," she said. "However, there remains structural failures that we are facing, and we have to be honest about that because those failures teach us more than the wins."
Jamie Levy, senior director of adversary tactics at Huntress, says effectiveness of takedowns to curb ransomware has waned. Before AI and vibe coding emerged, when law enforcement took a network down, there would be a void. Other ransomware actors would fill the void as they fought for their top position, but it wouldn't stop the threat and only hindered it for a time, she tells Dark Reading.
Now, she wonders if takedowns really do much at all, because threat actors can spin up infrastructure with AI, vibe coding, and other advanced tools. They're basically up and running moments later.
"We need to start thinking more long term," Levy says. "The big solution here is where the security community comes together as a whole to fight this problem. I know we're businesses and we have to compete, but I'm hoping at some point we can all be a little more collaborative."
Efforts have already begun. Huntress has relationships with various companies, and researchers converse in Slack channels to feed each other threat intelligence. For example, if they know for sure another company's software is being used in a campaign, they can warn them.
"I feel like this is the only way forward," she says.



.jpg?width=720&quality=80&disable=upscale)







