Skip to main content
Logo-300x300-colored-3
  • Home
  • Services
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • AI Advisory
    • AI Assessment
    • AI Integration
  • Products
  • About
    • About Us
    • FAQ's
  • Resources
    • Blog
    • In The Media
    • Podcasts
    • All Resources
Get a Free Assessment
Back to Blog
Threat Intelligence Ransomeware Incident Response Supply Chain Third-party vendor risk ShinyHunters Extortion

The Extortion Market Has Matured, And the Response Industry Is Part of It

Denis Calderone June 25, 2026 12 min read
Table of Contents

    In May, a criminal extortion group told 9,000 schools to hire breach coaches and negotiate ransom payments individually. A week later, the ed-tech vendor covering those schools called the ransom it paid an "agreement" and presented "shred logs" from the criminals as proof of data destruction. Both sides used professional language and treated the whole thing like a transaction between counterparties. That moment stuck with me. It made something click that I have been sensing all year. We are not watching a crime wave play out anymore. We are watching a market function.

    This piece is not another "ransomware is getting worse" article. The numbers tell that story well enough. What I want to talk about is what happens when both the attack side and the defense side of the extortion economy professionalize simultaneously, and whether the response industry that grew up around this problem has inadvertently become part of what keeps it running smoothly.

    The Market Economics

    Let me start with the economics, because you cannot understand the maturation without the numbers.

    Chainalysis tracked $820 million in on-chain ransomware payments in 2025. The Verizon DBIR found that 48 percent of all confirmed breaches last year involved ransomware, up from 44 percent the year before. NCC Group counted 7,874 victims on leak sites, a record and a 50 percent year-over-year increase. By every volume metric, the extortion economy is expanding.

    But here is where it gets interesting. The percentage of victims who actually pay has been falling for four consecutive years. It hit 28 percent in 2025 according to Chainalysis, and Coveware's incident response data shows it dropping to roughly 20 percent by Q4. That is a historic low. Fewer organizations are paying. And yet the total revenue barely moved, because the organizations that do pay are paying significantly more. The median on-chain payment grew 368 percent year-over-year to nearly $60,000. Coveware's average payment in Q4 reached $591,988.

    image (56)

    Fewer are paying, but those who pay are paying bigger. The market is concentrating. Honestly, that is an industry optimizing its unit economics. It just happens to be a criminal one.

    The Supply Side Has Industrialized

    The supply side of this market looks nothing like it did five years ago. It has industrialized into specialized roles with their own economics. Initial access brokers sell network access to ransomware operators the way wholesalers sell to retailers. The average price for basic network access has dropped from $1,427 in early 2023 to $439 by Q1 of this year. The market is saturated with credentials from infostealers, automation, and AI-assisted tooling. Supply is cheap and abundant.

    But enterprise admin access, MSP pivot points, supply chain positions that open the door to hundreds of downstream targets, those are going for $50,000 to over $100,000. Rapid7 found that IAB asking prices on certain forums increased over 4,000 percent in the second half of 2025 as brokers shifted from volume to high-value targets. The market bifurcated into commodity and premium tiers, the same way any maturing market does.

    And the operators themselves have professionalized their engagement with victims. Multiple operations now deploy AI-powered tools, such as chatbots to conduct initial victim negotiations. Qilin has added multiple features as outlined in GuidePoint Security's 2026 GRIT report which documented how the ransomware operation added a "Call Lawyer" feature for its affiliates, specifically designed to increase pressure during negotiations. It is believed to be an AI tool that parses stolen data for regulatory violations and legal exposure, then generates talking points affiliates can use to make threats more specific. "We found unencrypted PII for 2 million EU residents" hits different than a generic ransom note. They also offer "in-house journalists" to write blog posts for their leak site, essentially a content service that helps affiliates craft professional, damaging public write-ups about victims to amplify reputational pressure. The attackers are running a customer-facing business at this point. They are investing in their "customer experience" the same way a legitimate SaaS company would.

    We Watched This Happen in Real Time

    We watched this firsthand this year. Remember those 9,000 schools from the opening of this piece? Well, when ShinyHunters breached Instructure and the company did not immediately engage, they defaced 330 school login portals with a message telling individual institutions to "consult with a cyber advisory firm and contact us privately to negotiate a settlement." Think about that. They were directing victims into the professional negotiation pipeline. Coaching schools on how to be extorted efficiently.

    Compare that to what this market looked like five or six years ago. Early ransomware negotiations were chaos. No established protocols, no guarantee the attacker would actually hand over a decryption key, no way to verify anything. Companies paid and got nothing back. The whole interaction was adversarial and unpredictable, which is part of why payment rates were so low early on. What ShinyHunters has built, and what other groups are now copying, is the opposite of that. They honor deals. When Wynn reached a settlement earlier this year, the listing came down. AT&T paid, the data was confirmed deleted. Panera did not pay, and ShinyHunters published. Either way, they followed through. ShinyHunters has built a reputation for consistency on both sides of the transaction, and that reputation is a business asset. It builds trust in the process, which makes future victims more likely to engage, which makes the whole model more profitable. They are literally investing in customer service for their extortion operation.

    And the response side went through the same transformation. Early incident response for ransomware was ad hoc. A panicked CEO calling their outside counsel at 2am, who maybe knew a guy who knew a guy who had dealt with this before. No playbook, no established processes, no market. Today it is an industry. Both sides went from chaotic to professional on roughly the same timeline.

    image (57) The Defense Side Professionalized in Parallel

    Now here is the part that should make the industry uncomfortable.

    The ransomware negotiation services market was valued at $1.2 billion in 2025, with projections reaching $4.6 billion by 2034. That is a 14.8 percent compound annual growth rate. Palo Alto Networks, Sophos, GuidePoint Security, and Arctic Wolf all maintain dedicated negotiation practices. Breach coaching has been described as "one of the fastest growing areas of law, and incredibly lucrative" for the firms that practice it. One industry profile noted that the fastest-growing job in cybersecurity "requires no certifications, no specific academic background, and no single agreed-upon career path." What it requires is the ability to negotiate with criminals.

    I am not condemning these firms. They exist because organizations genuinely need help navigating what is an agonizing situation. When your systems are down, your data is being held hostage, and you have 48 hours before it gets published, you need someone who has done this before. GuidePoint's data shows that negotiations consistently reduce payments by 44 to 80 percent from initial demands. That represents real value for victims. And for the organizations making the payment decision, the calculus is often straightforward. You have a fiduciary responsibility to shareholders, a duty of care to customers, and employees who cannot do their jobs while systems are down. When the cost of prolonged disruption exceeds the cost of settlement, the decision stops being ideological and starts being economic. That is exactly the dynamic that makes this market function.

    The Symbiosis Problem

    But you have to be honest about the dynamic this creates. Attackers get more professional. Victims need more professional help. A response industry grows to meet that need. That industry makes the process smoother and more predictable. Which makes attacking more predictable and profitable. Which attracts more attackers. Both ecosystems are co-evolving, and the friction that used to make extortion messy and unreliable has been engineered out of the system by both sides.

    image (58)

    So let's look at how the Instructure deal actually played out. Instructure initially tried to ignore ShinyHunters. They patched their systems and let the first deadline pass. ShinyHunters responded by going around them, directly to the schools, creating enough downstream pressure that Instructure reversed course within days. Once both sides entered the negotiation, it resolved in under a week. Shred logs provided, listing removed, blanket settlement. If I described that sequence without naming the parties, it would sound like a business dispute where one side played hardball and the other brought a bigger bat to the negotiation. Both were forced to come to an understanding. It's all just business now.

    The Supply Chain Is the Target

    The Verizon DBIR found that third-party involvement in breaches increased 60 percent year-over-year in 2025, now accounting for 48 percent of all breaches. The extortion playbook has converged on the supply chain, and specifically on SaaS platforms that aggregate commercially sensitive data from hundreds of organizations at once. ShinyHunters proved it works at scale with Instructure. Icarus proved it is replicable with Klue. Both targeted platforms where a single point of compromise opens the door to hundreds of downstream victims' CRM data, customer contacts, pricing, deal intelligence, all the things companies will pay to keep private. That math is only going to get more attractive. More business data moves into SaaS platforms every year, integration sprawl keeps expanding the OAuth attack surface, and the playbook for exploiting it is now public knowledge. We are going to see more of these extortion plays, not fewer.

    Where This Leaves Organizations

    So where does this leave organizations? I think it reframes the vendor risk conversation in ways most companies have not caught up to yet. We have to move past "does our SaaS provider have an incident response plan" and "do they carry cyber insurance." The real question is what our vendor's playbook looks like when an attacker comes for our data on their platform. Will they negotiate on our behalf? Will they pay? Or will they let it burn? And do we know the answer to that before the incident happens?

    If Instructure had not paid, 9,000 institutions would have been on their own. Most of them have no breach counsel, no negotiating leverage, no playbook for a criminal group threatening to dump their students' private messages. The alternative to that payment was chaos. And honestly, if I were a school administrator at that time, I would probably be relieved my vendor stepped in, even if I am ideologically opposed to ransom payments.

    That tension is the whole story. The extortion market has matured to the point where payment feels rational, the negotiation process feels orderly, and the outcome feels manageable. Both sides built that. And the more frictionless this becomes, the more profitable it becomes, and the more targets follow.

    To be fair, the industry has made real progress. Payment rates are at historic lows. Organizations invested in backups, segmentation, and recovery, and it worked against encryption-based ransomware. But operators adapted. They pivoted from "pay or stay locked out" to "pay or we dump." Against data extortion, immutable backups do not help. Against "pay or we publish your students' private messages," your recovery playbook is irrelevant.

    I am not arguing that negotiation capability should not exist. Sometimes it is the only rational path forward, and pretending otherwise is naive. But gaming out these scenarios before they happen still matters, because the work you do proactively determines how much leverage the attacker has when they show up. Data retention policies, access controls, minimization of what lives in platforms you do not own, all of that directly reduces the volume and sensitivity of what can be held against you. If Instructure had purged private messages after twelve months, ShinyHunters would have had a fraction of the leverage they used to force that settlement. The goal is not to avoid the negotiating table entirely. The goal is to arrive at that table with less on the line. And that requires staying diligent on the controls that limit exposure long before the extortion email arrives. The negotiating table is going to be there whether we like it or not. The only question is how much you put on it before you sit down.

    image (59)

    Sources

    • Chainalysis, "2026 Crypto Crime Report: Ransomware," February 2026. chainalysis.com
    • Verizon, "2026 Data Breach Investigations Report," May 2026. verizon.com
    • Coveware, "Why Zero-Day Downstream Mass Data Extortion Campaigns Are Losing Their Bite" (Q4 2025 Data), February 2026. coveware.com
    • GuidePoint Security, "GRIT 2026 Ransomware and Cyber Threat Report," January 2026. guidepointsecurity.com
    • ZeroFox, "The Role of Initial Access Brokers in Ransomware Operations," 2026. zerofox.com
    • Rapid7, "Initial Access Brokers Have Shifted to High-Value Targets and Premium Pricing," March 2026. rapid7.com
    • MarketIntelo, "Ransomware Negotiation Services Market Research Report 2034," 2025. marketintelo.com
    • The Globe and Mail, "The Invisible Necessity of Ransomware Negotiations," 2026. theglobeandmail.com
    • The American Prospect, "Ransomware Recovery Firms Share in the Hacking Spoils," January 2026. prospect.org
    • BleepingComputer, "Instructure Reaches 'Agreement' with ShinyHunters to Stop Data Leak," May 2026. bleepingcomputer.com
    • BleepingComputer, "Klue OAuth Breach Victim List Grows as Icarus Hackers Claim Attack," June 2026. bleepingcomputer.com
    • NCC Group, "Annual Cyber Threat Intelligence Report 2025," January 2026 (7,874 leak-site victims). https://www.nccgroup.com/newsroom/ncc-group-annual-cyber-threat-intelligence-2025/
    • IBM, "2025 Cost of a Data Breach Report," 2025. ibm.com
    Share
    Tags: Threat Intelligence Ransomeware Incident Response Supply Chain Third-party vendor risk ShinyHunters Extortion
    Denis Calderone
    Denis Calderone

    As CTO of Suzu Labs, Denis Calderone draws on over 30 years of IT experience and 25 years in information security. He founded and led a security consultancy for over 17 years before its global acquisition, and now channels that experience into Suzu Labs, where he sets technical direction while overseeing cyber delivery, including penetration testing and a full host of advisory services. His approach is vendor-agnostic and operationally grounded, cutting through noise to deliver practical, sustainable risk management. He pairs deep industry expertise with early AI adoption to ensure security is built-in, not bolted on.

    ← Previous The ICS Exploit Pipeline Is Built for Destruction, Not Theft

    Latest Posts

    View All
    The Extortion Market Has Matured, And the Response Industry Is Part of It
    Threat Intelligence
    Jun 25, 2026 Denis Calderone

    The Extortion Market Has Matured, And the Response Industry Is Part of It

    In May, a criminal extortion group told 9,000 schools to hire breach coaches and negotiate ransom payments ...

    Read More: The Extortion Market Has Matured, And the Response Industry Is Part of It
    The ICS Exploit Pipeline Is Built for Destruction, Not Theft
    Vulnerability Management
    Jun 22, 2026 Jacob Krell

    The ICS Exploit Pipeline Is Built for Destruction, Not Theft

    The vulnerability pipeline feeding ICS attackers is structurally optimized for breaking infrastructure, not stealing ...

    Read More: The ICS Exploit Pipeline Is Built for Destruction, Not Theft
    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    Prompt Injection
    Jun 17, 2026 Jacob Krell

    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security

    At a Glance AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. Download ratios: ...

    Read More: 973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    AI Governance
    May 28, 2026 Jacob Krell

    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It

    On May 20, 2026, Verizon published the 2026 Data Breach Investigations Report with a dedicated AI section built on ...

    Read More: The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    Mean Time to Exploit
    May 21, 2026 Jacob Krell

    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower

    On May 20, 2026, Verizon published the [2026 Data Breach Investigations ...

    Read More: The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    Cybersecurity
    May 20, 2026 Jacob Krell

    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code

    GitHub's 3,800 Repositories Stolen Through a Single IDE Extension On May 19, 2026, a single VS Code extension on a ...

    Read More: The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    May 20, 2026 Hannah Perez

    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability

    If you think a basic pop-up banner that reads "By continuing to browse this site, you accept cookies" protects your ...

    Read More: The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Data Privacy
    May 19, 2026 Jacob Krell

    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore

    In April 2026 alone, the ShinyHunters extortion group breached ADT (5.5 million customers), Amtrak (2.1 million ...

    Read More: Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    Vulnerability Management
    May 05, 2026 Jacob Krell

    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.

    Mandiant's M-Trends 2026 report puts estimated mean time to exploit at negative seven days. That number should reset ...

    Read More: Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    Prompt Injection
    Apr 30, 2026 Hannah Perez

    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance

    When AI Billing Breaks Trust: Lessons from the Claude Code Backlash AI adoption is accelerating, but trust is still ...

    Read More: When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    Cybersecurity
    Apr 29, 2026 Suzu Labs

    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield

    Cybersecurity doesn’t start with tools, it starts with mindset. In this episode featuring Aaron Colclough, we get a ...

    Read More: From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    When Elite Cyber Teams Can't Crack Web Security
    Cybersecurity
    Apr 23, 2026 Jacob Krell

    When Elite Cyber Teams Can't Crack Web Security

    HTB's 2025 benchmark tested 796 security teams. Only 21% passed web security challenges. The Security Illusion Security ...

    Read More: When Elite Cyber Teams Can't Crack Web Security
    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Cybersecurity
    Apr 22, 2026 Jacob Krell

    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them

    In today's security landscape, some of the most dangerous vulnerabilities aren't flagged by automated scanners at all. ...

    Read More: The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Suzu Labs Acquires Emulated Criminals
    Apr 20, 2026 Hannah Perez

    Suzu Labs Acquires Emulated Criminals

    Bridging the gap between theory and the threat reality, Suzu Labs is proud to announce the acquisition of Emulated ...

    Read More: Suzu Labs Acquires Emulated Criminals
    The Wall Around Claude 4.7 Does Not Extend to Dread
    Cybersecurity
    Apr 17, 2026 Suzu Labs

    The Wall Around Claude 4.7 Does Not Extend to Dread

    Anthropic released Claude Opus 4.7 on April 16, 2026 with automated cybersecurity safeguards and a Cyber Verification ...

    Read More: The Wall Around Claude 4.7 Does Not Extend to Dread
    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    youtube
    Apr 10, 2026 Jacob Krell

    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control

    Earlier this year, YouTube began rolling out a row of algorithmically recommended videos at the top of the ...

    Read More: The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    The AI Revolution: How Jobs Will Change by 2030
    Cybersecurity
    Apr 07, 2026 Suzu Labs

    The AI Revolution: How Jobs Will Change by 2030

    Host Phillip Wylie sits down with Nicolas Chaillan to discuss the sobering reality of AI replacement, the critical need ...

    Read More: The AI Revolution: How Jobs Will Change by 2030
    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    Generative AI
    Apr 01, 2026 Hannah Perez

    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?

    In late 2024, Sydney tech entrepreneur Paul Conyngham was told his rescue dog, Rosie, had months to live. She was ...

    Read More: The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    Cybersecurity
    Mar 30, 2026 Suzu Labs

    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone

    The world of cybersecurity has undergone a massive transformation in just a few decades. In this episode of Simply ...

    Read More: From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    While TSA Made Headlines, CISA Went Dark
    Critical Infrastructure
    Mar 30, 2026 Jacob Krell

    While TSA Made Headlines, CISA Went Dark

    The Department of Homeland Security has been partially shut down for over 45 days. In that time, 460 TSA officers have ...

    Read More: While TSA Made Headlines, CISA Went Dark
    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    AI Security
    Mar 30, 2026 Suzu Labs

    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks

    In cybersecurity, we often operate in silos. The red team breaks things, the blue team fixes them, and management ...

    Read More: The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    Claude Mythos and the Cybersecurity Risk That Was Already Here
    Threat Intelligence
    Mar 27, 2026 Jacob Krell

    Claude Mythos and the Cybersecurity Risk That Was Already Here

    On March 26, Anthropic confirmed the existence of Claude Mythos, an unreleased AI model described internally as "a step ...

    Read More: Claude Mythos and the Cybersecurity Risk That Was Already Here
    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Critical Infrastructure
    Mar 26, 2026 Mike Bell

    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It

    Rapid7's research reveals China-linked kernel implants deep inside telecom signaling infrastructure. Here's what ...

    Read More: BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    Cybersecurity
    Mar 23, 2026 Hannah Perez

    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026

    We are incredibly proud to announce a monumental achievement. At this year’s Global InfoSec Awards 2026, hosted by ...

    Read More: Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Cybersecurity
    Mar 17, 2026 Suzu Labs

    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity

    In the world of cybersecurity, we often talk about "gatekeeping" or the "skills gap," but rarely do we find individuals ...

    Read More: From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    Cybersecurity
    Mar 16, 2026 Phillip Wylie

    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss

    The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss In this episode of Simply Offensive, ...

    Read More: Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Critical Infrastructure
    Mar 13, 2026 Denis Calderone

    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The ...

    Read More: From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    Social Engineering
    Mar 09, 2026 Suzu Labs Intelligence

    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation

    Executive Summary Even Realities markets its G2 smart glasses as the privacy-conscious alternative to Meta Ray-Bans. ...

    Read More: Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    Threat Intelligence
    Mar 06, 2026 Mike Bell

    The Company Reviewing Your Meta Glasses Footage Has a Security Problem

    Last week, Swedish journalists revealed that Meta sends video footage from Meta Ray-Ban smart glasses to human data ...

    Read More: The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    CTF
    Mar 03, 2026 Jacob Krell

    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    View White Paper Abstract: Agentic AI systems are compressing competitive hacking timelines faster than the ...

    Read More: The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Cybersecurity
    Mar 03, 2026 Phillip Wylie

    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration ...

    Read More: Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Anthropic and Claude: 2026 AI Powerhouse
    Supply Chain Security
    Feb 26, 2026 Hannah Perez

    Anthropic and Claude: 2026 AI Powerhouse

    In early 2026, the image of Anthropic as a cautious, safety-oriented "research lab" has effectively been replaced by ...

    Read More: Anthropic and Claude: 2026 AI Powerhouse
    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Cybersecurity
    Feb 24, 2026 Phillip Wylie

    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle

    In this episode of Simply Offensive, host Philip Wylie welcomes Darius Houle, an Application Security (AppSec) and ...

    Read More: Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Cybersecurity
    Feb 17, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown

    In the latest episode of the Simply Offensive podcast, host Philip Wylie sat down with Matt Brown, a renowned hardware ...

    Read More: Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Cybersecurity
    Feb 12, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs

    In today’s rapidly evolving technological landscape, the convergence of artificial intelligence (AI) and cybersecurity ...

    Read More: Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Threat Intelligence
    Feb 10, 2026 Phillip Wylie

    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss

    Beyond the Pentest: Why Adversarial Emulation is the Future of Defensive Training Many organizations operate under the ...

    Read More: Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Under Armour Breach: What The Forum Data Actually Shows
    Threat Intelligence
    Jan 30, 2026 Mike Bell

    Under Armour Breach: What The Forum Data Actually Shows

    On January 18, 2026, the Everest ransomware group made good on their threat and released Under Armour customer data to ...

    Read More: Under Armour Breach: What The Forum Data Actually Shows
    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Briefing Room
    Jan 29, 2026 Dahvid Schloss

    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers

    This article is in reference to our newest POC hosted on GitHub here: https://github.com/Emulated-Criminals/SilentFrame ...

    Read More: SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Brightspeed Breach: Crimson Collective and the Infostealer Problem
    Threat Intelligence
    Jan 20, 2026 Mike Bell

    Brightspeed Breach: Crimson Collective and the Infostealer Problem

    Recently Crimson Collective claimed they breached Brightspeed and grabbed 1 million+ customer records. The list of data ...

    Read More: Brightspeed Breach: Crimson Collective and the Infostealer Problem
    When Grid Data Goes Dark Web
    Power Grid
    Jan 19, 2026 Mike Bell

    When Grid Data Goes Dark Web

    Inside a threat actor's critical infrastructure targeting In January 2026, 139 gigabytes of engineering data from a ...

    Read More: When Grid Data Goes Dark Web
    The $150,000 Password
    Critical Infrastructure
    Jan 19, 2026 Mike Bell

    The $150,000 Password

    How one threat actor turned stolen credentials into a global breach portfolio Between December 2025 and January 2026, a ...

    Read More: The $150,000 Password
    Seeing Everything, Understanding Nothing
    Briefing Room
    Jan 16, 2026 Dahvid Schloss

    Seeing Everything, Understanding Nothing

    To help you get a head start on making your environment safer and in keeping with the theme of January’s “New Year, New ...

    Read More: Seeing Everything, Understanding Nothing
    New Year, New Priorities - So, what to fix first?
    Briefing Room
    Jan 08, 2026 Dahvid Schloss

    New Year, New Priorities - So, what to fix first?

    The most common phrase we hear from our prospects is, “We are overwhelmed, and we aren’t sure what to tackle first.” ...

    Read More: New Year, New Priorities - So, what to fix first?
    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Briefing Room
    Nov 21, 2025 Dahvid Schloss

    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)

    Repository purpose: this research was to evaluate the feasiabilty of using Alternate Data Stream (ADS) in staging and ...

    Read More: UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Logo copy 3-1

    Fortified Security. Intelligent Innovation.

    +1 (702) 766-6257
    P.O. Box 750111
    Las Vegas, Nevada 89136

    Follow Us

    About

    • About Us
    • Contact
    • FAQ's

    Solutions

    • AI Advisory
    • AI Assessment
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • Adversarial Operations
    • Social Engineering
    • Products

    Resources

    • Blog
    • In The Media
    • Podcasts
    © 2026 All rights reserved.
    • Privacy Policy
    • Terms & Conditions