# Cybercrime Has a Better Org Chart Than the Agencies Trying to Stop It


The FBI takes down a ransomware network. Three months later, a near-identical operation surfaces under a different name, with the same affiliate structure, the same cryptocurrency rails, and the same playbook. Repeat indefinitely.


This isn't a story about law enforcement failing. It's a story about structural asymmetry — and why the gap between how attackers organize and how defenders respond may be the defining security problem of the decade.


That was the argument Carole House made at Black Hat USA 2026, and it landed harder than most keynote-adjacent talks do. House — CEO of Penumbra Strategies, Atlantic Council senior fellow, and a former intelligence officer — didn't traffic in the usual hand-wringing about nation-states or zero-days. She came with a structural critique: the adversary has a better org chart than the coalition trying to stop them.


## Franchises, HR Departments, and Customer Support


The picture House painted of modern cybercrime operations is almost corporate in its banality. Ransomware-as-a-service groups run affiliate programs with revenue splits and brand guidelines. Pig butchering operations have recruitment pipelines, shift managers, and multi-language customer support. Romance scam networks operate with the kind of documented division of labor that would make a McKinsey consultant nod along.


The leap here isn't just technical sophistication — it's organizational sophistication. Non-state actors who couldn't code their way into a corporate VPN a decade ago are now generating eight-figure annual revenue by plugging into prebuilt criminal infrastructure. AI tools have compressed the skill gap further, automating the phishing lures, the social engineering scripts, the initial intrusion steps that used to require real expertise.


Cryptocurrency completed the picture. It's not that blockchain transactions are impossible to trace — they're not, and chain-analysis firms have gotten genuinely good at following the money. The problem is that the process takes time, requires legal agreements across jurisdictions, and moves at the speed of international bureaucracy. Threat actors move at the speed of a wire transfer.


## Why Takedowns Keep Failing to Stick


House's most pointed observation was one the cybersecurity community has been dancing around for years: law enforcement victories against major criminal networks have largely functioned as temporary inconveniences rather than structural dismantling.


Operation Endgame, the LockBit takedown, the infrastructure seizures against ALPHV — each generated legitimate headlines and genuine disruption. And then: the core operators rebuilt, the affiliates scattered to competing programs, and within months the TTPs showed up again under new branding. House's framing explains why: "no single actor controls enough to be deterred by law enforcement actions."


This is a deliberate design choice. Franchise models make operators replaceable by design. The criminal equivalent of a CEO getting arrested just means the deputy steps up. When the platform itself is decentralized across jurisdictions, seizing one node doesn't poison the network.


Compare this to how law enforcement actually operates: national agencies with hard jurisdictional limits, bilateral legal agreements that can take months to execute, intelligence that's classified and therefore can't be shared with private-sector defenders who are closest to the threat, and interagency coordination that requires political will from multiple governments simultaneously. The adversary's OODA loop is measured in hours. The defender's is measured in months.


## The Gray Zone Problem


House's session title — "Deny. Disrupt. Dismantle." — borrowed military targeting doctrine, which is deliberate. Her background as an Army intelligence officer informs a framework the cybersecurity industry has been slow to internalize: you don't defeat an adaptive adversary by targeting its endpoints. You target the business model.


The "gray zone" framing matters here. Most cybercrime today operates in jurisdictions that are either unable or unwilling to act — Russia, North Korea, parts of Southeast Asia where pig butchering compounds have been documented running for years with apparent state tolerance. Traditional law enforcement tools presuppose a legal system that will respond. When that system doesn't exist, or actively provides cover, the deterrence calculus breaks down entirely.


What House called for was a shift from reactive, siloed response to something closer to a coordinated national strategy — one that maps the business model, targets the chokepoints (crypto off-ramps, bulletproof hosting providers, the identity fraud pipelines that fuel initial access), and synchronizes action across agencies and allied governments simultaneously rather than sequentially.


---


## HackWire Analysis


The coordination gap House described at Black Hat is real, and the cybersecurity industry has done a poor job naming it clearly. Most security vendor messaging focuses on the technical sophistication of attackers — zero-days, living-off-the-land tradecraft, supply chain compromise. That framing serves a purpose: it sells products. But it obscures the harder problem, which is structural.


The ransomware ecosystem circa 2026 doesn't succeed primarily because of technical brilliance. It succeeds because of organizational resilience. The LockBit takedown in early 2024 was followed within months by operators spinning up under new affiliations. ALPHV's apparent exit scam just redistributed experienced affiliates to RansomHub and Play. The talent and the tooling are fungible. The coordination model is what persists.


This has a concrete implication for defenders that most threat intelligence reports undersell: your adversary is not a single actor to be profiled, blocked, and moved on from. Your adversary is a labor market. When you burn one group, you don't retire the threat — you redeploy it.


What that means practically: detection and response strategies built around group-specific indicators of compromise will keep generating headlines without generating durable protection. The more defensible investment is in chokepoint hardening — identity hygiene, credential monitoring, the phishing-resistant authentication that would have stopped half the major breaches of the past three years regardless of which specific group pulled the trigger.


House's military framework also surfaces something the private sector tends to ignore: synchronized action requires shared intelligence, and right now the classification wall between government threat intelligence and private-sector defenders is doing the adversary a genuine favor. Until that changes — until the agencies with visibility into criminal infrastructure can share it with the companies actually operating the targeted systems — the coordination gap will stay open.


That's the story Black Hat doesn't fully tell, because the conference is built on the product ecosystem that benefits from the current model.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)