Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage.
Geoff White is an award-winning investigative journalist whose reporting has taken him inside global hacking networks, cryptocurrency thefts and modern money-laundering operations.
A former Technology Correspondent for Channel 4 News, he has also reported for the BBC and The Sunday Times. Geoff co-created and presented the BBC World Service podcast The Lazarus Heist and has written three books on cybercrime and organised crime. Champions Speakers
In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Geoff explains how cybercrime became a mature global industry, why segmentation remains critical against ransomware and how criminals are using AI in practice. He also examines why stolen data has become one of their most useful assets.
What drove the convergence of lone hackers, organised crime gangs and state actors into today’s global cybercrime ecosystem?
Geoff White: “Hacking has always been a thing with computers. From the earliest days, there were people who hacked, which originally didn’t necessarily mean criminal behaviour.
“Hacking something together is an engineering term. If all you’ve got is some gaffer tape and string, you make the engine work. That was the principle behind hacking in the early days.
“The apple in the Garden of Eden was money. As soon as websites such as eBay and Amazon started getting set up, credit cards began flooding onto the web. That’s where organised crime gangs started to become interested in the technology.
“What’s happened since has been an evolution. You started to see organised crime gangs become interested in cyber and hacking. Governments also became interested because getting hold of secrets and manipulating other nations is very useful.
“You also had lone hackers, what they call hacktivists, the classic kid in a hoodie in a bedroom somewhere.
“Over time, these movements have moved together and learned from each other. Governments realised that the tactics used by bedroom hackers and activists could be used effectively to push other nations around.
“Organised crime gangs have sometimes obtained incredibly powerful cyber tools from government hackers.
“We’re starting to see all these different types of groups coming together. If you want to know why cyber has risen up the agenda, that’s the real explanation.”
Ransomware now operates like a mature industry. Why do major organisations remain vulnerable, and what defence matters most once attackers get inside?
Geoff White: “The thing to realise about ransomware is that this is a very mature industry, and it is an industry. There are hundreds of people working in it.
“It’s been through its start-up phase, seed-funding phase and venture-capital phase. It is now a fully fledged industry.
“At the last count, I found 62 different groups on the dark web who were all carrying out ransomware attacks. They’re extremely strategic.
“They will say: “Today, we are going to target the transport sector.” They will find companies in that sector and work out which ones are vulnerable, which are most valuable and which are juicy targets.
“The next day, they might decide to target pharmaceuticals. They are very strategic in how they work and will target those organisations until they find a way in.
“Unfortunately, the likelihood is that a ransomware gang will get inside your organisation. The only thing you can do to prevent the damage becoming much worse is segmentation.
“Make sure that if attackers get into one part of your organisation, they can’t access everything. If they break into one department, they shouldn’t be able to move into other departments.
“Segmentation, breaking things apart and introducing barriers for attackers, is your best defence.”
How are cybercriminals using AI in practice, and is the threat currently outpacing cyber defence?
Geoff White: “Like all industries, the cybercrime industry is looking very hard at artificial intelligence. Our working practices are gradually being revolutionised by AI, and the cybercrime space is no exception.
“However, there’s some good news.
“If you look at how cybercriminals are using AI in practice, rather than theoreticals, hypotheticals or unverified services being offered on the dark web, it’s the same stuff we’re using it for.
“They’re using it to improve their emails, audit their code and conduct reconnaissance on targets they might want to hit. That’s not reinventing the wheel.
“I would contrast that with what’s happening on the defensive side of cyber. AI has always been used in cyber defence. We used to call it machine learning.
“The cyber-defence industry is using AI at scale and pace. I think we’re in a good place.
“If we can double down on those AI wins in cyber defence now, we can hopefully stave off the day when cybercriminals start using AI at scale as well.”
What makes stolen data more useful to cybercriminals and nation states than assets such as cash or cryptocurrency?
Geoff White: “Cybercriminals have realised that the one thing organisations possess that is easy to obtain and use is data.
“I can get hold of credit cards as a crook, but then I’ve got to wash the credit card money. I can steal Bitcoin, but then I’ve got to put the Bitcoin somewhere.
“If I steal data, I’ve got an instant win. I can go on the dark web and sell it. If it’s customer data, I can contact people and send them phishing emails.
“I can also contact the organisation and say: “I’ve got a bunch of your data. Pay me and I won’t leak it.”
“There are many different ways data can be used. This isn’t limited to criminals. Nation states have become involved as well.
“We’ve seen massive data leaks and government hackers breaking into organisations. One famous example was the Democratic Party during the 2016 US presidential election. Incredibly sensitive data was stolen and then weaponised to cause damage.
“Data has become the new currency for cybercrime gangs in the same way it became the new currency for organisations.”
When audiences hear the stories behind your investigations, what do you want them to understand about cybercrime and how to confront it?
Geoff White: “When I give talks, I’m lucky as a journalist because I have these amazing stories.
“Regardless of how technical this becomes or how much financial crime might appear to concern spreadsheets, it’s always about people.
“There’s always a set of characters behind it who are interesting, sometimes crazy and sometimes extremely quirky.
“I look at the people and their motivations. Then we examine how they work and the lessons organisations need to learn to fight them.
“I hope people leave my talks with a thumping good story and some valuable, applicable lessons that they can start putting in place to stop the bad guys winning.”

