Cyberattackers are outpacing law enforcement in their coordinated efforts to commit crimes, leaving a trail of destruction and financial losses in their wake. The gap between the sophistication of attackers and the response of law enforcement agencies is growing wider by the day, with devastating consequences for individuals and organizations alike.
A recent session at Black Hat USA 2026 shed light on this alarming trend, which is being driven by the increasing use of artificial intelligence (AI) and cryptocurrency enablement. Threat actors are now able to operate with unprecedented levels of coordination and scale, using affiliate models to conduct complex attacks such as ransomware-as-a-service, pig butchering, and romance scams. These operations are not only financially lucrative but also highly adaptable, allowing them to evade detection and stay one step ahead of law enforcement.
Carole House, CEO of Penumbra Strategies and senior fellow at the Atlantic Council, highlighted the need for a coordinated national strategy to dismantle cybercrime operations. She emphasized that the lack of coordination among law enforcement agencies is a major obstacle in combating these threats, allowing attackers to exploit the gaps between different jurisdictions and response teams. “We are fighting a very coordinated, very sophisticated adversary with a very untimely response,” House said. “That gap between their coordination and ours leads to failures.”
House’s remarks were echoed by her own experiences working in government roles, including as a special adviser on cybersecurity and critical infrastructure policy at the White House National Security Council. She noted that while law enforcement agencies have had some successes in recent years, these efforts are often temporary and do not address the root causes of the problem. “We’re defending against a threat that’s being continuously regenerated,” she said.
One of the key challenges facing law enforcement is the use of messaging platforms like Telegram to coordinate attacks. Threat actors have set up complex networks with franchises, divisions of labor, human resources departments, and customer support channels – all designed to make them virtually uncatchable. Sanctions have been a go-to deterrent method in recent years, but House warned that they are not perfect for every context.
In March, the Trump administration released an executive order (EO) titled “Combatting Cybercrime, Fraud, and Predatory Schemes Against American Citizens.” While it acknowledged state support and had the right framing, House spotted some holes and called on everyone working in and engaging with agencies to weigh in with improvements. She emphasized that frameworks developed by law enforcement to coordinate anti-ransomware efforts could be applied more broadly to fight cybercrime.
Ultimately, House’s message is one of urgency: we need a coordinated national strategy to tackle the threat posed by cybercrime. Americans don’t care about who was behind the attack – they care about the impact on their daily lives. To close the gap between attackers and law enforcement, we need to focus on priority networks, organize efforts based on the breach, its impact, and threat actors across ecosystems, and target safe haven jurisdictions that protect threat actors.
For individuals and organizations, this means being more vigilant than ever in protecting themselves against cyber threats. It also requires policymakers and government agencies to work together to develop effective strategies for combating cybercrime – and to implement them quickly. As House said, “Failures teach us more than wins” – but it’s time to learn from those failures and take action before the problem gets even worse.
Source: Dark Reading — 2026-08-06