Threat Brief

Addressing the coordination gap: Enhancing law enforcement and industry collaboration

Black Hat USA 2026 – Las Vegas – Artificial intelligence (AI) and cryptocurrency enablement have allowed threat actors to reach new levels of sophistication, coordination, and scale, increasing the requirements for law enforcement and defense strategies to adapt.

Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, cryptocurrency investment fraud, and romance scams. Although these groups may possess fewer technical resources compared to nation-state actors, they have developed methods to cause equivalent operational friction, resulting in significant financial impacts for individuals and organizations.

At Black Hat USA 2026, Carole House, CEO of Penumbra Strategies and senior fellow at the Atlantic Council, led a session titled "Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone" that examined these trends. She emphasized that "no single actor controls enough to be deterred by law enforcement actions." House recommended shifting strategies to close the gap between the organized methods of threat actors and the currently fragmented coordination among law enforcement agencies.

To protect infrastructure more effectively, House proposed a coordinated national strategy to dismantle organized cybercrime. She demonstrated how applying organizational frameworks she learned during her time in the US Army and as an intelligence officer could structure a more cohesive response.

"The nature of the problem [is that] we are fighting a very coordinated, very sophisticated adversary with a very untimely response," House said. "That gap between their coordination and ours leads to failures."

Evaluating the limits of temporary disruption

Law enforcement agencies have conducted successful interventions and infrastructure seizures over the past few years. However, these actions often serve as temporary disruptions, as threat groups quickly establish new networks. House noted that franchise models are specifically designed to make operators easily replaceable.

Malicious actors currently demonstrate advanced coordination in their operational setup. They maintain franchises, divisions of labor, human resources departments, and customer support channels through the messaging platform Telegram. Conversely, the standard response from law enforcement often remains a linear process: investigate, attribute, indict, and hope for public attribution.

"They're defending against a threat that's being continuously regenerated," she said.

Sanctions have served as a primary deterrent because they can be applied quickly, aid in attribution, and establish public accountability. Yet, sanctions do not fit every context.

In March, the Trump administration released an executive order (EO) titled "Combatting Cybercrime, Fraud, and Predatory Schemes Against American Citizens." While it acknowledged state support and established a helpful framework, House identified areas for improvement and encouraged security professionals engaging with federal agencies to provide constructive feedback.

For instance, the frameworks law enforcement developed to coordinate anti-ransomware measures could be expanded to counter broader cybercrime. "That concept of putting multiple organizations against the most high-value network simultaneously — that is a really valuable tool," she said. "The new EO action plan should leverage that."

House has served in multiple government roles, including as a special adviser on cybersecurity and critical infrastructure policy at the White House National Security Council. She noted that some protective efforts have recently been rolled back.

"The [Trump] admin rescinded all the measures we put in place to fight fraud, which has been tough seeing that," she said.

Learning from structural failures

The public primarily cares about the immediate impact—such as a hospital or gas station experiencing an outage—rather than whether a nation-state or non-state actor caused it, House explained. Law enforcement actions should organize response efforts based on the impact of the security incident and prioritize high-value networks, with a particular focus on safe-haven jurisdictions that shield threat actors.

She advocated for international partnerships and developing new methods to impose operational friction on malicious networks. A persistent obstacle is information sharing, which is essential for joint defense. When agencies do not share their priority lists, they tend to optimize for their own internal metrics rather than systemic protection.

"We made a real paradigm shift in 2021 and I believe it had generally good results," she said. "However, there remains structural failures that we are facing, and we have to be honest about that because those failures teach us more than the wins."

How the security community can coordinate

Jamie Levy, senior director of adversary tactics at Huntress, observed that the effectiveness of network takedowns in curbing ransomware has decreased. Before AI and vibe coding became prevalent, removing a network created a temporary void. Other actors would compete to fill that space, hindering the threat briefly, Levy explained to Dark Reading.

With the current availability of AI, vibe coding, and automated deployment tools, threat actors can regenerate their infrastructure in moments, leading Levy to question the long-term impact of isolated takedowns.

"We need to start thinking more long term," Levy says. "The big solution here is where the security community comes together as a whole to fight this problem. I know we're businesses and we have to compete, but I'm hoping at some point we can all be a little more collaborative."

Partnerships are already forming. Huntress maintains relationships with various organizations, and researchers actively share threat intelligence through shared Slack channels. If researchers validate that a specific software component is being targeted in a campaign, they directly notify the affected company to help them secure their systems.

"I feel like this is the only way forward," she says.

Sources

  1. Threat groups are using AI to speed, scale cyberattacks Cybersecurity Dive, cybersecuritydive.com
  2. Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone Black Hat USA 2026, blackhat.com
  3. Infosec experts detail widespread Telegram abuse TechTarget, techtarget.com
  4. Executive Order on Combatting Cybercrime, Fraud, and Predatory Schemes Against American Citizens The White House, whitehouse.gov

Improve team velocity with
better security and privacy.