Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

ThreatVectr Newsdesk· 3 min read
A digital representation of a botnet network with police arrest imagery in the background
Share

Key points

  • Cybercriminals now operate structured organisations with HR departments, customer support, and franchise models that make individual arrests largely irrelevant.
  • Carole House, CEO of Penumbra Strategies and former White House National Security Council cybersecurity adviser, presented at Black Hat USA 2026 in Las Vegas.
  • House identified a core problem: attackers coordinate tightly, while law enforcement agencies still largely work in silos and prioritise their own internal metrics.
  • A March 2026 Trump administration executive order on cybercrime acknowledged the problem but House found significant gaps in its approach.
  • Jamie Levy of security firm Huntress warned that AI tools now let criminals rebuild their networks within minutes of a law-enforcement takedown.

Criminals who run ransomware, which is malicious software that locks a victim's files until a payment is made, no longer operate as lone hackers. They run businesses. There are divisions of labour, human resources departments, and customer support lines on Telegram. When police shut one operation down, a replacement franchisee spins up a new one almost immediately.

That was the blunt message from Carole House at Black Hat USA 2026 in Las Vegas, where she led a session on breaking the business model of cybercrime.

Why are takedowns not working?

Takedowns disrupt criminals for a while, but the franchise structure means no single arrest kills the operation. House put it plainly: "We are fighting a very coordinated, very sophisticated adversary with a very untimely response."

Law enforcement's default playbook, investigate, attribute, indict, and wait for extradition, was designed for a slower era. Today's criminal networks are built to absorb that kind of hit. Operators are replaceable by design. Sanctions, where governments freeze assets and name individuals publicly, help with attribution but do not dismantle the underlying network.

Jamie Levy, senior director of adversary tactics at Huntress, told Dark Reading that AI tools and so-called "vibe coding," where software is generated rapidly with minimal human input, have made things worse. Before those tools existed, a takedown at least created a temporary gap. Now criminals can rebuild infrastructure within minutes.

"The big solution here is where the security community comes together as a whole to fight this problem," Levy said.

What needs to change?

House wants a coordinated national strategy, modelled on military planning frameworks she used during her time in the US Army and as an intelligence officer. The core idea: focus multiple agencies simultaneously on the highest-value criminal networks, rather than each agency chasing its own priority list.

She pointed to a 2021 shift in anti-ransomware coordination as genuine progress, but said structural failures remain. A March 2026 executive order from the Trump administration addressed the issue, though House noted the Trump administration also rolled back earlier fraud-fighting measures she helped put in place.

"The admin rescinded all the measures we put in place to fight fraud, which has been tough seeing that," she said.

International partnerships matter too. Many criminal operations run from jurisdictions that offer them legal protection, and those safe havens will not close without diplomatic pressure.

Area Current approach What House recommends
Takedowns Single-agency, sequential Multi-agency, simultaneous
Sanctions Ad hoc deterrent Part of a broader coordinated plan
Information sharing Agencies prioritise own metrics Shared priority lists across agencies
Industry role Passive intelligence consumer Active, collaborative threat sharing

What should ordinary people watch for?

House made the point that ordinary people do not care which country a gang operates from when a hospital or petrol station goes dark. They care about the outage.

Ransomware victims are often targeted after a phishing email, where criminals send fake messages to trick staff into handing over passwords or clicking a dangerous link. Being sceptical of unexpected emails asking for login details remains the single most practical defence for employees at any organisation.

© 2026 Threat Vectr