Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A conference hall stage at a cybersecurity event with a speaker at a podium addressing an audience, with a visual diagram behind them showing the franchise-like
Share

Key points

  • Cybercriminals operate structured organisations with HR departments, franchise models, and customer support on Telegram, making individual arrests largely irrelevant.
  • Carole House, CEO of Penumbra Strategies and former White House National Security Council cybersecurity adviser, presented at Black Hat USA 2026 in Las Vegas.
  • House identified a core problem: attackers coordinate tightly, while law enforcement agencies still work in silos and prioritise their own internal metrics.
  • A March 2026 Trump administration executive order on cybercrime acknowledged the problem, but House found significant gaps in its approach.
  • Jamie Levy of Huntress warned that AI tools now let criminals rebuild their networks within minutes of a takedown.

Criminals who run ransomware, malicious software that locks a victim's files until a ransom is paid, don't operate as lone hackers anymore. They run businesses. There are divisions of labour, HR departments, and customer support lines on Telegram. When police shut one operation down, a replacement franchisee spins up almost immediately.

That was the blunt message from Carole House at Black Hat USA 2026 in Las Vegas, where she led a session on breaking the business model of cybercrime.

Why are takedowns not working?

Takedowns disrupt criminals temporarily, but the franchise structure means no single arrest kills the operation. House put it plainly: "We are fighting a very coordinated, very sophisticated adversary with a very untimely response."

Law enforcement's default playbook, investigate, attribute, indict, and hope for extradition, was designed for a slower era. Today's criminal networks are built to absorb that kind of hit. Operators are replaceable by design. Sanctions, where governments freeze assets and name individuals publicly, help with attribution but don't dismantle the underlying network.

Jamie Levy, senior director of adversary tactics at Huntress, told Dark Reading that AI tools and so-called "vibe coding," where software is generated rapidly with minimal human input, have made things worse. Before those tools existed, a takedown at least forced a temporary gap. Now criminals can rebuild infrastructure within minutes.

"The big solution here is where the security community comes together as a whole to fight this problem," Levy said.

Our coverage of the DOJ's June 2026 action against Southeast Asia pig-butchering rings made the same point: hitting infrastructure without dismantling the franchise model behind it doesn't hold.

What needs to change?

House wants a coordinated national strategy, modelled on military planning frameworks from her time in the US Army and as an intelligence officer. The core idea: focus multiple agencies simultaneously on the highest-value criminal networks, rather than each agency chasing its own priority list.

She pointed to a 2021 shift in anti-ransomware coordination as genuine progress, but said structural failures remain. A March 2026 executive order from the Trump administration addressed the issue, though House noted that administration also rolled back earlier fraud-fighting measures she'd helped put in place.

"The admin rescinded all the measures we put in place to fight fraud, which has been tough seeing that," she said.

International partnerships matter too. Many criminal operations run from jurisdictions that shield them from prosecution, and those safe havens won't close without sustained diplomatic pressure.

Area Current approach What House recommends
Takedowns Single-agency, sequential Multi-agency, simultaneous
Sanctions Ad hoc deterrent Part of a broader coordinated plan
Information sharing Agencies prioritise own metrics Shared priority lists across agencies
Industry role Passive intelligence consumer Active, collaborative threat sharing

What should ordinary people watch for?

House made the point that ordinary people don't care which country a gang operates from when a hospital or petrol station goes dark. They care about the outage.

Ransomware victims are often targeted after a phishing email, where criminals send fake messages to trick staff into handing over passwords or clicking a dangerous link. Scepticism toward unexpected emails asking for login details remains the most practical defence for employees at any organisation.

The plain judgement here: House is right that the franchise problem is structural, not tactical. Another indictment or another sweep won't fix it. Until agencies share priority lists and act simultaneously, criminals will keep absorbing the hits.

© 2026 Threat Vectr