Cybercriminals Have Become Better Business Operators Than Most Companies Think
Cybercrime has evolved into an industry built on specialization, efficiency, and continuous improvement.
Aaron Beardslee, Security Threat Researcher, Securonix
For a long time, it was easy to think about cybercriminals as individuals sitting behind keyboards, wearing a black hoodie, looking for vulnerabilities, writing malware, and launching attacks from wherever they happened to be. Spend enough time following ransomware operations, leaked chat logs, law enforcement takedowns, and threat intelligence reporting, and a very different image begins to emerge. Many of the groups behind today’s largest attacks are operating with a level of discipline and organization that looks surprisingly familiar to anyone who has worked inside a successful technology company.
Work is divided into specialist roles because specialization improves efficiency. Some groups specialize in gaining initial access while others focus entirely on malware development. Affiliates carry out the intrusions, negotiation teams handle victims, and dedicated operators maintain payment infrastructure. The work is divided because specialization improves efficiency, allowing every participant to become better at a smaller part of the operation rather than expecting one group to do everything. Each participant concentrates on one part of the operation because doing one thing well is more profitable than trying to do everything alone. The structure has changed for the same reason most successful businesses evolve. Specialization produces better outcomes and makes it easier to scale.
Ransomware-as-a-service accelerated that evolution because the economics continue to reward it. Sophos’ State of Ransomware 2025 found that 49% of organizations surveyed experienced a ransomware attack during the previous year, with recovery costs still reaching into the millions of dollars. Criminal groups see those same economics. As long as the returns justify the investment, there is every incentive to keep improving the business behind the attacks.
A criminal no longer needs to build an entire operation from scratch since the infrastructure already exists. Malware is maintained by dedicated developers, while payment systems, leak sites, negotiation support, and technical updates are provided as part of the service. Affiliates concentrate on compromising organizations while platform operators continue improving the product. This new model lowers the barrier to entry, shortens the time needed to become operational, and allows successful techniques to spread remarkably quickly across different groups. What started as isolated criminal campaigns has become a force with its own supply chains, partnerships, and commercial incentives.
Material released during law enforcement operations and internal ransomware leaks paints a consistent picture. These groups spend time discussing productivity, recruitment, infrastructure reliability, operational security, and affiliate performance in ways that look uncomfortably familiar. The objectives are illegal, but the conversations often resemble those taking place inside companies trying to improve products, streamline operations, or expand into new markets. That level of organizational maturity is probably more concerning than any individual malware family because it demonstrates how much organizational maturity now exists inside the criminal economy.
The economics tell an interesting story. The FBI’s Internet Crime Complaint Center received more than 859,000 complaints in 2024, with reported losses reaching a record $16.6 billion, the highest figure the bureau has ever recorded. And they extend well beyond ransomware but also illustrate the scale of the opportunity criminal groups continue pursuing. Like any successful market, profitable operations attract investment, specialization, and new participants which then creates stronger ecosystems. Legitimate businesses would recognize the pattern immediately since it mirrors how successful markets tend to grow when demand remains high and barriers to entry continue falling. (FBI IC3 2024 Report)
IBM’s 2024 Cost of a Data Breach report found the average global breach now costs $4.88 million, the highest figure the study has ever recorded. Sophos’ State of Ransomware continues to show that recovery costs routinely extend beyond ransom payments themselves, while blockchain analysis from Chainalysis demonstrates that ransomware ecosystems continue generating hundreds of millions of dollars despite sustained law enforcement disruption. Returns remain high enough to justify continued investment, which helps explain why these organizations continue improving despite sustained law enforcement pressure.
Looking back over the past decade, the organizations creating the greatest disruption were rarely the ones introducing entirely new malware families or discovering extraordinary exploits. More often, they were the ones that improved, learned from every campaign, and made the next operation just a little more efficient than the last. While missing from headlines, the maturity over hundreds of campaigns creates an attack vector that become remarkably difficult to compete against.
AI Is Now Another Operational Advantage
Artificial intelligence fits naturally into that operating model because it solves the kind of problems mature organizations have always tried to solve. Businesses invest in technology when it removes repetitive work and improves productivity. Cybercriminals are following the same logic. Nobody builds a ransomware operation because they enjoy writing phishing emails, translating content into multiple languages, reviewing publicly available information about potential victims, or manually modifying code to avoid straightforward detections. Those activities support the larger objective. If AI reduces the effort required to complete them, the organization becomes more efficient without changing its strategy. Most conversations about AI still focus on whether it will replace attackers. Looking at current campaigns suggests something much more practical is already happening.
Researchers from Carnegie Mellon University and other institutions found that large language models could produce spear phishing campaigns comparable to experienced operators under controlled testing while dramatically reducing the effort required to research and personalize messages. Google’s Threat Intelligence Group has also documented cases where threat actors used AI to accelerate vulnerability research and exploit development rather than replace experienced operators altogether. Microsoft has reached similar conclusions through its Cyber Signals research, observing attackers using AI to improve reconnaissance, social engineering, translation, and campaign preparation. The more interesting takeaway is how quickly the work around an attack is changing. Learning has become cheaper and research with preparation takes less time, while campaigns start to evolve more quickly because the work surrounding them requires less effort than it did only a short time ago. (Google Threat Intelligence Group, Microsoft Cyber Signals, Carnegie Mellon research)
Businesses have followed that approach for decades. Technology removes repetitive work so experienced people can spend more time making decisions that actually require experience. Mature criminal organizations are following much the same approach. Artificial intelligence is allowing operators to spend less time preparing campaigns and more time improving them. Every improvement reduces the effort required to run the next campaign, and every campaign creates another opportunity to refine techniques, improve tooling, and shorten preparation time. Artificial intelligence is making that learning cycle noticeably cheaper.
A vast majority of security teams still think about attacks as isolated events. Mature criminal organizations increasingly treat every operation as another opportunity to improve the business. That is more significant than any individual AI capability since it changes how quickly attackers can adapt while many defenders are still adapting one investigation at a time.
Efficiency is the Competitive Advantage
Studying today’s most successful criminal operations offers a key insight: Technology is critical, but efficiency now matters more.
Few successful businesses outperform competitors because they invent something revolutionary every year. They improve through hundreds of small decisions that reduce cost, remove friction, and help people work more effectively. Customer acquisition becomes cheaper; development becomes slightly faster and operations now become slightly more reliable. Over time those improvements compound until competitors struggle to keep pace.
Criminal organizations have quietly been following the playbook for years. An attacker who shortens reconnaissance by an hour rarely makes headlines, nor does a group that improves affiliate onboarding or automates infrastructure deployment. None of those improvements looks especially dramatic on its own. Together they allow more campaigns to run, more affiliates to succeed, and more revenue to flow back into the organization. The competitive advantage comes from those improvements compounding over hundreds of campaigns.
Attackers Don’t Need Better Tools
The gap between attackers and defenders increasingly comes down to how work moves through each organization. Mature criminal organizations have become remarkably good at reducing the operational friction in this era. They have started to understand where work slows them down and continuously look for ways to remove the barrier. Artificial intelligence now helps with research, phishing preparation, translation, and code analysis because those tasks consume time they would rather spend elsewhere.
Defenders often spend that same time reconstructing context instead. Identity information lives in one platform, endpoint telemetry in another, cloud investigations follow different workflows, and threat intelligence arrives independently of the operational context needed to understand whether it matters. Before an analyst can decide what an incident means, they often must rebuild the investigation itself. Organizations already possess enough information to understand what happened. Reaching that understanding quickly is a harder problem than collecting the information in the first place.
Business Model Is Now the Battleground
Security teams naturally spend time analyzing malware families, infrastructure, and exploitation techniques. Those remain essential parts of understanding the threat landscape. However, the business behind those attacks deserves equal attention.
LockBit demonstrated that disrupting infrastructure does not dismantle an ecosystem. Affiliates migrated, new groups appeared, and techniques spread. The brand disappeared far more quickly than the commercial model supporting it. Black Basta’s leaked internal chats confirm these patterns, exposing conversations about recruitment, operational performance, relationships, and technical quality that looked remarkably similar to discussions taking place inside high-growth software companies on Slack or Teams. Different objectives, clearly, but many of the same management problems.
Spend enough time following ransomware groups over several years and we see many changes across disciplines. Yet, the operating model survives remarkably well because the ecosystem keeps producing specialists willing to fill the same roles.
For years, we were measuring cybercrime by the malware it produced. Now, it makes more sense to measure it by the business it has become.