This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Executive Security Amidst Professionalization of Cyber Criminal Underground

Download resources

About this session

Olga Polishchuk, who leads tactical intelligence at ZeroFox, describes how the criminal underground has professionalised and why executives are its favourite targets. She opens with survey data showing CEOs now rank cyber risk first while many IT staff consider their own CEO a top risk, then reports that most executives ZeroFox protects appear in third-party breach data and about half recycle passwords, feeding combo lists that criminals operationalise with credential checkers. She maps the underground as a mirror of the legitimate economy: specialised actors packaging and reselling data, as-a-service offerings with money-back guarantees, rebranding after takedowns. Trends from 2022 include ransomware groups cherry-picking sensitive files (passport scans held by executive assistants, dating-site records) for extra leverage, and the collapse of the no-politics norm after the invasion of Ukraine, with hacktivist collectives doxxing executives on either side. Recommendations cover adding cybercrime expertise to executive protection teams, controlled engagement with sellers, monitoring the footprint of executives and their families, and feeding external intelligence to the SOC. A Q&A covers PII pricing, nation-state attribution and how analysts blend into criminal forums.

In this talk, ZeroFox will discuss several real-world use cases from the field to highlight the evolution of this criminal ecosystem, focusing on some its most effective operators and the risks they pose to C-Suite executives. ZeroFox will also offer recommendations to best protect your "Very Attacked People" against various forms of malicious exploitation from the cyber criminal underground. Cyber criminals have added additional complexity to executive security programs. These criminals are well funded, highly organized, and can pivot quickly within a dynamic ever-changing cyber threat landscape. Security teams no longer need only to have a competitive edge over their peers but are going toe-to-toe with cyber criminals who continuously innovate, cooperate, and adapt. “Very Attacked People,” like enterprise leadership and high-profile employees, are frequent targets of these criminal actors who aim to exfiltrate data, commit fraud, take over accounts, disseminate false information, or impersonate high-profile employees. By understanding common threat actor behavior and staying abreast of trends in the cyber criminal underground, organizations can develop a proactive response by anticipating threat actors’ next move, help educate the C-Suite, and improve their overall cyber safety posture.

Key takeaways

  • Assume your executives already appear in third-party breach dumps; enforce unique passwords and MFA because combo lists are replayed for years.
  • Executive assistants hold passport scans, licences and travel details; include them and family members in the protection scope and footprint monitoring.
  • Ransomware crews now hunt for reputationally sensitive files to pressure individuals, so extortion planning must cover personal as well as corporate data.
  • Bring cybercrime and dark-web expertise into executive protection, which has historically been a physical-security function.
  • Treat underground intelligence as context for the SOC: understand the 'so what' of a listing rather than expecting takedowns, which rarely remove data from circulation.

Speakers

Olga Polishchuk
Olga Polishchuk
Senior Director, Tactical Intelligence Op. · ZeroFox
Olga Polishchuk is a security and intelligence professional with over a decade of experience in executive security, open-source intelligence, threat & risk assessments, and a wide array of physical and information security investigations. Olga… Read moreRead less

Olga Polishchuk is a security and intelligence professional with over a decade of experience in executive security, open-source intelligence, threat & risk assessments, and a wide array of physical and information security investigations. Olga serves as the Senior Director in the Tactical Intelligence Operation Unit at ZeroFox, focusing on tactical investigations and threat assessments. In her current position, she acutely focuses on expanding organizations' understanding of the potential and emerging threats and aids in real-time operational and strategic decisions.

Resources

Tags

More from GoSec 2022

Also from Olga Polishchuk

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.