This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Les interventions policières contre la cybercriminalité sont-elles efficaces?

Download resources

About this session

Andréanne Bergeron, a digital forensics professor at UQTR and former GoSecure/Flare researcher, presents empirical research, built on Flare's data, asking whether police takedowns of cybercrime infrastructure produce lasting harm reduction or simply displace activity. Using 44 million stealer logs collected between June 2024 and June 2026 and an interrupted-time-series design, she evaluates four operations (Opération Secure, an FBI action against Lumma, Magnus, Endgame 3) on the targeted malware family and the wider infostealer ecosystem. Most interventions show only a short-lived dip, often followed by an activity spike of several hundred percent within a month, which she attributes to operator reorganization and free publicity drawing new buyers; the ecosystem keeps growing as displaced demand shifts to competing tools. The exception is the FBI/Microsoft action against Lumma, whose volume fell significantly out to 90 days, which she links to an unprecedented seizure of 2,300 domains, Microsoft leading rather than merely supporting, a parallel civil suit alongside the criminal case, and a possible operator exit scam afterward. She concludes policing alone is under-resourced for this problem and argues durable results need deeper, better-incentivized public-private partnership, questioning whether legally compelling private-sector participation is the answer.

Les opérations policières contre la cybercriminalité se multiplient, mais leur capacité à produire une réduction durable des activités criminelles demeure difficile à démontrer. Une question centrale se pose : les perturbations d’infrastructures criminelles réduisent-elles réellement la menace, ou entraînent-elles simplement un déplacement des activités vers de nouveaux acteurs et outils?Cette présentation propose une analyse empirique de l’efficacité des interventions policières dans le domaine de la cybercriminalité à travers l’étude des écosystèmes d’infostealers. À partir de 44 millions de stealer logs collectés entre juin 2024 et juin 2026, nous évaluons l’impact de plusieurs opérations internationales majeures au moyen d’une analyse quasi expérimentale de séries temporelles interrompues.Les résultats révèlent que la majorité des interventions n’ont pas entraîné de diminution durable de l’activité criminelle : les infrastructures perturbées sont souvent remplacées par des solutions concurrentes, maintenant un écosystème globalement stable. Toutefois, certaines opérations démontrent qu’une stratégie combinant perturbation technique, pression sur les réseaux de distribution et atteinte aux mécanismes de confiance criminels peut produire des effets significatifs à long terme. Les partenariats public-privé semblent également être un élément important de la réussite d'une intervention.Cette recherche met en lumière les limites des approches centrées uniquement sur la saisie d’infrastructures et propose une réflexion plus large sur le rôle du secteur privé et les conditions nécessaires pour que les interventions policières puissent réellement réduire la cybercriminalité.

Key takeaways

  • Do not judge a takedown's success by an initial drop alone: check the 30, 60 and 90-day windows, since most malware families in this study rebounded, some with a spike of several hundred percent, within a month.
  • When evaluating a takedown's real effect, measure the whole ecosystem, not just the targeted malware family, since displaced criminal demand often simply moves to a competing tool rather than disappearing.
  • Multi-layer operations that hit monetization mechanisms and distribution networks, not just servers and domains, appear far more likely to produce a durable reduction than infrastructure seizure alone.
  • Treat private-sector leadership, not just technical support, and parallel civil legal action alongside criminal proceedings as differentiators worth studying when a takedown does work.
  • Expect a short-term activity spike after a takedown as a normal reorganization/publicity effect rather than evidence of failure, but keep watching past 90 days before calling an operation a success.

Speakers

Andréanne Bergeron
Andréanne Bergeron
Professeure · Université du Québec à Trois-Rivières
Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an… Read moreRead less

Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an affiliated professor in the Department of Criminology of Montreal University, bridging academia and industry. Involved in the cybersecurity community, she is a board member of the Canadian Cybersecurity Network and the co-VP of engagement and outreach for Northsec.

Resources

Photos

Tags

More from GoSec 2026

Also from Andréanne Bergeron

On the same topic