International Cyber Expo International Cyber Expo
  • About Us
Saturday, 26 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White

Esteemed journalist and author Geoff White sits down with the Gurus to discuss the ransomware industry.

by Guru Writer
August 11, 2026
in Features, Insight
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Share on FacebookShare on Twitter

Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. 

Geoff White is an award-winning investigative journalist whose reporting has taken him inside global hacking networks, cryptocurrency thefts and modern money-laundering operations.  

A former Technology Correspondent for Channel 4 News, he has also reported for the BBC and The Sunday Times. Geoff co-created and presented the BBC World Service podcast The Lazarus Heist and has written three books on cybercrime and organised crime. Champions Speakers 

In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Geoff explains how cybercrime became a mature global industry, why segmentation remains critical against ransomware and how criminals are using AI in practice. He also examines why stolen data has become one of their most useful assets. 

What drove the convergence of lone hackers, organised crime gangs and state actors into today’s global cybercrime ecosystem? 

Geoff White: “Hacking has always been a thing with computers. From the earliest days, there were people who hacked, which originally didn’t necessarily mean criminal behaviour. 

“Hacking something together is an engineering term. If all you’ve got is some gaffer tape and string, you make the engine work. That was the principle behind hacking in the early days. 

“The apple in the Garden of Eden was money. As soon as websites such as eBay and Amazon started getting set up, credit cards began flooding onto the web. That’s where organised crime gangs started to become interested in the technology. 

“What’s happened since has been an evolution. You started to see organised crime gangs become interested in cyber and hacking. Governments also became interested because getting hold of secrets and manipulating other nations is very useful. 

“You also had lone hackers, what they call hacktivists, the classic kid in a hoodie in a bedroom somewhere. 

“Over time, these movements have moved together and learned from each other. Governments realised that the tactics used by bedroom hackers and activists could be used effectively to push other nations around. 

“Organised crime gangs have sometimes obtained incredibly powerful cyber tools from government hackers. 

“We’re starting to see all these different types of groups coming together. If you want to know why cyber has risen up the agenda, that’s the real explanation.” 

Ransomware now operates like a mature industry. Why do major organisations remain vulnerable, and what defence matters most once attackers get inside?

Geoff White: “The thing to realise about ransomware is that this is a very mature industry, and it is an industry. There are hundreds of people working in it. 

“It’s been through its start-up phase, seed-funding phase and venture-capital phase. It is now a fully fledged industry. 

“At the last count, I found 62 different groups on the dark web who were all carrying out ransomware attacks. They’re extremely strategic. 

“They will say: “Today, we are going to target the transport sector.” They will find companies in that sector and work out which ones are vulnerable, which are most valuable and which are juicy targets. 

“The next day, they might decide to target pharmaceuticals. They are very strategic in how they work and will target those organisations until they find a way in. 

“Unfortunately, the likelihood is that a ransomware gang will get inside your organisation. The only thing you can do to prevent the damage becoming much worse is segmentation. 

“Make sure that if attackers get into one part of your organisation, they can’t access everything. If they break into one department, they shouldn’t be able to move into other departments. 

“Segmentation, breaking things apart and introducing barriers for attackers, is your best defence.” 

How are cybercriminals using AI in practice, and is the threat currently outpacing cyber defence? 

Geoff White: “Like all industries, the cybercrime industry is looking very hard at artificial intelligence. Our working practices are gradually being revolutionised by AI, and the cybercrime space is no exception. 

“However, there’s some good news. 

“If you look at how cybercriminals are using AI in practice, rather than theoreticals, hypotheticals or unverified services being offered on the dark web, it’s the same stuff we’re using it for. 

“They’re using it to improve their emails, audit their code and conduct reconnaissance on targets they might want to hit. That’s not reinventing the wheel. 

“I would contrast that with what’s happening on the defensive side of cyber. AI has always been used in cyber defence. We used to call it machine learning. 

“The cyber-defence industry is using AI at scale and pace. I think we’re in a good place. 

“If we can double down on those AI wins in cyber defence now, we can hopefully stave off the day when cybercriminals start using AI at scale as well.” 

What makes stolen data more useful to cybercriminals and nation states than assets such as cash or cryptocurrency? 

Geoff White: “Cybercriminals have realised that the one thing organisations possess that is easy to obtain and use is data. 

“I can get hold of credit cards as a crook, but then I’ve got to wash the credit card money. I can steal Bitcoin, but then I’ve got to put the Bitcoin somewhere. 

“If I steal data, I’ve got an instant win. I can go on the dark web and sell it. If it’s customer data, I can contact people and send them phishing emails. 

“I can also contact the organisation and say: “I’ve got a bunch of your data. Pay me and I won’t leak it.” 

“There are many different ways data can be used. This isn’t limited to criminals. Nation states have become involved as well. 

“We’ve seen massive data leaks and government hackers breaking into organisations. One famous example was the Democratic Party during the 2016 US presidential election. Incredibly sensitive data was stolen and then weaponised to cause damage. 

“Data has become the new currency for cybercrime gangs in the same way it became the new currency for organisations.” 

 When audiences hear the stories behind your investigations, what do you want them to understand about cybercrime and how to confront it? 

Geoff White: “When I give talks, I’m lucky as a journalist because I have these amazing stories. 

“Regardless of how technical this becomes or how much financial crime might appear to concern spreadsheets, it’s always about people. 

“There’s always a set of characters behind it who are interesting, sometimes crazy and sometimes extremely quirky. 

“I look at the people and their motivations. Then we examine how they work and the lessons organisations need to learn to fight them. 

“I hope people leave my talks with a thumping good story and some valuable, applicable lessons that they can start putting in place to stop the bad guys winning.” 

ShareTweet
Previous Post

Anthropic Says AI Distillation Has Become An Industrial Extraction Business

Next Post

Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense

Recent News

Attackers build “silent” cryptominer on victim’s machine and give themselves away

Attackers build “silent” cryptominer on victim’s machine and give themselves away

September 25, 2026
OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

September 25, 2026
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

September 23, 2026
CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

September 23, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol