After twenty years in the FBI’s cybersecurity division and now senior vice president of Halcyon’s Grand Seminar Research Center, Cynthia Kaiser agreed to answer our questions during a meeting at Infosecurity Europe in London.
JDN. Why did you leave the FBI after twenty years in its cybersecurity division to join the private sector?
Cynthia Kaiser. I have always thought that the best practitioners combine experience in the public and private sectors. When choosing a company, I looked around, and the start-up world seemed the most stimulating to me. It alone allows us to be at the cutting edge of technologies and to help shape them.
The one that Halcyon is developing, namely a technical approach to blocking ransomware, immediately appealed to me, because I have spent a lot of time on the other side responding to an attack. So the idea of being able to prevent the attack in advance was really appealing.
You joined the FBI before the cloud wave, let alone the AI wave. The nature of cyberattacks and the way we think about cybersecurity have undoubtedly evolved significantly during this period…
Online crime has of course increased drastically. It has also changed its nature. Until around ten years ago, we were mainly facing attacks aimed at causing harm (DDoS to take sites offline, defacement, professional email compromises), as well as some very targeted espionage operations.
Today, the leading type of attack has become ransomware, which has increased by 20% since 2023. These attacks have also become much faster (sometimes less than an hour elapses between initial access and full attack) and more numerous. Cybercriminals are stealing the wealth of an entire generation.
Have private actors gained power to the detriment of state actors?
The nature of the attackers has indeed changed, but in a slightly more subtle way than that. A decade ago, state actors were the most dangerous, because they were the only ones with the capacity and means to carry out sophisticated attacks. Today, not only has cybercrime become more widespread, but the line between criminal actor and state actor has also become blurred. Some states, for example, authorize their civil servants to do “moonlighting”, to act as cybercriminals in their free time. As long as they show up for work the next day, the state turns a blind eye. Some state groups recruit criminal organizations to carry out activities on their behalf. There are also clearly state groups that try to pass themselves off as criminal entities, such as the Handala Hack Team in Iran.
Finally, the last major development is that States have fully integrated the cyber component into their military strategy. This is now clearly part of their war efforts. Russia has carried out cyber operations against Ukraine, Iran has carried out destructive attacks against Albania when it was unhappy with the presence of certain political dissidents in the country, while passing it off as a ransomware attack with financial motives.
Which brings us to another major change: the greater discretion of the actors. Whether it’s renting virtual private servers for just a few minutes, or so-called “living off the land” techniques (blending into the network, using native tools, and covering your tracks), criminals have more options to camouflage themselves. This makes their identification much more difficult and contributes to covering their tracks. This allows actors like Iran and Russia to play on chaos and confusion: we are almost sure that attacks come from them, without being able to attribute them with certainty.
You had a front-row seat during Russia’s invasion of Ukraine. Were you surprised by the Russian cyber effort or was it in line with what you expected?
We had seen Russia rise and carry out these types of activities for years, so the tactics themselves did not surprise me. What surprised me, however, was to see the extent to which they focused all their efforts on Ukraine, to the point that we have not seen, at least publicly, as many Russian operations targeting other countries since. They have dedicated so many resources to Ukraine that it has come at the expense of part of their global cyber activity.
Since the release of ChatGPT at the end of 2022, there has been a lot of talk about the threat of automated cyberattacks from A to Z, without any human intervention. Is this something you’ve seen happen before?
I haven’t seen anything like this yet, but it must be said that the ransomware ecosystem, which I have been focusing on for the past year, is very different from that of nation states. A country like China, which has tens of thousands of hackers, undoubtedly has the means to deploy entire teams to try to develop fully agentic attacks, but we have not yet seen the impact on their operations.
But from the moment you are a cybercriminal motivated by profit, with a method that works, a very high success rate, are you really going to change your mind to experiment with a type of entirely agentic operation? This type of actor prefers to wait until things are further tested and approved.
However, ransomware actors have indeed begun to integrate AI, particularly in initial access. It is easier to deceive with AI, the time window between the discovery of a flaw and its exploitation is reduced, we are also seeing the emergence of zero-day attacks.
AI is also widely used by amateur criminals, those who would never have been able to carry out a successful attack yesterday. These attacks are not very sophisticated, not very effective, often the ransomware does not even work properly, you cannot decrypt the data even by purchasing a decryptor. So they continue to fail most of the time, but going from 0% to 5% success is already enormous for this type of actor.
Your intervention at the conference at Infosecurity Europe in London was focused on AI tools used in the cybercriminal environment. Can you tell us more?
We have identified four distinct categories. The first is dark LLMs, think for example of WormGPT, which has been around for a while. They present themselves as LLMs without restrictions. They can be a wrapper around DeepSeek, or something else. WormGPT, for example, would be wrapped around a Grok layer, or perhaps Mistral. They pivot from these existing models. Some are scams, others are real. We also see jailbreaking, with for example ChatGPT identifiers circulating on the Darknet, prompts to circumvent restrictions, etc.
Then, identity fraud augmented by AI is increasingly popular: phishing, voice cloning for fake calls, deepfake videos, etc. Voice clones, in particular, are so good that we are seeing more and more exchanges and transactions around them. The videos are not yet up to par, even if the progress is impressive. This includes all the ways to bypass KYC processes, identity checks that financial institutions do, etc.
Finally, there are also attacks made more powerful via AI. For example, we have identified call center services managed entirely by AI, capable of making 120 simultaneous calls in 25 different languages, and of simulating the keyboard sounds you hear in a real call center. This is a service that can be hired on the Darknet to carry out social engineering while pretending to be a real company. We have also seen some cases of AI-created malware available for sale.
Perhaps what is most striking is the speed at which this ecosystem has grown and professionalized. Many of these services now look a lot like SaaS companies, offering a free tier to attract the customer and a premium paid model. They develop and test their solutions on criminal forums, then migrate to Telegram to reach less technically sophisticated actors. Contrary to what we said earlier about amateurs using AI to carry out attacks, here we are witnessing a real professionalization of cybercrime.