
How initial access offers power intrusions and ransomware
Initial access brokers (IABs) sell access to compromised organizations on underground forums. Here's an analysis looking at whether these offers can be correlated to ransomware attacks.
Ransomware attacks have sharply increased in 2023, and payments to ransomware gangs and affiliates are nearing all-time highs. With law enforcement and governments sharply focused on disrupting and imposing costs on ransomware groups, why is ransomware stubbornly sticking around?
In this edition of Studio 471, Jacqueline Burns Koven of Chainalysis discusses how ransomware is evolving and what challenges it poses for defenders.
Participants:
Jacqueline Burns Koven, Head of Cyber Threat Intelligence, Chainalysis
Jeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471
Initial access brokers (IABs) sell access to compromised organizations on underground forums. Here's an analysis looking at whether these offers can be correlated to ransomware attacks.
The disruption of the XSS cybercrime forum and arrest of its administrator in Ukraine in July 2025 has shook Russian-speaking cybercriminal communities to their core and raised questions if the forum can recover.
The Lumma infostealer malware collects highly sensitive data including logins and session tokens. Here's how to conduct a threat hunt leveraging up-to-date tactics, techniques and procedures used by Lumma.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.