The a16z Podcast
The a16z Podcast

Cybercrime, Incorporated

with Joel de la Garza, Jonathan Lusthaus, and @omnivorousread Cybercrime is unfortunately as evergreen a topic as the problem itself—which is why we’re re-running this popular security episode all about the criminal industry of cybercrime from 2019. The idea of the cybercriminal as lone wolf or hobb

Featured Speakers

a16z Host

Topics Discussed

Episode Summary

Executive Summary: The episode reframes cybercrime as a mature, global industry rather than a lone-hacker problem. It traces how online value, marketplaces, specialization, and weak enforcement drove cybercrime’s professionalization, and explains how criminals now resemble legitimate tech firms in structure, branding, and labor markets. The speakers also argue that fighting cybercrime requires economic disruption, talent diversion, and better identity/security controls.

Main Topics: Cybercrime evolved from hobbyist hacking to organized industry (Priority: 5/5): The conversation explains that as valuable assets moved online in the 1990s, cybercrime shifted from isolated troublemakers to coordinated, profit-driven organizations with specialized roles and marketplaces. Markets, specialization, and firm-like structures (Priority: 5/5): Cybercriminals use trading forums, vendors, operators, and coders in ways that mirror conventional businesses; online groups often stay small due to trust/risk constraints, while offline setups can scale larger. Geographic specialization in cybercrime (Priority: 4/5): Different regions tend to supply different functions: former Soviet states often focus on malware development, Western actors on cash-out and monetization, while Nigeria and Romania are linked to distinct fraud ecosystems. Anonymity, reputation, and branding (Priority: 5/5): Nicknames function like brands in underground markets, building trust over time but also creating exposure if law enforcement or rivals connect the alias to the actor. Cybercrime’s offline roots and local trust networks (Priority: 4/5): Despite being internet-enabled, cybercrime is grounded in real-world relationships, local criminal infrastructure, and preexisting communities that help offenders coordinate and trust one another. Why enforcement alone is insufficient (Priority: 5/5): Arrests matter, but transnational jurisdiction, corruption, and enforcement limits mean disruption also needs economic pressure, better authentication, and incentives that pull talent into legitimate work. Technology shifts push criminals to adapt (Priority: 4/5): As banks improve defenses and two-factor authentication spreads, criminals pivot from account theft toward extortion, targeted ransomware, and other higher-friction tactics.

Key Arguments: Cybercrime became organized once valuable targets and payment mechanisms moved online, making profit-maximizing specialization worthwhile. Underground marketplaces created a functional division of labor similar to legitimate tech companies: coders, vendors, cash-out specialists, and managers. Trust is the central operating problem; criminals solve it through reputation, consistent aliases, social networks, and repeated trade. Cybercrime is best understood as a local phenomenon with global reach: online attacks are enabled by offline communities and physical infrastructure. There is no single cybercriminal profile; participants range from educated coders to opportunistic intermediaries and street gangs. Arrests alone cannot solve cybercrime because the ecosystem is transnational and often insulated by weak enforcement or corruption. Reducing the supply of cybercriminal talent requires creating legitimate opportunities, especially in regions with strong technical education but limited startup capital. As defenses improve, cybercriminals shift to extortion, targeted ransomware, and other tactics that exploit human and organizational weaknesses rather than just credentials.

Data Points: Shift to structured cybercrime: Mostly in the 1990s - The point when valuable assets began moving online and cybercrime became more organized and profit-driven. Rapid commercialization period: Around 1999–2000 - Chat rooms and marketplaces were flooded with stolen data, especially credit card numbers. Marketplace scale example: 20,000 credit card numbers - Illustrative quantity posted in underground marketplaces for sale and validation. Typical malware group size: 8–10 people - Suggested upper bound for many online malware operations due to trust and coordination limits. Research duration: 7 years - The amount of field research Jonathan Lusthaus said it took to study cybercriminal networks. Breach cause statistic: 93% of all breaches are spear phishing emails - Joel cites this as evidence that cybercrime is largely a secrets-management problem. Credential theft share: 80% - Within spear phishing-driven breaches, most involve straight credential theft. Ransomware pivot example: Hospitals - A Chinese group was described as focusing ransomware on hospitals because they are more likely to pay. Credit card fraud earnings: Tens of millions of dollars - Roman Seleznev and his group generated this amount through credit card fraud.

Pivotal Quotes: "it's now really a much larger, highly organized, and profit-driven organization" — Hannah: Framing the episode’s central thesis about cybercrime as an industry. "This is the quintessential Byzantine generals problem" — Jonathan Lusthaus: Describing the trust/cooperation challenge in decentralized criminal networks. "the longer you hold one of these brands, the longer you hold one of these nicknames, the more you're tied to them" — Jonathan Lusthaus: Explaining how underground reputation becomes both an asset and a liability.

Implications: For defenders, cybercrime should be treated like an adversarial business ecosystem: disrupt economics, improve authentication, track local networks, and create legitimate pathways for technical talent. Expect continued shifts toward extortion, ransomware, and hybrid offline-online crime.

🔓 Sign Up for Unlimited Episode Search

About The a16z Podcast

The a16z Podcast discusses tech and culture trends, news, and the future – especially as ‘software eats the world’. It features industry experts, business leaders, and other interesting thinkers and voices from around the world. This podcast is produced by Andreessen Horowitz (aka “a16z”), a Silicon Valley-based venture capital firm. Multiple episodes are released every week; visit a16z.com for more details and to sign up for our newsletters and other content as well!

View all episodes from The a16z Podcast