Jul 31, 2026 · 45 min · 11 segments
Ransomware continues to pose a dominant threat across the EU. Criminal actors persist in exploiting vulnerabilities in the digital supply chain and are increasingly employing social engineering…
Michel De LaetGuestGabrie RyelandHost
This is basically what we've been putting in the IOCTA year after year, and it goes without saying that as long as they want to protect this cybercriminal business model, they need to keep evolving along with, uh, law enforcement and cybersecurity, for example.

And we've seen in the past that as defenses get better, as companies have, uh, backup solutions, we saw, uh, ransomware actors moving more towards ex- uh, exfiltration of data and then just, um, if the company can get back online, good for you, but we still ask money and not to leak your data.

Similarly, we've seen, uh, that for example, uh, employees are maybe a little bit better, uh, trained for their awareness, um, against, uh, like phishing attempts.

Uh, and now we see that there's more a move towards info stealers, where the data or the credentials are being stolen from, uh, the devices, uh, let's say, against the will, uh, so the user doesn't need to input their credentials.

And we even see now, uh, some threat actors, uh, going for bribes, basically, uh, trying to get insider information from employees that sell their credentials.

And one remarkable thing we also saw in 2025 is that, um, the brands, the ransomware brands are much shorter-lived than they used to be.

Uh, I think that is partly due to successes that ran- that law enforcement has had in the past.

Now, I don't want to oversell this because clearly ransomware is still a big problem, but law enforcement has had some good successes.

We've seen like 120 different brands mentioned in messages that Europol received over the last year.

And then this evolution of ransomware is probably also accelerated, and probably is an understatement, uh, due to the advan- advancements in AI.

And now, uh, this is being leveraged by everyone, uh, in society, and cyber criminals are definitely taking, uh, very big advantage of that as well.

I would say towards the end of 2025 and early this year, we see this really accelerating, and not just in, on the low-tech side of cybercrime, but really also in, in, uh, actually leveraging these models to, to basically, uh, carry out intrusions or code malware, et cetera.

Now, uh, ransomware is, I would say, surprisingly easy to get into because this image that people have, a little bit romanticized maybe from the media of like a lone hacker or genius sitting in a basement and hacking, uh, complicated computer networks, that's a thing of the past.

It's an underground ecosystem where you can basically just buy or rent what you need.

And so you don't need to be an expert in, sometimes not even in any of these subdomains to be a successful, uh, cybercrime actor.

And what we also see is that people are working together across these cyber criminal groups a lot.

This is basically what we've been putting in the IOCTA year after year, and it goes without saying that as long as they want to protect this cybercriminal business model, they need to keep evolving along with, uh, law enforcement and cybersecurity, for example.

And we've seen in the past that as defenses get better, as companies have, uh, backup solutions, we saw, uh, ransomware actors moving more towards ex- uh, exfiltration of data and then just, um, if the company can get back online, good for you, but we still ask money and not to leak your data.

Similarly, we've seen, uh, that for example, uh, employees are maybe a little bit better, uh, trained for their awareness, um, against, uh, like phishing attempts.

Uh, and now we see that there's more a move towards info stealers, where the data or the credentials are being stolen from, uh, the devices, uh, let's say, against the will, uh, so the user doesn't need to input their credentials.

And we even see now, uh, some threat actors, uh, going for bribes, basically, uh, trying to get insider information from employees that sell their credentials.

And one remarkable thing we also saw in 2025 is that, um, the brands, the ransomware brands are much shorter-lived than they used to be.

Uh, I think that is partly due to successes that ran- that law enforcement has had in the past.

Now, I don't want to oversell this because clearly ransomware is still a big problem, but law enforcement has had some good successes.

We've seen like 120 different brands mentioned in messages that Europol received over the last year.

And then this evolution of ransomware is probably also accelerated, and probably is an understatement, uh, due to the advan- advancements in AI.

And now, uh, this is being leveraged by everyone, uh, in society, and cyber criminals are definitely taking, uh, very big advantage of that as well.

I would say towards the end of 2025 and early this year, we see this really accelerating, and not just in, on the low-tech side of cybercrime, but really also in, in, uh, actually leveraging these models to, to basically, uh, carry out intrusions or code malware, et cetera.

Now, uh, ransomware is, I would say, surprisingly easy to get into because this image that people have, a little bit romanticized maybe from the media of like a lone hacker or genius sitting in a basement and hacking, uh, complicated computer networks, that's a thing of the past.

It's an underground ecosystem where you can basically just buy or rent what you need.

And so you don't need to be an expert in, sometimes not even in any of these subdomains to be a successful, uh, cybercrime actor.

And what we also see is that people are working together across these cyber criminal groups a lot.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.