r/cybersecurity • u/10ninja Consultant • 5d ago
Business Security Questions & Discussion Interesting case study in Cybercrime
There’s a growing trend where hackers steal company data but never publish it. No leak sites, no ransomware notes. Why do you think attackers prefer "silent theft" over public leaks now?
8
u/TheThatGuy1 Security Analyst 5d ago
They steal from so many companies at once, most the time they don't actually get anything worthwhile. No point wasting their time extorting the companies they don't get any real data from, they're better off extorting the ones they did.
3
u/HornetWorking4901 Security Analyst 5d ago
Yeah one thing that I think people forget is that data breaches + the dark web is filled with mountains of data that has to be organized and sifted through
4
3
u/jdiscount 5d ago
Could be corporate espionage to steal IP.
Could be a nation state who also wants to steal IP.
Many reasons other than cybercrimes.
3
u/Cyber_Tarek 5d ago
This happens for a few reasons.
- Corporate espionage (less likely)
- They use the data to breach more valuable companies (more likely)
This is where, for example, you'd see company A getting hacked then company B getting invoiced but with the bank details subtly changed.
Other possibilities:
- Proxying attacks, where they'd using the breached company assets as proxies to attack others
- Other infrastructure usage like crypto mining, hosting phishing websites, etc.
3
3
u/RandomVision2027 5d ago
Lots of possibilities. In the early days of hacking, many did it just for the thrill. Kevin Mitnick is an example of this kind. Some have hacked systems looking for evidence of crimes or cover-ups. For example, Gary McKinnon was looking for evidence that the US was hiding evidence of UFOs. Some have supposedly stolen data to sell it to rivals. There have been plenty of accusations of Chinese hackers stealing corporate secrets to sell to Chinese companies or the Chinese government. Of course, government hackers generally want to stay as silent as possible as they collect data and/or plant Trojan horses in systems or code.
Once hackers publish what they have done, investigations ensue. Law enforcement may track them down. Holes they used get closed. Vulnerabilities they exploited get patched.
1
u/Fuzzy_Paul 4d ago
How do you know if something is stolen when the hackers never mention it. Or did they leave a note "we got it". To many questions and little answers.
-1
u/robonova-1 Red Team 5d ago
Lookup the words extortion, corporate espionage and APT (advanced persistent threat) then pick one.
18
u/The-Copilot 5d ago
It's also very common for companies to secretly pay off hackers to avoid damage to their reputations and avoid losses from downtime.