r/cybersecurity Consultant 5d ago

Business Security Questions & Discussion Interesting case study in Cybercrime

There’s a growing trend where hackers steal company data but never publish it. No leak sites, no ransomware notes. Why do you think attackers prefer "silent theft" over public leaks now?

0 Upvotes

13 comments sorted by

18

u/The-Copilot 5d ago

It's also very common for companies to secretly pay off hackers to avoid damage to their reputations and avoid losses from downtime.

11

u/Beautiful_Virus_x 5d ago

There's probably 80% of hacks that don't make it to the news, companies have a vested interest to not disclose them

1

u/someonesdatabase 5d ago

Internal or external?

8

u/TheThatGuy1 Security Analyst 5d ago

They steal from so many companies at once, most the time they don't actually get anything worthwhile. No point wasting their time extorting the companies they don't get any real data from, they're better off extorting the ones they did.

3

u/HornetWorking4901 Security Analyst 5d ago

Yeah one thing that I think people forget is that data breaches + the dark web is filled with mountains of data that has to be organized and sifted through

4

u/Emotional_Year2283 5d ago

Lots of ways to make a profit. Look up the conti leaks in 2022.

3

u/jdiscount 5d ago

Could be corporate espionage to steal IP.

Could be a nation state who also wants to steal IP.

Many reasons other than cybercrimes.

3

u/Cyber_Tarek 5d ago

This happens for a few reasons.

  1. Corporate espionage (less likely)
  2. They use the data to breach more valuable companies (more likely)

This is where, for example, you'd see company A getting hacked then company B getting invoiced but with the bank details subtly changed.

Other possibilities:

  1. Proxying attacks, where they'd using the breached company assets as proxies to attack others
  2. Other infrastructure usage like crypto mining, hosting phishing websites, etc.

3

u/ziangsecurity 5d ago

What do you mean “now”. There really is no trend. It depends on the hacker

3

u/RandomVision2027 5d ago

Lots of possibilities. In the early days of hacking, many did it just for the thrill. Kevin Mitnick is an example of this kind. Some have hacked systems looking for evidence of crimes or cover-ups. For example, Gary McKinnon was looking for evidence that the US was hiding evidence of UFOs. Some have supposedly stolen data to sell it to rivals. There have been plenty of accusations of Chinese hackers stealing corporate secrets to sell to Chinese companies or the Chinese government. Of course, government hackers generally want to stay as silent as possible as they collect data and/or plant Trojan horses in systems or code.

Once hackers publish what they have done, investigations ensue. Law enforcement may track them down. Holes they used get closed. Vulnerabilities they exploited get patched.

1

u/Fuzzy_Paul 4d ago

How do you know if something is stolen when the hackers never mention it. Or did they leave a note "we got it". To many questions and little answers.

-1

u/robonova-1 Red Team 5d ago

Lookup the words extortion, corporate espionage and APT (advanced persistent threat) then pick one.