Our free webinar on network security will take place on 17.06.2025 at 16:00. Find out more now.

+ 0 Security scans
make the DEFENDERBOX trustworthy.

From ransomware to returns

How cyber criminals become investors!

Cybercrime has grown up.

Long gone are the days when online criminals spent their loot on luxury cars, expensive watches or parties in Dubai. Today, many criminals are thinking long-term — and surprisingly business-like.

A recent analysis by Sophos X‑Ops shows that proceeds from ransomware, phishing or business email compromise attacks are increasingly flowing into real companies.

The goal: an inconspicuous but effective entry into the world of the legal economy — using all means of camouflage and professionalism.

Our recommendation at DEFENDERBOX:

We help to distinguish the real players from the fake ones. Because cybercrime has become more professional. It’s high time our response was too.

What makes the DEFENDERBOX so special?

  • Plug & PlaySimply connect — done. No IT knowledge or project required.
  • Automated detection of security vulnerabilitiesInside & outside, around the clock.
  • Compact all-rounderRecognizes risks before attacks occur.
  • Transparent reportsClear and prioritized recommendations for action in the event of exploitable security gaps — for greater security.

Now to the Familiarization price test.

Business plans instead of botnets

The modern cybercrime generation no longer looks like the old hacker movies: no hoodies in dark basements, but business suits, pitch decks and AI. The perpetrators act with real entrepreneurial discipline:

  • Business plans: well thought out, professionally presented
  • Structure: Clear allocation of roles, operational processes
  • Channels: Contact via WhatsApp Business, Telegram or LinkedIn
  • Locations: Investments in countries with a stable legal system — e.g. Switzerland, USA


At first glance, the whole thing looks legal — but it is often only legal in formal terms. Because in the background, criminally generated funds are laundered, disguised or simply “rededicated”.

What is being invested in?

Cyber criminals are now diversifying their portfolios in a similar way to traditional investors. Particularly popular:

IT companies: Not just because they are profitable — but because they offer access to know-how, infrastructure and customer contacts. Some perpetrators specifically buy into start-ups, others set up their own.

Real estate and precious metals: A perennial favorite for investing money — ideal for parking large sums inconspicuously.

Educational initiatives & coding schools: Cynical, but real: by investing in training, the perpetrators secure access to talent — and build up long-term structures.

Gastronomy and retail: Cash-intensive sectors in particular are ideal for concealing the origin and volume of sales.

The perfect double: criminal & entrepreneur

What used to be done via letterbox companies in offshore areas is now done with a more modern touch: start-up mentality, investor events, LinkedIn profiles.

The perpetrators learn from the real business world — and skillfully exploit its mechanisms. Legality is often just a facade.

What does this mean for IT security?

The analysis clearly shows: Cybersecurity does not end at the firewall.

We need to think further — beyond the code, the malware and the phishing mail. If you want to understand how modern cybercrime networks work, you also have to look at the economic and social dynamics behind them.

What to do?

  • Promote education: in companies, schools and public authorities
  • Check suspicious business models: also in the context of investments and partnerships
  • Sensitize partners: not only technically, but also economically
  • Conduct digital due diligence: especially in the channel environment


Conclusion: When cybercriminals play investor, the security community needs a better look behind the scenes.

DEFENDERBOX unterstützt seine Kunden und Partner not only with technical security expertise, but also with the necessary intuition for new forms of digital threat — from attacks to start-up financing.

Ihre Cybersicherheit ist unser Auftrag! Automatisiertes Pentesting — höchster Managed Security Service speziell für den Mittelstand.

 

Do you want to know how secure your company is?

Try it out! Click here for a test installation of DEFENDERBOX. The trial offer has been extended until June 30, 2025!

Managed Security Service
en_USEN
Cookie Consent with Real Cookie Banner