ICAEW's latest piece nails why Crime as a Service is the business model that should worry you most

Started by EventHorizon27, Jul 29, 2026, 11:20 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: ICAEW's latest piece nails why Crime as a Service is the business model that should worry you most   Views(Read 99 times)

EventHorizon27

ICAEW ran a good explainer this month on Crime as a Service, the idea that illegal operations have started copying legitimate Software as a Service methodology almost exactly, and the argument is that AI is now supercharging that model rather than creating an entirely new threat from scratch

What makes CaaS genuinely dangerous compared to old school hacking is the division of labour, you no longer need deep technical skill to run a ransomware campaign or a phishing operation, you just rent the tooling from someone else who built it, the same way any legitimate business rents cloud infrastructure instead of building a data centre

AI slots into that model at almost every stage, better phishing copy that reads naturally instead of the broken English that used to be a red flag, deepfake voice and video convincing enough to pass casual verification checks, and malware that can be tweaked and iterated faster than defenders can catalogue new signatures

The professionalisation angle is what really separates this from the cybercrime of a decade ago, these operations increasingly look like actual SaaS companies internally, support channels, tiered pricing, even customer service for the criminals renting the tools, which tells you the market has matured well past chaotic amateur hour

None of this needs nation state resources anymore, that's really the core warning, a barrier to entry that used to require serious technical investment has collapsed to the point where renting or prompting your way into sophisticated criminal capability is realistic for far more people than it used to be

The uncomfortable conclusion is that defenders are stuck playing the same catch up game they always have, except the pace has changed, tools that used to take criminal groups months to develop and refine now iterate on a timeline measured in weeks

IronQuarry48

The SaaS analogy is uncomfortably accurate, ransomware gangs genuinely run affiliate programs with revenue splits now, it really is just a business model wearing a criminal mask
Posted from a machine that definitely needs a clean install

Depot76

Renting sophisticated capability instead of needing to build it yourself is exactly what lowered the barrier for legitimate startups too, funny how the same economic logic applies on both sides of the law

Delulu67

The phishing quality point matters more than people give it credit for, broken English used to be free training for spotting scams and that signal is basically gone now

FridayFeeling

Deepfake voice bypassing casual verification is the one that worries me most personally, so much authentication still just relies on someone sounding like themselves on a phone call

Ronan76

Curious whether accountants and auditors specifically are a bigger target now given how much of this piece is aimed at ICAEW's own membership, feels like a pointed audience choice
Trained so hard the GPU asked for a break

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer