riscs.org.uk
Notes from the 9th Cambridge Cybercrime Conference – Daniel Thomas
The 9th Cambridge Cybercrime Conference took place on Monday 22nd June 2026, drawing academics and industry practitioners internationally, including many researchers who have used the cyber crime datasets that the Cambridge Cybercrime Centre makes available to researchers. The most interesting talk was the keynote by the anonymous speaker, but you had to be there, I cannot tell you about it beyond: be careful out there researchers, and do not pay ransoms. The rest of the talks were public and I will highlight some of my favourite talks in this post.
Emily Kate Marie Blakseth and Tuva Heggen Thiis presented ‘How to behave in underground hacker forums: A sentiment analysis using machine learning’. This was an impressive bit of work involving manually labelling 45,000(!) reputation posts from the centre’s CrimeBB dataset and using it to train a machine learning classification that analysed 300k user profiles over 10 years. They found that the way to get a good reputation among cyber criminals was to be on your best behaviour: kindness, compassion, and generosity are key. In some ways this is not surprising, as this lesson holds for communities in general—cyber criminals are people too, and their communities are in many ways much like other communities—but this was a nice rigorous way of showing that.
Janina Eggers presented ‘A situated learning approach to learning trajectories of criminal hackers in online hacker communities’. In Situated Learning Theory (SLT), learning is a socially situated process within a community of practice involving ‘learning by doing’ alongside others already working in that area. In this interview-based study they found that cyber criminal learning is a vicarious apprenticeship. Most of the instructional materials used were initially found through Google searches on the clear web. When these learners ran into issues following tutorials that they could not fix themselves, they then asked a hacking community for help. Cyber criminals try to learn using materials intended for ethical hackers and cyber security professionals as they perceive the risk of malware on this to be much lower and they do not want to compromise their systems (though they do then use this knowledge to compromise other people’s systems). The participants found underground forums and progressed to more problematic types of cyber crime e.g., from e-whoring to CSAM blackmailing. There was a gradual escalation to more serious crime through apprenticeships with more serious cyber criminals.
My thought at the end of this was: since individuals who are trying to learn how to do cyber crime are principally relying on training content produced by the professional cyber security community, this presents us with an opportunity to influence their perceptions. What would be the most effective ways of embedding normative messaging around acceptable behaviour by people with cyber security skills within technical training content? We would need to go beyond the ‘don’t use this to do bad things’ disclaimer as that doesn’t effectively engage with the identity of the reader or the idea of learning as a socially situated process within a community of practice.
Towa Kaido and Shogo Ito presented ‘Disposable accounts, persistent ecosystem: A cross-forum study of Initial Access Brokers’, where they analysed data on initial access brokers using data from CrimeBB. I found the methodological approach used the most interesting. It involved significant careful manual annotation, then using a relatively simple model to pre-filter, before bringing in an LLM (and doing significant manual validation of the results). This seems much more robust than the common ‘hit it with an LLM hammer and who cares how much it costs or whether it works reliably’ approach.
Roy Ricaldi presented ‘Characterising external communication references in underground forums’, analysing CrimeBB data to understand how external communications are used within them. This was a nice approach for digging into an under-explored aspect of cyber crime forum operations. I’m looking forward to the full paper and the longitudinal analysis (which will be a _lot_ of work).
Sara Rubini presented ‘An application of neutralisation theory on pro-Ukrainian and pro-Russian hackers’ and my take-away was that much greater use of neutralisation techniques is required when it is harder to justify the activity (because you are engaged in an illegal war of aggression).
_**Bio** : Dr Daniel R. Thomas is a current RISCS Senior Fellow and Senior Lecturer at the University of Strathclyde where he is Director of the NCSC-certified Academic Centre of Excellence in Cyber Security Research (ACE-CSR). His research interests are in measuring security, cyber-resilience, and cyber crime so that we can monitor improvement, evaluate interventions, and inform regulators._