At Black Hat 2026 Derek Manky of Fortinet FortiGuard Labs, chief security strategist and global vice president of threat intelligence, discusses Fortinet's Cybercrime Bounty initiative with Crime Stoppers International, the Cybercrime Atlas project and partnerships with the International Criminal Police Organization, INTERPOL. Krista Case of theCUBE Research hosts the conversation. Manky examines attribution, methods for unmasking dark web actors, the role of artificial intelligence, AI, in accelerating attacks, operationalizing anonymous tips and building a scalable trusted crowdsourced intelligence model.
Key insights include that fewer than 1% of cybercrimes receive prosecution, creating the need for scaled anonymous reporting and stronger accountability. Manky notes that Fortinet validates, correlates and packages submitted intelligence to make tips actionable for law enforcement via Project Gateway and partner networks. The Cybercrime Atlas supports over 2,000 arrests and helps recover roughly $200 million, demonstrating that collaborative intelligence-driven operations enable takedowns and deterrence. Watch the full conversation to learn practical frameworks for collaboration among the private sector, non-governmental organizations and law enforcement.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Derek Manky, Fortinet FortiGuard Labs
At Black Hat 2026 Derek Manky of Fortinet FortiGuard Labs, chief security strategist and global vice president of threat intelligence, discusses Fortinet's Cybercrime Bounty initiative with Crime Stoppers International, the Cybercrime Atlas project and partnerships with the International Criminal Police Organization, INTERPOL. Krista Case of theCUBE Research hosts the conversation. Manky examines attribution, methods for unmasking dark web actors, the role of artificial intelligence, AI, in accelerating attacks, operationalizing anonymous tips and building a scalable trusted crowdsourced intelligence model.
Key insights include that fewer than 1% of cybercrimes receive prosecution, creating the need for scaled anonymous reporting and stronger accountability. Manky notes that Fortinet validates, correlates and packages submitted intelligence to make tips actionable for law enforcement via Project Gateway and partner networks. The Cybercrime Atlas supports over 2,000 arrests and helps recover roughly $200 million, demonstrating that collaborative intelligence-driven operations enable takedowns and deterrence. Watch the full conversation to learn practical frameworks for collaboration among the private sector, non-governmental organizations and law enforcement.
Chief Security Strategist and Global VP of Threat IntelligenceFortinet FortiGuard Labs
search
Krista Case
>> Welcome back to theCUBE's live coverage of Black Hat 2026. I'm Krista Case, and we're hearing a lot about the adversarial perspective these days and really how cybercrime has become this global criminal ecosystem. These attackers are collaborating across borders. They're adapting and operating more quickly than ever before with the help of AI. And at the same time, our ability to hold them accountable has become very difficult. And what this does is it means that they're not disrupted in terms of their operating costs. Their criminal networks continue to function. So this is certainly a problem that we're looking to hopefully address as an industry. I have the pleasure of sitting down today with Derek Manky, who's the chief security strategist and global VP of threat intelligence with Fortinet. Derek, thank you so much for joining us today.
Derek Manky
>> Thank you so much. It's great to be back on theCUBE.
Krista Case
>> Yes.Yeah, great to have you back and welcome back to Black Hat. We were just saying before we came on camera, you've been attending since what,
Derek Manky
>> 2008?2008,
Krista Case
>> yes.Caesars Palace,
Derek Manky
>> right?Yes, a long time ago. So the conference itself has changed, but the threat landscape has changed a lot, just as you were saying in the intro as
Krista Case
>> well.Absolutely, and I know there's a lot to dig into, especially with the cybercrime, Derek. So maybe you could talk a little bit about this, Cybercrime Bounty initiative that Fortinet launched. So maybe can you talk a little bit about what it is and also maybe why Fortinet chose to start it and what were some of the gaps that you saw in the industry that you wanted to address with it?
Derek Manky
>> SureI think a lot of the reason is what you're talking about or what we were talking about initially is that especially if you compare the last 15, 20 years, it's a formula. We know as the attack surface grows, attackers are gonna capitalize on that. We do mapping of the cybercriminal ecosystem, and it's not just your standard threat intelligence now, it's the human intelligence, right? We know that cybercriminals are converging their groups. They're working with nation-state APT. They're also launching crime services that continue to fuel the third largest GDP in the world, which is cybercrime. Just think about that for a second. The reality is that while cybercrime is growing, us, the blue team and defenders, we're constantly on the defense. So the idea and the gaps that we're trying to solve is to really focus on the human intelligence. And that's why we launched the CyberCrime Bounty Program with Crime Stoppers International, was really to look at that human aspect, to do the attribution, which is the toughest thing to do in the world of threat intelligence. If we don't go after the threat actors themselves for arrests and prosecutions, the problem is just going to snowball and it's going to get worse.
Krista Case
>> Absolutely, absolutely.
Derek Manky
>> So yeah, I was just going to say, with CyberCrime Bounty, the reason we launched this was to actually create— to leverage Crime Stoppers International. They have a trusted anonymous platform that's worked on physical crimes since 1976. It did not have a cybercrime element to it, so it was a perfect opportunity. It's an industry first. We've launched the program, we've operationalized it, launched the first bounty called Operation Silent Vector 1.
Krista Case
>> That's really exciting. And you kind of talked aboutthis concept that it's anonymous, right? So I'm wondering, if somebody submits an anonymous tip, how does, I guess, the program or Fortinet, how do you help make that information actionable for law enforcement?
Derek Manky
>> So yeah, this is the other piece of the puzzle. We've done a lot of work, Fortinet has. We have great partnerships with INTERPOL through Project Gateway. The industry needs to do more. It's a great example of collaboration. Law enforcement has resources, the industry, cybersecurity, we have resources. Those resources can be limited, so the idea is to team up, and this is what we've done with the platform. We're trying to unmask the dark web, right? It really takes OSINT, human intelligence, to do that legwork up front through the Crime Stoppers anonymous platform. Fortinet, with the launch of this platform and partnership, we're verifying that data. Because traditionally, tips and leads like that will go direct to law enforcement. Some of them are dead ends, some of them are false positives. That can put a big strain on law enforcement resources. So again, that's the idea of what we're trying to do. When a submitter, an anonymous submitter, submits a tip related to whatever bounty's posted, we step in to fuse that data. So we correlate it, we verify it, we package it, and then pass it to law enforcement so it makes their job easier, and then we can start to scale with that.
Krista Case
>> Absolutely. That makes sense.
Derek Manky
>> Yeah.
Krista Case
>> And I know that it's also part of this broader effort. You and I were talking before we went on camera that there is the Cybercrime Atlas. There's potentially support for INTERPOL operations. Can you give the audience a little bit of additional context on some of that?
Derek Manky
>> Yeah, we have found— so Cybercrime Atlas is a great project. We launched that 3 years ago, and that's another project where we have an ecosystem of over 70 volunteers working together, weekly meetings to map the cybercriminal ecosystem and then disrupt it. So this is focused on looking not only at botnets and malware and ransomware, but the movers behind that. So crypto, cryptocurrency, crypto wallet addresses. We have subject matter experts from the crypto space, from the threat research space, all coming together. And it's been a success. That initiative has led, working with INTERPOL and other law enforcement partners, to over 2,000 arrests, about $200 million US recovered. To victims, which is very encouraging. Now, there's a lot more work to be done, but that model has shown we can have success. We need to grow it at scale. And that's very encouraging for Cybercrime Bounty, where we're trying to open that up into the broader public now for crowdsourcing information that can lead to, incentives and monetary rewards.
Krista Case
>> Absolutely. And can you maybe talk through what that might look like? Like you say, open sourcing and crowdsourcing it. If I might put you on the spot to speculate a little bit, what might that look like?
Derek Manky
>> Yeah. So this is, again, if you look at communities like Atlas, that's a closed community. It's not closed, actually, I should say it's open. It's a limited community. It's a trusted community, that we've built over time. And that's a fantastic initiative. With Cybercrime Bounty, this is opening up at global scale. They have 800 chapters worldwide that have been built. So the network and the infrastructure is there. So that means anybody who might know something about a hacker, they could be a grey hat, they could be communicating with them on the dark web, they might know somebody just in the real world, Or they might not, they might have been able to analyze a certain case that's happening with, let's say, ransomware or that target that's been posted. So, what we're trying to do is really open those channels into a broader scale because, as I said, the reality is less than 1% of cybercrimes are prosecuted. We need to get that number higher. This is how we do it through scale. And it all sits with this trusted anonymous reporting nature.
Krista Case
>> Absolutely. And then, you were saying a couple of minutes ago, Fortinet is taking the effort to validate that information. So even if it is anonymous— submitted anonymously, I should say— it's known to be trusted.
Derek Manky
>> Correct. Exactly. That's the idea. Trusted. And then also to correlate data with our own threat intelligence, right? Because we sit on trillions of events coming in a day. And if we can add pieces to the puzzle from a new piece that's coming in, that makes it very powerful for law enforcement and their operations.
Krista Case
>> Absolutely. And it's a great point about Fortinet's threat intelligence. And it leads me to another thing that I'm curious about, Derek. So you said that basically this was previously kind of a program for physical crime, and now obviously this is the first year that it's been for cybercrime. Can you talk through some of the unique challenges of cybercrime, especially compared to physical attacks? And I'm thinking in particular through the lens of these AI-driven attacks. They're moving more quickly. I'm sure that's created some challenges especially when we talk about, like you say, correlating and validating the information.
Derek Manky
>> Correct. Yeah. So I think one of the biggest challenges, especially with adversarial AI now, first of all, the attacks are— it's a different scale because with physical crime, you're talking about complete human networks. There's only so many humans in the world. When you talk about cybercrime, you're talking about artifacts, you're talking about safe havens and storage and all these different indicators that can lead to these virtual campaigns, virtual groups and communities coming together. And agents now. So not real humans, but agents, shadow agents we call them, coming on. That's the challenge. How do you distinguish between a shadow agent and the human? And these are all the things why it's actually important to do that human intelligence and map that. So that's a challenge. So that window of attack is moving to under 20 hours right now. That's how fast attackers are moving. And the other thing I should say is that we're noticing is that there's— and this is something that Crime Stoppers has been focused on, Crime Stoppers International, and we're focused on with the program is converged crime. So we're starting with cybercrime, but more and more we're seeing cybercrime tied to human trafficking, to scam farms, to narcotics and drug trade. It's becoming a very real thing today, and that's the horizon that we're looking at.
Krista Case
>> It's far beyond a business being taken down. It's far beyond just a ransom for data and a ransomware attack. It has actual implications, like you say, for human lives potentially.
Derek Manky
>> Absolutely, and that's absolutely real. So, we've started now with the first bounty, Operation Silent Vector 1, which was posted. That's on ransomware because that's a real thing that obviously we've been talking about for decades, we're trying to solve. But the door is open, right, to looking at all these other challenges that we want to tackle.
Krista Case
>> And I'm wondering if you can talk about maybe some of the different types of attacks that you might anticipate moving forward, based on the years of experience that you have with the program?
Derek Manky
>> Yeah, so this is the exciting part. We've seen success with operations we've done in the past, like with INTERPOL, with Cybercrime Atlas, and now with Cybercrime Bounty. It's very exciting. This is an industry first. We're just getting started. We've reached a significant milestone by launching Operation Silent Vector 1. If I look a year from now in the future, it's going to be looking at building that community. When I say community, getting more— so it's different roles. You have the bounty posters, and they could be someone who has been attacked or has a certain target they want to go after. And then the submitters. And these submitters, they're— it's not meant to be victims of fraud or ransomware. It's meant to be actual researchers. So we want to be able to expose it, open up the channels more, have more bounties posted, grow that community, and bring other intelligence. Not— so Fortinet has founded this with Crime Stoppers International, but we want to also bring more intelligence subject matter expertise into a fusion center where we can just really, truly operate at scale and get that number higher than that less than 1% prosecutions we're seeing.
Krista Case
>> So this fusion center, it'd be Fortinet with other companies collaborating, like you say, and there is research, potentially ethical hacking. Maybe I'm speculating a little bit.
Derek Manky
>> Correct. Yes. Yeah. So still with Crime Stoppers platform, that's the trusted anonymous platform.
Krista Case
>> Yes.
Derek Manky
>> But then building on that to have more points of view from threat intelligence because that's just going to make the vetting process easier. It's going to make the, the linkages and enhance the chances of having higher, even higher confidence on attribution, the human intelligence angle, which is something we're trying to solve. So that's the goal, a year from now. And then obviously the other piece of that is looking at the operational actionable results, right? So the whole reason we're doing this, going back to the start of our conversation, is to provide accountability That's a big piece to let cybercriminals know that their actions are not going to go unnoticed or unheard or unactioned. And the other piece we don't talk about enough is the deterrence, right? By doing that and by posting these bounties, adding an element of fear. And to me, that also means youth, right? Because we have a big problem of youth getting into cybercrime and we want to also be able to educate and curb that as well.
Krista Case
>> Yeah, there will be, a repercussion if they do choose to engage in this behavior, for lack of a better way to put it.
Derek Manky
>> Absolutely.
Krista Case
>> It's a great point. And maybe you can even elaborate a little bit further. I know we've talked about why accountability is important, but I really want to just sort of underscore that for our audience because I think it's an important point here.
Derek Manky
>> Yeah. Yeah. So accountability has been, again, if we look at it, it's been a drop in the bucket when it comes to, there's been a lot of good initiatives, but if you look at the amount of people that are getting into these cybercrime rings, a lot of them are doing it on a, on a knowing basis. They know what they're getting into, but there's no element of fear. And if you don't have accountability and examples that, just because they don't think they're a major player in a cybercrime ring that they're invincible, That's an issue. So that's what we're going after. For example, if we look at these cybercrime rings, it's often perceived that only the kingpin, the malicious CEO of these criminal organizations, is going to be sought after, right, when it comes to bringing them to justice. There's examples where that hasn't been the case, and we need to build on that. So you look at affiliates, right, people that, the middle layer network that are getting commissions to spread ransomware, ransomware as a service. That's the cash cow that's fueling these operations. And those operations also need to be held accountable where traditionally they have not. So again, by going after all aspects of that ecosystem, it starts to close the door of that invincible feeling, that, cybercriminals can have.
Krista Case
>> They're no longer operating in the dark. And also, like you say, it's holding everyone involved accountable versus just sort of that kingpin, that's going to deter them from potentially joining that organization and engaging in that behavior.
Derek Manky
>> Absolutely. Absolutely. And I like what you said, not only operating in the dark, because that is the other challenge, right? They have safe havens, they have shadows. We're exposing that. It's actually what we've been saying with Operation Silent Vector 1 is our goal is to unmask the dark. That's the goal of the operation. It's lifting that, shining light on it, applying as much threat intelligence with confidence to really bring those to justice and to identify who they are.
Krista Case
>> And Derek, I know you talked a little bit already about this, but I wanted to really put a finer point on it as well because I think it's a really important point. So what are— so it sounds like a lot of kind of the further community involvement and kind of the further traction with the Cybercrime Bounty initiative. But based on what you've already seen over the past year and as you reflect over the year ahead, what are some of those key metrics that you wanted to really make sure to leave our audience with as they're thinking about this program?
Derek Manky
>> Yeah, I think some of the key metrics are look out for more updates on new operations. We've launched Operation Silent Vector 1. That's the first one. So look for new additions to that series beyond just the initial target. Look for actionable operational updates as we proceed, right? We'll be definitely putting out updates as we go along. To also look at key metrics at the broader ecosystem. So number of arrests, threat actors that have been identified, brought to justice behind those campaigns. That's the goal. The goal here isn't to boil the ocean because we can't do that when it comes to cybercrime, but to start specifically on some of these needle movers, right? On some of these groups that are causing significant damage and do something that resonates with these organizations that are consistently being hit with ransomware. That's precisely the idea that we're going after.
Krista Case
>> And it's going to be even more important, like we've been talking about, especially as AI just makes it easier to get into cybercrime and also accelerates the pace that they move as well.
Derek Manky
>> Yeah. And I think near term— so we're talking about a year from now. If I were to think 5 to 10 years from now, that bigger picture, it's really looking at the dashboard, right? So we talk about cybercrime being the third largest GDP in the world. Why is that? How has it flourished into such a large operation? It's because accountability hasn't been there over the years, not enough anyway. It has been, but not in enough measure. So can we start to curb the growth and see some noticeable impact on that? Those are all the things we're going to be tracking and looking at on the long-term horizon. Obviously getting the prosecutions up higher as well, the number of arrests that we're doing. And it's not just arrests, by the way, it's all of that combined. It's infrastructure takedown. You can't just arrest people, but you can't just take infrastructure down. You need to do all of it holistically together.
Krista Case
>> That holistic approach to remediation.
Derek Manky
>> YepYeah, absolutely. And that's why, again, we have various initiatives, they all come together to form that holistic approach, right, between INTERPOL and law enforcement and Gateway work we've been doing, Cybercrime Atlas, Cybercrime Bounty, which is the latest one, which I'm very excited about as well.
Krista Case
>> Absolutely. Well, Derek, thanks so much for sitting down with us today. Really interesting research. And again, thank you so much for joining.
Derek Manky
>> It's a pleasure to be here.
Krista Case
>> Yeah, absolutely. And thank you so much to our audience for listening. We'll be right back in just a few minutes with more coverage live here from Black Hat 2026. Again, this is Krista Case at theCUBE. Thank you.
>> Welcome back to theCUBE's live coverage of Black Hat 2026. I'm Krista Case, and we're hearing a lot about the adversarial perspective these days and really how cybercrime has become this global criminal ecosystem. These attackers are collaborating across borders. They're adapting and operating more quickly than ever before with the help of AI. And at the same time, our ability to hold them accountable has become very difficult. And what this does is it means that they're not disrupted in terms of their operating costs. Their criminal networks continue to function. So this is certainly a problem that we're looking to hopefully address as an industry. I have the pleasure of sitting down today with Derek Manky, who's the chief security strategist and global VP of threat intelligence with Fortinet. Derek, thank you so much for joining us today.
Derek Manky
>> Thank you so much. It's great to be back on theCUBE.
Krista Case
>> Yes.Yeah, great to have you back and welcome back to Black Hat. We were just saying before we came on camera, you've been attending since what,
Derek Manky
>> 2008?2008,
Krista Case
>> yes.Caesars Palace,
Derek Manky
>> right?Yes, a long time ago. So the conference itself has changed, but the threat landscape has changed a lot, just as you were saying in the intro as
Krista Case
>> well.Absolutely, and I know there's a lot to dig into, especially with the cybercrime, Derek. So maybe you could talk a little bit about this, Cybercrime Bounty initiative that Fortinet launched. So maybe can you talk a little bit about what it is and also maybe why Fortinet chose to start it and what were some of the gaps that you saw in the industry that you wanted to address with it?
Derek Manky
>> SureI think a lot of the reason is what you're talking about or what we were talking about initially is that especially if you compare the last 15, 20 years, it's a formula. We know as the attack surface grows, attackers are gonna capitalize on that. We do mapping of the cybercriminal ecosystem, and it's not just your standard threat intelligence now, it's the human intelligence, right? We know that cybercriminals are converging their groups. They're working with nation-state APT. They're also launching crime services that continue to fuel the third largest GDP in the world, which is cybercrime. Just think about that for a second. The reality is that while cybercrime is growing, us, the blue team and defenders, we're constantly on the defense. So the idea and the gaps that we're trying to solve is to really focus on the human intelligence. And that's why we launched the CyberCrime Bounty Program with Crime Stoppers International, was really to look at that human aspect, to do the attribution, which is the toughest thing to do in the world of threat intelligence. If we don't go after the threat actors themselves for arrests and prosecutions, the problem is just going to snowball and it's going to get worse.
Krista Case
>> Absolutely, absolutely.
Derek Manky
>> So yeah, I was just going to say, with CyberCrime Bounty, the reason we launched this was to actually create— to leverage Crime Stoppers International. They have a trusted anonymous platform that's worked on physical crimes since 1976. It did not have a cybercrime element to it, so it was a perfect opportunity. It's an industry first. We've launched the program, we've operationalized it, launched the first bounty called Operation Silent Vector 1.
Krista Case
>> That's really exciting. And you kind of talked aboutthis concept that it's anonymous, right? So I'm wondering, if somebody submits an anonymous tip, how does, I guess, the program or Fortinet, how do you help make that information actionable for law enforcement?
Derek Manky
>> So yeah, this is the other piece of the puzzle. We've done a lot of work, Fortinet has. We have great partnerships with INTERPOL through Project Gateway. The industry needs to do more. It's a great example of collaboration. Law enforcement has resources, the industry, cybersecurity, we have resources. Those resources can be limited, so the idea is to team up, and this is what we've done with the platform. We're trying to unmask the dark web, right? It really takes OSINT, human intelligence, to do that legwork up front through the Crime Stoppers anonymous platform. Fortinet, with the launch of this platform and partnership, we're verifying that data. Because traditionally, tips and leads like that will go direct to law enforcement. Some of them are dead ends, some of them are false positives. That can put a big strain on law enforcement resources. So again, that's the idea of what we're trying to do. When a submitter, an anonymous submitter, submits a tip related to whatever bounty's posted, we step in to fuse that data. So we correlate it, we verify it, we package it, and then pass it to law enforcement so it makes their job easier, and then we can start to scale with that.
Krista Case
>> Absolutely. That makes sense.
Derek Manky
>> Yeah.
Krista Case
>> And I know that it's also part of this broader effort. You and I were talking before we went on camera that there is the Cybercrime Atlas. There's potentially support for INTERPOL operations. Can you give the audience a little bit of additional context on some of that?
Derek Manky
>> Yeah, we have found— so Cybercrime Atlas is a great project. We launched that 3 years ago, and that's another project where we have an ecosystem of over 70 volunteers working together, weekly meetings to map the cybercriminal ecosystem and then disrupt it. So this is focused on looking not only at botnets and malware and ransomware, but the movers behind that. So crypto, cryptocurrency, crypto wallet addresses. We have subject matter experts from the crypto space, from the threat research space, all coming together. And it's been a success. That initiative has led, working with INTERPOL and other law enforcement partners, to over 2,000 arrests, about $200 million US recovered. To victims, which is very encouraging. Now, there's a lot more work to be done, but that model has shown we can have success. We need to grow it at scale. And that's very encouraging for Cybercrime Bounty, where we're trying to open that up into the broader public now for crowdsourcing information that can lead to, incentives and monetary rewards.
Krista Case
>> Absolutely. And can you maybe talk through what that might look like? Like you say, open sourcing and crowdsourcing it. If I might put you on the spot to speculate a little bit, what might that look like?
Derek Manky
>> Yeah. So this is, again, if you look at communities like Atlas, that's a closed community. It's not closed, actually, I should say it's open. It's a limited community. It's a trusted community, that we've built over time. And that's a fantastic initiative. With Cybercrime Bounty, this is opening up at global scale. They have 800 chapters worldwide that have been built. So the network and the infrastructure is there. So that means anybody who might know something about a hacker, they could be a grey hat, they could be communicating with them on the dark web, they might know somebody just in the real world, Or they might not, they might have been able to analyze a certain case that's happening with, let's say, ransomware or that target that's been posted. So, what we're trying to do is really open those channels into a broader scale because, as I said, the reality is less than 1% of cybercrimes are prosecuted. We need to get that number higher. This is how we do it through scale. And it all sits with this trusted anonymous reporting nature.
Krista Case
>> Absolutely. And then, you were saying a couple of minutes ago, Fortinet is taking the effort to validate that information. So even if it is anonymous— submitted anonymously, I should say— it's known to be trusted.
Derek Manky
>> Correct. Exactly. That's the idea. Trusted. And then also to correlate data with our own threat intelligence, right? Because we sit on trillions of events coming in a day. And if we can add pieces to the puzzle from a new piece that's coming in, that makes it very powerful for law enforcement and their operations.
Krista Case
>> Absolutely. And it's a great point about Fortinet's threat intelligence. And it leads me to another thing that I'm curious about, Derek. So you said that basically this was previously kind of a program for physical crime, and now obviously this is the first year that it's been for cybercrime. Can you talk through some of the unique challenges of cybercrime, especially compared to physical attacks? And I'm thinking in particular through the lens of these AI-driven attacks. They're moving more quickly. I'm sure that's created some challenges especially when we talk about, like you say, correlating and validating the information.
Derek Manky
>> Correct. Yeah. So I think one of the biggest challenges, especially with adversarial AI now, first of all, the attacks are— it's a different scale because with physical crime, you're talking about complete human networks. There's only so many humans in the world. When you talk about cybercrime, you're talking about artifacts, you're talking about safe havens and storage and all these different indicators that can lead to these virtual campaigns, virtual groups and communities coming together. And agents now. So not real humans, but agents, shadow agents we call them, coming on. That's the challenge. How do you distinguish between a shadow agent and the human? And these are all the things why it's actually important to do that human intelligence and map that. So that's a challenge. So that window of attack is moving to under 20 hours right now. That's how fast attackers are moving. And the other thing I should say is that we're noticing is that there's— and this is something that Crime Stoppers has been focused on, Crime Stoppers International, and we're focused on with the program is converged crime. So we're starting with cybercrime, but more and more we're seeing cybercrime tied to human trafficking, to scam farms, to narcotics and drug trade. It's becoming a very real thing today, and that's the horizon that we're looking at.
Krista Case
>> It's far beyond a business being taken down. It's far beyond just a ransom for data and a ransomware attack. It has actual implications, like you say, for human lives potentially.
Derek Manky
>> Absolutely, and that's absolutely real. So, we've started now with the first bounty, Operation Silent Vector 1, which was posted. That's on ransomware because that's a real thing that obviously we've been talking about for decades, we're trying to solve. But the door is open, right, to looking at all these other challenges that we want to tackle.
Krista Case
>> And I'm wondering if you can talk about maybe some of the different types of attacks that you might anticipate moving forward, based on the years of experience that you have with the program?
Derek Manky
>> Yeah, so this is the exciting part. We've seen success with operations we've done in the past, like with INTERPOL, with Cybercrime Atlas, and now with Cybercrime Bounty. It's very exciting. This is an industry first. We're just getting started. We've reached a significant milestone by launching Operation Silent Vector 1. If I look a year from now in the future, it's going to be looking at building that community. When I say community, getting more— so it's different roles. You have the bounty posters, and they could be someone who has been attacked or has a certain target they want to go after. And then the submitters. And these submitters, they're— it's not meant to be victims of fraud or ransomware. It's meant to be actual researchers. So we want to be able to expose it, open up the channels more, have more bounties posted, grow that community, and bring other intelligence. Not— so Fortinet has founded this with Crime Stoppers International, but we want to also bring more intelligence subject matter expertise into a fusion center where we can just really, truly operate at scale and get that number higher than that less than 1% prosecutions we're seeing.
Krista Case
>> So this fusion center, it'd be Fortinet with other companies collaborating, like you say, and there is research, potentially ethical hacking. Maybe I'm speculating a little bit.
Derek Manky
>> Correct. Yes. Yeah. So still with Crime Stoppers platform, that's the trusted anonymous platform.
Krista Case
>> Yes.
Derek Manky
>> But then building on that to have more points of view from threat intelligence because that's just going to make the vetting process easier. It's going to make the, the linkages and enhance the chances of having higher, even higher confidence on attribution, the human intelligence angle, which is something we're trying to solve. So that's the goal, a year from now. And then obviously the other piece of that is looking at the operational actionable results, right? So the whole reason we're doing this, going back to the start of our conversation, is to provide accountability That's a big piece to let cybercriminals know that their actions are not going to go unnoticed or unheard or unactioned. And the other piece we don't talk about enough is the deterrence, right? By doing that and by posting these bounties, adding an element of fear. And to me, that also means youth, right? Because we have a big problem of youth getting into cybercrime and we want to also be able to educate and curb that as well.
Krista Case
>> Yeah, there will be, a repercussion if they do choose to engage in this behavior, for lack of a better way to put it.
Derek Manky
>> Absolutely.
Krista Case
>> It's a great point. And maybe you can even elaborate a little bit further. I know we've talked about why accountability is important, but I really want to just sort of underscore that for our audience because I think it's an important point here.
Derek Manky
>> Yeah. Yeah. So accountability has been, again, if we look at it, it's been a drop in the bucket when it comes to, there's been a lot of good initiatives, but if you look at the amount of people that are getting into these cybercrime rings, a lot of them are doing it on a, on a knowing basis. They know what they're getting into, but there's no element of fear. And if you don't have accountability and examples that, just because they don't think they're a major player in a cybercrime ring that they're invincible, That's an issue. So that's what we're going after. For example, if we look at these cybercrime rings, it's often perceived that only the kingpin, the malicious CEO of these criminal organizations, is going to be sought after, right, when it comes to bringing them to justice. There's examples where that hasn't been the case, and we need to build on that. So you look at affiliates, right, people that, the middle layer network that are getting commissions to spread ransomware, ransomware as a service. That's the cash cow that's fueling these operations. And those operations also need to be held accountable where traditionally they have not. So again, by going after all aspects of that ecosystem, it starts to close the door of that invincible feeling, that, cybercriminals can have.
Krista Case
>> They're no longer operating in the dark. And also, like you say, it's holding everyone involved accountable versus just sort of that kingpin, that's going to deter them from potentially joining that organization and engaging in that behavior.
Derek Manky
>> Absolutely. Absolutely. And I like what you said, not only operating in the dark, because that is the other challenge, right? They have safe havens, they have shadows. We're exposing that. It's actually what we've been saying with Operation Silent Vector 1 is our goal is to unmask the dark. That's the goal of the operation. It's lifting that, shining light on it, applying as much threat intelligence with confidence to really bring those to justice and to identify who they are.
Krista Case
>> And Derek, I know you talked a little bit already about this, but I wanted to really put a finer point on it as well because I think it's a really important point. So what are— so it sounds like a lot of kind of the further community involvement and kind of the further traction with the Cybercrime Bounty initiative. But based on what you've already seen over the past year and as you reflect over the year ahead, what are some of those key metrics that you wanted to really make sure to leave our audience with as they're thinking about this program?
Derek Manky
>> Yeah, I think some of the key metrics are look out for more updates on new operations. We've launched Operation Silent Vector 1. That's the first one. So look for new additions to that series beyond just the initial target. Look for actionable operational updates as we proceed, right? We'll be definitely putting out updates as we go along. To also look at key metrics at the broader ecosystem. So number of arrests, threat actors that have been identified, brought to justice behind those campaigns. That's the goal. The goal here isn't to boil the ocean because we can't do that when it comes to cybercrime, but to start specifically on some of these needle movers, right? On some of these groups that are causing significant damage and do something that resonates with these organizations that are consistently being hit with ransomware. That's precisely the idea that we're going after.
Krista Case
>> And it's going to be even more important, like we've been talking about, especially as AI just makes it easier to get into cybercrime and also accelerates the pace that they move as well.
Derek Manky
>> Yeah. And I think near term— so we're talking about a year from now. If I were to think 5 to 10 years from now, that bigger picture, it's really looking at the dashboard, right? So we talk about cybercrime being the third largest GDP in the world. Why is that? How has it flourished into such a large operation? It's because accountability hasn't been there over the years, not enough anyway. It has been, but not in enough measure. So can we start to curb the growth and see some noticeable impact on that? Those are all the things we're going to be tracking and looking at on the long-term horizon. Obviously getting the prosecutions up higher as well, the number of arrests that we're doing. And it's not just arrests, by the way, it's all of that combined. It's infrastructure takedown. You can't just arrest people, but you can't just take infrastructure down. You need to do all of it holistically together.
Krista Case
>> That holistic approach to remediation.
Derek Manky
>> YepYeah, absolutely. And that's why, again, we have various initiatives, they all come together to form that holistic approach, right, between INTERPOL and law enforcement and Gateway work we've been doing, Cybercrime Atlas, Cybercrime Bounty, which is the latest one, which I'm very excited about as well.
Krista Case
>> Absolutely. Well, Derek, thanks so much for sitting down with us today. Really interesting research. And again, thank you so much for joining.
Derek Manky
>> It's a pleasure to be here.
Krista Case
>> Yeah, absolutely. And thank you so much to our audience for listening. We'll be right back in just a few minutes with more coverage live here from Black Hat 2026. Again, this is Krista Case at theCUBE. Thank you.