Summary
The core message of the session is that earlier detection of phishing and ransomware-related activity depends on turning large, noisy cybercrime supply-chain data into actionable intelligence. The speakers frame the work as a public-private and research-driven effort involving Delft University, TNO, CFLW, law enforcement partners, and prosecution authorities. Rather than focusing only on individual attacks, they emphasize the surrounding criminal ecosystem: credential theft, resale of valuable access, ransomware groups, cash-out mechanisms, and the need to identify meaningful signals before harms escalate. The stated challenge is a “needle in the haystack” problem: data volume is not the bottleneck, but detecting the right signals and knowing how to act on them is.
Key Topics
5 key topics from Mark van Staalduinen, Georgios Smaragdakis and Ruggero Montalto at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Map cybercrime supply chains beyond the attack itself.
- Use certificate transparency logs for earlier phishing detection.
- Train models on positive examples to find lookalike domains.
- Investigate parking domains with fresh-IP testing strategies.
- Turn detected signals into actionable law-enforcement intelligence.
“data is not a problem. But finding the right needles or the right signals in huge amounts of data, that is where the big problem is.”
Up Next



Next in agenda
Humans as crucial partners in cybersecurity & resilience

EAlso on cybercrime
Leading the fight against cybercrime
MAlso on infostealers
