Key takeaways
- Crime as a Service definition: Crime as a Service (CaaS) is an online marketplace providing malicious tools, malware and support infrastructure that enable non-technical criminals to execute sophisticated cyber attacks.
- Impact of AI on CaaS marketplaces: AI has significantly expanded the scale, automation and capability of CaaS tools available to cyber criminals.
- Future CaaS threats (quantum and agentic AI): The convergence of agentic AI and quantum-secure encryption represents the next evolution of CaaS, enabling fully autonomous cyber threats capable of bypassing traditional data security protocols.
Crime as a Service (CaaS) first entered the cyber security lexicon around 2013, inspired by the legitimate, subscription-based Software as a Service (SaaS) model.
These criminal enterprises equip their less technologically fluent affiliate ‘customers’ with illicit digital tools, access, crypto wallets and other resources needed to carry out cyber attacks. CaaS networks also tend to be decentralised across multiple locations jurisdictions where extradition is difficult.
Just as with legitimate entities, their affiliates pay subscriptions for software and services such as access credentials, server hosting and even 24/7 helpdesk support. Payment often includes a performance-related or profit-sharing element for each successful attack.
Because ransomware is increasingly the weapon of choice for extorting millions of pounds a year from organisations, Ransomware as a Service is now a recognised subset of CaaS. It features software designed to take control of vulnerable private networks in order to steal and encrypt their data, rendering the network unusable until a ransom is paid to have it restored.
UK firms caught in a CaaS web
The dispersed nature of CaaS and its enthusiasts means that cash-rich and vulnerable entities can be assaulted from any corner of the globe, across any time zone.
“With AI and other Ransomware as a Service tools, it’s never been easier to run a ransomware attack,” says Jeff Crume, an IBM Distinguished Engineer and cyber security expert. “You can just ‘set it and forget it’. Let your AI go and figure out what your targets will be, what exploits they will be using, and then launch the attack and do the collections. And because the barrier’s the lowest it’s ever been, the attackers are more dispersed and more difficult to track down.”
For Jake Moore, Global Cybersecurity Advisor at ESET, the advent of AI-assisted CaaS appeals to an inherent “laziness” among criminals and a tendency “to take the path of least resistance” in their operations.
“They're excellent at finding that. And if that happens to be one phishing email to one person in a company that they get credentials from, then they will do that,” he says.
AI can enable agents to automate attacks across multiple platforms at scale, targeting data vulnerabilities across businesses or even entire industries.
“Companies are not realising that this is their way in now, because we’re all familiar with cyber attacks but not necessarily familiar with the extent to which AI can just offer it up,” Moore adds. The technology is also able to create fake websites, which are more precise given they are now practically clones, and do so at speed. “Now it just takes 15 minutes to copy a website that looks the same,” he adds.
How to fight back
But, while the frequency of CaaS-driven attacks remains relentless, the criminals don’t always get their own way. "What we tend to find now is that few companies are paying to get the decryption key because they've got a backup, meaning they can use the restore function to get their data back,” says Moore.
This June saw Europol, the European Union’s law enforcement agency, along with global partner organisations, secure a win against a large criminal network after disrupting the infrastructure it uses to launch various malware and ransomware attacks.
Operation Endgame blocked criminal crypto assets worth more than €41m from use and as many as 27 million stolen login credentials were recovered. The action also disrupted 326 servers and 142 domains, dealing cumulative hammer blows to the malware’s distribution network.
Corporations themselves are also being more cooperative with each other, being more forthcoming with details of attacks and what they have learned from them, ultimately raising awareness and vigilance across their industries.
The next trend: harvest now, decrypt later
Enterprising cyber criminals are now planning ahead. Through his work at ESET, Moore says he has seen a new cyber crime service offering evolving on the dark web this year: harvest now, decrypt later.
“You steal the data, again through Crime as a Service, but it's encrypted. You then give it to the business that lives online and they ‘harvest’ it and attempt to decrypt it every so often with the latest technology - with the latest being quantum,” Moore explains.
It means that data could be stolen now and be decrypted in five years’ time once technology allows it, he adds. “You look back all over all those files, emails, data; lots of it won't have changed. We've got major problems that we're sitting on right now.”
The banks are apparently leading the way to get ‘quantum ready’ in order to preempt this trend, but the extent of the challenge cannot be overstated, says Moore. “When you match quantum computing with AI in three to five years’ time…it’s a very worrying thought, and I don’t know how many government organisations have got to grips with this yet.”
Cyber security support
ICAEW has a host of resources addressing the latest cyber security issues and guidance on how to protect your business.
Stay up to date
You can receive regular email updates from ICAEW insights, including weekly or monthly enewsletters. Subscribe to whichever works for you.
Sign up