


















Cybercrime, no longer just a technical problem, now functions as an economic system, a marketplace for services, and a model for global collaboration. Modern cybercriminals have operationalized their networks to enable shared infrastructure, sell access, recruit talent, transfer funds, and exploit gaps in visibility, trust, and jurisdiction.
During the recent World Economic Forum Annual Meeting in Davos, leaders from the cybercrime disruption sector gathered for the session “Incentivizing the Disruption of Cybercrime” to discuss the issue. Attendees included Derek Manky, Fortinet’s chief security strategist and global vice president of threat intelligence; Hayley van Loon, CEO of Crime Stoppers International; Michael Daniel, president and CEO of the Cyber Threat Alliance; and Edvardas Šileris, head of Europol’s European Cybercrime Centre.
The session focused on a central challenge: how to create stronger incentives to disrupt cybercrime at scale.
One answer is taking shape through the Cybercrime Bounty program, launched by Crime Stoppers International and Fortinet. The program provides individuals, cybersecurity professionals, ethical hackers, researchers, business owners, and other private-sector contributors a safe and anonymous platform to report suspected cybercriminals and organizations.
To explore why this model matters, Glenn Maiden, chief security officer for Fortinet Australia, spoke with Hayley van Loon, CEO of Crime Stoppers International, about the partnership, Fortinet’s role, and how the Cybercrime Bounty initiative can help turn information into action.
Hayley van Loon: Crime Stoppers has spent nearly 50 years building trusted reporting channels that let people share information about crime without revealing their identities. That model has helped law enforcement around the world address traditional crime, organized crime, and community harm by turning public information into actionable intelligence.
Cybercrime needs a similar bridge. People in the private sector may have information about cybercriminal activity but not know how or where to report it. They may also fear retaliation, exposure, or becoming involved in a complex legal process. Those are rational fears, and a trusted, anonymous reporting channel removes them.
Even though cybercrime is borderless, people and communities still see things. For example, they may notice activity in online forums, marketplaces, networks, businesses, or even in their own communities that could be relevant to law enforcement. The challenge is providing them with a safe, responsible way to share that information.
Hayley van Loon: Cybercrime has become one of the world’s most pervasive and costly threats. It crosses borders, sectors, and traditional definitions of crime. No single organization, company, or government can solve it alone.
We partnered with Fortinet because this initiative requires both trust and technical expertise. Crime Stoppers International brings the trusted anonymous reporting model and global crime-reporting infrastructure. Fortinet provides advanced threat intelligence, cybersecurity expertise, and extensive experience collaborating with both public and private entities, including law enforcement, to disrupt cybercrime.
When Crime Stoppers was founded, information was scarce. If a member of the public didn’t call, in many cases nobody knew a potentially important detail. Our value was that we were often the only channel, anonymous, trusted, and frequently the only route that information had.
That’s not the world of 2026. Law enforcement is no longer information-poor; they have cameras, social media, open source intelligence, and a constant flow of data from the private sector. The problem has inverted. It isn’t that investigators can’t get information. It’s that they’re drinking from a firehose, and the signal is buried somewhere in it.
The question we have to keep asking ourselves is whether what we do is still fit for purpose. Being a channel isn’t enough anymore. Anonymity still matters enormously; that hasn’t changed, and it never will. But if all we do is add another stream to the flood, we’re part of the problem we’re trying to solve.
That’s exactly why Fortinet is in this. Tips come to us, and Fortinet’s threat intelligence validates, analyzes, and enriches them before anything moves. What reaches law enforcement isn’t raw volume, it’s triaged, contextualized, and prioritized. We’re not adding to the noise. We’re doing the work that turns noise into something usable.
This partnership creates a practical framework for deterrence. It’s not only about responding to cybercrime after the damage is done. It’s about improving visibility, increasing intelligence sharing, and enabling coordinated disruption to occur earlier and more effectively.
Hayley van Loon: Fortinet adds the cybersecurity intelligence layer to Crime Stoppers International’s trusted reporting pathway. Cybercrime information often requires technical context before it can be useful to investigators. A tip may include a handle, a forum, a marketplace, infrastructure, payment information, or other details that must be assessed by people who understand the cybercrime ecosystem.
Fortinet validates and enriches that information. Its threat intelligence expertise can determine whether a submission has investigative value, how it may connect to known activity, and whether it can be turned into an intelligence package for law enforcement partners.
That is what makes the model so powerful. It connects people who may have information with experts who can evaluate it and authorities who can act on it.
Hayley van Loon: This is not a bug bounty. Bug bounty programs usually focus on identifying and responsibly disclosing vulnerabilities in software, systems, or digital services. They are about finding technical weaknesses.
The Cybercrime Bounty program is focused on identifying the human actors behind cybercrime and cyber-enabled crime. The goal is to uncover information about individuals, groups, forums, marketplaces, and networks involved in cybercriminal activity.
Useful submissions might include information on threat actors, criminal forums, cybercrime marketplaces, infrastructure, online handles, recruitment channels, payment activity, or individuals suspected of involvement in cybercrime.
A vulnerability doesn’t hurt anyone until a person decides to use it. Behind every ransomware attack on a hospital is someone who chose to do it knowing what happens when a hospital goes dark. Behind every fraud that empties a retiree’s account is someone who knew exactly what they were taking. Human beings make those decisions, and human beings can be identified, arrested, and put in front of a court. That’s what we’re here for. Not the flaw. The person who used it.
Hayley van Loon: The bounty program was designed for non-government contributors who might possess credible information on cybercriminal activity. This includes cybersecurity professionals, ethical hackers, researchers, business owners, private-sector specialists, and community members. Even if someone doesn’t see themselves as part of the cybersecurity community, they might still have important knowledge about a person, group, forum, or criminal network.
It also isn’t a personal security help desk. If someone is dealing with a personal security issue, they should turn to local resources or appropriate incident-reporting channels, they deserve help, but this isn’t the place for it. The Cybercrime Bounty program targets criminal networks and their operatives.
Hayley van Loon: Anonymity is fundamental because trust is what makes people willing to come forward. The Crime Stoppers model was designed so people can submit information without revealing personal details. Law enforcement receives the intelligence, not the identity of the person who submitted it.
Such protection is especially important in the context of cybercrime. Some people may have information about organized criminal groups but fear retaliation or exposure. Others may simply not want to become part of a formal investigative process. If we want people to share what they know, we need to protect them.
That said, anonymity is the tipster’s choice, not a restriction we impose. Someone can stay completely anonymous and never tell us who they are. Someone else may choose to provide their details and they’d need to if they want to claim a bounty. Either way, it’s their decision, and staying anonymous doesn’t mean we lose contact: We can communicate through the platform without ever knowing who someone is.
What we don’t do is compromise the person’s choice. If someone chooses anonymity, we protect it, full stop, because the moment someone believes their name might leak, the tips stop.
Hayley van Loon: A credible tip may help launch a new investigation, strengthen an existing case, support international coordination, or contribute to arrests, search warrants, prosecutions, or digital takedowns.
Once credible information has been submitted, the goal is to turn that information into something useful for disruption. Fortinet threat intelligence validates, analyzes, and enriches these cybercrime-related reports, and depending on the jurisdiction and type of threat, that information can then be shared and coordinated with appropriate law enforcement partners.
Not every submission leads to an immediate or visible outcome, and I won’t pretend otherwise. But intelligence is cumulative. The fragment that looks like nothing today can be the piece that completes the picture much later.
Hayley van Loon: Cybercrime does not fit neatly inside boundaries. A person with information may be in one country. The victims may be in several others. The infrastructure may be hosted somewhere else. And the criminal network may be operating through online marketplaces, encrypted channels, or hidden identities. That means disruption requires cooperation.
I think of it as a testudo. Every organization carrying its own shield is a target. Lock the shields together and you have a formation that can advance and one where nothing gets through the gaps.
Law enforcement has investigative authority. Cybersecurity companies have technical visibility and threat intelligence. Organizations like Crime Stoppers International have experience protecting sources and managing trusted reporting. Communities and private-sector contributors may have information that no single institution could gather on its own. Separately, those are four partial views of the same crime. Locked together, they’re a formation. The Cybercrime Bounty program brings those critical pieces together in a practical way.
Hayley van Loon: Cybercrime is a massive global threat, and no single program will eliminate it. But this bounty initiative can help make cybercrime harder, riskier, and more expensive for criminals.
When people have a safe way to share what they know, defenders gain more visibility. When that information is validated and connected to law enforcement, it can support disruption. And when cybercriminals face a greater likelihood of detection, arrest, prosecution, or takedown, the economics begin to change.
Cybercrime is the small business owner who built something over 30 years and watched it end in an afternoon. It’s the family who lost the deposit on a house. It’s the hospital diverting ambulances because its systems are encrypted. It’s the person too ashamed to tell their family they were scammed, carrying it alone. That’s the harm we’re talking about. Every tip that helps disrupt a network is someone who doesn’t join that list.
The program also gives people outside law enforcement or professional cybersecurity organizations a practical role in cybercrime disruption. That matters. Cybercrime affects communities, businesses, and individuals everywhere. This model allows more people to contribute safely and responsibly to address issues that directly or indirectly affect their lives, and this model lets more people contribute safely and responsibly to something that directly affects their lives.
Hayley van Loon: This is a long-term framework, not a one-time campaign. As more organizations, communities, and partners engage with the program, it can continue to scale. It can support future awareness efforts, targeted disruption campaigns, new participation opportunities, and additional milestones in the fight against cybercrime. But the broader goal is to turn fragmented information into coordinated intelligence, and then help that intelligence move toward responsible action.
Crime has evolved, and we have to evolve to meet it. The crime of 2026 doesn’t look like the crime this organization was built for, and it won’t sit still and wait for us to catch up. Cybercriminals already collaborate across borders, they specialize, they franchise, they run better operations than most legitimate businesses. Defenders need to do the same. The Cybercrime Bounty program is one way to help build that collaboration, protect those who come forward, and create new consequences for the people and networks behind cybercrime.
Hayley van Loon: If someone has credible information about cybercriminals or cybercriminal organizations, they should know there is a safe and anonymous way to share it. They do not need to reveal who they are. They do not need to become part of a public process. And they should not assume that what they know is too small to matter.
A single piece of information may help connect a larger picture. When handled responsibly, information can become intelligence. And intelligence can help disrupt cybercrime.
Read the announcement: Fortinet and Crime Stoppers International Launch Global Cybercrime Bounty Program
Read the blog: Driving Accountability: New Cybercrime Bounty Program Expands the Fight Against Cybercrime
Watch: Scaling Disruption, The Next Chapter of Cybercrime Defense
Explore: Fortinet’s work with the World Economic Forum Cybercrime Atlas
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。