











Cybercriminals do not organize their operations around national borders. Instead, they exploit differences in jurisdiction, capability, and visibility, moving infrastructure, data, and illicit proceeds across borders faster than any single organization can respond. Countering this model requires more than collecting information on malicious activity. It requires turning intelligence into coordinated action that disrupts the people, infrastructure, and services behind cybercrime.
That challenge framed the recent 11th Americas Working Group on Cybercrime for Heads of Unit, which brought together INTERPOL, the World Economic Forum, the Paraguayan National Police, the Paraguayan Ministry of the Interior, and public- and private-sector experts from across the region.
I represented Fortinet and FortiGuard Labs at a session titled “From Intelligence to Disruption,” organized around a clear yet difficult question: How can we support more operations against cybercrime in Latin America?
Ransomware, malware, botnets, fraud, and extortion are often framed as technical threats, yet their consequences extend well beyond compromised devices and networks. Cybercrime can disrupt businesses and public institutions, erode confidence in digital services, damage economies, and harm individuals. It is therefore not only a cybersecurity problem. It is a national and regional challenge that demands operational cooperation across sectors and borders.
The regional threat landscape makes such cooperation especially important. At the 10th Americas Working Group in 2025, participants identified ransomware, phishing and malware attacks, cyber-enabled financial scams, the misuse of AI, and Cybercrime-as-a-Service platforms as priority concerns.
The group also emphasized the importance of structured public-private cooperation, joint cybercrime operations, real-time intelligence sharing, and sustained investment in technical capabilities. This year’s meeting built on that foundation by focusing on how shared intelligence can support concrete investigative and operational outcomes.
FortiGuard Labs uses telemetry and threat intelligence to understand how the threat landscape is evolving, identify ransomware, malware, botnet activity, and other relevant campaigns, and provide information to support investigations and operations.
The distinction between collecting data and producing actionable intelligence is critical. Indicators, infrastructure patterns, malware behavior, and connections among campaigns become more valuable when placed in context and delivered in a form partners can use.
For law enforcement, this intelligence can help reveal connections among incidents that might otherwise appear isolated, identify infrastructure used across multiple campaigns, and inform decisions about where and when to act. For private-sector organizations, collaboration with law enforcement and international organizations enables threat insights to contribute to broader disruption efforts. Each participant brings distinct authorities, visibility, and capabilities, and effective cooperation combines those strengths around a shared operational objective.
Intelligence sharing is essential, but sharing alone is not the end goal. The true measure of its value is whether it helps partners prevent harm, advance investigations, seize criminal infrastructure, disrupt illicit services, or otherwise make it harder for cybercriminals to operate. Achieving those outcomes requires trusted relationships, timely information sharing, clear processes for using shared intelligence, and continued coordination after a meeting concludes.
The Working Group provides an important forum for building those relationships. Law enforcement agencies contribute investigative authority and the ability to act through legal processes. International organizations help coordinate efforts across jurisdictions. Private-sector partners contribute technical expertise, agility, telemetry, and visibility into threats affecting organizations and individuals. Academia strengthens research and helps develop the next generation of practitioners. While no participant has the full picture, together they can develop a clearer view of criminal activity and act on it more effectively.
Fortinet’s participation in the Working Group reflects a long-standing public-private collaboration with INTERPOL, focused on threat intelligence sharing, capability building, and supporting coordinated cybercrime disruption efforts. That collaboration dates to 2015, and in 2018 Fortinet joined the INTERPOL Gateway initiative, which provides a framework for sharing threat intelligence with law enforcement.
Fortinet also works closely with the World Economic Forum and was a founding member of its Centre for Cybersecurity, a contributor to the Partnership against Cybercrime, and a participant in the World Economic Forum Cybercrime Atlas. This engagement reinforces the broader collaboration model among industry, law enforcement, and international organizations, connecting partners with diverse expertise and authority around the shared goal of disrupting cybercrime.
As we discussed following last year’s Working Group, cybercriminals continually adapt their tactics, infrastructure, and business models. Defenders must be able to move from awareness to action just as quickly. Frequent engagement between public authorities, international organizations, private companies, and academic institutions helps build the trust and operational readiness needed before the next major campaign emerges.
This year’s Working Group reinforced a central principle: Intelligence generates value when it is turned into action, and collaboration generates impact when that action leads to disruption. By continuing to share expertise, strengthen regional capabilities, and pursue coordinated operations, we can raise the cost of cybercrime and help create a safer digital environment across Latin America.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。