Brett Leatherman speaks with Daniel Kroese, Katie Sutton and Nick Andersen at Black Hat USA 2026.

Black Hat 2026: FBI Says Operation Riptide Netted More Than 200 Cybercrime Arrests

The 60-day campaign targets not only suspected hackers, but also the hosting providers, anonymization services and financial infrastructure that keep cybercrime operations running.

LAS VEGAS — The FBI arrested more than 200 suspected cybercriminals worldwide, charged another 50 defendants and extradited six international fugitives during a roughly 60-day campaign aimed at dismantling the infrastructure and financial networks supporting cybercrime, a senior bureau official said Tuesday.

Brett Leatherman, assistant director of the FBI’s Cyber Division, disclosed the figures during the opening session at Black Hat USA 2026 but did not provide a breakdown of the arrests, charges or extraditions.

The results were attributed to Operation Riptide, an FBI campaign launched June 9 to target cybercriminals and the services they depend on, including hosting providers, VPN services, communications platforms, malware tools and cryptocurrency accounts.

Beyond the Break weekly cybersecurity newsletter — Subscribe

“We can’t always get an actor in custody, so we go after the underlying ecosystem,” Leatherman said. “We go after their infrastructure. We go after their finances. We go after their tools.”

The FBI had not published the aggregate results as of Tuesday evening. The figures therefore remain based on Leatherman’s remarks at Black Hat rather than a detailed bureau report.

Attacking the cybercrime supply chain

Operation Riptide represents an effort to move beyond one-off arrests and takedowns by coordinating cases across the FBI’s 56 field offices, overseas legal attachés, international law enforcement agencies and private cybersecurity companies.

The campaign’s targets include not only ransomware operators and fraud crews, but also the businesses and technical services that help those groups hide, launch attacks and collect payments.

One early Riptide action involved the international seizure of FirstVPN, an anonymization service that authorities said was used by at least 25 ransomware groups to conceal malicious traffic and compromise victims.

[Related: Black Hat 2026: AI Breakouts, Identity Risk and After-Hours Vibes]

Brett Leatherman, assistant director, Cyber Division, FBI

Another targeted the Russian bulletproof-hosting companies Media Land and ML.Cloud. Federal prosecutors said the companies supplied servers and other infrastructure used to deliver malware, operate criminal marketplaces, register fraudulent domains and support ransomware attacks.

The Justice Department said Media Land infrastructure was used to target at least 42 victims in 21 states. The companies allegedly promoted their ability to protect criminal customers from law enforcement scrutiny.

Leatherman said the FBI is also seizing cryptocurrency and providing decryption assistance to ransomware victims. The bureau has previously said its ransomware operations have distributed thousands of decryption keys and helped victims avoid hundreds of millions of dollars in ransom payments.

The objective, Leatherman said, is to make cybercrime more expensive even when suspects remain beyond the immediate reach of U.S. law enforcement.

“If they can’t monetize their activity, it serves as a deterrent as well,” he said.

The FBI has adopted “No Safe Harbor” as Riptide’s operating message, reflecting an effort to pursue suspects when they travel outside countries that have historically protected them while simultaneously dismantling the systems they leave behind.

Leatherman stressed that private companies often possess the earliest visibility into malicious infrastructure, compromised accounts and financial transfers.

“It is industry that engages us early and often that allows us to move upstream against the actors,” he said.

White House pushes a more offensive cyber posture

The Riptide results were presented as an early implementation of President Donald Trump’s Cyber Strategy for America, released in March.

The strategy calls for the government to impose greater costs on foreign hackers and cybercrime networks instead of relying primarily on defensive measures. It also seeks closer coordination among law enforcement, intelligence agencies, military cyber operators and private companies.

National Cyber Director Sean Cairncross

National Cyber Director Sean Cairncross told the Black Hat audience that the administration wants attackers to understand that operations against the United States will not be “cost-free.”

“The lead piece of that is shaping adversary behavior,” Cairncross said. “What that really means, when you boil it right down, is introducing the concept of deterrence in this space.”

Trump also signed a March executive order targeting foreign cybercrime and fraud networks. The order directs federal agencies to coordinate efforts against transnational criminal organizations operating ransomware, scam centers and other cyber-enabled fraud schemes.

The order calls for an operational cell to coordinate disruption efforts and directs agencies to incorporate technical capabilities and threat intelligence from commercial cybersecurity firms.

Cairncross said the administration is trying to build relationships that can be activated during an attack rather than relying on government advisory groups that move too slowly.

“When there is a breach, when there is an event, that network of connections can exist, adapt to that and seek to remedy that as quickly as possible,” he said.

CISA calls for ‘ruthless prioritization’

Acting CISA Director Nick Andersen used the session to press companies and federal agencies to move away from vulnerability programs driven primarily by severity scores.

Nick Andersen, acting director, CISA

CISA’s June Binding Operational Directive 26-04 instructs civilian federal agencies to prioritize vulnerabilities according to factors such as active exploitation, internet exposure, automation potential and the operational consequences of a compromise.

The directive does not apply directly to private companies, but CISA is promoting the model to critical infrastructure operators.

“We’re not going to be able to secure everything everywhere all at once,” Andersen said. “That is an unreasonable goal.”

Instead, he called for “ruthless prioritization” of systems whose failure could affect public health, national security, the economy or defense-related infrastructure.

Andersen also promoted Gold Eagle, a government-industry clearinghouse created to coordinate AI-assisted vulnerability discovery, validation and patching.

Meanwhile, Assistant Secretary of War for Cyber Policy Katie Sutton said the department is working to integrate cyber capabilities into conventional military planning rather than treating cyber operations as a separate specialty.

She also said the department is beginning to implement Cyber Mastery Incentive Pay, which will provide additional compensation to personnel who develop advanced cyber skills and certifications.

Assistant Secretary of War for Cyber Policy Katie Sutton

Taken together, the officials described a cyber strategy built around offensive disruption, more selective defense and deeper operational ties with industry.

For the FBI, Leatherman said, the goal is to make campaigns such as Riptide a sustained operating model rather than a succession of temporary crackdowns.

“We really look to close the gap with industry, our partners in the intelligence community and our international partners,” he said, “and make this more steady-state counter-cyber operations.”

AI ambition meets operational reality

Artificial intelligence ran through both opening sessions as a force accelerating attacks, expanding defensive capabilities and testing the government’s ability to keep policy aligned with rapidly changing technology.

Black Hat President Suzy Pallett

“AI is reshaping attack and defense at a pace we’ve never seen before,” Black Hat President Suzy Pallett said in opening the conference. “Cyber operations are influencing global events in real time, and critical systems are more interconnected and more vulnerable than ever.”

Pallett framed collaboration across government, industry and the research community as a necessary response rather than a conference talking point.

“The future of cybersecurity won’t be built by one person, one company or one government,” she said. “It will be built by all of us working together, learning from each other, and refusing to accept that the problems we face are unsolvable.”

Cairncross struck an optimistic tone, describing AI as an American strategic advantage while arguing against a traditional regulatory approach that could become outdated almost as soon as it is adopted. He said the administration wants to move AI capabilities quickly into the hands of defenders while working with technology companies to address security risks.

“AI is a tremendous story of American innovation,” Cairncross said. “America leads the world in this, and we are extremely interested in looking at ways to build U.S. open source, make it competitive, and make it the preferential adoption by planet Earth.”

The administration’s AI posture was presented alongside a broader effort to become more aggressive against cybercriminals. Leatherman pointed to Operation Riptide as evidence of that shift.

“We’re executing over the last 60 days what we call Operation Riptide,” he said. “We have arrested, in 60 days, over 200 actors engaged in cyber-enabled or cybercrime operations globally, charged another 50, and extradited six international fugitives to the homeland to face charges. The tagline for Operation Riptide is ‘no safe harbor.’”

The government’s message was not that AI would make it possible to fix every weakness. Andersen said organizations must use better intelligence and automation to identify the systems and vulnerabilities that matter most.

“We’re not going to be able to secure everything everywhere all at once,” Andersen said. “It really has to be focused on ruthless prioritization. We’re focused on things that are going to be most consequential and focused on public health and safety, national security, and the overall economy.”

The officials did not address several of the hardest unresolved questions, including how organizations should secure AI agents with autonomous access to sensitive systems or determine accountability when those systems cause harm. They also offered little detail on how government and industry will measure AI-enabled risk, coordinate vulnerability disclosure or prevent the same tools being promoted for defense from accelerating attacks.

Together, the remarks outlined an AI-era cyber posture built on three ideas: accelerate American innovation, use emerging technology to strengthen defenders and concentrate limited resources on the threats capable of causing the greatest damage.

Total
0
Shares
Previous Article
Fake Xeno Roblox Cheat Malware

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading