Cybercrime continues to generate billions of dollars in losses while investigators, banks, law enforcement, and victims are often forced to play defense. In this episode of Rexxfield Investigates, Ronnie Tokazowski and Stephen Dougherty discuss whether a new framework for offensive cyber operations could finally start changing that equation.
Rather than looking at offensive operations as simply “hacking the hackers,” Ronnie and Stephen explore what happens when investigators can move deeper into criminal infrastructure, identify connected bank accounts and money mules, uncover additional victims, disrupt email accounts and infrastructure, and turn intelligence over to banks and law enforcement for action. Historically, a single compromised inbox could expose dozens or even hundreds of additional victims, but getting that visibility often required extensive legal process, federal resources, prosecutors, and time.
The conversation also examines one of the biggest weaknesses of modern cybercrime: criminals rarely operate in isolation. Money launderers, business email compromise groups, romance scammers, nation-state actors, and even terrorist organizations can share infrastructure, financial networks, and intermediaries. Offensive investigations may provide an opportunity to follow those connections much further than a traditional single-victim investigation allows.
Ronnie and Stephen also discuss disruption techniques that go beyond simply taking systems offline. Feeding bad data into criminal marketplaces, identifying and burning financial accounts, forcing criminals to verify information, and creating uncertainty inside criminal networks can increase their costs while making them question whether interference is coming from investigators, competitors, or rival criminal groups.
The goal isn't vigilantism. It's creating a controlled framework that gives qualified investigators another tool against transnational cybercrime while protecting victims, investigators, and innocent third parties.
For decades, defenders have largely been forced to react while cybercriminals choose the targets, infrastructure, timing, and tactics.
The question now is: Are we finally reaching a point where we can start bringing the fight back to them?