Spain blackout: uncovering unknowns with Hypothesis Competition Analysis
On April 28, 2025, a blackout hit the Iberian Peninsula, leaving Spain and Portugal powerless for hours. The GiCP used this event to conduct a practical exercise in structured intelligence analysis, aiming to uncover insights and better understand the incident.
RansomHouse: The Rising Sophistication of Ransomware Toolkits
Recent analysis reveals significant advancements in the encryption capabilities of RansomHouse, a ransomware-as-a-service (RaaS) operation carried out by a group known as Jolly Scorpius.
Join the GroundUp Hackathons: create innovations for Real-World CBRNE Challenges
Malware - short for malicious software - remains one of the most pervasive threats in cyberspace, encompassing various types of malicious code designed to disrupt, damage, or gain unauthorised access to computer systems.
Decentralized Crime, Centralized Response: Why LEAs Need Blockchain Intelligence Platforms
Blockchain brings financial freedom and innovation, but also new criminal challenges. Law Enforcement Agencies are turning to blockchain intelligence platforms to track and combat crypto-enabled crime.
Profiling of CSAM offenders
A new systematic review in Sexual Medicine Reviews (2026) analyzes 35 studies to profile those who create demand for Child Sexual Abuse Material (CSAM), helping us understand how to stop its spread.
Initial Access Brokers and why they matter
Initial Access Brokers (IABs) are specialised cybercriminals who access/infiltrate networks and then sell that access to others, therefore acting as brokers of information (and entry points) in the cybercriminal economy.
RansomHouse: The Rising Sophistication of Ransomware Toolkits
RansomHouse RaaS now uses multi-layered encryption and double extortion, hitting critical sectors and showing the need for proactive, adaptive cyber defense.
CTI good practices with hyperlinks
Working with CTI means handling risky data safely, use defanging, secure channels, encryption (PGP/E2EE), OPSEC, proper file handling and sandboxing.
Malware-as-a-Service (MaaS): a new business model
MaaS turns cybercrime into a paid service, letting even low-skill actors launch sophisticated attacks at scale, driving over half of recent malware threats worldwide.
In the labyrinth of cybercrime money laundering
The laundering of money from cybercrime involves a complex network of transfers, and investigators tracking these funds navigate a maze of cryptocurrency transactions and conversions.


