In the latest episode of Aviatrix “In Progress,” Aviatrix CEO Doug Merritt sat down with Keith Wojcieszek, former Chief of the Secret Service's Cyber Intelligence Section, for a conversation about what modern cybercrime actually looks like, why preparation beats reaction every time, and what keeps a career threat hunter up at night. Here are some highlights:
Cybercrime Acts Like a Fortune 500 Company
Doug asked Keith to walk through a real takedown. Keith described the case that defined his career: Roman Seleznev, once one of the world's most prolific traffickers of stolen credit card data.
“When people actually hear about cyber criminal, they usually picture one person, back in the old school, in a dark room, hoodie on. But reality couldn't be more different,” Keith said. He described an operation with developers writing malware, brokers moving stolen cards, and money launderers spreading profits around the globe. “Everyone had a role and everyone got paid accordingly. It kind of looks like a Fortune 500 company.”
The investigation took years, not months, and attribution came down to a mountain of small clues rather than one smoking gun. Seleznev was eventually arrested during a vacation in the Maldives and sentenced to 27 years, which Keith noted is “still the largest sentencing of a cybercriminal the world has ever seen.”
Even Ransomware Has a Business Case
One of the more surprising threads in the episode is how ransomware itself has changed shape. Keith traced the arc back to 2019, when groups began pairing encryption with public shaming sites for double extortion. Today, many groups have dropped encryption altogether, and the reason is surprisingly mundane: cost.
“You're grabbing, it's not gigabytes, it's terabytes, could be petabytes of information,” Keith said, describing the infrastructure needed just to hold stolen data. Add in the expense of running a help desk to hand data back after payment, and many groups have decided that step is not worth it anymore. It is a small detail, but it says a lot about how criminal groups are optimizing for margin the same way any other business would.
The Underworld Runs like a Cartel
When Doug asked Keith to describe the structure of these groups, Keith compared them to a cartel. Groups divide labor along clear lines of responsibility, and loyalty often outlasts any single payday.
That structure is exactly why these networks are so hard to dismantle. With everyone covering for everyone else, and infrastructure constantly on the move, Keith said it “really makes it so difficult for law enforcement to go ahead and apprehend” anyone in these groups.
Preparation Beats Action Every Time
Keith emphasized the value of preparation in dealing with security incidents. He credited the Secret Service for drilling this into him early. “Preparation is key to everything,” he said. “Don't build your crisis plan during a crisis.” The organizations that handle a breach well, he says, are the ones that practiced long before the alarm ever went off.
That principle extends all the way to the boardroom. Keith argued that every board should be asking one question well before an incident happens: “If we're attacked tomorrow, what decisions do we have to make in the first 24 hours, and who's responsible for each one?” Most boardrooms simply assume someone else already has the answer. Usually, nobody does.
Crime Syndicates that Collaborate with Nation States
Doug asked Keith how the cybersecurity landscape has changed in the last few years. Keith explained that there's been a shift in the relationship between crime syndicates and nation-states: now the lines between the two have blurred.
"Nation states leverage criminal infrastructure," he said. North Korea serves as the prime example: they run a remote IT worker scam to fund their weapons program. Now, the same criminals steal data, extort victims, conduct espionage, and influence public opinion as one big enterprise rather than keeping those functions separate.
The merge of criminal enterprises and nation-states makes the landscape more dangerous for businesses because moving to the cloud expanded everyone's attack surface. AI has made it “dramatically easier” to impersonate identity with tactics like deepfakes and phishing, giving threat actors a more efficient way to get access and move laterally in systems.
AI Speeds Up Both Sides of the Fight
Doug and Keith discussed artificial intelligence in general. Keith refused to treat it as either a miracle cure or a doomsday device. “AI makes the defenders dramatically more efficient, but it also lowers the barriers for attacks,” he said. Criminals no longer need to write malware from scratch, and phishing, impersonation, and reconnaissance can all be automated. “AI isn't replacing the attackers or defenders. It's making both sides faster.”
The upside, in his view, is that defenders who embrace AI as part of their own toolkit gain real ground. The organizations that sit on the sidelines are the ones that fall behind.
It’s Not About How They Get In, But How They Move
Reflecting on incidents like the Colonial Pipeline shutdown and the Stryker attack, Doug framed the real lesson: “The reachability graph was insane at Stryker and at Colonial. People get so interested in how they get in. That's not the hard part. It's easy to get in. It's how quickly can you move? How pervasively can you move?”
Keith agreed without hesitation, pointing to how fast the damage spread once attackers had a foothold. “Two hours, and they got all these thousands and thousands of devices,” he said. “It's just phenomenal.”
Key Takeaways
Keith closed the episode by recommending two leadership books that shaped how he thinks about security: Turn the Ship Around and The Five Dysfunctions of a Team, both centered on trust and communication inside a team. Doug and Keith agreed on the importance of this trust and communication when it comes to cybersecurity.
“Cyber has certainly got a technical backbone . . . but it's a business problem and a business risk,” said Doug. Companies that treat it that way, with the CEO and board genuinely engaged rather than delegating it, are the ones that come out ahead.
Listen to the full episode for the rest of Keith's stories, including his take on nation-state actors, the changing economics of stolen credentials, and why he thinks the next major breach may already be quietly underway.
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.


















