July 6, 2026

It's Just Blackmail: Geoff White's Field Guide to the Billion-Dollar Cybercrime Economy

It's Just Blackmail: Geoff White's Field Guide to the Billion-Dollar Cybercrime Economy

 

Here is the mental shift most businesses never make: cybercrime is not chaos. It is a mature, profitable industry — with franchises, pricing departments, career ladders and, by one count, its "first billion dollar year" already behind it. As Geoff White puts it, ransomware alone made "more than a billion" in a single year, "and by the way, that's a conservative estimate. That's just the ransoms we know about."

On BEYOND, Geoff White — an investigative journalist and cybercrime expert who reports for the BBC, Channel 4 and the Sunday Times — takes the fear out of the subject by doing something rare: he explains the business model. Understand how the money is made, and you understand exactly where to stand to protect your own. Here is his field guide.

 

Ransomware, Defined in One Sentence

Forget the jargon. "A hacker breaks into your computer, scrambles all your files, and charges you a ransom to unscramble them," Geoff says. "It's just blackmail." He points to Marks & Spencer as a recent, very public UK victim. The technology is sophisticated; the crime is ancient.

What makes it lucrative is not the encryption — it's the pricing. Gangs don't pluck a number from the air. They research you. "They can say you're insured for a million. We know you can pay a million. The ransom's a million," Geoff explains. Your revenue, your market cap, even a copy of your cyber-insurance certificate becomes the price tag. You are, in effect, being invoiced against your own accounts.

 

It Runs Like a Franchise

The detail that reframes everything is how the industry is *organised*. Ransomware, Geoff explains, operates on an affiliate model: the person who breaks in keeps most of the takings, and a cut flows back to the gang that supplied the software. "If the victim pays up, you get 80% and 20% kicks back to the ransomware," he says. "It's like Starbucks, Burger King, McDonald's."

This is not a metaphor for effect — it's the literal structure. There are software providers, operators, customer-service functions for victims who need help paying, and a brand reputation to maintain. Geoff calls it a "generational industry… around arguably 30 years now." You are not being attacked by a lone genius. You are up against a supply chain.

 

Geoff White making a point during his BEYOND interview, hand raised, podcast microphone beside him

 

The Con That May Out-Earn Ransomware

Ask most executives to picture a cyber-attack and they picture ransomware. Geoff wants you to worry more about something quieter: business email compromise. It is the fake invoice, the "we've changed our bank details" email that looks exactly like it came from a supplier you trust. It is unglamorous, and it is enormous — it "makes billions of dollars for crime gangs every year," Geoff says, and may now out-earn ransomware entirely.

Its evil twin is CEO fraud, now supercharged by AI. A finance employee gets a call, or even a video call, from the "boss" authorising an urgent transfer — and the voice and face are deepfaked. "Tens of millions has been taken out of company," Geoff notes. No malware, no locked files. Just a convincing lie, delivered at the speed of a Teams call.

 

Follow the Money — Because They Have To

The reason any of this matters to a criminal is the same reason it matters to you: at some point the stolen money has to be turned into spendable, clean money. That's laundering, and Geoff is one of the sharpest chroniclers of how it works– the subject of his most recent book, Rinsed. He describes the grubby, analogue reality behind the digital crime: the "placement" stage where dirty cash first enters the system, the cash-heavy small business quietly inflating its takings, a friend turned away from a dealership for trying to buy a car with £60,000 in cash. (For more on how dirty money moves through the legitimate economy, hear Aleksandra's conversation with financial-crime expert Jessica Cath on tackling financial crime.)

The takeaway for a business is bracing: you are not just a potential victim of theft. Your invoices, your accounts and your payment rails are the exact machinery criminals rely on to move value around. Defending them is a commercial responsibility, not just an IT one.

 

The Defence Is Cheaper Than the Attack

Geoff's most encouraging message is that you don't need a fortune to be a bad target. Criminals, like all rational businesses, chase the "low-hanging fruit." Make yourself marginally harder work, and the economics push them towards someone else. That means slowing down the moments that con artists exploit– the urgent payment, the changed bank details, the unexpected download– and building a culture where a moment's suspicion is rewarded, not overridden by politeness or panic.

 

Actionable Takeaways for Founders and Operators:

  • Verify every change of payment details out of band.** A "we've changed our bank account" email is guilty until proven innocent — confirm it by calling a known number, never the one in the email. This single habit neutralises most business email compromise.
  • Price your own risk before a criminal does.** Assume attackers can see your revenue and insurance. Know what you'd be quoted, and invest in prevention accordingly — it's cheaper than the ransom.
  • Make suspicion a policy, not a personality trait. Give staff explicit permission to pause an urgent payment or challenge an unexpected instruction from the "CEO." The friction you build in is the defence.

 

Listen to the full conversation on the Aleksandra King YouTube Channel, and browse the rest of the BEYOND library for more fearless conversations on how the modern world really works.