
Technology
Cyber Gangs and Identity Access Management
In the Age of AI, bad actors have exploited digital toolboxes to impersonate individuals.

In the Age of AI, bad actors have exploited digital toolboxes to impersonate individuals. Many of these toolkits are accessible on the dark web, where Cybercrime as a Service (CaaS) has flourished, fostering the development of intricate supply chains as malicious actors specialise in various facets of attack engineering.
An attack surface may therefore involve many subcontractors focusing on specific verticals during an assault. CaaS operates as a business model in which threat actors or vendors provide various hacking and cybercrime services to others, often on a subscription basis, allowing those with limited technical skills to undertake sophisticated attacks. Clients identify the type of service they wish to procure and then pay a subscription fee or a commission, typically using cryptocurrency to preserve anonymity.
Ransomware as a service (RaaS) is a business model that deploys skilled cyber gangs that code bespoke ransomware strains and package them with other useful tools for deploying a successful attack. This service is offered as a toolkit and as a subscription-based service. Partners who subscribe to these services either pay a monthly subscription or a commission. RaaS is a segment of a larger malware-as-a-service (MaaS) model where clients have access to trojans, viruses, and worms for a fee. Some service providers offer “off the shelf” packages ready for immediate deployment without any need for customisation. This allows bad actors to target who they want, and with whatever delivery mechanism they prefer to deploy, during a multiphase wave attack sequence.
A distributed denial of service (DDoS) attack overpowers targeted resources with a deluge of malicious traffic. This disrupts access for legitimate users making the affected service or App frustratingly inaccessible. The swarming influx of traffic in a DDoS attack emanates from a network under the control of an adversary, known as a botnet. Each machine in the botnet is typically infected with malicious software that enables outside control of the device.
Zero-day vulnerabilities usually attract millions of dollars on the dark web. A zero-day vulnerability exploits a software glitch that the software developer is unaware of and therefore has had zero days to create a working patch that fixes it. This is “exploit-as-a-service”. Exploit-as-a-service is an emerging trend. Purveyors of zero-day services lease zero-day vulnerabilities to customers rather than sell them.
The most fascinating trend in Identity Access Management (IAM) is the recognition of Non-Human Identities. Managing the identities and access permissions of machines, algorithms, and Apps has become as crucial as managing Human Identities. This trend is the most worrisome one in the Age of AI and underscores the significance of a comprehensive IAM strategy that encompasses both human and non-human identities.
At the core of digital workspaces and e-commerce strategies, there must be a robust identity and access management (IAM) system. IAM comprises the processes, technologies, and tools used to control and monitor access to a firm’s digital resources, networks, applications, and data sets. IAM serves both as a shield and as a target for attackers. Recently, the complexity of identities has become a favoured target for malicious actors in the infosphere.
An IAM system is used to verify users’ identities, manage role – and permission-based access, and secure sensitive information from unauthorized access, data breaches, and legal penalties. Bureaucracies and private companies must stay abreast of emerging trends to maintain and manage effective IAM systems.
The level of administrative complexity has increased with multicloud and hybrid deployments. Cloud Native Computing Foundation and the OpenID Foundation are collaborating with vendors and enterprises on standards to address emerging concerns and enhance the interoperability of access systems. Anti-money laundering mandates have traditionally been the domain of financial institutions and state agencies. However, this represents a fresh frontier in enterprise identity and access management. The growing need for standards to prevent phishing and denial of service (DoS) attacks is now drawing attention.
Cyber insurance risk management requires bureaucracies and private companies to implement sound identity hygiene and access management for their employee and citizen-facing platforms, which can help reduce cyber insurance premiums. Cyber insurance brokers will seek to examine frameworks for cyber risk governance, privilege access reviews and rectifications, least privilege access, and critical account protection to measure and calibrate risks.
Every second, in a world where authority is delegated to AI, millions of automated processes and service accounts access sensitive data without human oversight. These automated non-human identities (NHIs) operate beneath the AI assemblages and platforms to power cloud applications, automation, and microservices.
These NHIs authenticate and execute automated processes between cloud technologies and third-party integrations. This allows Apps, virtual machines, and scripts to have secure access to resources. The number of NHIs is growing. NHIs now outnumber human users creating a tapestry of identities that needs curation. Traditional identity and access control fall short.
At this juncture, Latin America and the Caribbean must consider the building of Zero-Trust Architectures (ZTAs). This is unlike the old security architectures. ZTA makes no assumptions. It trusts no one whether inside or outside the network. It is cumbersome and requires constant authentication and verification of users and devices. The constant need to authenticate and verify makes it difficult for threat actors to navigate networks with ease.
, Fazal Ali · 01 May 2025 -
Next entry · Technology
AI and these brown leaves of islands
The war has always been between what we should become and what we could become. Our unfinished souls remain moored in the sea, our monuments and memories locked in a blue vault.
