Cybercrimeology
Whodunit.gov.org: Behaviour and Cyber Attribution
Episode Summary
Can the choices made during a cyberattack help tell us who is behind it? Priscilla F. Aybar from Florida International University joins us to discuss her research examining the behaviour of state-sponsored and non-state cyber actors. We talk about rational choice, behavioural signatures, the challenges of cyber incident data and what different approaches to visibility, targeting and disruption might tell us about attribution.
Episode Notes
Notes:
- Ms. Aybar traces her interest in criminal justice, government and politics back to childhood. She recalls her father having her choose a current event from the Sunday newspaper and then discussing it with him, and says she already knew by seventh grade that she wanted to attend John Jay College of Criminal Justice.
- Her route into cybercrime came through advertising and political campaigns. As digital advertising became increasingly important, she encountered problems with advertisements being directed toward bots rather than people and became involved in applying fraud-prevention techniques to campaigns. This experience sparked a wider interest in cybercrime.
- After beginning her PhD, Ms. Aybar worked on a research assignment involving USAID and DAI focused on enhancing Ukraine’s cybersecurity posture. The work led her further into the national-security side of cybersecurity and into studying nation-state, non-state and other cyber actors.
- Ms. Aybar and her dissertation chair, Dr. Rob T. Guerette, used environmental criminology and rational choice theory to examine whether state-sponsored and non-state cyber actors demonstrate different behavioural signatures. Rather than focusing only on the tools used in an attack, the approach considers the choices attackers make around risk, reward, effort, visibility, operational security and what they are ultimately trying to accomplish.
- The study uses data from the European Repository of Cyber Incidents (EuRepoC), allowing the researchers to look for patterns across a large number of publicly documented cyber incidents over time. Ms. Aybar notes that this scale is useful, but also stresses that the data only represent incidents that are visible, recorded and attributable rather than the full universe of cyber activity. Changes in the threat landscape, actor names and APT naming conventions also create challenges for classification and consistency.
- The clearest distinction in the study was that non-state actors were more associated with high-visibility and immediate-impact activity, including ransomware, disruption, doxxing and publicly confirming responsibility for an attack. State-sponsored or state-affiliated actors were more associated with lower-visibility strategic activity, particularly data theft and reduced operational disruption.
- From a rational choice perspective, Ms. Aybar suggests these differences reflect different incentives. Non-state actors may benefit from visibility, pressure or immediate financial gain, while state-linked actors may have reasons to preserve access, avoid attention and quietly collect intelligence or strategically valuable data. She emphasizes that, regardless of the category of actor, there are still people behind the screens making these choices.
- Not all of the study’s expectations were supported. The researchers expected state-sponsored actors to be more likely to target state and political systems, but this was not supported in their first theoretically guided model. Ms. Aybar suggests this may reflect strategic indirection: a state-linked actor can pursue a state-level objective by targeting contractors, universities, infrastructure dependencies, supply-chain intermediaries or private companies rather than attacking a government agency directly.
- Ms. Aybar’s planned dissertation consists of three studies. The first will develop behavioural baselines for state-linked cyber operations associated with China, Iran, North Korea and Russia and compare their operational and visibility patterns. The second will examine time to public attribution and whether behavioural characteristics are associated with how quickly an actor is publicly named.
- Her third dissertation study will examine ransomware crime scripts in the biotechnology and life sciences sector compared with general enterprise cases. The aim is to identify points in the ransomware process where situational crime-prevention techniques could potentially disrupt an attack.
- This work has also led Ms. Aybar toward the emerging area of cyber biosecurity. She is interested in what happens when cyber threats intersect with biological data, laboratory systems, pharmaceutical research, AI and the wider bioeconomy, approaching these issues from a cybercrime and national-security perspective.
About our guest:
Priscilla F. Aybar, M.A.
Florida International University — International Crime and Justice PhD Program
https://ccj.fiu.edu/people/ph.d.-students/
Papers or resources mentioned in this episode:
Aybar, P. F., & Guerette, R. T. (2026). Rational choices in cyberspace: Quantitative insights into targeting and attack behavior among cyber offenders. Journal of Criminal Justice, 103, 102621. https://doi.org/10.1016/j.jcrimjus.2026.102621
Pixalate & The Democratic Congressional Campaign Committee (DCCC): How the DCCC used Pixalate to reduce ad fraud
A case study featuring Ms. Aybar’s work using invalid-traffic detection and advertising analytics to reduce ad fraud in political digital campaigns.
https://www.pixalate.com/case-study-dccc-ad-fraud-protection
European Repository of Cyber Incidents (EuRepoC)
https://eurepoc.eu/database/