Women Are Playing an Expanding Role in Cybercrime. Security Teams Are Not Paying Enough Attention

New Sophos research reveals that women are playing a growing and diverse role in cybercrime, from social engineering and insider recruitment to ransomware development and hacktivist operations. Security teams that ignore this shift are building incomplete threat models.

Salma Mubarak
Cloud Security & AI Security Contributor6 min read
Cybersecurity analyst reviewing threat intelligence data on a monitor in a modern corporate office environment

Cybersecurity analyst reviewing threat intelligence data on a monitor in a modern corporate office environment

The profile of the typical cybercriminal has long been a fixture of security awareness training: a young man in a hoodie, likely Russian or British, almost certainly operating alone. New research from Sophos is challenging that assumption directly, with findings that show women are playing an increasingly significant and varied role across the criminal cyber ecosystem, and that enterprise security teams which have not updated their threat models accordingly are operating with a blind spot.

Rebecca Taylor, a cybersecurity researcher at Sophos, has been conducting a study into the gender dynamics of underground forums and criminal cyber operations. Her findings, shared at the Cybernews-reported conference and covered in a detailed analysis, point to a measurable shift in how the criminal underground operates and recruits.

Underground forums: from hostile to meritocratic

A decade ago, female participation in underground forums was actively discouraged. Women who identified themselves on hacker forums were frequently harassed, and their reputation scores (the currency of trust in criminal communities) were deliberately undermined. That dynamic has changed significantly.

"Forums are very open to diversity of thought, experience, and skill sets now," Taylor says. The shift appears to be tied to the professionalisation of the cybercriminal economy. As underground forums have evolved into functioning marketplaces with service listings, reviews, and affiliate programmes, merit has increasingly trumped identity. In some documented cases, being female may now function as an advantage.

A 2023 Trend Micro study by researcher Mayra Rosario Fuentes, which surveyed five English- and Russian-language forums, found that 40% of visitors to those forums were women. That figure is notably higher than the proportion of women working in legitimate cybersecurity roles, and it carries a direct implication: the criminal labour pool is drawing from a broader demographic than the security industry has historically assumed.

The same study found that underground forums actively sought out women for specific roles, particularly social engineering and recruitment of insiders within target organisations. The reasoning given by forum members was practical: female callers are perceived as more trustworthy by potential victims, making them more effective in voice-based phishing (vishing) operations.

Ransomware gangs and skilled female operatives

The case of Alla Witte, a 55-year-old Latvian mathematician who went by the alias "Max" within the Trickbot malware network, is one of the clearest examples of how gender assumptions fail in cybercrime attribution. Witte was responsible for creating and managing key malware used by the Trickbot operation. When she was arrested by the FBI in 2021 and charged with 19 counts relating to the cybercriminal network, members of the Conti ransomware group, which the Trickbot infrastructure served, rallied to provide legal support for her. The fact that she used a gender-neutral alias, and that her colleagues knew her gender and supported her regardless, is illustrative of the meritocratic shift Taylor describes.

The internal Conti data leaked in 2022 (the "ContiLeaks") confirmed Witte's role and the use of female pronouns in internal communications -- evidence that, within the operational structure of one of the world's most damaging ransomware operations, gender was not a barrier to technical leadership.

Hacktivist operations and state-linked activity

Women have also appeared in documented roles within state-backed hacktivist operations. Yuliya Vladimirovna Pankratova, who appeared on a US sanctions list in 2024, managed the Telegram channel for Cyber Army of Russia Reborn (CARR) and served as its public voice under the alias "Mother of Bears." According to Google's Mandiant threat intelligence team, she helped produce content linked to a cyberattack on a Texas-based water treatment facility. Far from retreating after being identified, Pankratova publicly celebrated female participation across the group's operational roles: designers, defacers, and distributed denial-of-service operators.

This pattern of female involvement in state-adjacent hacktivist activity is consistent with broader research indicating that adversarial states, particularly Russia, have increasingly integrated civilian technical talent into information operations regardless of gender.

The insider recruitment channel

One of the more operationally significant findings in Taylor's research concerns the use of women to recruit insiders within target organisations. Underground forums have posted requests specifically for female participants in social engineering operations that extend into the physical workplace, convincing employees to provide credentials, bypass access controls, or install remote access tools under pretexts such as IT support.

For enterprise security teams in the region, this is a direct concern. Insider threat programmes that profile potential risks using demographic assumptions, skewing toward younger male employees with technical roles, will miss the recruitment vectors that criminal organisations are actively exploiting.

What this means for enterprise security teams

The practical implication of Taylor's research is straightforward: threat models built on a demographic stereotype of who commits cybercrime are incomplete and will generate detection gaps. This applies at multiple levels.

Social engineering detection programmes that train employees to recognise "suspicious" callers based on assumed profiles should be revised to focus on behaviour rather than voice, gender, or assumed technical sophistication. Vishing remains one of the most effective initial access methods available to criminal organisations, and the evidence suggests it is increasingly delivered by female operatives precisely because that delivery channel carries lower suspicion.

Insider threat programmes should similarly audit their detection logic for demographic bias. If risk scoring systems assign lower weight to female employees or to roles perceived as non-technical, those systems may be systematically underweighting real threat vectors.

For organisations building or reviewing their security awareness training, the message is also relevant. Threat actors, whether operating for criminal or state-aligned purposes, recruit opportunistically and meritocratically. Any employee with access to sensitive systems or credentials is a potential recruitment or manipulation target, regardless of role or demographic profile.

"If we are trying to prevent, detect, and respond, we need to really open our eyes to the fact that the attacker or the threat is not just a boy, or a man; it could genuinely be anyone," Taylor says.

Security operations teams across the MENA region that are building or refreshing their insider threat and social engineering detection programmes should treat this research as an input to their modelling, not a peripheral concern.

Salma Mubarak

Cloud Security & AI Security Contributor

Salma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.

At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.

Intelligence Focus Areas

threat intelligencesocial engineering attacksinsider threat managemententerprise security awarenesscybercriminal underground economyMENA threat landscaperansomware ecosystemsecurity operationsattribution challengesworkforce security risk