---
title: "Cybercriminals Are Always Evolving Their Techniques; Your…"
description: "Stay ahead of cyber threats by understanding how cybercriminals exploit IoT, use QR codes, evolve ransomware, bypass MFA, and use sophisticated social…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Cybercriminals Are Always Evolving Their Techniques; Your Cyber Team Should Too - Christian Espinosa",
      "description": "Stay ahead of cyber threats by understanding how cybercriminals exploit IoT, use QR codes, evolve ransomware, bypass MFA, and use sophisticated social…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/fbbc079c-e918-4540-9b8f-f3efc699ba0c/cybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too-card.png",
      "datePublished": "2023-02-09T04:17:19+00:00",
      "dateModified": "2026-06-26T05:32:46.425Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/cybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Cybercriminals Are Always Evolving Their Techniques; Your Cyber Team Should Too - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "In this post, we review trends related to cybercriminals, their approaches, and discuss ways to arm your technical team with the right skills to win the cyber war."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, technical leaders trying to build teams that actually communicate, not just execute. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Secure Methodology](/blog/category/secure-methodology)

# Cybercriminals Are Always Evolving Their Techniques; Your Cyber Team Should Too

February 9, 2023 7 min read 1,536 words 

Cybercriminals are persistent and determined. These are great qualities to have in a technical field. For my organization, it means risk and threats are never static. They are always changing, evolving their techniques to exploit weaknesses and vulnerabilities.

![](/__l5e/assets-v1/e78d4b04-4b43-4c8d-afe8-e31621805209/cybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too-hero.webp)

The takeaways

1.  01 
    
    These are great qualities to have in a technical field.
    
    What to do next Name one person on your team where great is the bottleneck, and coach them on it this quarter.
    
2.  02 
    
    For my organization, it means risk and threats are never static.
    
    What to do next Score your team from 1 to 10 on risk this week, then share the score with them and ask what would move it up one point.
    
3.  03 
    
    They are always changing, evolving their techniques to exploit weaknesses and vulnerabilities.
    
    What to do next Run a 15-minute conversation with your team about always at the next stand-up, and listen more than you talk.
    
4.  04 
    
    While some of this upskilling is technical, much of it involves soft skills and developing the attributes that enable flexibility, proactiveness, and perseverance.
    
    What to do next Name one person on your team where upskilling is the bottleneck, and coach them on it this quarter.
    

Cybercriminals are persistent and determined. These are great qualities to have in a technical field. For my organization, it means risk and threats are never static. They are always changing, evolving their techniques to exploit weaknesses and vulnerabilities. My team must as well. I can’t use the same methods against new challenges.

While some of this upskilling is technical, much of it involves [soft skills](https://christianespinosa.com/blog/how-to-develop-soft-skills-in-your-cybersecurity-team/) and developing the attributes that enable flexibility, proactiveness, and perseverance. In this post, I'll review trends related to cybercriminals and their approaches. I'll discuss ways to arm my technical folks with the right skills to win the cyber war.

## Cybercriminal Trends

Cybercriminals diversify their attacks and find new avenues to pursue all the time. The trends in cybersecurity relating to their approaches offer some insights for me, a cybersecurity professional.

### Vulnerable Entry Points Are Attractive Targets

The proliferation of IoT (Internet of Things) devices has been a monumental implementation for many industries. They collect data for various applications that deliver intelligence to organizations, including health care, manufacturing, and retail.

For all the benefits they bring, they are also the most vulnerable endpoints. Cybercriminals are becoming IoT experts and have infiltrated these devices and been able to transfer between them. It’s familiar ground for hackers to find out how to endanger security through something that helps businesses operate based on data-driven decisions.

### The QR Code Comeback

Cybercriminals look for ways to use technology trends to plan attacks. QR codes have been around for some time and had a resurgence during the pandemic, including scanning them for menus. Advertisers use them in CTV (connected TV) and broadcast TV ads, prompting users to scan them while watching. A [Super Bowl commercial in 2022 for Coinbase](https://www.theverge.com/2022/2/13/22932397/coinbases-qr-code-super-bowl-ad-app-crash) featured a QR code (and not much else). It was so popular that the site crashed.

Hackers follow consumer preferences and create malicious QR codes that direct people to fake sites.

### Ransomware Keeps Adapting

Cybercriminals invested lots of time and energy into ransomware attacks in 2022. According to data, ransomware increased [by 13%](https://www.verizon.com/business/resources/reports/dbir/) in 2022. Cybersecurity has great concerns over ransomware, as many organizations experience it regularly, some with dire consequences, such as disrupting healthcare delivery.

The attraction to this method is the money. Many businesses have paid the ransom to retrieve access to data. Even those with backups and mature cybersecurity defenses can be a victim. The adaptation of ransomware occurs as hackers attempt to breach networks.

### Hackers Expose Multifactor Authentication Shortcomings

Multifactor authentication (MFA) has been a tenet of cybersecurity and access control. The premise is to require more than a password, but hackers have found ways around this. One example is an attack created by Lapsus$ and Yanluowang threat actors. It bypasses the MFA framework through spamming original account holders, referred to as MFA bombing, MFA spamming, or MFA fatigue. It’s worked successfully in incidents involving Microsoft and T-Mobile.

### Phishing and Social Engineering Are So Sophisticated

The earliest days of phishing were almost comical in delivery. The misspellings and awkward phrases were easy to spot. That was long ago, and hackers are more advanced and sophisticated in social engineering efforts.

It hinges on manipulation and the receiver believing the hacker is truly someone else. More of this is happening at the business level, with employees receiving communications from leadership asking for help. This email spoofing to impersonate others has become very effective. Hackers also use multiple channels, including email, SMS, SIM jacking, and piggybacking.

There has also been an increase in the use of [Google properties for phishing](https://www.techrepublic.com/article/hackers-exploit-google-docs-in-new-phishing-campaign/). Millions of people use Google Drive and Google Ads for business. Hackers are attempting to “share” documents, “tagging” in the comments of documents, or inviting you to access a Google Ad account. For many, it would seem a logical email to receive and click, and that’s what hackers are counting on them doing.

### Cybercriminals Focus More on Smaller Fish

Most of the headlines about cyberattacks involve well-known companies. It’s more newsworthy since these can cause outages and downtime and impact millions. However, most hackers don’t put a target on these whales. Smaller fish are easier to penetrate, and many have valuable data. Small- and medium-sized businesses (SMBs) often have less strong cybersecurity protocols and may be dealing with being understaffed as well.

It’s an ideal scenario for hackers eager to infiltrate a network and take control. The result can be a data breach with the aim of selling these assets on the dark web or ransomware. SMBs are highly aware that they are a target but lack the resources to combat them in many cases.

### Cybercrime as a Service Lowers the Barrier to Entry

A new phenomenon, cybercrime as a service, is another troubling hacking trend. Hackers are for hire, so bad actors no longer need technical aptitude. Rather, they can find a cybercriminal on the dark web to do their bidding. These groups operate like legit businesses in many ways, with developers and engineers.

Seeing the commoditization of cybercrime is a concern for tech teams. It’s increasing the number of attacks, and their sophistication is improving daily.

As you can see, hackers never rest on their laurels. They evolve their methods consistently to reach their goals. It’s the same approach the good guys should also take. Here’s how to keep pace with cybercriminals.

## Keeping Pace with Cybercriminals; Cyber Professionals Must Adapt Too

Developing your team’s capabilities and expanding them should be a priority for you as a leader. Such a strategy involves both technical and people skills. Focusing on continuous improvement is a requirement to outperform today’s hackers. Here are some critical steps you can take.

### Being Proactive versus Reactive

A lot of cybersecurity is reactive. It’s how you’ll respond to a threat or attack. All that’s necessary. You have to have a cyber resilience and contingency plan in place. It can often overshadow being proactive, which is something organizations find difficult.

The barrier to being proactive is not so much technical failures. Much of the time, it’s the people and the way they communicate, collaborate, and operate. Cyber professionals tend to think in black and white and crave certainty. There’s much fear around what they perceive as new territory, so they stay set in their ways. As a result, you incur more risk because there’s limited exchange of information or ideas.

To be more proactive, you’ve got to break down those silos and create an environment where communication and collaboration are a priority. You must be an example and find ways to hone these people skills through exercises and other activities. If everyone’s not on the same page, you’ll be stuck in reactive mode, which gives hackers an edge.

### Creating a Cybersecurity Culture

A [cybersecurity culture](https://christianespinosa.com/blog/the-cyber-threat-no-one-talks-about-the-absence-of-a-cybersecurity-culture/), in this respect, alludes to the principles and values of your technical team. Building a team that can swiftly adapt requires healthy people skills, including [communication](https://christianespinosa.com/blog/why-communication-aptitude-is-the-number-one-soft-skill-cybersecurity-professionals-must-possess/), awareness of self and others, trust, a growth mindset, and empathy. It may seem daunting to pursue this, but it’s critical in the cyber war.

When these things are absent, your company increases risk. The environment may be toxic, with bullying, posturing, and disengagement. Any hacker would love to attack such an organization, so it’s critical not to be one of these!

Constructing and maintaining this culture requires several key elements:

-   Employees need to know that their contributions matter and how they align with the company’s goals and wins.
-   Encouraging the growth of each individual and acknowledging their improvements.
-   Continuous development of strong communication skills, including what people say, how they say it, and how they listen.
-   Removing self-centered thinking patterns and embracing [cognitive empathy](https://christianespinosa.com/blog/the-secure-methodology-step-six-empathy/?roistat_visit=172849).

### Emphasizing Innovation

Cyber professionals understand innovation, often more from a technical lens. That’s crucial, but a culture of innovation is where new ideas thrive. If you open up your team to operate this way, many great things can happen regarding security. One way to make it front and center is to define what innovation means to your team and discuss ways to sustain it over time.

There is often a misnomer about security being the downfall of innovation. That’s not true, and the two can work in tandem, such as in the framework of [DevSecOps](https://christianespinosa.com/blog/why-organizations-should-pivot-to-devsecops/). There should be a constant link between security and innovation. It’s a continuous cycle of improvement that enables better results, which are easy to understand for technical folks.

## Cybercriminals vs. Cyber Professionals: Winning the War

On the battlefield, cybercriminals and cyber professionals are at war. Cybercriminals have had many advantages, much of which are due to their constant evolution and adaptability. Keeping up with hackers involves cyber professionals doing the same thing.

With these tips, your team can forge ahead. You can find more advice and resources for this in my book, _The Smartest Person in the Room_, which features the Secure Methodology™, a seven-step guide to transforming technical people into better communicators and collaborators. [Get your copy today](https://christianespinosa.com/books/the-smartest-person-in-the-room/).

Frequently asked

### What is the core idea behind "Cybercriminals Are Always Evolving Their Techniques; Your Cyber Team Should Too - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too&text=Cybercriminals%20Are%20Always%20Evolving%20Their%20Techniques%3B%20Your%20Cyber%20Team%20Should%20Too) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too) [Email](mailto:?subject=Cybercriminals%20Are%20Always%20Evolving%20Their%20Techniques%3B%20Your%20Cyber%20Team%20Should%20Too&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Does Your Cyber Team Have a “Bad” Reputation? Why Their Lack of Soft Skills Causes Friction - Christian Espinosa
    
    Same thread: secure methodology.
    
    Read essay → ](/blog/does-your-cyber-team-have-a-bad-reputation-why-their-lack-of-soft-skills-causes-friction)
-   [
    
    ### Does Your Cyber Team Truly Understand Your Threat Landscape? - Christian Espinosa
    
    Same thread: secure methodology.
    
    Read essay → ](/blog/does-your-cyber-team-truly-understand-your-threat-landscape)
-   [
    
    ### Cybersecurity Isn’t Black and White: Why Cyber Leaders and Their Teams Must Embrace the Gray - Christian Espinosa
    
    Same thread: secure methodology.
    
    Read essay → ](/blog/cybersecurity-isnt-black-and-white-why-cyber-leaders-and-their-teams-must-embrace-the-gray)

[← Previous essay 

Cybersecurity Workforce Retention: Keep Top Talent with the Secure Methodology - Christian Espinosa

](/blog/cybersecurity-workforce-retention-keep-top-talent-with-the-secure-methodology)[Next essay → 

Does Your Cyber Team Have a “Bad” Reputation? Why Their Lack of Soft Skills Causes Friction - Christian Espinosa

](/blog/does-your-cyber-team-have-a-bad-reputation-why-their-lack-of-soft-skills-causes-friction)

Related, Leadership

### Bring this conversation to your team

Christian keynotes on cybersecurity leadership, ego in tech, and building human-first technical teams. Available for corporate events, conferences, and executive offsites.

[Book Christian to speak](/speaking)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)