Mandiant: one-third of all hacker groups exploiting zero-days in 2021 were financially motivated criminals as opposed to government-backed cyberespionage groups
Patrick Howell O'Neill / MIT Technology Review :
Context & Ripple Effects
Mandiant's predecessor FireEye spent the 2010s framing zero-days as a state weapon: its global tracking of exploits from 2012 to 2019 tied the use of 55 zero-days to state-sponsored operations. The new 2021 finding — that a third of groups exploiting zero-days were financially motivated criminals — marks a break from that picture.
The shift fits the broader arc in the coverage: China's state hacking already increasingly relies on private-sector hackers, and criminal crews like Lapsus$ have shown that commodity-grade intrusions can hit weaknesses neither spies nor ransomware gangs had prioritized. Mandiant's data suggests top-tier exploits are no longer the exclusive province of espionage.
First-order effects
- Mandiant's incident-response clients can no longer assume a zero-day intrusion means a nation-state actor — triage, attribution and disclosure decisions now have to weigh criminal motive, with different legal and insurance implications.
- Financially motivated crews now compete in the same exploit market as intelligence agencies, putting upward pressure on zero-day prices and squeezing defenders who budget for state-grade attacks only.
Second-order effects
- Exploit brokers and vulnerability researchers gain a second deep-pocketed buyer class: where espionage stockpiles exploits quietly, criminal buyers monetize them fast through ransomware and extortion, changing how quickly discovered flaws burn out.
- The monetization channels the coverage documents — from concentrated cryptocurrency-theft operations to extortion campaigns — give criminal groups the revenue to justify zero-day spend that was previously uneconomic.
Third-order effects
- If the pattern holds, the zero-day economy structurally splits into two demand curves — state stockpiling and criminal monetization — eroding the assumption that exploit capability maps to geopolitical actors and complicating export-control and disclosure policy built around that assumption.
- Defenders and insurers will increasingly price risk on capability rather than motive, pushing the industry toward treating any zero-day use as financially motivated until proven otherwise — a reversal of two decades of attribution doctrine.
The trend: Zero-day exploitation is shifting from a near-monopoly of state-sponsored espionage groups toward a mixed state-and-criminal market, with financially motivated buyers becoming a structural share of demand.