Full Report
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
Analysis Summary
# Morning News Roll-up August 19, 2026
## Overview
Today's intelligence focus centers on the adoption of **Crime Script Analysis (CSA)** as a narrative-driven method to bridge the gap between technical security teams and non-technical stakeholders. By decomposing complex attacks—specifically Business Email Compromise (BEC)—into human-readable stories, defenders can better identify "choke points" where AI-driven industrialization of cybercrime can be disrupted.
## Top Stories
### Describing Attacks with Crime Script Analysis
- Summary: Martin Lee explores how Crime Script Analysis (CSA) provides a narrative alternative to MITRE ATT&CK, making threat intelligence accessible to non-technical audiences. The report highlights how attackers use AI to automate the reconnaissance and social engineering phases of BEC, transitioning from high-value/low-volume fraud to low-value/high-volume "industrialized" attacks.
- Source: [hxxps://blog[.]talosintelligence[.]com/describing-attacks-with-crime-script-analysis/]
---
# Crime Script Analysis for BEC Disruption
## Key Points
- **Narrative-Driven Defense**: CSA decomposes attacks into a sequence of actions, decisions, and situational requirements, acting as an "architect's artistic impression" compared to the "blueprints" of MITRE ATT&CK.
- **AI Industrialization**: AI is now used to automate the first four stages of the BEC script (Target Identification, Role Identification, Lure Preparation, and Personalization), making previously unprofitable small-scale targets viable for attackers.
- **Strategic Choke Points**: By viewing the attack as a script, defenders can identify specific intervention points where the workflow can be broken, such as during the delivery phase or through the use of "canary organizations."
## Threat Actors
- **BEC Scammers**: Historically focused on high-value corporate targets due to the manual research required.
- **AI-Enabled Fraudsters**: Now expanding scope to small businesses, community organizations, and sports clubs by leveraging Large Language Models (LLMs) to automate reconnaissance and lure generation.
## TTPs
- **Target Identification**: Using AI agents to crawl public personas and identify organizations with financial authority.
- **Social Engineering (Lure Generation)**: Generating urgent, context-aware payment requests via LLMs to improve credibility.
- **Impersonation**: Spoofing superiors or those with financial authority within an organization.
- **Phishing/Email Delivery**: High-volume delivery of fraudulent payment requests.
- **Money Laundering**: Rapid movement of funds through various accounts to disguise origin immediately after victim payment.
## Affected Systems
- **Email Infrastructure**: Primary delivery mechanism for BEC lures.
- **Financial Processing Systems**: Targeted for unauthorized payment releases.
- **AI/LLM Platforms**: Exploited by attackers to generate malicious content and conduct reconnaissance.
- **Victims**: Small to medium-sized businesses and community organizations previously considered "low value."
## Mitigations
- **Canary Organizations**: Deploying fictitious honeypot entities to seed AI reconnaissance tools. If a honeypot receives a lure, the source can be immediately blocked.
- **AI Provider Monitoring**: Implementation of detection patterns by LLM providers to identify repeated malicious prompts or social engineering generation.
- **Email Rate Limiting**: Implementing reputation-based blocks and rate-limiting on accounts showing anomalous high-volume outgoing mail.
- **Strict Financial Controls**: Requiring verified purchase orders and mandatory delays/multi-person approvals before payments are released.
- **Security Awareness**: Training staff to recognize the specific narrative "tone" and urgency common in BEC scripts.
## Conclusion
Crime Script Analysis serves as a vital communication tool that complements technical frameworks like MITRE ATT&CK. As threat actors increasingly use AI to scale BEC operations, defenders must move beyond technical indicators and focus on disrupting the operational narrative. The most effective defense remains a combination of automated email filtering (Step 6) and rigorous internal financial processes (Step 7).