Threat Trifecta: How Criminals Become You, Corner You and Watch You

Svperior’s passive scans across Swiss private wealth map early exposure signals to three outcomes: digital impersonation, extortion and invisible access.

The answer

Passive exposure signals matter because they show the openings criminals can use to impersonate trusted people, create extortion leverage or preserve invisible access. They do not prove compromise. Leaders should map each signal to a plausible attack sequence, identify the control that should stop it and demand current internal evidence that the control works.

At 08:42, a relationship manager receives a message from a managing partner.

The name is right. The writing sounds right. The conversation contains details from a live transaction. A second message arrives through another channel. The same identity confirms a revised payment instruction.

Everything works because the criminal has become the managing partner inside systems carrying real authority.

At 14:10, a different firm receives a sample of its own confidential files. Trust deeds. Passport scans. Private correspondence. A board recording. The sender offers a price for silence and a second price for restoration.

At a third firm, nothing dramatic happens. A quiet implant stays inside the environment. It reads, copies and waits. The operator learns who approves transfers, which clients face family disputes, where sensitive records live and how executives speak under pressure. Months can pass before access turns into action.

These are three distinct uses of digital access. Together, they form the Threat Trifecta:

  1. Become you: digital impersonation with genuine authority
  2. Corner you: extortion built from stolen information and operational disruption
  3. Watch you: unauthorised, persistent access that converts privacy into intelligence

Svperior maps early exposure signals to these three outcomes during periodic passive scans across private equity, private banks, wealth managers, trustees, fiduciaries and family offices in Switzerland.

A passive scan observes an organisation from public vantage points. It stays outside target systems and uses public signals only. Those signals reveal pieces of attack surface criminals can see: domain registrations, mail-security posture, exposed services, internet-facing software, leaked credentials, public staff information, forgotten subdomains, certificates, remote-access portals and infrastructure drift.

Exposure signals show opportunity. Internal telemetry and forensic evidence establish compromise. Keeping those categories separate protects the integrity of every finding.

Become you

Most discussions of impersonation stop at a lookalike domain.

A criminal registers a variation of a company’s name, copies its website and sends a crude message to a client. That technique still appears. It also represents the outer edge of the problem.

High-value impersonation aims for digital equivalence.

The attacker acquires a real password, steals a live session, enrols an authentication device, compromises an executive’s browser or persuades a help desk to reset an account. They enter a genuine mailbox, collaboration platform or client system. They inherit its history, address book, permissions and institutional credibility.

From that position, a criminal can:

  • Read current conversations and learn their cadence
  • Identify pending transfers, distributions and capital calls
  • Study who questions instructions and who executes quickly
  • Create mailbox rules that hide warnings and replies
  • Send from a genuine address inside an existing thread
  • Approve requests through a trusted account
  • Reach shared files, calendars, contact lists and recorded meetings
  • Impersonate an adviser across email, voice, messaging and video
  • Use one trusted identity to compromise another

Systems respond to valid credentials, sessions and tokens. A successful identity takeover gives the criminal the same digital treatment as the legitimate user until another control interrupts the session.

Swiss reporting shows the distinction clearly. NCSC recorded 73 cases of invoice-manipulation fraud in the second half of 2025, rising from 49 during the same period a year earlier. Its analysis explains how criminals enter company email accounts, search real correspondence for customer orders or invoices, then alter live communications so payments reach an attacker-controlled IBAN.

This is impersonation at system level. The criminal writes from inside the relationship.

The FBI reported over 5,100 account-takeover complaints and losses exceeding US$262 million from the start of 2025 through its account-takeover alert. Criminals impersonated financial institutions, captured credentials and gained access to financial, payroll and savings accounts. The objective was authority over an existing account.

Artificial intelligence raises the quality of the performance. Public speeches provide voice samples. Video calls provide facial movement. Websites and social media expose names, roles and relationships. Compromised mailboxes supply private vocabulary. A persuasive impersonation can now carry a familiar face, familiar voice, familiar context and genuine account.

Early signals connected to impersonation

Passive scanning can surface:

  • Newly registered domains resembling a firm, executive or investment vehicle
  • Weak or unenforced SPF, DKIM and DMARC controls
  • Public email addresses tied to finance and executive roles
  • Exposed reporting lines, travel, transactions and new appointments
  • Corporate credentials appearing in breach data
  • Forgotten login portals and legacy authentication endpoints
  • Brand-copy websites, cloned social profiles and fraudulent advertisements
  • Domain and certificate changes around subsidiaries or portfolio companies
  • External services that permit weak authentication
  • Public details that reveal payment authority and approval structure

FINRA’s 2026 oversight report specifically directs financial firms to monitor newly created imposter domains, fraudulent social accounts and customer-account takeover activity. Those activities belong in the same defensive picture. Brand monitoring watches the costume. Identity security protects the person criminals want to become.

Controls that break digital equivalence

  • Phishing-resistant multifactor authentication for email, cloud, remote access and privileged accounts
  • Managed-device requirements and conditional access
  • Short session lifetimes for sensitive systems
  • Strict recovery and help-desk verification
  • OAuth application and token review
  • Registrar locks, defensive domains and enforced DMARC
  • Separate-channel verification for payment and account changes
  • Behavioural alerts for new devices, locations, forwarding rules and authentication methods
  • Executive protection across personal and corporate identities
  • Rapid revocation procedures for credentials, tokens and active sessions

An email warning banner has limited value once a criminal owns the real account. Identity controls decide the outcome.

Corner you

Private wealth organisations hold concentrated leverage.

A modest fiduciary can possess a client’s passport, trust structure, tax records, beneficial ownership, banking instructions, property records, legal disputes, private photographs, health information, security arrangements and family correspondence. A private-equity firm may hold deal models, lender terms, investor details, management communications and portfolio-company access. A family office can contain an entire life in digital form.

Extortion converts that concentration into pressure.

A modern extortion operation usually moves through a sequence:

  1. Enter through an exposed service, compromised identity, supplier or employee
  2. Discover data, identities, backups and administrative systems
  3. Expand access across the environment
  4. Copy sensitive information to attacker-controlled infrastructure
  5. Damage recovery by targeting backups, identity systems or virtualisation
  6. Encrypt production data or disrupt operations
  7. Prove possession with selected files
  8. Apply pressure through clients, regulators, employees, media and leak sites

CISA calls the combination of data theft and encryption “double extortion.” Criminals can also run a pure data-extortion attack, using disclosure as the sole weapon.

Swiss authorities have watched this model at close range. NCSC describes Akira campaigns that exfiltrate information, encrypt systems and publish stolen data through a darknet leak site when payment fails. During periods of intense activity, authorities observed four to five cases a week in Switzerland.

The pressure extends far beyond system restoration.

A trustee may face exposure of beneficiary identities and private family arrangements. A wealth manager may have to warn clients whose security depends on discretion. A private bank can face regulatory reporting, legal discovery, client flight and questions about cross-border data. A private-equity firm may see confidential transactions, portfolio vulnerabilities and investor communications released in sequence.

Criminals can study stolen material before negotiation. They know which documents carry emotional force, which clients generate reputational risk and which deadlines create urgency. Some ransomware groups now use stolen information to identify regulatory consequences and sharpen their demands.

Mandiant’s 2026 research describes criminals systematically targeting backups, identity services and virtualisation. These systems determine whether a victim can recover independently. Control over them gives the attacker stronger leverage at the negotiating table.

Early signals connected to extortion

Passive scanning can surface:

  • Internet-facing VPNs, firewalls, remote desktops and file-transfer products
  • Software versions linked to known exploitation
  • Exposed administrative interfaces and remote-management services
  • Public storage endpoints and misconfigured applications
  • Leaked corporate, supplier and contractor credentials
  • End-of-life systems visible at the perimeter
  • Forgotten infrastructure linked to acquisitions, funds or former offices
  • Sudden changes in hosting, certificates, DNS or public services
  • Exposed development, backup or staging environments
  • Third-party services with privileged connectivity into the firm

CISA’s exposure-reduction guidance explains why this work matters. Misconfigured systems, default credentials and outdated software can appear through public internet-discovery platforms. Criminals and defenders can observe the same exterior.

Verizon’s 2026 breach report places vulnerability exploitation at the front of 31 percent of breaches. Third-party involvement appears in 48 percent. An exposed edge device or supplier connection can become the opening scene of an extortion event.

Controls that reduce criminal leverage

  • Continuous inventory of internet-facing assets
  • Rapid patching for actively exploited edge vulnerabilities
  • Phishing-resistant authentication for remote and privileged access
  • Segmentation between users, servers, identity, backups and administration
  • Immutable backups protected by separate credentials
  • Rehearsed restoration of critical services and data
  • Data classification and reduction of unnecessary copies
  • Monitoring for unusual outbound data movement
  • Strict supplier access, logging and expiry
  • An extortion playbook covering leadership, counsel, regulators, insurers and clients

Backup recovery solves one piece of the event. Stolen information creates a separate crisis with its own timeline.

Watch you

Some intruders value continued access above immediate payment.

They install an implant, create a hidden account, abuse a remote-management tool, preserve a stolen token or place a backdoor on an edge device. The access becomes a listening post.

Security teams use terms such as malware, spyware, backdoor, persistence mechanism and command-and-control implant. “Daemon” captures the behaviour in plain language: a background process runs quietly and performs work for a remote operator.

Its capabilities depend on the device, privileges and malware. A capable implant may:

  • Record keystrokes and capture screens
  • Steal browser sessions, passwords and authentication tokens
  • Copy files and email
  • Observe chats and collaboration tools
  • Activate microphones or cameras on compromised endpoints
  • Collect network and system information
  • Monitor new documents and removable media
  • Open an encrypted channel to an operator
  • Install additional tools
  • Survive restarts, password changes or ordinary maintenance

The human equivalent would be an unseen observer sitting inside every sensitive meeting, copying every document and learning every routine. Digital access scales that surveillance across time and systems.

Patience creates strategic value.

An operator can wait for a capital call, transaction, family dispute, leadership absence or market event. They can sell the foothold to another criminal group. They can prepare an extortion operation. They can manipulate a payment at the precise moment it appears routine. The same access can serve fraud, espionage, blackmail or competitive intelligence.

Mandiant’s 2026 incident data puts numbers around the silence. Global median dwell time rose to 14 days. BRICKSTORM, a stealthy backdoor associated with long-running intrusions, averaged 393 days of dwell time in examined cases. Mandiant warns that common 90-day log retention can erase the evidence needed to reconstruct such an intrusion.

Edge devices deserve special attention. Firewalls, VPNs and network appliances often sit beyond conventional endpoint monitoring. An implant living there can observe traffic and preserve access while laptop security dashboards remain green.

FINMA’s 2025 Risk Monitor supplies a local measure. Among cyberattack reports from supervised institutions, unauthorised access represented 37 percent, identity fraud 14 percent and malware 9 percent. FINMA also found limited monitoring of people with legitimate access to sensitive systems and data.

Invisible access includes criminals, compromised suppliers, former employees and abused legitimate tools. Every pathway deserves evidence, telemetry and expiry.

Early signals connected to invisible access

External observation has a firm boundary. A passive scan can identify conditions that support persistence. Internal investigation establishes whether an intruder currently occupies the environment.

Relevant external signals include:

  • Internet-facing management services and edge appliances
  • Weak authentication on remote-access systems
  • Legacy gateways with known persistence techniques
  • Unmanaged hosts and certificates outside the approved inventory
  • Services appearing through unfamiliar providers or locations
  • Breached credentials tied to administrators and suppliers
  • Publicly exposed development or monitoring tools
  • Long-lived forgotten subdomains and infrastructure
  • Remote-management products facing the internet
  • Technology fingerprints associated with unpatched vulnerabilities

These findings answer a crucial question: where could an operator establish and preserve a foothold?

Internal threat hunting answers the next one: has anyone already done it?

Controls that make silent access visible

  • Endpoint detection across workstations and servers
  • Network detection focused on unusual outbound communication
  • Identity telemetry for sessions, tokens, privilege and account creation
  • Logging from firewalls, VPNs, cloud control planes and edge appliances
  • Retention measured against long-dwell intrusions
  • Regular audits of OAuth applications, forwarding rules and service accounts
  • Strict control of remote-monitoring and management tools
  • Egress filtering and DNS monitoring
  • Privileged-access workstations and time-bound administration
  • Periodic threat hunts guided by external exposure findings

Antivirus sees a portion of this terrain. Visibility has to reach identity, network, cloud, email, endpoints and infrastructure at the edge.

Little-guy syndrome

Private wealth firms often ask a reasonable question:

“Why would a criminal choose us when UBS exists?”

Scale is one part of attacker economics. Defensive friction is another.

A global bank carries immense value. It also carries security operations centres, fraud teams, threat intelligence, hardened payment controls, specialist responders, legal power and intense regulatory attention. A successful campaign may require a long, expensive confrontation with a well-equipped institution.

A boutique wealth manager, trustee or family office can hold similarly consequential information for a smaller group of people. Its technology team may consist of a few staff and several suppliers. Security monitoring may run during office hours. One employee may administer email, endpoints, backups and remote access. Incident response may exist as a document awaiting its first live test.

This creates an attractive ratio: concentrated value divided by defensive friction.

Automation strengthens the economics. Criminals can scan thousands of domains, mail servers, VPNs and credentials. They identify exposed organisations before learning their revenue or headcount. A vulnerable service selects the victim.

Verizon’s 2025 analysis found ransomware in 88 percent of breaches affecting smaller organisations in its SMB data. Financial services also remained among persistently targeted industries. Mandiant’s 2026 investigations placed finance at 14.6 percent of targeted industries, second across its casework.

Small firms also provide routes into larger institutions. A fiduciary communicates with banks. A family office instructs custodians. A fund manager connects to administrators, lawyers and portfolio companies. Trust flows across those relationships. Criminals can monetise the firm directly or use its identity to reach everyone who trusts it.

“Little” describes headcount. It says nothing about the value of access.

Reading early signals correctly

An external scan produces clues. Mature security work converts those clues into decisions.

For each signal, leadership should ask:

  1. Which Threat Trifecta outcome can this exposure enable?
  2. What sequence would connect the signal to money, information or control?
  3. Which control should interrupt that sequence?
  4. Can the firm prove the control operates today?
  5. Which internal evidence would confirm active exploitation?
  6. Who owns investigation and how quickly must it begin?

A lookalike domain maps first to impersonation. A vulnerable VPN maps to extortion and invisible access. A leaked administrator credential can feed all three. One exposure can sit at the intersection of several criminal outcomes.

Priority should follow consequence and ease of exploitation. A public typo on a brochure carries little urgency. A remote-access gateway with active exploitation and privileged connectivity carries immediate risk. A leaked password protected by phishing-resistant authentication creates a different decision from one protecting email with a reusable code.

The framework keeps scanning connected to human stakes.

Become you means trusted systems and people accept a criminal as genuine.

Corner you means private information and operational dependence become leverage.

Watch you means an unseen operator learns the organisation from inside and chooses the moment of action.

Authority begins before impact

Switzerland’s private-wealth economy runs on discretion, authority and trusted instruction. Each quality creates value for clients. Each quality also attracts criminals who know how to copy identity, weaponise confidentiality and exploit silence.

Periodic passive scanning gives defenders an attacker’s exterior view. It reveals the openings, names and technical signals available before a campaign reaches its decisive stage.

The Threat Trifecta gives those signals meaning.

A domain issue becomes a possible route to impersonation. An exposed service becomes a possible route to extortion. A forgotten gateway becomes a possible home for invisible access. Leaders can then assign urgency according to the outcome at stake.

The decisive question carries three parts:

Who could become us?

What could corner us?

Where could someone watch us?

An organisation that can answer those questions with current evidence has authority over its digital exposure.

Everyone else is waiting to learn which threat arrives first.

Sources

  1. Swiss NCSC: Semi-Annual Report 2025/2Swiss NCSC

    Primary authority

  2. Swiss NCSC: Cybercrime — The AKIRA group steps up its activitiesSwiss NCSC

    Primary authority

  3. FINMA: Risk Monitor 2025FINMA

    Regulator

  4. FBI: Account Takeover Fraud via Impersonation of Financial Institution SupportFBI / IC3

    Primary authority

  5. FBI: 2025 Internet Crime ReportFBI / IC3

    Primary authority

  6. FINRA: 2026 Annual Regulatory Oversight ReportFINRA

    Regulator

  7. CISA: Internet Exposure Reduction GuidanceCISA

    Primary authority

  8. CISA: StopRansomware GuideCISA

    Primary authority

  9. Google Cloud and Mandiant: M-Trends 2026 Executive EditionGoogle Cloud and Mandiant

    Industry guidance

  10. Verizon: 2026 Data Breach Investigations ReportVerizon

    Industry guidance

  11. Verizon: 2025 Data Breach Investigations ReportVerizon

    Industry guidance

Jonathan P. De Collibus

Jonathan co-founded Svperior in 2014 and leads its cyber practice. His work sits where adversarial pressure, technical architecture, and consequential decisions meet, with experience across clinical, financial, public-sector, and private-client systems where confidentiality, continuity, and technical correctness carry material consequences.

Cyber strategy / Adversarial assessment / Security architecture / Private systemsRead Jonathan's full biography

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry