A Crew of Teenagers

Lapsus$ was not a nation-state. It was a group of teenagers. In 2022, City of London Police arrested seven people between the ages of sixteen and twenty-one, and two of them, aged sixteen and seventeen, were convicted in a London court. Before any adult knew their names, that crew of kids had already breached Microsoft, Nvidia, Okta, Samsung, and Rockstar Games.

Sit with that. A handful of teenagers, no state behind them, walked a structured path from no capability to inside some of the most defended companies on earth. Nobody sold them a weapon. Somebody sold them the training and the tooling, and nobody checked who they were.

That is the problem I want to talk about, and it runs in both directions.

Why I Am Writing This

I spent eight years in the Marine Corps. I served as a police officer and worked gang investigations. I now work as a platform and application security engineer, building and securing the systems this piece is about. I am writing in my personal capacity. The views here are mine alone.

I have done intelligence collection under a legal framework. Association mapping, social media exploitation, pattern of life, source development. Every piece of it was governed. There were rules of evidence, chain of custody, supervisory review, and a standard I could lose my career over. When I built a profile on a subject, someone could audit how I built it.

I now watch the identical collection happen commercially, at scale, against anyone, sold by operators nobody has vetted to buyers nobody has identified. Same tradecraft. No framework.

I also watched gang recruitment work up close. I know what it looks like when a fourteen-year-old gets pulled into something he does not understand the consequences of, and I know the difference between the ones who got intercepted and the ones who did not. That is why what follows is not only restrictive. Interdiction without an off-ramp does not work. It did not work on the street and it will not work here.

One Capability, Both Sides of the Problem

A single unregulated capability sits on both sides of the child safety problem. It is the on-ramp for the minor who becomes an offender, and it is the targeting tool used against the minor who becomes a victim.

Children as offenders

The Lapsus$ crew was not an outlier. Scattered Spider, responsible for major casino and retail intrusions, has included minors among its membership. Booter and stresser services have been marketed to minors for over a decade, and the UK National Crime Agency ran deterrence advertising aimed specifically at teenagers searching for those services, because the buyer population was that young.

These were not state actors. They were adolescents who found a structured path from no capability to enterprise intrusion, followed it, and were inside major corporations before any adult knew their names.

Children as targets

The same open-source collection capability that gets sold as OSINT training is being used to locate, identify, and coerce minors. The FBI has issued public advisories on violent online networks that deliberately target children, using doxxing and open-source identification to build leverage against victims and to coerce escalating self-harm and abuse content. Financial sextortion targeting minors has produced documented suicides in the United States.

Every one of those operations depends on identifying and locating a child. That identification capability is sold commercially, with no verification of the purchaser of any kind.

We regulate neither side. That is the whole problem in one sentence.

What I Am Not Saying

I need to be exact here, because this is the part people skip when they get angry.

I am not asking anyone to take security research off the internet. I am not proposing a restriction on tool possession, publication, or research. Not a ban on security education, conference talks, or academic instruction. Not anything that touches independent study or unpaid practice on systems you own or are authorized to test.

Offensive cyber knowledge is the defensive skill. Detection engineering, threat modeling, and incident response all require understanding attacker technique. Any framing that criminalizes the blue team is a framing I will oppose, loudly, including if it comes from my own side.

What I am asking is narrower. The commercial layer, the part where money changes hands and access is granted to unverified people, should carry the same accountability every comparable trade already carries.

The Law Already Points This Way

People assume the First Amendment makes all of this untouchable. It does not, and the case law is clearer than most assume.

Start with Giboney v. Empire Storage and Ice Co. (1949). Speech that is integral to criminal conduct gets no First Amendment protection at all. That is the foundation under everything else.

Rice v. Paladin Enterprises (4th Cir. 1997) makes it concrete. A publisher put out a murder-for-hire instruction manual, and the court held it was not shielded by the First Amendment, because the publisher intended the work to be used by actual criminals. The theory was aiding and abetting, not incitement. The lesson is the one that matters most here: instructional content loses its protection based on intent and audience, not on subject matter. What the manual was about did not decide it. Who it was for, and why, did.

Holder v. Humanitarian Law Project (2010) is the single most important case in this whole argument. The Supreme Court upheld a federal ban on providing training and expert advice to certain groups, including instruction that was itself entirely peaceful. Training can be criminalized based on who receives it. That is the constitutional footing for a knowing-transfer rule.

A few more do real work. United States v. Williams (2008) held that offers to provide or requests to obtain unlawful material are unprotected even when the deal never closes. New York v. Ferber (1982) put weight on the other side of the scale, holding that protecting children is a governmental interest of surpassing importance, strong enough to sustain content restrictions that would fail anywhere else. And Universal City Studios v. Corley (2d Cir. 2001) settled that code has both an expressive and a functional side, and regulation aimed at the functional side draws intermediate scrutiny, not the strictest kind.

The Cases That Cut Against Me

I am not going to hide the authority that runs the other way. Any proposal that dodges its own weak points is not ready to be drafted, so here they are.

Brandenburg v. Ohio (1969) is the one people will throw at me first. Incitement requires speech directed at imminent lawless action and likely to produce it, and general instructional content will never clear that bar. That is exactly why I do not rest any of this on incitement. The theory is aiding and abetting under Rice and Holder, which turns on intent and recipient, not imminence.

Junger v. Daley (6th Cir. 2000) held that computer source code is protected speech, and it is live precedent. Bernstein v. Department of Justice (9th Cir. 1999) held the same in the export-control context, though that opinion was withdrawn pending rehearing and the case resolved without a governing holding, which limits its weight. It will still get cited against me in every room, so I name it myself.

Free Speech Coalition v. Paxton (2025) upheld Texas age verification under intermediate scrutiny, and it looks more helpful to me than it actually is. That material was obscene as to minors and therefore already unprotected for that audience. Security instruction is protected speech, including for minors, so age verification for training would likely draw strict scrutiny instead. I flag that against my own interest, because a legislator will find it eventually and should hear it from me first.

Van Buren v. United States (2021) narrowed the Computer Fraud and Abuse Act, part of a judicial trend that has run toward narrowing computer-crime liability, not expanding it. And NIFLA v. Becerra (2018) draws the line I have to stay on the right side of: licensing that regulates conduct is valid, licensing that restricts the content of speech is not.

Congress Has Already Built This Once

The model already exists in federal law. 18 U.S.C. 842(p) makes it an offense to distribute explosives information with intent that it be used for a crime of violence, or knowing the recipient intends exactly that. The information stays lawful. The knowing transfer to someone you know means harm does not. That intent element is the entire reason the statute has survived, and it is the spine of what I am proposing.

It is not the only precedent. 18 U.S.C. 2339B, the statute upheld in Holder, already criminalizes material support that expressly includes training and expert advice. 18 U.S.C. 1030(a)(6) makes trafficking in passwords with intent to defraud a crime. 18 U.S.C. 1029(a)(4) reaches device-making equipment. And 18 U.S.C. 2258A already imposes reporting duties on providers around child exploitation, which is precedent for putting affirmative obligations on platforms in exactly this context.

Put it together and Congress has already accepted that transfers of capability around computer intrusion can be criminalized on their own, separate from the intrusion itself. What I am asking for is an extension of an accepted line, not a brand new one.

The Rest of the World Is Ahead of Us

This is not theoretical anywhere else.

The UN Convention against Cybercrime, the Hanoi Convention, was adopted by the General Assembly in December 2024 and opened for signature in Hanoi in October 2025. It matters here because it carries both halves of my argument in a single treaty. It provides for punishing the misuse of devices, covering procurement, production, sale, import, and distribution, and it is the first global treaty to criminalize online child sexual abuse material and the online grooming of children. The international community has already put tool distribution and child protection inside one frame. I am asking the United States to implement that link at home.

The older Budapest Convention (2001) did the same in narrower form. Its Article 6 requires criminalizing the production, sale, procurement, import, and distribution of tools designed to commit computer offenses, and Article 9 addresses child exploitation material. The United States ratified in 2006, but with reservations that narrowed how far Article 6 reaches domestically, so anyone leaning on this in testimony needs to check the exact scope of that reservation first.

There is more, and it is worth naming. The Lanzarote Convention (2007) protects children against sexual exploitation and abuse. The UN Convention on the Rights of the Child, in Articles 19 and 34, requires protection from violence and exploitation. In the European Union, Directive 2013/40 requires member states to criminalize the production and distribution of intrusion tools, and Germany implemented it through StGB 202c. The United Kingdom's Computer Misuse Act, at section 3A, reaches making, supplying, or obtaining articles for use in computer misuse, and it also shows the failure mode I want to avoid: its "believes it is likely to be used" standard has been criticized by the UK security industry as chilling legitimate research, to the point that prosecutors had to issue guidance to contain it. The tighter "intends or knows" standard in 842(p) is the correct model, and it is why I keep coming back to it.

On the licensing side, Singapore has licensed penetration testing and managed security providers since 2022, and Malaysia stood up a parallel regime in 2024. Neither security industry collapsed. And the United Kingdom runs Cyber Choices, a diversion program for young people drifting toward computer crime. The United States has no equivalent, and that gap is the entire reason my last proposal item exists.

The Proposal

Here is what I would actually build, ordered from most durable to most fragile. I have flagged the weak items rather than hiding them.

  1. License commercial offensive security services. If you perform or offer penetration testing, red team, or adversary emulation against systems you do not own, you hold a state license. Background check, insurance, written authorization on file per engagement, revocable for cause. This is conduct regulation, the same authority under which Georgia already licenses private detectives, security agencies, and locksmiths. Licensure also cuts the other way: it gives good-faith testers a real legal safe harbor instead of the prosecutorial discretion they operate on today.

  2. Clarify that commercial OSINT collection already falls under private detective licensing. Georgia's own guidance treats computer forensics as private detective business. Commercial OSINT collection is the same activity. This is a clarification, not an expansion, and the cheapest first step is a letter asking for a ruling, not a legislative session.

  3. A knowing-transfer offense for operator-tier instruction, modeled directly on 842(p). Knowingly providing offensive instruction with intent that it be used to break the law, or knowing the recipient intends to. The intent element is not negotiable. It is the entire constitutional basis, and it is what keeps general publication, academic instruction, conference talks, and independent study untouched.

  4. Purchaser verification at the operator tier. Identity verification for platforms selling operator-grade offensive curricula, records available on lawful process. This is the weakest item on constitutional grounds, per the Paxton problem above, and I would advance it as a study-committee question rather than a bill in the first instance.

  5. Diversion and a legitimate way in. A diversion pathway for minors drifting toward computer crime, modeled on the UK's Cyber Choices. Paired with funded legitimate entry: VA-eligible training for transitioning service members, apprenticeships that do not require a degree, a credentialed path for people with no money.

The Off-Ramp Is Not Decoration

That last item is the one I will not trade away.

I came into this field through free training. If a framework closes that door without opening another, it produces fewer defenders and the same number of offenders. I watched interdiction without an off-ramp fail in gang work, over and over, on real kids. I am not going to propose it again here and pretend the outcome will be different.

Regulating who may sell the service, verifying who may purchase operator-grade instruction, and attaching liability to a knowing transfer to someone intending a crime, all of that can be done without touching the research, the teaching, or the kid teaching himself in his bedroom. That kid might be the next great defender. The goal is to keep his door open while closing the storefront that sells targeting capability to the person hunting him.

What This Is Not, and Where It Goes

To say it one more time, plainly. This is not a restriction on tool possession, publication, or security research. Not a ban on education, conference talks, or academic instruction. Not applicable to independent study or unpaid work on systems you own or are authorized to test.

Regulating artifacts fails. The Wassenaar Arrangement's 2013 intrusion-software controls were drafted broadly enough to burden defensive coordination and took years to renegotiate. Regulating who may sell the service, verifying who may buy operator-grade instruction, and attaching liability to knowing transfer to a person intending a crime does not carry that defect.

The next step I am asking for is a study committee to examine licensing of commercial offensive security and OSINT services, using Singapore and Malaysia as reference models, and to evaluate the constitutional viability of the harder items. I am available to testify, to give a technical briefing, or to work with counsel on the language. I spent a career on both sides of this, the collection and the protection. I would rather help build the framework than keep watching the gap where one should be.