Letter No. 118 July 2026 Cybersecurity · Dark Web · Investment

Tom & Jerry

The dark web runs 24 hours a day, 7 days a week, across every jurisdiction on earth. Global law enforcement agencies coordinate against it constantly. The dark web still somehow wins. Stay alert — and invest in cybersecurity.

There is a game being played right now — at this exact moment — on servers bounced through Tor nodes in Romania, Indonesia, and the Netherlands. Stolen credit card numbers are being sold. Ransomware toolkits are being rented for $200 a month. Corporate login credentials harvested in last Tuesday's data breach are being auctioned to the highest bidder. Fentanyl is being shipped in padded envelopes marked as vitamins. Child exploitation material is being distributed. And somewhere in a government operations centre in Washington, London, The Hague, or Canberra, a team of analysts is watching, tracing, preparing. They will make arrests. They will seize servers. They will celebrate. And within weeks, sometimes days, the market relocates, rebrands, and reopens. Tom and Jerry. Except Tom never quite catches Jerry.

This letter is not about the horror of the dark web — though the horror is real and should not be minimised. It is about what this persistent, unresolvable cat-and-mouse game means for investors. Because the answer is clear: it means the cybersecurity industry is structurally guaranteed to grow, structurally guaranteed to be funded, and structurally incapable of declaring victory. That combination — permanent necessity, permanent demand, no finish line — is an unusual investment thesis. It deserves serious attention.

"Cybercrime is now estimated to cost the global economy $10.5 trillion annually by 2025 — more than the GDP of every country except the United States and China."

What the Dark Web Actually Is

The internet most people use — Google, banks, social media, news sites — is the surface web, indexed by search engines and accessible through standard browsers. Below it sits the deep web: everything behind login screens, paywalls, and databases — your bank account, hospital records, corporate intranets. The dark web is a subset of the deep web that requires specific software to access, most commonly Tor (The Onion Router), which anonymises traffic by bouncing it through multiple encrypted relays before it reaches its destination. The IP address you see is not the IP address of the sender. Tracing it requires compromising multiple nodes simultaneously — a technically and legally complex operation across multiple jurisdictions.

The dark web is not inherently criminal. Journalists in authoritarian countries use it. Whistleblowers use it. Privacy advocates use it. But it is also home to an economy of extraordinary scale and sophistication. Silk Road — the first major dark web marketplace, shut down by the FBI in 2013 — processed over $1 billion in transactions in its lifetime. Its successors have been larger, faster, and more resilient. AlphaBay, shut down in 2017, was ten times the size of Silk Road at its peak. Hydra, the Russian-language dark web market, processed an estimated $1.37 billion in 2020 alone before being seized in 2022. Each shutdown spawns multiple successors within months.

The Five Pillars of the Dark Web Economy

Stolen data. Credit card numbers, bank login credentials, social security numbers, passport scans, corporate email credentials. The 2021 RockYou2021 compilation contained 8.4 billion leaked password records. A fresh batch of credit card numbers sells for $10–$20 each. Corporate VPN credentials — the keys to an entire company's network — sell for $500–$15,000 depending on the revenue of the target organisation. This is not a cottage industry. It is a mature commodity market with price discovery, reviews, and refund policies.

Ransomware-as-a-Service (RaaS). Ransomware — malicious software that encrypts a victim's files and demands payment for the decryption key — has become a franchise business. Criminal groups develop the ransomware and rent it to affiliates who conduct the attacks, splitting the ransom payment. LockBit, ALPHV/BlackCat, and Cl0p operated as RaaS platforms at scale. The average ransom payment in 2024 reached $2.73 million. Colonial Pipeline paid $4.4 million. Change Healthcare paid $22 million. These are not exceptional cases — they are the business model.

Drug markets. The dark web drug trade has profoundly changed the global narcotics market. Fentanyl analogues synthesised in Chinese and Mexican laboratories reach users in Kansas, Kent, and Kyoto through postal systems. The quality is more consistent than street supply. The distribution is more anonymous. The violence associated with traditional drug distribution networks is substantially reduced — replaced by logistics, customer reviews, and escrow services. Law enforcement finds this simultaneously easier and harder than street dealing: the digital trail is richer, but jurisdiction is a permanent problem.

Cybercrime tools. Zero-day exploits — previously unknown software vulnerabilities — are sold for hundreds of thousands of dollars. Phishing kits, credential harvesters, malware loaders, and botnet access are available on a subscription basis. The commoditisation of these tools has dramatically lowered the barrier to entry for cybercrime. You no longer need technical sophistication to execute a ransomware attack. You need $200 and a willingness to follow instructions.

Illicit financial services. Cryptocurrency mixing services launder the proceeds of dark web transactions by breaking the blockchain trail. Fake identity documents — passports, driving licences, national ID cards — enable money mule networks and fraud. The dark web has, in effect, built a parallel financial system optimised for anonymity and deniability.

Why Law Enforcement Cannot Win

This is the Tom and Jerry problem stated precisely. Law enforcement wins individual battles constantly. Operation Bayonet took down AlphaBay and Hansa simultaneously in 2017 — a masterstroke of coordinated international policing that briefly collapsed the dark web drug market. Operation SpecTor in 2023 resulted in 288 arrests across nine countries and the seizure of $53 million in cash and cryptocurrency. Europol, the FBI, the DEA, and a constellation of national agencies coordinate at a level that would have been impossible fifteen years ago.

And yet. The structural problem is irreducible. The dark web is not a building you can raid. It is a protocol running on servers distributed across every jurisdiction on earth, including jurisdictions with no extradition treaty with the investigating country, no interest in cooperating, and no capacity to police their own digital infrastructure even if they wanted to. Russia hosts significant dark web infrastructure. North Korea runs state-sponsored cybercrime operations that have stolen billions. Iran and China maintain offensive cyber capabilities that blur the line between state and criminal activity. Jurisdiction is not a technicality — it is the fundamental problem.

The second structural problem is economic. The expected value calculation for a capable cybercriminal operating from a non-extradition country is strongly positive. The probability of prosecution is low. The probability of extradition, if prosecuted, is lower still. The potential upside — a successful ransomware campaign against a hospital or infrastructure operator — can yield millions. This is a rational economic choice for people with the requisite skills living in economies where those skills command wages a fraction of what a successful attack yields.

"Every time law enforcement seizes a dark web marketplace, the announcement of its closure is simultaneously an advertisement for its successors."

The Investment Case — Why This Is Structural

The cybersecurity market was valued at approximately $172 billion in 2023. It is projected to exceed $400 billion by 2030 — a compound annual growth rate of approximately 13%. This growth is not driven by marketing or fashion. It is driven by the expanding attack surface of the global economy: more devices connected, more critical infrastructure digitised, more sensitive data stored in cloud systems, more remote work creating more entry points for attackers.

Every major geopolitical event accelerates this. The Russia-Ukraine war produced the largest volume of state-sponsored cyber attacks in history. Colonial Pipeline demonstrated that ransomware could shut down fuel supply to the US East Coast. The Change Healthcare attack in 2024 paralysed US healthcare billing for weeks and exposed data on potentially one-third of all Americans. These events do not just generate headlines — they generate board-level decisions to increase cybersecurity budgets. They generate government mandates. They generate insurance requirements. The industry's customers have no choice.

This is the investment thesis in its simplest form: the attack surface grows every year, the attackers grow more sophisticated every year, the consequences of failure grow more severe every year, and the budget allocated to defence must therefore grow every year. Unlike most technology markets, this one does not face the risk of market saturation — because the adversary never stops innovating.

The Companies — Where the Money Is Going

CrowdStrike (CRWD). The dominant endpoint detection and response platform. Its Falcon platform uses AI to detect and respond to threats across endpoints — laptops, servers, cloud workloads — in real time. Annual recurring revenue exceeded $3.6 billion in FY2025. Net revenue retention above 120% — existing customers expand their spending year over year. The July 2024 software update incident caused a global IT outage affecting 8.5 million Windows devices and was a significant reputational event. CrowdStrike recovered — ARR continued to grow, customer retention remained high — demonstrating the structural stickiness of a platform that is deeply integrated into enterprise security operations. Replacing it has a switching cost that most enterprises are unwilling to pay.

Palo Alto Networks (PANW). The broadest platform in enterprise cybersecurity — network security, cloud security, AI-driven operations, and threat intelligence. Revenue exceeded $8 billion in FY2025. CEO Nikesh Arora's platformisation strategy — moving customers from point solutions to integrated platforms — has driven significant cross-sell revenue and deepened customer relationships. The company operates at the intersection of every major security trend: cloud, AI, zero-trust architecture. It is not cheap on a valuation basis, but it has demonstrated consistent execution over a decade.

SentinelOne (S). The autonomous AI security platform. Where CrowdStrike uses AI as an enhancement, SentinelOne was built from the ground up around autonomous threat detection and response — the platform takes action without human intervention. Annual recurring revenue growing above 30% year-over-year from a smaller base. Still loss-making but with a clear path to profitability as scale improves margins. The pure-play AI security story, for investors with a longer horizon.

Zscaler (ZS). The zero-trust network access specialist. As corporate networks have dissolved — remote work, cloud applications, no defined perimeter — the traditional approach of "trust everything inside the firewall" has become obsolete. Zscaler's cloud-native platform enforces zero-trust: every user, every device, every application authenticated and verified every time, regardless of location. Annual recurring revenue exceeding $2.5 billion, growing above 25% year-over-year. The structural beneficiary of hybrid work becoming permanent.

Fortinet (FTNT). The value play in enterprise security. Lower valuation multiples than CrowdStrike or Palo Alto, strong cash generation, dominant position in the mid-market firewall and network security segment. Less exciting story — more consistent execution. For investors who want cybersecurity exposure without paying peak growth multiples.

Darktrace (DARK — London). British AI cybersecurity company, listed on the London Stock Exchange. Its "immune system" approach uses unsupervised machine learning to establish a baseline of normal behaviour for every user and device, then detects anomalies without relying on known threat signatures. Particularly relevant for detecting novel attacks — including AI-generated attacks — that signature-based systems miss. Significant insider selling in 2023 was a concern; the company has subsequently stabilised and refocused under new management.

The AI Dimension — Both Threat and Opportunity

Artificial intelligence has changed the cybersecurity landscape in both directions simultaneously, and this is the most important development of the past two years. On the attack side: AI enables the generation of highly convincing phishing emails personalised to the target, voice cloning for social engineering, automated vulnerability scanning at scale, and the creation of polymorphic malware that changes its signature to evade detection. The barrier to a convincing, targeted attack has collapsed. A criminal with access to a large language model can now generate a phishing email indistinguishable from a genuine message from the target's CEO — in any language, at no marginal cost.

On the defence side: AI enables the real-time analysis of billions of events across an enterprise network to identify anomalous behaviour, the automated response to detected threats faster than any human analyst could act, and the prediction of attack vectors before they are exploited. The companies building AI-native security platforms — SentinelOne, Darktrace, the AI operations layers at CrowdStrike and Palo Alto — are not simply adding AI as a feature. They are building systems that learn the normal behaviour of every entity in a network and detect deviation at machine speed.

The net effect: AI has raised the capability ceiling for both attackers and defenders simultaneously. But the defenders have one structural advantage that the attackers do not — budget. The cybersecurity market's growth is funded by enterprise and government spending that dwarfs what criminal organisations can deploy. The long-term bet is that well-funded, AI-native defence platforms outpace well-funded but structurally constrained criminal operations. That bet has held for thirty years. AI makes it both more urgent and more interesting.

What to Watch and What to Avoid

Watch for platform consolidation. The enterprise security market has historically been fragmented — dozens of point solutions for different threats. The trend is toward consolidation around a small number of integrated platforms. CrowdStrike, Palo Alto Networks, and Microsoft are the three most likely platform winners. Companies that cannot achieve platform status — that remain point solutions without integration — face commoditisation and margin pressure. Watch which vendors your enterprise customers are consolidating onto.

Watch the insurance market. Cyber insurance pricing and underwriting requirements have become the most powerful force driving enterprise security investment. When insurers refuse to cover organisations without specific controls in place — multi-factor authentication, endpoint detection, network segmentation — those controls get implemented. The cyber insurance market is simultaneously a demand signal for cybersecurity spending and a quality filter for which security products are considered adequate. The companies whose products satisfy insurance underwriting requirements have a structural distribution advantage.

Avoid pure-play dark web intelligence companies that have not demonstrated clear enterprise revenue models. The dark web monitoring space has attracted significant venture capital on the thesis that every enterprise needs to monitor criminal marketplaces for its own stolen data. This is true — but the market structure for these products is less clear than for endpoint or network security, and many players have struggled to build durable revenue.

"The dark web does not need to win. It only needs to keep playing. And as long as it keeps playing, the companies defending against it will be paid."

The Verdict

The Tom and Jerry dynamic is not a failure of law enforcement. It is a structural feature of a technology that was designed for resilience and anonymity. The internet was built to survive a nuclear attack — to route around damage. The dark web exploits exactly that resilience. Every node taken down, the traffic reroutes. Every market seized, the vendors migrate. Every criminal arrested, three more start operating in jurisdictions beyond reach.

For the investor, this is not depressing — it is clarifying. The cybersecurity industry does not need the dark web to be defeated. It needs the dark web to keep existing, keep innovating, and keep attacking. And the dark web will oblige. The global cost of cybercrime growing at double digits every year is a guarantee of budget for the companies building the defences. Not a nice-to-have. A necessity — for every bank, hospital, power grid, government agency, and corporation on earth.

Stay alert. And invest in cybersecurity.

Core positions: CrowdStrike (CRWD), Palo Alto Networks (PANW), Zscaler (ZS). Secondary: SentinelOne (S), Fortinet (FTNT), Darktrace (DARK-L). Size according to your risk tolerance — these are growth-multiple stocks in a sector that does not have off years. The threat does not take a year off.

Pawan Bhatia

Founder, NextGen Economics · Bangalore, India · July 2026
Sources: Cybersecurity Ventures Global Cybercrime Report 2025 · Europol Internet Organised Crime Threat Assessment 2025 · FBI Internet Crime Complaint Center IC3 Annual Report 2025 · CrowdStrike FY2025 Annual Report · Palo Alto Networks FY2025 Annual Report · SentinelOne ARR Reports 2025–2026 · Zscaler Annual Report 2025 · Chainalysis Crypto Crime Report 2025 · Colonial Pipeline ransomware settlement documentation · Change Healthcare breach disclosure SEC filing 2024.
Not investment advice. All investments carry risk including loss of capital. This is independent research with no relationship to any company mentioned.