Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Underground Economy 2026

Solution Category Threat Intelligence
Type Conference
Organization Team Cymru
Event Format Physical
Size 500+ approximate delegates
Registration Not Free
SPEAKING OPPORTUNITIES

Search for other Cybersecurity Conferences in France in 2026-2027.

Conference Description

Key Takeaways

  • Invite-only cyber threat intelligence conference bringing together analysts, law enforcement and policymakers
  • Focus areas include malware analysis, cryptocurrency tracing, infrastructure hunting and cross-border operational collaboration
  • Closed-door format with confidential agenda designed to enable candid intelligence sharing
  • Hands-on workshops and practitioner-led sessions emphasise actionable skills over theoretical discussion
  • Eighteenth year of operation, reinforcing its established position within the global defender community

Introduction

The Underground Economy 2026 (UE26) returns to Strasbourg, France, as an invite-only gathering for the global cyber threat intelligence community. Now in its eighteenth year, the conference serves as a closed-door operational forum where cybersecurity analysts, law enforcement investigators and government policymakers work together on active cybercrime threats. At a time when criminal infrastructure spans multiple jurisdictions and threat actors operate with increasing sophistication, UE26 addresses the persistent challenge of coordinating defensive efforts across organisational and national boundaries.

About This Event

UE26 operates under strict confidentiality protocols, with its full agenda disclosed only to vetted and accepted attendees. This approach creates an environment where participants can engage in frank, operationally sensitive discussions without concern for public disclosure. The event is free for those who pass the vetting process, reflecting its emphasis on community contribution rather than commercial participation.

The conference format combines analyst-led sessions with hands-on workshops and live exercises. Rather than passive presentations, attendees engage directly with investigative techniques and defensive methodologies applicable to their daily work. Networking receptions provide additional opportunities for relationship-building among professionals who may later need to collaborate on time-sensitive incidents.

Threat Intelligence and Operational Collaboration

The conference programme centres on practical threat intelligence disciplines. Malware analysis sessions examine current attack tooling and techniques, while cryptocurrency tracing workshops address the financial investigation methods increasingly necessary as ransomware and fraud operations rely on digital currencies. Infrastructure hunting—the practice of identifying and mapping adversary command-and-control networks—features prominently, equipping analysts with skills to disrupt criminal operations before they escalate.

A distinguishing characteristic of UE26 is its treatment of cybercrime as inseparable from broader geopolitical and national security concerns. Sessions explore how state-affiliated actors, organised criminal groups and opportunistic attackers intersect, requiring defenders to understand motivations and relationships that extend beyond purely technical indicators. This perspective proves particularly valuable for attendees from critical infrastructure sectors, where attacks may carry consequences beyond data loss or financial harm.

Addressing Cross-Jurisdictional Challenges

One of the most persistent obstacles in cybercrime response is the mismatch between borderless criminal activity and jurisdiction-bound legal authorities. UE26 directly addresses this gap by convening professionals from multiple countries and sectors within a trusted environment. The relationships formed at the conference often prove essential when rapid coordination is required during active incidents, as established trust reduces the friction that typically delays cross-border information sharing.

The event’s longevity—spanning nearly two decades—has allowed it to develop into a recognised node within the global defender network. Many attendees return annually, creating continuity that strengthens collaborative capacity over time.

Who Should Attend

UE26 is designed for professionals with direct operational responsibilities in cyber defence and criminal investigation. Security operations centre analysts, incident responders, crime intelligence analysts and threat researchers represent the core audience. The conference also draws chief information security officers and security executives from government agencies, law enforcement bodies and critical infrastructure organisations who require current intelligence on the threat landscape.

Given the invite-only structure and vetting requirements, the event maintains a participant profile focused on practitioners rather than observers. This selectivity ensures that discussions remain operationally relevant and that sensitive methodologies can be shared without inappropriate exposure.

Industry Support

UE26 receives backing from organisations across the threat intelligence and security sectors. Cisco serves as diamond sponsor, with additional support from Human Security, ICANN, SpyCloud, Intel471, VulnCheck, TRM Labs and others. Meta and Google participate as digital and registration sponsors respectively. This breadth of industry involvement reflects the shared interest in strengthening collective defence capabilities against cybercrime.