Google has officially launched a new taxonomy for tracking cybercrime groups, signaling a departure from the collaborative efforts previously led by industry giants like Microsoft and CrowdStrike. The move suggests a shift in how major tech players categorize and report on digital threats, prioritizing internal clarity over universal consistency.
A Fragmented Landscape
For years, cybersecurity firms have attempted to align their naming conventions to help researchers and organizations identify common threats. However, with Google's decision to 'go it alone,' the industry faces a more fragmented landscape. While Microsoft and CrowdStrike have advocated for standardized names, Google’s new system will use its own internal identifiers to track state-sponsored and criminal actors.
The decision highlights a growing trend among tech leaders to develop proprietary intelligence frameworks. While this may provide Google with more flexibility in its reporting, it could complicate efforts for multi-vendor security teams who must now translate different names for the same threat actors across various platforms.








