EDBT 2026 Demo / reviewers in the wild / expert
Rolf van Wegberg
dblp:224/9337
· DBLP profile ↗
12ranked-venue papers
2as first author
10since 2021 · last 2026
0009-0004-1491-9867ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 9 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTsabstractIn this paper, we study the experiences of practitioners in sectoral Computer Security Incident Response Teams (CSIRTs)—specialized teams that mediate between national cybersecurity authorities and the sector constituency. Through interviews with 18 professionals connected to the Informatiebeveiligingsdienst (IBD-CSIRT) for Dutch local governments, we uncover tensions in how key services are valued. For vulnerability notifications, while the CSIRT staff consider them a core service, many constituents hardly mention them, and systemic gaps in information forwarding mean that crucial alerts often never arrive. We extend these insights with 5 interviews across other sector CSIRTs and a validation workshop with 7 participants, all security officers from sector CSIRTs, revealing shared challenges in balancing technical expertise with sector knowledge, building trust-based relationships, and navigating institutional bottlenecks. Our findings contribute the first systematic account of how sector CSIRT professionals understand and perform their role, highlighting the tensions in providing sector-wide support to professionals with differing security needs. Aksel Ethembabaoglu, Natalia Kadenko, Yana Angelova, Yury Zhauniarovich, Rolf van Wegberg, Simon Edward Parkin, Michel van Eeten |
CHI | 5 |
| 2026 | Tickets to Hide: An Inside Look into the Anti-Abuse Ecosystem through Internal Abuse Data
Hugo L. J. Bijmans, Michel van Eeten, Rolf van Wegberg |
NDSS | 3 |
| 2026 | APT to Disagree: A Comparative Analysis of Attribution in Commercial TI
Aksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van Eeten |
SP | 2 |
| 2025 | A Longitudinal Analysis of LockBit 3.0's Extortion Lifecycle and Response to Law EnforcementabstractIn this study, we present a 532-day longitudinal analysis of LockBit 3.0’s leak site. We track 1,856 victims across multiple states-countdown, data publication, deletion, and relisting-and reconstruct a structured, three-stage extortion lifecycle: (1) pre-listing negotiation, (2) countdown negotiation, and (3) post-leak monetization. We find that $8.5 \%$ of countdownstate victims are deleted before their data is published, suggesting private settlements. In the post-leak phase, victims with price tags exhibit significantly more variable deletion timing compared to those without, despite sharing the same median exposure. This indicates that LockBit actively manages some listings after data publication, potentially extending monetization or negotiation efforts.We also measure the operational impact of law enforcement actions-including Operation Cronos and affiliate arrests-on LockBit’s infrastructure and victim activity. While the group rapidly restored services after takedowns, we observe a sustained decline in new victim onboarding, reduced infrastructure redundancy, and delayed payment behavior, suggesting long-term weakening.To our knowledge, this is the first empirical study to model a ransomware extortion lifecycle based on continuous monitoring of leak site behavior. Our findings provide actionable insights into ransomware monetization tactics, negotiation patterns, and post-takedown adaptation. Yin Minn Pa Pa, Yuji Sekine, Yamato Kawaguchi, Tatsuki Yogo, Kelvin Lubbertsen, Rolf van Wegberg, Michel van Eeten, Katsunari Yoshioka |
RAID | 6 |
| 2025 | Ghost Clusters: Evaluating Attribution of Illicit Services through Cryptocurrency Tracing
Kelvin Lubbertsen, Michel van Eeten, Rolf van Wegberg |
USENIX Security Symposium | 3 |
| 2024 | The Unpatchables: Why Municipalities Persist in Running Vulnerable Hosts
Aksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van Eeten |
USENIX Security Symposium | 2 |
| 2023 | Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service
Fieke Miedema, Kelvin Lubbertsen, Verena Schrama, Rolf van Wegberg |
USENIX Security Symposium | 4 |
| 2022 | Measurement by Proxy: On the Accuracy of Online Marketplace Measurements
Alejandro Cuevas Villalba, Fieke Miedema, Kyle Soska, Nicolas Christin, Rolf van Wegberg |
USENIX Security Symposium | 5 |
| 2021 | Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit Detection
Hugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat, Rolf van Wegberg |
USENIX Security Symposium | 5 |
| 2021 | Risky Business? Investigating the Security Practices of Vendors on an Online Anonymous Market using Ground-Truth Data
Jochem van de Laarschot, Rolf van Wegberg |
USENIX Security Symposium | 2 |
| 2020 | Go See a Specialist? Predicting Cybercrime Sales on Online Anonymous Markets from Vendor and Product CharacteristicsabstractMany cybercriminal entrepreneurs lack the skills and techniques to provision certain parts of their business model, leading them to outsource these parts to specialized criminal vendors. Online anonymous markets, from Silk Road to AlphaBay, have been used to search for these products and contract with their criminal vendors. While one listing of a product generates high sales numbers, another identical listing fails to sell. In this paper, we investigate which factors determine the performance of cybercrime products. Rolf van Wegberg, Fieke Miedema, Ugur Akyazi, Arman Noroozian, Bram Klievink, Michel van Eeten |
WWW | 1 |
| 2018 | Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous Markets
Rolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi, Carlos Gañán, Bram Klievink, Nicolas Christin, Michel van Eeten |
USENIX Security Symposium | 1 |