Skip to content
CISA promotes a fresh way to deter cyberattackers: Lie to them

CISA promotes a fresh way to deter cyberattackers: Lie to them

Cyberscoop •Tim Starks • September 16, 2026

For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered.

The Wednesday guidance, “Using Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters and penetration testers how decoys can be a cheap, effective way to disrupt attackers, said Chris Butera, acting executive director of the cybersecurity division.

‘We’ve been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who’s already gained access to networks,” Butera told CyberScoop at Google Cloud’s Cyber Defense Summit 26.

It’s especially complementary for zero-trust (maintaining that no user or device is trustworthy by default) and assume-compromise (assuming that hackers have already gotten into a network) approaches, Butera said.

While the guidance is “really relevant for everyone,” it’s something that can be especially useful in critical infrastructure sectors that don’t have the most personnel or money, he said.

“This could be something to prioritize as a lower cost solution,” Butera said. “You can create your own honey tokens yourself.”

The 22-page guidance includes decoy principles and goals, definitions of the different kinds of decoys and how to use them and scenarios for deployment.

Honeytokens, for instance, are “Data elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity.”

“Cyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” Butera said in a news release. “With this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.”

What the Section 702 lapse means for cybersecurity

AI-adaptable security platforms are critical for autonomous decision-making

Defending in the middle of the vulnpocalypse

The Vulnpocalypse arrived early

Supreme Court denies Trump request to allow USPS mail ballot changes

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

Hawley probes OpenAI over Hugging Face breach

Governments ‘buying time’ in race between innovation, security, national cyber director says

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

European parliament members call for slowdown of Serbia’s EU entry over spyware use

The G7 tells industry to hurry up and prep for post-quantum encryption

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

GitLab's critical flaw is already drawing internet-wide probes

Conti ransomware crew member sentenced to four years in prison

Chinese espionage groups swarm to exploit triple-link chain of zero-days

FTC rescinds policy statement requiring health apps to notify customers after a breach

Lawmakers call on Commerce to sanction hackers-for-hire

FBI cyber chief worries private sector not sharing enough cyber threat information

Wyden seeks upgraded NSA security guidance on commercial VPN use

Extracted Entities

Companies (1)

Countries (2)

Platforms (2)

Ransomware Groups (1)