Security News

CISA's New Advice: Fight Hackers by Feeding Them Fake Data

CyberScoop · 17 Sept 2026
Key Takeaway Small businesses can boost their threat detection cheaply by planting a few fake files or credentials that would only be touched by an intruder, giving an early warning of a breach.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued its first formal guidance on using cyber decoys, such as fake accounts, systems and data, to trick attackers who have already gained access to a network. The document, titled 'Using Cyber Decoys to Strengthen Detection and Response,' was developed after internal discussions among CISA's threat hunters and penetration testers about low-cost ways to disrupt hackers.

According to Chris Butera, acting executive director of CISA's cybersecurity division, decoys can be a cheap but highly reliable way to spot intruders who have already breached a network. He noted that this approach works well alongside 'zero-trust' security models, which assume no user or device should be automatically trusted, and 'assume-compromise' strategies, which plan for attackers already being inside a network.

The 22-page guidance explains different types of decoys, including 'honeytokens': fake records, credentials or files that have no real business purpose. Because these fake elements should never be accessed legitimately, any interaction with them is a strong sign of malicious activity. CISA highlighted that organisations with limited budgets and staff, such as smaller operators in critical infrastructure sectors, can create these decoys themselves at low cost.

CISA cyber deception threat detection critical infrastructure zero trust

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.