Cybersecurity has spent decades trying to stop hackers after they become the criminal kind. The Hacking Games Foundation wants to get there earlier.
During Hacker Summer Camp in Las Vegas last week, The Hacking Games brought that argument to the Black Hat USA Main Stage, where a closing panel featuring Marcus Hutchins, Ricky Handschumacher and former FBI cyber investigator Will McKeen focused on young hackers and the choices that can push technically gifted teenagers toward — or away from — cybercrime.
More from Hacker Summer Camp:

Behind that conversation is a much larger effort taking shape. The Hacking Games Foundation is building a nonprofit initiative centered on mentoring cyber-curious teenagers, researching the conditions that make young people vulnerable to cybercrime recruitment and pushing governments and educators toward earlier intervention.
The premise is that curiosity isn't the problem. What happens to that curiosity next can be.
"The Hacking Games Foundation is a non-profit tackling the pipeline of young people into cybercrime," the organization says in its foundation plan. Its mentorship programs are designed to give teenagers "a route into cybersecurity careers instead of cybercrime."
It's an ambitious idea. It's also an effort that is still being built.
More on The Hacking Games:



Cybercriminals are getting younger
The Foundation starts from an uncomfortable observation familiar to anyone who has followed groups such as Lapsus$ and Scattered Spider: some people conducting serious cyberattacks aren't seasoned criminals. They're teenagers.
The Foundation says the average age of someone arrested for cybercrime is 19, compared with 37 for serious crime more broadly in the U.S. It also cites children as young as 12 or 13 running serious cyber campaigns and says the average age of referral to the UK's National Crime Agency Cyber Choices program is 15.
The problem isn't necessarily a shortage of technical aptitude.
It's where that aptitude gets developed.
Young people can find hacking tools, communities, tutorials and potential collaborators online without ever walking into a classroom or meeting a security professional. A teenager experimenting with technology can move from curiosity to activity that crosses legal boundaries before recognizing how far they've gone.
A case reported this week illustrates the other side of the problem. A 17-year-old British student who discovered a critical vulnerability in an education platform said he was met with resistance and threats when he attempted to disclose it responsibly. The UK's National Cyber Security Centre later recognized him for how he handled the vulnerability.
That's precisely the crossroads The Hacking Games wants to reach.
Rather than treating cyber-curious teenagers as potential criminals, the Foundation wants to connect them with people who can show them what legitimate hacking looks like.
Build the legitimate path before someone finds the other one
Mentorship is the most immediate part of the plan.
The Foundation intends to pair cyber-curious teenagers with working security professionals who can provide structured guidance and a legitimate community around their interests.
The scale being proposed is significant.
The Hacking Games says it plans school-based programs in the UK, U.S. and Saudi Arabia, with an initial goal of engaging more than 200,000 young people during its first two years. Its longer funnel envisions reaching roughly 2 million young people through school, gaming and government-backed programs.
The Foundation argues that intervention can work. Its plan cites research showing participants were 54% less likely to be arrested after 18 months in a mentoring program, as well as a 0.5% five-year reoffending rate associated with the Dutch National Police's Hack_Right program.
But The Hacking Games isn't positioning itself simply as another cybersecurity education or workforce program.
Its more interesting bet may be figuring out why some young people are more vulnerable to cybercrime recruitment in the first place.
A vulnerability index for people, not software
The Foundation is developing what it calls the Global Vulnerability Index, an annual country-by-country assessment of where young people face the greatest risk of recruitment into cybercrime and other forms of online harm.
The difference is timing.
Most cybersecurity measurements look backward: breaches, attacks, losses, vulnerabilities exploited or crimes committed.
The proposed index is explicitly forward-looking. It is intended to measure upstream socioeconomic, psychological and other conditions that could help identify emerging geographic hotspots of at-risk youth before those young people become offenders.
The cybercrime component is being led by Professor Jonathan Lusthaus, associate professor of global sociology at the University of Oxford and director of its Human Cybercriminal Project. The Foundation says the methodology will combine research across criminology, computer science, psychology and related disciplines with expert validation and country-level scoring.
The eventual ambition is much larger than publishing another annual cyber report. The Foundation wants the index to become an international benchmark used by governments, law enforcement and other institutions to guide intervention and policy.
Its own stated measure of success includes turning the Vulnerability Index into "an international benchmark for youth online risk and safety."
That's an aspiration, not yet an outcome.
And that distinction matters.
The Foundation still has to build it
The plans unveiled around Hacker Summer Camp describe an organization in its early stages.
Its roadmap includes expanding its board, hiring an executive director and operations manager, developing its research and school-program frameworks, establishing safeguarding policies and piloting curricula with schools in the U.S., UK and Saudi Arabia.
It also plans to move the Vulnerability Index into execution with Oxford and develop metrics for evaluating whether its programs actually work.
There is also the matter of paying for it.
The Foundation is seeking $2.5 million over its first 24 months to fund the Vulnerability Index, mentorship programs, policy engagement and a dedicated execution team. An initial $250,000 is being sought for the first six months.
The people behind the effort bring some substantial cybersecurity credentials.
The founding board includes L0pht co-founder and Veracode founder and CTO Chris Wysopal, along with investor Jillian Manus and entertainment executive Sandy Climan. McKeen, who spent 15 years in the FBI's cyber division and led juvenile cybercrime diversion efforts there, is part of the Foundation's founding team and now serves as its president.
Hacker Summer Camp was the right place to make the argument
There's something fitting about pushing this message during Hacker Summer Camp.
For decades, the hacker community has argued that breaking things, experimenting with technology and refusing to accept the boundaries placed around systems aren't inherently criminal behaviors. Those traits have produced security researchers, penetration testers, bug hunters and some of the industry's most influential practitioners.
They have also produced criminals.
The difference isn't necessarily technical ability.
Sometimes it's simply which community finds a young hacker first.
That's the bet behind The Hacking Games Foundation. Instead of waiting until a teenager appears in an incident report, criminal indictment or ransomware investigation, build another path while they're still figuring out what they can do.
The cybersecurity industry has gotten pretty good at finding vulnerabilities in technology.
The Hacking Games is asking whether it can get better at recognizing potential in the people finding them.



