// Comparison

Fancy Bear Goes Phishing vs Kingpin: Which Should You Read?

Two cybersecurity books on Narrative, compared honestly: who each is for, what each does best, and which to read first.

Beginner
4/52023
Fancy Bear Goes Phishing

The Dark History of the Information Age, in Five Extraordinary Hacks

Scott J. Shapiro

Five famous hacks used as a way into the deeper question of why software is insecure at all, written by a Yale law professor who learned to code to write it. More a history and theory of vulnerability than a how-to.

Beginner
5/52011
Kingpin

How One Hacker Took Over the Billion-Dollar Cybercrime Underground

Kevin Poulsen

Kevin Poulsen's reconstruction of Max Butler's career — from white-hat consultant to running CardersMarket, the carding forum that consolidated the early-2000s underground — and the FBI investigation that finally took him down.

Read this if

Readers who want the why behind the headlines, the conceptual and historical reasons computers can be broken into, told through memorable cases.
Anyone interested in cybercrime as an economy rather than as a series of incidents. Poulsen, himself a former hacker turned journalist, has both the access and the technical fluency to make the carding-economy mechanics legible.

Skip this if

Practitioners after current technique or precise forensics. Skip this if a non-specialist explaining your field back to you, occasionally over-tidily, will grate.
Readers wanting current ransomware-economy detail; the book is 2011 and pre-dates the modern affiliate / RaaS structure. The mechanics generalize, the actors don't.

Key takeaways

  • Insecurity is not a series of accidents but a structural property of how general-purpose computers and the industry around them are built.
  • The famous hacks are interesting less for their cleverness than for what they reveal about incentives, law, and human nature.
  • Treating hacking as purely a technical problem misses the legal and economic machinery that keeps it profitable.
  • Cybercrime markets are markets — they have liquidity, reputation, dispute resolution, and trust topology, and they fail in market-like ways.
  • Most underground takedowns are won by HUMINT and OSINT inside the forums, not by exploitation; Butler's downfall was social.
  • The book's pacing makes the carding economy legible without flattening the moral complexity of its inhabitants.

How they compare

We rate Kingpin higher (5/5 against 4/5 for Fancy Bear Goes Phishing). For most readers, that means Kingpin is the primary pick and Fancy Bear Goes Phishing is a useful follow-up.

Both books target beginner-level readers, so the choice is about topic, not difficulty.

Fancy Bear Goes Phishing and Kingpin both cover Narrative, History, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics