Skip to main content

For years, cybercrime was described as a linear sequence: a vulnerability, malware, unauthorised access, an encrypted system, a ransom demand. It was a common simplification, of course, but it worked. Not anymore.

According to data from the FBI Internet Crime Report 2025, cybercrime can no longer be viewed simply as a series of technical attacks against vulnerable systems. The picture that emerges is more complex: criminal actors are transforming fraud, social engineering, cryptocurrencies, compromised identities, generative AI and payment infrastructures into an increasingly industrialised operational chain. In 2025, the IC3 received over 1 million reports, with reported losses exceeding $20.8 billion.

The most important finding, however, is not merely financial. It is methodological: a significant proportion of the losses do not stem from complex exploits, but from the manipulation of legitimate processes: payments, corporate communications, technical support, remote onboarding, investments and relationships of trust. Attackers do not always need to breach a firewall. In many cases, it is enough to control the context, impersonate a trusted identity and steer the victim towards a wrong decision.

Modern cybercrime does not merely compromise endpoints and servers. It compromises the context: the way an organisation communicates, verifies, approves and trusts. And it is precisely this point that IT managers and CISOs need to pay the closest attention to.

 

Digital fraud has become an operational model

Technology-enabled fraud accounts for around 45 per cent of reports, but generates nearly 85 per cent of total losses. This means that the greatest financial damage does not always stem from traditional malware, ransomware or data breaches. Very often, it arises from schemes that use technology to lend credibility to a request, an investment, a payment or an identity.

Many schemes work because they exploit channels already trusted by victims: corporate emails, messaging platforms, investment portals, support calls, QR codes, bank transfers, crypto wallets and financial accounts. From a technical perspective, the attack does not always require the execution of malicious code. Often, it is enough to control the communication, impersonate a trusted identity and steer the victim towards a transaction.

The technical aspect exists, but it often operates behind the scenes: compromised accounts, lookalike domains, fake social media profiles, crypto wallets, money mule accounts, fraudulent call centres, remote access tools, voice cloning, deepfakes and AI-generated content. These are not separate incidents. They are components of the same criminal infrastructure, designed to reduce friction and increase credibility.

  • compromised email accounts or spoofed domains for BEC and phishing;
  • social media profiles and messaging accounts for initial engagement;
  • fake investment platforms with simulated dashboards and returns;
  • crypto wallets and cash-out services to move funds quickly;
  • fraudulent call centres for tech support and government impersonation;
  • mule accounts and intermediary bank accounts for money laundering;
  • AI tools to generate credible content, voices, videos and conversations.

This is the real quantum leap: the attack no longer exists solely within a malicious attachment or a suspicious connection to a C2 server. It exists within a conversation, a procedure, an approval workflow, a financial transaction.

This is why it is a mistake to regard fraud as a lesser category compared to malware. Today, digital fraud is a mature offensive discipline: it combines intelligence, social engineering, automation, identity theft and rapid monetisation. It is technical in its preparation, psychological in its execution and financial in its outcome.

 

Investment fraud and crypto: when the victim sees a platform, not a scam

The costliest category remains investment fraud, with over 8.6 billion dollars in losses. The most significant variant is that linked to cryptocurrencies, which in 2025 generated over $7.2 billion in reported losses. But reducing it all to ‘cryptocurrency scams’ would be too simplistic: the key point here is the architecture of trust built by the attackers.

The most interesting aspect, from a threat intelligence perspective, is the quality of the environment constructed by the attackers. The victim is not simply persuaded to send money to a wallet. They are led into a fictitious ecosystem that resembles a real financial service: dashboards, charts, available balance, transaction history, simulated profits, notifications, customer support, withdrawal procedures.

This is a crucial detail. The victim does not immediately perceive a loss, because they see their capital ‘growing’ within a platform that appears to be functioning. The scam is not based solely on the promise of profit, but on the creation of false operational evidence.

The initial contact may come via text message, social media, advertising, dating apps or investment groups. The conversation then shifts to more controllable channels, often messaging platforms, where the attacker can isolate the victim, manage the pace of the interaction and build trust over time.

When the time comes to make a withdrawal, artificial obstacles appear: taxes, fees, fake KYC checks, temporary blocks, and requests for further deposits to ‘unlock’ the funds. By that point, in reality, the money has already been transferred, fragmented and moved through various wallets and services.

Cryptocurrencies are not just a method of payment. They become part of the criminal logistics, because they enable speed, layering, pseudonymisation and cross-border transfers.

There is also a second, often underestimated level: recovery scams. Following the initial loss, the same victim is contacted again by fake law firms, debt recovery agencies or purported officials. It is a second exploitation of the same emotional and financial vulnerability. From a criminal perspective, this is not a new incident: it is the continuation of the cycle of exploitation.

 

BEC: when the compromise lies in the process, not in the malware

Business Email Compromise remains one of the most costly threats to businesses, with losses exceeding 3 billion dollars. And it continues to be dangerous precisely because it does not always resemble a cyberattack in the traditional sense of the term.

In a BEC case, there isn’t necessarily malware to analyse, a file to sandbox, an exploit to correlate or C2 traffic to block. Sometimes there is a genuinely compromised mailbox. Other times, a domain almost identical to that of the supplier. Still others involve simple impersonation, crafted with sufficient care to appear credible.

  • actual compromise of a corporate email account;
  • spoofing or typosquatting of a similar domain;
  • impersonation of an executive, supplier or business partner.

The sequence is well-known: gathering OSINT on the company, identifying financial roles, studying internal terminology, applying time pressure, requesting confidentiality, altering bank details or issuing an urgent payment instruction. Nothing out of this world. That is precisely why it works.

SPF, DKIM and DMARC are necessary controls, but they cannot be regarded as a complete solution. If the attacker uses a legitimate, already compromised email account, or if they enter the conversation via a genuine supplier’s account, the problem is no longer simply one of authenticating the domain. The problem becomes verifying whether the request is consistent with the process.

For a CISO, this means shifting part of the defence from the purely technical level to the operational level: out-of-band verification for changes to bank details, dual approval for critical payments, monitoring of anomalous forwarding rules, checking for impossible access attempts, and correlating suspicious logins with sensitive financial activity.

The right question today is no longer simply ‘Is this email genuine?’. The right question is: ‘Is this request following the expected authorisation process?’.

 

AI-enabled fraud: the automation of credibility

Artificial intelligence did not invent social engineering, but it makes it more scalable and credible. By 2025, AI-related incidents had resulted in losses amounting to hundreds of millions of dollars. AI’s main contribution is the reduction in the cost of personalisation: a criminal actor can generate thousands of different conversations, adapt their tone to the victim, translate messages into multiple languages, mimic corporate communications, and create visual or audio content that is difficult to distinguish at first glance.

For years, anti-phishing training has focused on grammatical errors, rough translations, odd formatting and suspicious senders. It was useful, in a certain context. But that context is rapidly disappearing. Today, an attacker can generate emails that are correct, natural, localised, consistent with the company’s tone and tailored to the recipient’s role.

In BEC, this means more natural emails, without obvious grammatical errors and with a style consistent with the corporate context. In investment scams, it means videos and synthetic voices of CEOs, celebrities or figures deemed trustworthy. In employment scams, it means online interviews with voice spoofing or potential deepfakes, where the objective is not always an immediate financial loss, but initial access to private corporate networks.

The point for organisations is that malicious content is no longer necessarily crude. It may be well-written, arrive at the right moment, use a plausible tone and contain no obvious red flags. This renders detection based solely on static message analysis insufficient.

Defences must focus on behaviour: an unusual request, a sudden change of communication channel, pressure not to verify, a change in the payee, access from an unknown device, or a session behaving differently from usual. It is no longer enough to ask whether the message ‘looks like phishing’. One must ask whether the requested action is consistent with the risk, the role and the process.

 

Ransomware: the reported figures do not reflect the true damage

In the IC3 report, ransomware features with over 3,600 reports and declared losses exceeding 32 million dollars. Taken at face value, it might seem almost less significant than financial fraud. That would be a mistake.

Ransomware is one of the categories where the reported figure tends to be furthest removed from the actual impact. Often, the following are not included in the tally: downtime, business disruption, external consultants, infrastructure reconstruction, loss of productivity, reputational damage, legal costs, communications with customers and authorities, special audits and increased insurance premiums.

Furthermore, ransomware almost never starts with the ransomware itself. Encryption is the final visible stage in a longer chain: initial access, persistence, privilege escalation, discovery, lateral movement, exfiltration and, only at the very end, encryption or extortion. If defences only intervene once encryption begins, it is already too late.

The most frequently reported variants include Akira, Qilin, INC./Lynx/Sinobi, BianLian, Play, Ransomhub, LockBit, Dragonforce, SAFEPAY and Medusa. The sectors most affected include critical manufacturing, healthcare, public administration and government organisations, but the report also highlights numerous reports from non-critical sectors such as law firms, contractors, engineering firms, consultancy firms and non-critical manufacturing.

From a technical perspective, the recommendations remain consistent with the TTPs observed in ransomware incidents. A list is useful here, as it allows us to see where defences must intercept the attack chain before encryption takes place:

  • offline or off-site backups, encrypted and immutable;
  • removal of default passwords and weak credentials;
  • MFA for webmail, VPNs, administrative access and critical systems;
  • reduction of unnecessary protocols;
  • audits of privileged accounts;
  • least privilege for users and service accounts;
  • MDR to detect lateral movement and anomalous activity on hosts;
  • logging of internal traffic, not just perimeter traffic;
  • network segmentation to limit lateral movement;
  • prioritised patching of known vulnerabilities being exploited on exposed systems.

The question to ask is not ‘are we protected against ransomware?’. That is too broad. The more useful question is: ‘At which stage of the attack chain are we actually able to detect, contain and stop the attacker?’.

 

Account Takeover and tech support fraud: when access is legitimate, but the use is not

Another important technical element is Account Takeover. The IC3 reports around 4,700 ATO complaints, with losses totalling approximately $359.7 million. In these cases, the problem is not just the theft of credentials. It is the use of legitimate sessions or accounts to carry out fraudulent operations.

Once inside, the attacker may not do anything technically conspicuous. They may change recovery methods, set up email forwarding, create new payees, authorise payments, approve requests, view documents, or search for information useful for a subsequent fraud. The account is valid. The session may appear valid. The problem lies in the behaviour.

Tech support fraud follows a similar logic, but with an even more insidious dynamic: it is often the victim themselves who grants remote access. The criminal poses as technical support, a bank, an internet service provider, a government body or an anti-fraud service. They convince the user to install remote access software, share their screen, enter OTP codes or follow operational instructions.

For businesses, this requires a change in approach. It is not enough to monitor malware and exploits. It is necessary to monitor accounts, sessions, devices, authorisations, geolocations, remote access tools, anomalous changes and sensitive transactions. Identity is no longer merely a means of authentication. It is an attack surface.

 

Financial Fraud Kill Chain: in financial fraud, time is the most important control

The section on the Recovery Asset Team and the Financial Fraud Kill Chain is particularly relevant for organisations. In 2025, the FFKC process was activated in response to 3,900 incidents, involving over $1.16 billion in attempted theft and approximately $679 million frozen.

The operational evidence is clear: in financial fraud, time is the most important security control. The sooner a fraudulent transaction is reported, the greater the chance of blocking the funds at the receiving bank or at subsequent stages, known as ‘second hops’.

This means knowing immediately who to contact at the bank, what information to gather, who authorises escalation, who verifies the accounts involved, who retains the evidence, who contacts the relevant authorities and who manages internal communication. In practice, a truly useful playbook should cover at least the following elements:

  • direct contact details for the bank and the relationship manager;
  • internal procedure for urgent escalation;
  • immediate collection of the amount, time, beneficiary, IBAN, SWIFT/ACH, wallet or transaction hash;
  • blocking or recalling the transaction;
  • retention of emails, headers and access logs;
  • verification of the accounts involved, revocation of sessions and reset of credentials;
  • analysis of forwarding rules, OAuth grants and subsequent anomalous activity;
  • rapid communication with the relevant authorities and internal departments involved.

Time, in this case, is not merely a management variable. It is a security control.

An organisation that discovers fraud days later has very little room for manoeuvre. An organisation that intercepts it within the first few hours can still implement blocks, recalls, freezes and checks on subsequent steps. But this requires well-prepared processes, not just installed tools.

 

Security must also protect decision-making

Cybercrime in 2026 must be understood in light of this evidence: attackers are increasingly capitalising on trust, not just technical vulnerabilities. Not everything that is dangerous appears technically anomalous. A request may come from a genuine account. A conversation may be well-written. A dashboard may look professional. A voice may sound authentic. A payment may be authorised by someone authorised to do so.

MDR, MFA, patching, backups, segmentation, logging and hardening remain essential. But they must be integrated with process controls: payments, onboarding, changes to bank details, supplier management, remote access, executive communications, financial approvals, account recovery and anti-fraud escalation.

Indicators are no longer just IP addresses, hashes, domains, URLs and signatures. They also include behavioural patterns: artificial urgency, pressure not to verify, requests outside standard procedures, sudden changes of communication channel, new payees, anomalous logins, persistent sessions, unexpected forwarding, fragmented transactions, and interactions shifted to external platforms.

This does not mean replacing technical security with training or procedures. It means stopping treating them as separate worlds. Effective security arises when telemetry, threat intelligence, identity security, process governance and operational awareness work together.

The conclusion is simple, but uncomfortable: today, attackers monetise trust with the same discipline with which they once exploited technical vulnerabilities. Modern cybercrime does not merely attack technology. It attacks the way in which people and organisations make decisions. And that is precisely where the defence must focus.

Analysis by Vasily Kononov – Threat Intelligence Lead, CYBEROO