Europol warns that artificial intelligence, end-to-end encryption, proxies, and cryptocurrencies are accelerating cybercrime in the EU, making online fraud, ransomware, and online sexual exploitation of children harder to investigate. In short Europol has published the IOCTA 2026 report, which analyzes the main threats of cybercrime affecting the European Union.
The report indicates AI, encryption, proxies, the dark web, cryptocurrencies, and anonymized services as factors that expand the operational capacity of criminal networks.
Online fraud is described as the fastest-growing area of organized crime, with schemes such as investment fraud, business email compromise, romance scams, tech support scams, and fraud against payment systems.
Europol observed over 120 active ransomware brands in 2025, in a volatile, fragmented ecosystem increasingly connected with hybrid threats.
The report warns of the increase in online sexual extortion, the monetization of child sexual abuse materials, and AI-generated synthetic materials. Europol has published the new edition of the Internet Organised Crime Threat Assessment, IOCTA 2026, the annual report on the developments of organized crime on the internet affecting the European Union. The report is titled "How encryption, proxies, and AI are expanding cybercrime" and presents the main trends in cybercrime, online fraud, cyberattacks, and online sexual exploitation of children. According to the report, the accelerated pace of cybercrime creates increasingly sophisticated threats to society, with effects both online and offline. Europol shows that law enforcement authorities need to reduce a growing "speed gap" against criminals, in conditions where AI tools allow for faster launches of attacks, their expansion, and greater customization. The report emphasizes that the use of end-to-end encrypted platforms, jurisdictional and technical barriers, and restrictive or insufficient data retention policies create blind spots for investigations. These obstacles hinder the identification of suspects, corroboration of evidence, and rapid intervention against imminent threats. "IOCTA 2026 provides an updated roadmap for law enforcement authorities and involved actors to understand and respond to evolving threats generated by cybercrime. As criminals continue to exploit technological advancements, it is essential to strengthen our capabilities and collaborate more effectively to protect citizens and critical infrastructure," said Edvardas Šileris, head of the European Cybercrime Centre at Europol. The report describes the dark web as a central facilitator of the cybercrime ecosystem. Criminal markets and forums are becoming more fragmented and specialized, and users quickly migrate to other platforms after law enforcement operations. Europol shows that these platforms are increasingly intertwined with encrypted messaging applications and anonymized services, in a hybrid ecosystem that offers criminals greater operational protection. Cryptocurrencies remain the preferred payment method in ransomware attacks, especially due to their cross-border nature and level of anonymity. The report indicates an increasing use of highly opaque coins, offshore exchange services, mixers, and rapid asset transfer mechanisms between blockchains, complicating the tracking of illicit financial flows. Europol also notes that the popularity of cryptocurrencies expands the base of potential victims, including minors and young adults attracted by "get rich quick" schemes on social networks. According to the report, minors can participate without knowing about money laundering, by renting digital wallets or receiving "gifts" in cryptocurrencies from criminals. Online fraud is presented as the fastest-growing area of organized crime. Criminal networks target individuals, public and private organizations, and their data, generating large profits through investment fraud, especially in the cryptocurrency area, business email compromise, romance scams, tech support scams, and fraud against payment systems. Europol shows that the use of generative AI allows criminals to personalize social engineering techniques, create more convincing messages, and operate on a larger scale. The report mentions AI-assisted impersonation of bank support staff or law enforcement authorities, as well as increased realism in business email compromise and CEO fraud schemes. The technical infrastructure of online fraud is becoming more industrialized. SIM boxes, devices that can host hundreds of SIM cards, are used for massive phishing campaigns, calls, SMS messages, and fake accounts on online platforms. The report mentions a network operated by seven Latvian citizens, with at least 1,200 SIM-box devices and 40,000 SIM cards linked to numbers from over 80 countries, through which over 49 million online accounts were created. The report also warns about relay attacks on payment terminals, which have increased in the EU in 2025. In these attacks, the data of a transaction is transmitted in real-time between the victim's card or digital wallet and a device controlled by criminals, for withdrawing money or making a payment. Ransomware remains one of the main cyber threats in the EU. Europol observed over 120 active ransomware brands in 2025, and attacks continued to grow. The ecosystem is described as volatile and fragmented, with groups quickly changing their names, using leaked code from previous operations, and resorting to ransomware-as-a-service models. The extortion model has increasingly shifted from simple data encryption to the threat of publishing stolen information. Europol shows that many victims are more willing to pay for their data not to be published than to recover it after encryption. Simultaneous DDoS attacks, bombarding corporate email addresses, and pressure phone calls are part of the toolkit used by ransomware groups. The report notes the increasing overlap between cybercrime and hybrid threats. Hybrid actors use criminal networks as intermediaries for DDoS attacks, intrusions, data theft, and ransomware, and in the crime-as-a-service economy become clients of these services, alongside other criminal actors. Europol also mentions Operation Eastwood against the pro-Russian NoName057(16) network, known for attacks against governments and companies. The infographic of the report shows 19 countries involved, over 100 servers disrupted worldwide, 24 searches, 9 arrest warrants, over 1,000 supporters notified regarding legal liability, 6,032 unique hosts attacked, 674 public websites attacked, and 5,358 private websites attacked. In the area of online sexual exploitation of children, the report indicates a rapid adaptation of criminals to new technologies. Sexual extortion remains a major threat, and the number of CyberTips reports regarding financial extortion received by NCMEC between January and June 2025 increased by approximately 70% compared to the same period of the previous year. Europol warns that child sexual abuse materials are increasingly being monetized, and encrypted platforms have become an important medium for communication, grooming, material exchange, and networks among criminals. The report also mentions the network The Com, where child sexual exploitation, cyberattacks, extortion, violence, crime, and violent extremism intersect. AI generates an additional challenge by increasing the volume of synthetic child sexual abuse materials. The report shows that AI tools allow for both the production of completely synthetic images and the modification of existing images, multiplying the volume of materials online and complicating the identification of victims and perpetrators. Europol states that law enforcement authorities need to invest in AI capabilities, improve cross-border cooperation, obtain legal access to essential data, and collaborate more closely with the private sector. The report emphasizes that the response to cybercrime will depend on the ability of authorities to use technology to close the gap against the speed of criminal networks. The Internet Organised Crime Threat Assessment is Europol's annual strategic report on organized crime facilitated by the internet. The first Europol assessment of this type was published in 2011, and the report is used to inform strategic decisions, public policy, and operational responses in combating cybercrime. IOCTA 2026 is based on information from operational activities supported by the European Cybercrime Centre, EC3, contributions from EU member states and operational partners, as well as the expertise of Europol specialists. The report identifies four major risk areas: facilitators of cybercrime, online fraud infrastructure, cyberattacks, and online sexual exploitation of children. Looking ahead to the coming years, Europol warns about autonomous cybercrime, hybrid threats related to ransomware and hacking coalitions, the increase of synthetic child sexual abuse materials, and online fraud accelerated by AI.
Sources
Latest News
22:51
22:43
22:33
22:14
21:54
See more news