
A new INTERPOL report finds cybercrime now makes up 30% of all recorded crime in over half the countries surveyed across Asia and the South Pacific — and the data suggests the region has become the world’s proving ground for AI-driven fraud.
30%+ Of national crime is cyber
135,000+ Ransomware attacks, 2024
92% Rise in DDoS attacks
600% Rise in deepfake forum chatter
6.5 BnThreats detected in 2024
$37 BnRegional scam losses
The Headline Finding
INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, released on 17 June 2026, draws on responses from 18 member countries alongside private-sector intelligence partners, covering the period from January 2024 to March 2025. Its central finding is stark: more than half of the countries surveyed reported that cybercrime now accounts for at least 30 percent of all crime recorded nationally — meaning that in a majority of the region’s jurisdictions, nearly one in three crimes police record is now a cyber offence rather than a traditional one.
INTERPOL Cybercrime Director Neal Jetton described the landscape as one where criminals are “leveraging artificial intelligence, ransomware-as-a-service models and sophisticated social engineering techniques on an industrial scale” — language that signals this is no longer a story about opportunistic individual hackers, but about organised, semi-professionalised criminal enterprise operating at regional scale.
The Numbers Behind the Headline
Ransomware: 135,000 Attacks and Counting
The region recorded more than 135,000 ransomware-related attacks in 2024, with the real estate, manufacturing, and financial services sectors bearing the brunt. This volume places Asia and the South Pacific among the most heavily targeted regions globally for ransomware, and the sector spread — real estate and manufacturing alongside finance — suggests attackers are no longer concentrating solely on data-rich financial targets but exploiting any organisation with operational dependency on IT systems and the ability to pay to resume operations.
Phishing at Twice the Global Rate
Phishing emerged as the most widespread and financially damaging cybercrime category, with a third of surveyed countries reporting more than 10,000 cases each between January 2024 and March 2025. Regionally, 5.5 out of every 1,000 individuals clicked on phishing links monthly — nearly double the global average of 2.9 per 1,000 — with cloud applications the primary target, reflecting how deeply cloud-based work tools have penetrated the region’s workforce without commensurate security awareness.
DDoS Attacks Surging 92%
Distributed denial-of-service attacks rose 92 percent in 2024 compared to the previous year, with government websites targeted earlier in the year and financial institutions increasingly targeted later — a pattern suggesting attackers shifted focus from disruptive, symbolic targets toward financially motivated extortion-linked disruption as the year progressed.
Deepfakes: From Novelty to Operational Weapon
Perhaps the most alarming trend line in the report is the 600 percent increase in deepfake-related discussion on cybercriminal forums and Telegram channels popular among Southeast Asian threat actors, between February and June 2024 alone. This is not a measure of attacks but of criminal capability-building — forum chatter is typically a leading indicator of tooling maturing from experimental to operationally deployed.
Case in point: the $25 million deepfake callIn February 2024, an employee in Hong Kong authorised a transfer of $25 million after fraudsters used AI-generated deepfake video to impersonate senior company executives on a video call. In March 2025, a Singapore finance director very nearly lost more than $499,000 in an almost identical Zoom-based deepfake attack. INTERPOL frames these not as isolated incidents but as an accelerating and repeatable pattern — a template other criminal groups are now replicating across the region.
Data Breaches: System Intrusion Is the Dominant Vector
System intrusions accounted for approximately 80 percent of all data breaches in 2024, with malware present in 83 percent of cases and ransomware specifically present in 51 percent — indicating that most regional data breaches aren’t the result of insider leaks or misdirected data, but of active, malware-driven network compromise.
The Human Cost: Scam Centres and Forced Labour
Beyond the technical statistics, the report documents a disturbing structural feature of the region’s cybercrime economy: transnational organised crime groups operating extensive scam centres in countries including Cambodia, Laos, Myanmar, and the Philippines, in some cases resembling modern-day slavery. These centres reportedly used deepfake technology in “romance baiting” scams — blending AI-generated personas with social engineering to build fraudulent relationships with victims — contributing to an estimated $37 billion in regional cyber-enabled fraud losses.
This detail matters because it reframes part of the cybercrime problem as a labour-trafficking and human rights issue running in parallel with the technical fraud problem — the people executing many of these scams are, in a substantial number of documented cases, themselves victims of the same criminal networks, trafficked or coerced into running the scam operations they appear to be conducting.
What INTERPOL and Member States Are Doing About It
The report isn’t purely diagnostic — it also documents a coordinated regional response. Operation SECURE, run by the Asia and South Pacific Joint Operations Against Cybercrime (ASPJOC) initiative from November 2024 to April 2025, targeted infostealer malware infrastructure across 26 participating countries, resulting in the takedown of more than 20,000 malicious IP addresses and domains, 30 arrests, and the seizure of over 100 GB of criminal data.
| Metric | Result |
|---|---|
| Countries participating | 26 |
| Malicious IPs / domains taken down | 20,000+ |
| Arrests made | 30 |
| Data seized | 100+ GB |
| Victim notifications issued | Hundreds of thousands |
INTERPOL frames this operation as proof of concept for what coordinated regional action can achieve, and has signalled intent to scale similar operations going forward, alongside ongoing quarterly threat advisories and working group meetings bringing together heads of cybercrime units from across the region.
Why This Report Matters Beyond Law Enforcement
Two industries are already treating this report as a structural signal rather than a routine update:
- Cyber insurance underwriting. Analysts have noted that many current cyber insurance pricing frameworks in the Asia-Pacific region were built before deepfake fraud, organised scam compounds, and AI-enabled attack patterns became prominent — meaning premiums may not adequately reflect the threat environment INTERPOL has now documented, even as the region is expected to see the fastest cyber insurance market growth of any region globally.
- Regulatory design. Some jurisdictions have already moved to build reporting obligations around this exact threat pattern — for instance, mandatory ransomware payment disclosure requirements that require businesses to report any extortion payment to national authorities within a short window, creating a new compliance dimension for incident response planning.
The report’s own framing is telling: it explicitly notes that ransomware groups are now weaponising companies’ own regulatory disclosure obligations to intensify pressure during extortion — threatening to report the breach to regulators themselves if the victim doesn’t pay, turning compliance law into a second lever of extortion.
Reading the Data With Appropriate Caution
A few caveats are worth keeping in mind when interpreting these figures. The 30 percent “share of national crime” statistic comes from survey responses rather than a uniform regional measurement standard, so cross-country comparisons should account for differing definitions of cybercrime and differing reporting infrastructure between countries — a country with more mature cyber-specific reporting channels may show a higher percentage partly because it captures cyber incidents more completely, not necessarily because its underlying cybercrime rate is higher than a country with weaker reporting mechanisms.
Similarly, the report’s coverage window ends in March 2025, meaning the trends it captures — already alarming — describe a threat environment that multiple industry analysts believe has continued to intensify through the report’s June 2026 publication date, particularly around AI-enabled fraud tooling that has matured further in the intervening period.
Conclusion
INTERPOL’s assessment paints a picture of a region where cybercrime has moved from a peripheral law enforcement concern to a dominant category of criminal activity in its own right — one increasingly organised, industrialised, and augmented by AI tools that make fraud both more convincing and more scalable. The 135,000 ransomware attacks and 92 percent DDoS surge are significant on their own, but the report’s more important contribution may be documenting how thoroughly criminal capability-building (600 percent more deepfake chatter) is now outpacing both individual awareness and institutional response capacity, even as coordinated operations like Operation SECURE show meaningful disruption is possible when member states act together rather than in isolation.