Abstract The boundary between traditional organized crime and cybercrime is eroding. Long-established criminal groups increasingly rely on encrypted communications, darknet markets, and cryptocurrency-based money laundering, while profit-driven cybercriminal groups adopt the durable structures, division of labor, and governance mechanisms long associated with organized crime. This article examines this convergence, understood as the organizational, operational, financial, and technological integration of traditional criminal groups and cybercriminal networks. The study combines a qualitative analysis of documents published between 2020 and 2026, including law enforcement reports, court records, and assessments by international organizations, with a case study of the Hive ransomware group and its disruption in 2023, complemented by supporting cases such as Conti, Hydra Market, EncroChat, and the online fraud compounds of Southeast Asia. Three vectors of convergence are identified: ransomware-as-a-service models and inter-group alliances; darknet marketplaces and the wider crime-as-a-service economy; and direct alliances between hackers and conventional criminal groups, including trafficking-based forced criminality. The article develops an integrative framework that links each vector to the organizational features it produces, to established criminological theories, and to corresponding enforcement levers. It concludes that convergence is a profit- and opportunity-driven adaptation to a weakly guarded digital environment and that effective responses require synchronized pressure on offenders, finances, infrastructure, and criminal service providers.
Abstract Decentralized finance (DeFi) platforms have gained in popularity over the last few years, as they offer a wide range of accessible, innovative, and complex financial services. Because they evolve quickly under limited regulation, it is easy for malicious parties to target them for profit when they notice a vulnerability in these emergent protocols. Existing work has focused on understanding typical attack flows and securing the technology to alleviate crime. However, little is known about what other attributes, beyond technical vulnerabilities, may put DeFi actors at risk. Drawing on Cookâs (Crime Justice 7:1â27, 1986) crime opportunity framework of target attractiveness, this study investigates which attributes are associated with an increase or a decrease in the likelihood of DeFi victimization. We compare actors victimized in 2022 with those that were not across several target dimensions: propinquity, vulnerability, potential payoff, main area of operation, and self-protection activities. Results show that being listed on a popular centralized exchange, operating on a layer-2 blockchain, offering lending services, and having high trading volumes are associated with an increased likelihood of victimization, while operating a dApp and having experienced past victimization are associated with a decrease. By contrast, self-protection measures such as publicly disclosed audits, and bug bounty programs show no measurable effect, likely reflecting variation in their quality and implementation or the fact that undisclosed audits could not be observed. By integrating criminological theory into DeFi security research, this study provides a holistic framework for understanding crime opportunities in this novel ecosystem, while informing potential prevention strategies to reduce associated harms.
Amid the rapid evolution of digital currencies and the decentralized finance (DeFi) ecosystem, technology-driven, anonymous, and cross-border financial crimes pose systemic challenges to traditional regulatory frameworks. Grounded in three core theories of criminal psychologyâRational Choice Theory, Routine Activity Theory, and Techniques of Neutralizationâand integrating the âtechnologyâsociety co-constructionâ perspective from the sociology of technology, this study constructs a three-dimensional analytical framework encompassing âtechnological ecology, social cognition, and individual psychology.â It systematically elucidates the psychological formation logic and evolutionary pathways of financial crimes within the DeFi domain. The research reveals that the technical features of DeFiâanonymity, decentralization, and code autonomyâcollectively create a âstructural opportunity spaceâ characterized by low accountability costs and weakened moral constraints. Subcultural communities further supply âmorally neutralizing scriptsâ through narratives of crypto-libertarianism and the myth of âcode as law.â Under these dual influences, individual psychology undergoes transformation, manifesting as complex motivations, distorted risk perceptions, and heightened moral disengagement, ultimately leading to a rationalization mechanism for criminal acts veiled behind âtechnological neutrality.â
Abstract: Identity theft has emerged as a psychologically consequential form of cybercrime enabled by the proliferation of digital platforms, the expansion of datafication, and the collapse of traditional criminalâvictim proximity. As personal identity becomes increasingly externalized through financial accounts, medical records, biometric templates, and algorithmically curated social profiles, offenders exploit cognitive biases, disclosure fatigue, and habituated oversharing to acquire and weaponize personal information. Criminal psychology research demonstrates that social engineering, authority mimicry, and emotional urgency manipulate victims into bypassing rational scrutiny, while cyberpsychology highlights the affective attachment individuals form with their digital representations. Unlike conventional theft, in which tangible objects are removed, identity theft appropriates informational components of the self, enabling prolonged impersonation, reputational distortion, and chronic anxiety that cannot be readily restored. Geographic detachment, encrypted communication channels, and anonymizing technologies reduce offendersâ perceived accountability, encouraged moral disengagement and facilitating mass victimization at minimal personal risk. Victims, confronted with unauthorized transactions or corrupted medical histories, report hypervigilance, loss of digital agency, and destabilization of narrative coherence. Emerging technologies, including Internet of Things devices, deepfake media, decentralized finance, and eventually quantum computing, further expand the attack surface and amplify criminogenic opportunity structures. Meanwhile, jurisdictional fragmentation complicates forensic attribution and legal recourse. Collectively, these developments reveal that traditional, place-based models of personal security are insufficient in networked environments. Safeguarding informational sovereignty requires interdisciplinary approaches that integrate behavioral criminology, cognitive vulnerability assessment, cyberpsychological resilience, and international policy coordination. Understanding identity theft as an ontological, relational, and psychologically persistent violation offers critical insight for prevention, victim support, and regulatory design in the digital epoch. Keywords: Identity Theft; Cyberpsychology; Criminal Psychology; Datafication; Digital Proximity Collapse; Social Engineering; Informational Sovereignty; Biometric Fraud; Cognitive Vulnerability; Cybercrime Scalability
Open access
2 source records
Cybercrime and Law Enforcement Studies
Crime Patterns and Interventions
Psychopathy, Forensic Psychiatry, Sexual Offending
The rise in illicit financial activities across the South AfricaâZimbabwe corridor, with an estimated annual loss of $3.1 billion demands advanced AI solutions to augment traditional detection methods. This study introduces FALCON, a groundbreaking hybrid transformerâGNN model that integrates temporal transaction analysis (TimeGAN) and graph-based entity mapping (GraphSAGE) to detect illicit financial flows with unprecedented precision. By leveraging data from South Africaâs FIC, Zimbabweâs RBZ, and SWIFT, FALCON achieved 98.7%, surpassing Random Forest (72.1%) and human auditors (64.5%), while reducing false positives to 1.2% (AUC-ROC: 0.992). Tested on 1.8 million transactions, including falsified CTRs, STRs, and Ethereum blockchain data, FALCON uncovered $450 million laundered by 23 shell companies with a cross-border detection precision of 94%, directly mitigating illicit financial flows in Southern Africa. For regulators, FALCON met FAFT standards, yielding 92% court admissibility, and its GDPR-compliant design (Δ = 1.2 differential privacy) met stringent legal standards. Deployed on AWS Graviton3, FALCON processed 2 million transactions/second at $0.002 per 1000 transactions, demonstrating real-time scalability, making it cost-effective for financial institutions in emerging markets. As the first AI framework tailored for Southern Africaâs financial ecosystems, FALCON sets a new benchmark for ethical AML solutions in emerging economies with immediate applicability to CBDC supervision. The transparent validation of publicly available data underscores its potential to transform global financial crime detection.
The Police Complaint Management System (PCMS) is a decentralized application template designed to modernize the processes of lodging, tracking, and resolving complaints within law enforcement systems. Leveraging the Next.js framework, Web3 technologies, and blockchain integration, the system ensures tamper-proof complaint records, real-time updates, and enhanced transparency for citizens and authorities. By utilizing Wagmi and Ethers.js for seamless wallet connections, IPFS for decentralized evidence storage, and a user-friendly interface styled with Tailwind CSS, the PCMS provides a scalable, efficient, and accessible platform. With automated processes for complaint categorization and routing, as well as immutable blockchain records, the system fosters greater accountability and trust in public services. Built with TypeScript for reliability and enhanced with modular tools for rapid deployment, the PCMS exemplifies a modern, citizen-centric approach to grievance management, ensuring data security and operational efficiency in law enforcement agencies
We examine cryptocurrency fraud cases prosecuted by Nigeria's Economic and Financial Crimes Commission (EFCC). We considered the lens of the Space Transition Theory (STT) in exploring the dynamics of these digital crimes. Our data analysis reveals common types of fraud, including cryptocurrency investment schemes. The results show an exclusive male demographic (100%), with the majority under 30 years old and only a quarter possessing a degree, providing insights into the socio-demographic characteristics of cryptocurrency fraudsters. Additionally, while most fraudsters (55%) targeted victims in the United States, Bitcoin, leveraging blockchain technology, was the most commonly used method (46%) for cryptocurrency fraud. Our examination of the methods and mediums used for cryptocurrency fraud supports some aspects of STT, while others do not. We advocate for a multifaceted strategy that prioritises stringent regulation, implementation, and heightened scrutiny of digital currency ecosystems in Nigeria and beyond. This study contributes to the broader discourse on cybercrime prevention and enforcement by emphasising the novel methodological approach utilised.
Hongzhou Chen, Xiaolin Duan, Abdulmotaleb El Saddik, Wei Cai
Harnessing the transparent blockchain user behavior data, we construct the Political Betting Leaning Score (PBLS) to measure political leanings based on betting within Web3 prediction markets. Focusing on Polymarket and starting from the 2024 U.S. Presidential Election, we synthesize behaviors over 15,000 addresses across 4,500 events and 8,500 markets, capturing the intensity and direction of their political leanings by the PBLS. We validate the PBLS through internal consistency checks and external comparisons. We uncover relationships between our PBLS and betting behaviors through over 800 features capturing various behavioral aspects. A case study of the 2022 U.S. Senate election further demonstrates the ability of our measurement while decoding the dynamic interaction between political and profitable motives. Our findings contribute to understanding decision-making in decentralized markets, enhancing the analysis of behaviors within Web3 prediction environments. The insights of this study reveal the potential of blockchain in enabling innovative, multidisciplinary studies and could inform the development of more effective online prediction markets, improve the accuracy of forecast, and help the design and optimization of platform mechanisms. The data and code for the paper are accessible at the following link: https://github.com/anonymous.
Detecting malicious activity in advance has become increasingly important for public safety, economic stability, and national security. However, the disparity in living standards incites the minds of certain undesirable members of society to commit crimes, which may disrupt societyâs stability and mental calm. Breakthroughs in deep learning (DL) make it feasible to address such challenges and construct a complete intelligent framework that automatically detects such malicious behaviors. Motivated by this, we propose a convolutional neural network (CNN)-based Xception model, i.e., BlockCrime, to detect crimes and improve public safety. Furthermore, we integrate blockchain technology to securely store the detected crime scene locations and alert the nearest law enforcement authorities. Due to the scarcity of the dataset, transfer learning has been preferred, in which a CNN-based Xception model is used. The redesigned Xception architecture is evaluated against various assessment measures, including accuracy, F1 score, precision, and recall, where it outperforms existing CNN architectures in terms of train accuracy, i.e., 96.57%.
Gibran GĂłmez, Pedro Moreno-SĂĄnchez, Juan Antonio Caballero-HernĂĄndez
Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-and-forth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges. We evaluate back-and-forth exploration on 30 malware families. We build oracles for 4 families using Bitcoin for C&C and use them to demonstrate that back-and-forth exploration identifies 13 C&C signaling addresses missed by prior work, 8 of which are fundamentally missed by forward-only explorations. Our approach uncovers a wealth of services used by the malware including 44 exchanges, 11 gambling sites, 5 payment service providers, 4 underground markets, 4 mining pools, and 2 mixers. In 4 families, the relations include new attribution points missed by forward-only explorations. It also identifies relationships between the malware families and other cybercrime campaigns, highlighting how some malware operators participate in a variety of cybercriminal activities.
Crime research has repeatedly shown that small proportions of offenders are responsible for large proportions of crimes. While there is a substantial body of evidence for this âoffending concentrationâ in connection to traditional offline crime, there is limited research assessing the concentration of offending for cybercrime. This research analyzes victim reports of Bitcoin-related cybercrimes (blackmail, ransomware, sextortion, darknet market fraud, Bitcoin tumbler fraud) to illuminate the extent of cybercrime offending concentration and to identify groups of offenders involved in online crime. Our results indicate that a large proportion of cybercrimes are associated with a small number of very active Bitcoin addresses. However, Bitcoin addresses associated to high numbers of reports are not necessarily those that generate the largest financial benefits.
In this explorative study we provide empirical insight into how organized crime offenders use IT to launder their money. Our empirical data consist of 30 large-scale criminal investigations into organized crime. These cases are part of the most recent, fifth data sweep of the Dutch Organized Crime Monitor (DOCM). We do not focus on cybercrime alone. Instead, we explore the financial aspects of criminal operations in a broad range of types of organized crime, i.e. from âtraditionalâ types of organized crime, such as offline drug smuggling, to cybercrime. Regarding the spending of criminal proceeds (consumption and investment), the analyses show several similarities and no major differences between traditional crime and cybercrime. When it comes to concealing criminal earnings (money laundering), we do see important differences. Financial innovation, such as the use of cryptocurrencies, seems to be limited to cases of IT-related crime. One of the most striking similarities between cybercrime and traditional crime is the offendersâ preference for cash. In the analysed cases, malware and phishing offenders as well as online drug traffickers change their digital currencies for cash, at least in part.
The scale of criminal networks (e.g. drug syndicates and terrorist networks) extends globally and poses national security threat to many nations as they also tend to be technologically advance (e.g. Dark Web and Silk Road cryptocurrency). Therefore, it is critical for law enforcement agencies to be equipped with the latest tools in criminal network analysis (CNA) to obtain key hidden links (relationships) within criminal networks to preempt and disrupt criminal network structures and activities. Current hidden or missing link predictive models that are based on Social Network Analysis models rely on ML techniques to improve the performance of the models in terms of predictive accuracy and computing power. Given the improvement in the recent performance of Deep Reinforcement Learning (DRL) techniques which could train ML models through self-generated dataset, DRL can be usefully applied to domains with relatively smaller dataset such as criminal networks. The objective of this study is to assess the comparative performance of a CNA hidden link prediction model developed using DRL techniques against classical ML models such as gradient boosting machine (GBM), random forest (RF) and support vector machine (SVM). The experiment results exhibit an improvement in the performance of the DRL model of about 7.4% over the next best performing classical RF model trained within 1500 iterations. The performance of these link prediction models can be scaled up with the parallel processing capabilities of graphical processing units (GPUs), to significantly improve the speed of training the model and the prediction of hidden links.
Rolf van Wegberg, J.J. Oerlemans, Oskar van Deventer
Purpose -This paper aims to shed light into money laundering using bitcoin. Digital payment methods are increasingly used by criminals to launder money obtained through cybercrime. As many forms of cybercrime are motivated by profit, a solid cash-out strategy is required to ensure that crime proceeds end up with the criminals themselves without an incriminating money trail. The authors examine how cybercrime proceeds can be laundered using services that are offered on the Dark Web.
Cryptocurrencies are private, decentralized currencies that operate via the Internet and have attracted criminals because of the convenience and virtual anonymity they offer. While there are many descriptive accounts of cryptocurrencies and their use both in legal and illegal operations, to date there is no empirical research to understand the use of cryptocurrencies in transnational crime operations, specifically why transnational criminals may find them attractive to either conduct business or to launder their illicit proceeds. Using the environmental criminological framework, this study analyzed 100 cases of cryptocurrency use in transnational crime activities identified through various secondary sources, including online newspaper articles and publicly available court case information. Essentially this study used both quantitative and qualitative analysis to examine the ways in which cryptocurrencies facilitate transnational crimes. The findings indicate that criminals have been using cryptocurrencies to conceal the enormous amounts of money they are receiving for their crimes, specifically money laundering, drug trafficking (illicit drug sales), and terrorism financing. It was found that offenders can conduct business, launder money, and make a profit by using cryptocurrencies to facilitate their crimes, creating for crime opportunities permitted by cryptocurrencies. These opportunities include the ease of floating from one crime to another and using cryptocurrencies to cover offendersâ tracks, where cryptocurrencies can transact, launder, and conceal all in one. It was found that offenders gravitate towards using bitcoin to facilitate their operations, most likely due to its popularity and reliability. When looking at the crime of money laundering and illicit drug sales specifically, it was found that offenders can generate higher operation amounts, spanning into billions of dollars, all while evading detection. With the assumption that transnational criminals are rational beings, money laundering using cryptocurrencies has enormous benefits with these high operation amounts. This coupled with the low chances of being caught by law enforcement, makes money laundering a feasible crime where the benefits far outweigh the risks. This exploratory research is innovative and imperative to expanding academic knowledge on the evolution of crime with the use of cryptocurrencies and assisting in reducing the opportunities cryptocurrencies allow in transnational crime operations.