Abstract The boundary between traditional organized crime and cybercrime is eroding. Long-established criminal groups increasingly rely on encrypted communications, darknet markets, and cryptocurrency-based money laundering, while profit-driven cybercriminal groups adopt the durable structures, division of labor, and governance mechanisms long associated with organized crime. This article examines this convergence, understood as the organizational, operational, financial, and technological integration of traditional criminal groups and cybercriminal networks. The study combines a qualitative analysis of documents published between 2020 and 2026, including law enforcement reports, court records, and assessments by international organizations, with a case study of the Hive ransomware group and its disruption in 2023, complemented by supporting cases such as Conti, Hydra Market, EncroChat, and the online fraud compounds of Southeast Asia. Three vectors of convergence are identified: ransomware-as-a-service models and inter-group alliances; darknet marketplaces and the wider crime-as-a-service economy; and direct alliances between hackers and conventional criminal groups, including trafficking-based forced criminality. The article develops an integrative framework that links each vector to the organizational features it produces, to established criminological theories, and to corresponding enforcement levers. It concludes that convergence is a profit- and opportunity-driven adaptation to a weakly guarded digital environment and that effective responses require synchronized pressure on offenders, finances, infrastructure, and criminal service providers.
Abstract Decentralized finance (DeFi) platforms have gained in popularity over the last few years, as they offer a wide range of accessible, innovative, and complex financial services. Because they evolve quickly under limited regulation, it is easy for malicious parties to target them for profit when they notice a vulnerability in these emergent protocols. Existing work has focused on understanding typical attack flows and securing the technology to alleviate crime. However, little is known about what other attributes, beyond technical vulnerabilities, may put DeFi actors at risk. Drawing on Cookâs (Crime Justice 7:1â27, 1986) crime opportunity framework of target attractiveness, this study investigates which attributes are associated with an increase or a decrease in the likelihood of DeFi victimization. We compare actors victimized in 2022 with those that were not across several target dimensions: propinquity, vulnerability, potential payoff, main area of operation, and self-protection activities. Results show that being listed on a popular centralized exchange, operating on a layer-2 blockchain, offering lending services, and having high trading volumes are associated with an increased likelihood of victimization, while operating a dApp and having experienced past victimization are associated with a decrease. By contrast, self-protection measures such as publicly disclosed audits, and bug bounty programs show no measurable effect, likely reflecting variation in their quality and implementation or the fact that undisclosed audits could not be observed. By integrating criminological theory into DeFi security research, this study provides a holistic framework for understanding crime opportunities in this novel ecosystem, while informing potential prevention strategies to reduce associated harms.
Amid the rapid evolution of digital currencies and the decentralized finance (DeFi) ecosystem, technology-driven, anonymous, and cross-border financial crimes pose systemic challenges to traditional regulatory frameworks. Grounded in three core theories of criminal psychologyâRational Choice Theory, Routine Activity Theory, and Techniques of Neutralizationâand integrating the âtechnologyâsociety co-constructionâ perspective from the sociology of technology, this study constructs a three-dimensional analytical framework encompassing âtechnological ecology, social cognition, and individual psychology.â It systematically elucidates the psychological formation logic and evolutionary pathways of financial crimes within the DeFi domain. The research reveals that the technical features of DeFiâanonymity, decentralization, and code autonomyâcollectively create a âstructural opportunity spaceâ characterized by low accountability costs and weakened moral constraints. Subcultural communities further supply âmorally neutralizing scriptsâ through narratives of crypto-libertarianism and the myth of âcode as law.â Under these dual influences, individual psychology undergoes transformation, manifesting as complex motivations, distorted risk perceptions, and heightened moral disengagement, ultimately leading to a rationalization mechanism for criminal acts veiled behind âtechnological neutrality.â
Abstract: Identity theft has emerged as a psychologically consequential form of cybercrime enabled by the proliferation of digital platforms, the expansion of datafication, and the collapse of traditional criminalâvictim proximity. As personal identity becomes increasingly externalized through financial accounts, medical records, biometric templates, and algorithmically curated social profiles, offenders exploit cognitive biases, disclosure fatigue, and habituated oversharing to acquire and weaponize personal information. Criminal psychology research demonstrates that social engineering, authority mimicry, and emotional urgency manipulate victims into bypassing rational scrutiny, while cyberpsychology highlights the affective attachment individuals form with their digital representations. Unlike conventional theft, in which tangible objects are removed, identity theft appropriates informational components of the self, enabling prolonged impersonation, reputational distortion, and chronic anxiety that cannot be readily restored. Geographic detachment, encrypted communication channels, and anonymizing technologies reduce offendersâ perceived accountability, encouraged moral disengagement and facilitating mass victimization at minimal personal risk. Victims, confronted with unauthorized transactions or corrupted medical histories, report hypervigilance, loss of digital agency, and destabilization of narrative coherence. Emerging technologies, including Internet of Things devices, deepfake media, decentralized finance, and eventually quantum computing, further expand the attack surface and amplify criminogenic opportunity structures. Meanwhile, jurisdictional fragmentation complicates forensic attribution and legal recourse. Collectively, these developments reveal that traditional, place-based models of personal security are insufficient in networked environments. Safeguarding informational sovereignty requires interdisciplinary approaches that integrate behavioral criminology, cognitive vulnerability assessment, cyberpsychological resilience, and international policy coordination. Understanding identity theft as an ontological, relational, and psychologically persistent violation offers critical insight for prevention, victim support, and regulatory design in the digital epoch. Keywords: Identity Theft; Cyberpsychology; Criminal Psychology; Datafication; Digital Proximity Collapse; Social Engineering; Informational Sovereignty; Biometric Fraud; Cognitive Vulnerability; Cybercrime Scalability
Open access
2 source records
Cybercrime and Law Enforcement Studies
Crime Patterns and Interventions
Psychopathy, Forensic Psychiatry, Sexual Offending
The rise in illicit financial activities across the South AfricaâZimbabwe corridor, with an estimated annual loss of $3.1 billion demands advanced AI solutions to augment traditional detection methods. This study introduces FALCON, a groundbreaking hybrid transformerâGNN model that integrates temporal transaction analysis (TimeGAN) and graph-based entity mapping (GraphSAGE) to detect illicit financial flows with unprecedented precision. By leveraging data from South Africaâs FIC, Zimbabweâs RBZ, and SWIFT, FALCON achieved 98.7%, surpassing Random Forest (72.1%) and human auditors (64.5%), while reducing false positives to 1.2% (AUC-ROC: 0.992). Tested on 1.8 million transactions, including falsified CTRs, STRs, and Ethereum blockchain data, FALCON uncovered $450 million laundered by 23 shell companies with a cross-border detection precision of 94%, directly mitigating illicit financial flows in Southern Africa. For regulators, FALCON met FAFT standards, yielding 92% court admissibility, and its GDPR-compliant design (Δ = 1.2 differential privacy) met stringent legal standards. Deployed on AWS Graviton3, FALCON processed 2 million transactions/second at $0.002 per 1000 transactions, demonstrating real-time scalability, making it cost-effective for financial institutions in emerging markets. As the first AI framework tailored for Southern Africaâs financial ecosystems, FALCON sets a new benchmark for ethical AML solutions in emerging economies with immediate applicability to CBDC supervision. The transparent validation of publicly available data underscores its potential to transform global financial crime detection.
The Police Complaint Management System (PCMS) is a decentralized application template designed to modernize the processes of lodging, tracking, and resolving complaints within law enforcement systems. Leveraging the Next.js framework, Web3 technologies, and blockchain integration, the system ensures tamper-proof complaint records, real-time updates, and enhanced transparency for citizens and authorities. By utilizing Wagmi and Ethers.js for seamless wallet connections, IPFS for decentralized evidence storage, and a user-friendly interface styled with Tailwind CSS, the PCMS provides a scalable, efficient, and accessible platform. With automated processes for complaint categorization and routing, as well as immutable blockchain records, the system fosters greater accountability and trust in public services. Built with TypeScript for reliability and enhanced with modular tools for rapid deployment, the PCMS exemplifies a modern, citizen-centric approach to grievance management, ensuring data security and operational efficiency in law enforcement agencies
We examine cryptocurrency fraud cases prosecuted by Nigeria's Economic and Financial Crimes Commission (EFCC). We considered the lens of the Space Transition Theory (STT) in exploring the dynamics of these digital crimes. Our data analysis reveals common types of fraud, including cryptocurrency investment schemes. The results show an exclusive male demographic (100%), with the majority under 30 years old and only a quarter possessing a degree, providing insights into the socio-demographic characteristics of cryptocurrency fraudsters. Additionally, while most fraudsters (55%) targeted victims in the United States, Bitcoin, leveraging blockchain technology, was the most commonly used method (46%) for cryptocurrency fraud. Our examination of the methods and mediums used for cryptocurrency fraud supports some aspects of STT, while others do not. We advocate for a multifaceted strategy that prioritises stringent regulation, implementation, and heightened scrutiny of digital currency ecosystems in Nigeria and beyond. This study contributes to the broader discourse on cybercrime prevention and enforcement by emphasising the novel methodological approach utilised.
Hongzhou Chen, Xiaolin Duan, Abdulmotaleb El Saddik, Wei Cai
Harnessing the transparent blockchain user behavior data, we construct the Political Betting Leaning Score (PBLS) to measure political leanings based on betting within Web3 prediction markets. Focusing on Polymarket and starting from the 2024 U.S. Presidential Election, we synthesize behaviors over 15,000 addresses across 4,500 events and 8,500 markets, capturing the intensity and direction of their political leanings by the PBLS. We validate the PBLS through internal consistency checks and external comparisons. We uncover relationships between our PBLS and betting behaviors through over 800 features capturing various behavioral aspects. A case study of the 2022 U.S. Senate election further demonstrates the ability of our measurement while decoding the dynamic interaction between political and profitable motives. Our findings contribute to understanding decision-making in decentralized markets, enhancing the analysis of behaviors within Web3 prediction environments. The insights of this study reveal the potential of blockchain in enabling innovative, multidisciplinary studies and could inform the development of more effective online prediction markets, improve the accuracy of forecast, and help the design and optimization of platform mechanisms. The data and code for the paper are accessible at the following link: https://github.com/anonymous.
Transactions on the darknet are notoriously difficult to examine. Prior criminological research has generally used web scraping and qualitative text analysis to examine illegal darknet markets. One disadvantage of this process is that individuals can lie. Fortunately for researchers, the currency used for transactions on the darknet, cryptocurrency, is designed to be tracked. In this article, we examine transactions from a former darknet marketplace, AlphaBay. Using the blockchain, we examine the interconnectedness of both legal and illegal cryptocurrencies. In addition, we provide a structured approach to quantitatively examine the Bitcoin blockchain ledger, offering both the tools and our own experiences for other researchers interested in such approaches. While cybersecurity, information technology, accounting, and other disciplines can examine the financial data itself, we believe that criminologists can provide additional benefits in pattern analysis and organizing the context and theory around the transactions. Our results show that cryptocurrency transactions are generally identifiable (90%) and involve likely illegal transactions, transactions that attempt to obfuscate other transactions, and legal transactions. We end with a discussion of newer cryptocurrencies and related technology and how they will likely shape future work.
Detecting malicious activity in advance has become increasingly important for public safety, economic stability, and national security. However, the disparity in living standards incites the minds of certain undesirable members of society to commit crimes, which may disrupt societyâs stability and mental calm. Breakthroughs in deep learning (DL) make it feasible to address such challenges and construct a complete intelligent framework that automatically detects such malicious behaviors. Motivated by this, we propose a convolutional neural network (CNN)-based Xception model, i.e., BlockCrime, to detect crimes and improve public safety. Furthermore, we integrate blockchain technology to securely store the detected crime scene locations and alert the nearest law enforcement authorities. Due to the scarcity of the dataset, transfer learning has been preferred, in which a CNN-based Xception model is used. The redesigned Xception architecture is evaluated against various assessment measures, including accuracy, F1 score, precision, and recall, where it outperforms existing CNN architectures in terms of train accuracy, i.e., 96.57%.
Gibran GĂłmez, Pedro Moreno-SĂĄnchez, Juan Antonio Caballero-HernĂĄndez
Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-and-forth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges. We evaluate back-and-forth exploration on 30 malware families. We build oracles for 4 families using Bitcoin for C&C and use them to demonstrate that back-and-forth exploration identifies 13 C&C signaling addresses missed by prior work, 8 of which are fundamentally missed by forward-only explorations. Our approach uncovers a wealth of services used by the malware including 44 exchanges, 11 gambling sites, 5 payment service providers, 4 underground markets, 4 mining pools, and 2 mixers. In 4 families, the relations include new attribution points missed by forward-only explorations. It also identifies relationships between the malware families and other cybercrime campaigns, highlighting how some malware operators participate in a variety of cybercriminal activities.
Purpose Cryptocurrencies have been used to commit various offences, but enforcement efforts remain underdeveloped relative to the value of these crimes. This paper aims to examine factors associated with outcomes of US-based cryptocurrency financial crime prosecutions. Design/methodology/approach The authors studied the 37 resolved cryptocurrency-based financial crime cases in the USA to date, exploring the impact of offence, defendant and evidence characteristics on the mode of disposition and penalties. The authors used bivariate analyses and logistic regression models to determine relationships among these variables. Findings The presence of individual defendants only (rather than a corporate defendant or combination thereof) and the use of only a cryptocurrency other than Bitcoin in committing a crime each made a case less likely to be resolved by dismissal, trial or summary or default judgement. Originality/value This paper is the first to examine variables contributing to financial crime prosecution outcomes and has implications for prosecutorial decision-making, resource allocation and the prevention and detection of financial offences involving cryptocurrencies.
Crime research has repeatedly shown that small proportions of offenders are responsible for large proportions of crimes. While there is a substantial body of evidence for this âoffending concentrationâ in connection to traditional offline crime, there is limited research assessing the concentration of offending for cybercrime. This research analyzes victim reports of Bitcoin-related cybercrimes (blackmail, ransomware, sextortion, darknet market fraud, Bitcoin tumbler fraud) to illuminate the extent of cybercrime offending concentration and to identify groups of offenders involved in online crime. Our results indicate that a large proportion of cybercrimes are associated with a small number of very active Bitcoin addresses. However, Bitcoin addresses associated to high numbers of reports are not necessarily those that generate the largest financial benefits.
In recent years, crimes using bitcoin as a tool have brought severe impacts to the social order. Bitcoin has the characteristics of high anonymity, decentralization, peer-to-peer, and the use of asymmetric encryption. These high tech features make bitcoin a new criminal tool which often used by organized criminal groups. Therefore, analyzing bitcoin flow has become critical for law enforcement to conduct a criminal investigation. However, due to its UTXO (Unspent Transaction Output) transaction pattern, many change wallets are generated in analyzing bitcoin flow, which affects the judgment of actual money flow analysis. In this research, we implement input-output differential and temporary rules to detect change wallets by analyzing bitcoin transaction pattern characteristics. Furthermore, we design web crawlers as a tool to collect and parse transactions of highly suspected criminal bitcoin wallets. Micro and macro perspectives of network analysis are provided by social network analysis (SNA) and visualization technology. The experimental results indicate that the proposed rules can detect both clustered and marginal change wallets. By eliminating the noise information caused by change wallets can provide coherent financial flows of interpretation for criminal investigation.
Alexandra Yuryevna Bokovnya, Đ. A. Shutova, Tatyana Gennadievna Zhukova, Liliya Viktorovna Ryabova
Cryptocurrency crime cases continue to increase. The legal nature of cryptocurrency is analyzed, and it is concluded that nowadays, despite of some attempts to regulate cryptocurrency circulation legislatively, there are numerous gaps, most of which are in the field of criminal law. Based on the study of the available theoretical views of domestic, as well as the analysis of the judicial investigative practice materials of the legal sphere under consideration, the authors consider the necessity to carry out a work to formulate several areas that will streamline the criminal law relations in the field of cryptocurrency circulation.
This article examines cryptocurrency cases decided in the U.S. District and Circuit Courts to determine the applicability of Gottschalkâs convenience theory of white-collar crime to cryptocurrency crime litigation and to empirically analyze whether the conditions under which cryptocurrency offenses occurred show support for the convenience theory. Analysis of U.S. federal district and circuit court case law involving cryptocurrency crimes and fraud indicates support for the convenience theory of white-collar crime. Defendants in various schemes were motivated by financial gain, either for the company or for personal use. Their roles and positions in the businesses allowed them access to resources that helped them perpetrate fraud through the following mechanisms: (1) operating front companies; (2) relationship building by defendants; (3) over representing profits that investors would obtain from purchases of virtual currencies, representing that cryptocurrencies were safe and reliable investments when they were risky, and overestimating abilities and capacities to provide services promised to investors in securities fraud; (4) breaching fiduciary duties to their clients and corporate stockholders by misappropriating profits for their own personal gain; and (5) engaging in dark web transactions that guaranteed anonymity. Defendants also employed various neutralization techniques to justify their crimes.
In this explorative study we provide empirical insight into how organized crime offenders use IT to launder their money. Our empirical data consist of 30 large-scale criminal investigations into organized crime. These cases are part of the most recent, fifth data sweep of the Dutch Organized Crime Monitor (DOCM). We do not focus on cybercrime alone. Instead, we explore the financial aspects of criminal operations in a broad range of types of organized crime, i.e. from âtraditionalâ types of organized crime, such as offline drug smuggling, to cybercrime. Regarding the spending of criminal proceeds (consumption and investment), the analyses show several similarities and no major differences between traditional crime and cybercrime. When it comes to concealing criminal earnings (money laundering), we do see important differences. Financial innovation, such as the use of cryptocurrencies, seems to be limited to cases of IT-related crime. One of the most striking similarities between cybercrime and traditional crime is the offendersâ preference for cash. In the analysed cases, malware and phishing offenders as well as online drug traffickers change their digital currencies for cash, at least in part.
The scale of criminal networks (e.g. drug syndicates and terrorist networks) extends globally and poses national security threat to many nations as they also tend to be technologically advance (e.g. Dark Web and Silk Road cryptocurrency). Therefore, it is critical for law enforcement agencies to be equipped with the latest tools in criminal network analysis (CNA) to obtain key hidden links (relationships) within criminal networks to preempt and disrupt criminal network structures and activities. Current hidden or missing link predictive models that are based on Social Network Analysis models rely on ML techniques to improve the performance of the models in terms of predictive accuracy and computing power. Given the improvement in the recent performance of Deep Reinforcement Learning (DRL) techniques which could train ML models through self-generated dataset, DRL can be usefully applied to domains with relatively smaller dataset such as criminal networks. The objective of this study is to assess the comparative performance of a CNA hidden link prediction model developed using DRL techniques against classical ML models such as gradient boosting machine (GBM), random forest (RF) and support vector machine (SVM). The experiment results exhibit an improvement in the performance of the DRL model of about 7.4% over the next best performing classical RF model trained within 1500 iterations. The performance of these link prediction models can be scaled up with the parallel processing capabilities of graphical processing units (GPUs), to significantly improve the speed of training the model and the prediction of hidden links.
Purpose The purpose of this paper is to present the findings from a literature review, which aimed to identify previous studies evaluating cryptolaundering from a systems thinking perspective. The aim of this paper is to first confirm that cryptolaundering systems can indeed be defined as complex socio-technical systems and second to present the findings from a systematic review of the literature to determine the extent to which previous research has adopted a systems thinking perspective. Design/methodology/approach The study involved a SLR of studies published in the peer-reviewed literature between 2009 and 2018. Rasmussenâs risk management framework (Rasmussen, 1997) was used to evaluate the extent to which a systems thinking perspective had been adopted. Findings The cryptolaundering process is considered to be a complex socio-technical system. The review demonstrates that no previous studies have defined cryptolaundering as a complex socio-technical system or used systems thinking framework approach to evaluate how criminals, regulatory bodies or law enforcement entities understand processes and assess risk within cryptolaundering systems. It is argued that using such an approach to the cryptolaundering process would likely improve assessing criminal risk analyses of cryptolaundering and assist law enforcement and regulatory bodies with understanding risk management during the laundering of cryptocurrencies. Originality/value Future assessments of cryptolaundering using socio-technical system analytical processes may afford law enforcement and regulatory bodies the opportunity to improve intervention techniques and identify gaps in regulations and enforcement.
Rolf van Wegberg, J.J. Oerlemans, Oskar van Deventer
Purpose -This paper aims to shed light into money laundering using bitcoin. Digital payment methods are increasingly used by criminals to launder money obtained through cybercrime. As many forms of cybercrime are motivated by profit, a solid cash-out strategy is required to ensure that crime proceeds end up with the criminals themselves without an incriminating money trail. The authors examine how cybercrime proceeds can be laundered using services that are offered on the Dark Web.