Cyber-enabled fraud, ransomware, trafficking, money laundering, and organized criminal activity are increasingly converging into a highly sophisticated cybercrime economy that is outpacing traditional, siloed security defenses. This comes as a Fortinet executive warned that AI (artificial intelligence) is accelerating both the speed and scale of attacks, lowering barriers for threat actors while enabling more automated and targeted campaigns. As cybercriminal ecosystems become more interconnected, the executive stressed that stronger cross-sector collaboration, intelligence sharing, and coordinated public-private action are essential to disrupt these networks and shift the economics of cybercrime away from attackers.

“This convergence changes the nature of the threat. Criminal groups are not merely adopting new tools. They are combining capabilities, sharing infrastructure and building operating models that span technical, geographic and jurisdictional boundaries,” Derek Manky, chief security strategist and global vice-president for threat intelligence at Fortinet, wrote in a recent World Economic Forum post. “The same ecosystem that supports credential theft or ransomware can also fund scam compounds, exploit trafficked labor, move illicit proceeds and goods and enable broader organized crime.”

For defenders, Manky mentioned that this requires a radical shift in thinking. “Cybercrime can no longer be treated as a series of isolated technical incidents. It is an economic system with supply chains, service providers, affiliates, recruiters, money movers and physical infrastructure. Disrupting it requires a shared understanding of how these networks operate, supported by coordinated action across cybersecurity, law enforcement, government, financial institutions, civil society and the private sector.”

Cybercrime is increasingly converging into a more interconnected and dangerous ecosystem, as threat actors that once operated in separate domains now collaborate or share services. Groups specializing in social engineering, SaaS intrusions, credential theft, ransomware, extortion, or monetization are combining their expertise, creating more agile and sophisticated operations. The rise of cybercrime-as-a-service and criminal marketplaces has further accelerated this shift, enabling broader access to specialized tools and professionalizing the underground economy.

A second layer of convergence is emerging between cybercriminal groups and advanced persistent threat actors, as the lines between criminal and state-aligned operations continue to blur. Although their motives may differ, these actors increasingly share infrastructure, tactics, and enabling services, making attribution more difficult and complicating defensive responses. This overlap gives criminal groups access to advanced techniques once primarily associated with nation-state campaigns, strengthening their operational capabilities.

Cybercrime is also becoming more deeply intertwined with physical crime, with scam compounds in Southeast Asia offering a stark example. These operations combine online fraud with human trafficking, forced labor, money laundering, and physical coercion, forming highly integrated criminal enterprises. Individuals are often lured under false pretenses, trafficked, and forced to conduct large-scale online scams, while cybercrime profits fund the infrastructure, logistics, and corruption that sustain these exploitative networks.

“The good news is that coordinated disruption is effective, as demonstrated by INTERPOL’s Operation Red Card 2.0,” Manky detailed. “Executed from December 2025 to January 2026, this operation united law enforcement agencies from 16 African countries, resulting in 651 arrests and the recovery of over $4.3 million. It focused on infrastructure and individuals involved in high-yield investment scams, mobile money fraud and fake mobile loan apps.”

He added that these operations are important because they do more than just make arrests. They target the underlying systems that support cybercrime, such as infrastructure, financial channels, devices, accounts and physical assets. This approach is crucial, especially when the threat functions as an ecosystem.

The U.S. Department of Justice has taken action through its Scam Centre Strike Force, targeting Southeast Asian scam centres that target Americans. These initiatives not only seek to prosecute individual perpetrators but also dismantle the underlying infrastructure, financial channels and criminal networks responsible for extensive fraud.

Manky also highlighted that Singapore’s anti-scam efforts offer another useful model. ScamShield is a joint effort by the Ministry of Home Affairs, the Singapore Police Force, 

Open Government Products and the National Crime Prevention Council, combining public education, reporting channels and operational tools to help citizens identify and respond to scams. “While these efforts are not identical, they share a common principle: cybercrime disruption improves when information moves faster than the criminal ecosystem can adapt.”

He pointed out that cybercriminal networks depend on a fragmented response ecosystem. Different organizations witness different aspects of a cyber incident: one might see the phishing domain, another the infrastructure provider, a bank sees the fraudulent transfer, law enforcement receives the victim’s report, a nonprofit sees indicators of human trafficking and cybersecurity firms see the malware, command-and-control infrastructure, or the actor’s behavior.

Individually, these signals might appear incomplete, but collectively, they can reveal the operating model, according to Manky. “By charting the cybercriminal ecosystem, the community can identify relationships among threat actors, infrastructure, marketplaces, criminal services and monetization chains. This shared ecosystem view is crucial because defenders don’t need to eliminate every criminal actor immediately to have an impact. Instead, they can target chokepoints, identify shared infrastructure, expose service providers, disrupt financial transactions and help law enforcement link digital evidence to physical operations. That is how disruption becomes scalable.”

Manky observed that the convergence of crime is becoming increasingly significant as emerging technologies such as physical AI become more embedded in real-world infrastructure, including industrial systems, healthcare, logistics, supply chains, and robotics. While distributed AI at the edge enables faster analytics, real-time decision-making, and greater automation, it also creates new dependencies and risks. 

When AI is integrated with physical infrastructure, cyber intrusions can trigger consequences far beyond data loss or downtime, potentially disrupting production, healthcare delivery, safety systems, and the movement of goods. This makes such environments especially attractive to sophisticated criminal actors that combine cyberattacks, fraud, extortion, and physical-world exploitation, underscoring the need for security strategies that address both cyber and physical risks across interconnected IT and OT environments.

He suggests that organizations have a critical role in combating converged cybercrime beyond simply strengthening internal defenses. They need to actively share threat intelligence, including indicators, attacker behaviors, infrastructure details, and fraud patterns, since these signals become far more valuable when combined across organizations. Timely reporting of cyber incidents and attempted fraud is equally important, as underreporting helps criminal groups evade detection and prevents broader campaign patterns from being identified.

Furthermore, organizations must also engage in public-private partnerships and foster cross-domain collaboration across cybersecurity, fraud, legal, and financial teams, as well as with banks, law enforcement, NGOs, and information-sharing groups. Because cybercrime now spans multiple domains, isolated responses are increasingly ineffective. Beyond prevention, organizations should prioritize disruption by increasing friction across criminal ecosystems, making infrastructure harder to reuse, financial flows harder to move, victims harder to exploit, and criminal operations more difficult to scale.

Clearly, cybercrime has evolved into a highly networked, transnational, and increasingly converged enterprise, requiring a response that matches its scale and sophistication. Effective defense depends on collaboration through intelligence sharing, signal correlation, incident reporting, and coordinated support for law enforcement and collective disruption initiatives. The broader objective extends beyond stopping attacks at individual organizations to weakening the cybercrime ecosystem itself by making criminal operations less profitable, less scalable, and less capable of financing wider harm.

He concluded that, “That requires a converged response: cybersecurity expertise, law enforcement action, financial intelligence, civil society insight and global cooperation, all working together against a shared criminal economy.”

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *