general
INTERPOL: Cybercrime Hits 30% of Crime Across Asia-Pacific
2026-06-22

INTERPOL's latest Asia and South Pacific Cyberthreat Assessment is not a comfortable read. More than half of member countries in the region now report that cybercrime accounts for at least 30% of all recorded crime nationally. A third of them logged more than 10,000 phishing cases between January 2024 and March 2025, with phishing taking the dubious crown as the most widespread and financially damaging category.
Ransomware keeps climbing
The region recorded over 135,000 ransomware-related incidents in 2024. Real estate, manufacturing, and financial services took the heaviest hits. Ransomware-as-a-service has done what every maturing industry does: lowered the barrier to entry. More groups can play, attacks have multiplied, and most victims had no idea they were on anyone's list until their files stopped opening.
The AI angle gets weird
This is where the assessment shifts from familiar to genuinely strange. INTERPOL points to deepfakes being used to impersonate executives and authorise fraudulent payments. Organised crime groups operating out of Myanmar, Cambodia, and Laos are blending AI-generated personas with classic social engineering, running operations out of scam compounds that frequently rely on trafficked labour.
Their romance baiting operations, where victims are slowly groomed into fake relationships and then drained financially, are estimated to have contributed to $37 billion in regional cybercrime losses. That figure is not a typo.
Industrial-scale social engineering
INTERPOL's cybercrime director Neal Jetton called the shift social engineering on an industrial scale, which is about as accurate a summary as you'll find. The tooling has improved. The business models have matured. The people running these operations are not lone opportunists working from a basement. They are organised, well-resourced, and increasingly transnational, with infrastructure, HR problems, and revenue targets.
What it means on the ground
For anyone working in or alongside businesses in the region, the practical takeaway is that the average phishing email or unexpected video call is no longer the clumsy thing it was five years ago. The grammar is fine. The logo is right. The voice on the line genuinely sounds like the CFO, because it is a clone of the CFO.
- Unusual payment requests get verified through a second channel. Always.
- Urgency in a message is a feature of the scam, not a reason to skip checks.
- Staff need to know that a convincing voice or face is not authentication.
None of this is dramatic advice. It is the baseline now. The threat landscape described in the INTERPOL report is what businesses across the region are already operating in, whether they have caught up to it or not.