What is Cybercrime? Definition, Types, and Examples

Cybercrime is criminal activity that targets or uses computers, networks, and data. Explore its types, the as-a-service economy, laws, and reporting channels.
Published on
Tuesday, October 6, 2026
Updated on
October 6, 2026

Cybercrime is criminal activity that targets computers, networks, and data, or that uses them as the instrument of a traditional crime such as fraud, extortion, or theft. Cybercrime spans everything from ransomware against hospitals to romance scams against retirees, and classification along two axes makes that range navigable.

Scale is measured best through reported losses. In the FBI's 2025 Internet Crime Report, losses reached 20.877 billion US dollars across more than one million complaints, a 26% rise in a single year, and the report tracked AI-assisted crimes for the first time.

Cybercrime Classification

Law enforcement bodies including Europol and the UK National Crime Agency classify cybercrime along a technology-dependency axis, and prosecutors add a second axis based on the target. Both axes together locate any offense precisely.

Cyber-Dependent Crimes

Cyber-dependent crimes exist only because computers exist. Hacking, malware deployment, ransomware, denial-of-service attacks, and cryptojacking fall in this class, since each offense is committed against or through a computing system and has no offline equivalent.

Cyber-Enabled Crimes

Cyber-enabled crimes predate the internet and scale through it. Fraud, extortion, stalking, trafficking, and intellectual property theft all existed on paper and by phone, and digital channels multiplied their reach, speed, and anonymity. Cyber-enabled fraud alone produced 17.7 billion dollars of the 2025 reported losses, nearly 85% of the total.

cyber dependent vs cyber enabled crime

Classification by Target

Target-based classification separates crimes against individuals, against organizations, and against governments, and the same technique lands differently in each cell. A phishing email against a retiree is consumer fraud, against an enterprise it is initial access for ransomware, and against a ministry it is espionage.

Class Against Individuals Against Organizations Against Governments
Cyber-dependent Device hijacking, cryptojacking, personal account hacking Ransomware, network intrusion, DDoS against services Critical infrastructure sabotage, state system intrusion
Cyber-enabled Identity theft, romance and investment scams, cyberstalking Business email compromise, invoice fraud, IP theft Espionage, election interference, disinformation operations

Common Types of Cybercrime

These ten types account for nearly all reported cybercrime, and several routinely chain together in a single campaign. Current cyber threat trends show the same pattern year over year: social engineering opens the door, and monetization follows through fraud, extortion, or resale.

  • Phishing and business email compromise: Deceptive messages harvest credentials or redirect payments. Phishing drew the highest complaint volume in 2025, and business email compromise alone produced losses above 3 billion dollars.
  • Ransomware: Malware encrypts systems and exfiltrates data for double extortion. Investigators cataloged 63 new ransomware variants in 2025, an average of more than five per month.
  • Identity theft: Stolen personal data opens accounts, files claims, and commits crimes under the victim's name.
  • Investment and payment fraud: Fake platforms and manipulated trust drain savings, and investment fraud led every loss category in 2025 at 8.6 billion dollars.
  • Cryptocurrency crime: Theft, laundering, and crypto-investment scams referenced in 18% of complaints, carrying more than 11.3 billion dollars in losses.
  • Malware distribution: Infostealers, Trojans, and spyware harvest credentials and card data at scale, feeding the resale markets described below.
  • Denial-of-service attacks: Traffic floods knock services offline for extortion, competition, or ideology.
  • Cyberstalking and harassment: Persistent digital surveillance, threats, and non-consensual image abuse targeting individuals.
  • Intellectual property theft and espionage: Trade secrets, source code, and state secrets exfiltrated for competitive or geopolitical advantage.
  • Online child exploitation: Grooming, abuse material, and sextortion, prosecuted as priority offenses in every major jurisdiction.
common types of cybercrime

Cybercrime Examples From Recent Years

Three recent examples show the classification above operating in practice, one from each actor category.

  • RAMP forum seizure (2026): A ransomware-friendly underground forum connected ransomware groups, affiliates, and access brokers from 2021 until the FBI seized it in January 2026, and its fall fragmented the trade into smaller, harder-to-track communities.
  • Salt Typhoon espionage campaign: A China-linked state operation intruded into US internet service providers, a textbook cyber-dependent crime against critical infrastructure aimed at long-term intelligence access.
  • Crypto investment fraud wave (2025): Fake trading platforms and long-con romance-investment schemes produced 7.2 billion dollars in reported losses, the top loss-producing scheme type in the FBI's 2025 data.

How Cybercrime Operates: The As-a-Service Economy

Modern cybercrime runs as a supply chain, not as lone actors writing their own tools. Specialization splits the work into tradable services, and that division of labor explains both the volume of attacks and the difficulty of stopping them.

Initial access brokers breach networks and sell the entry point. Ransomware-as-a-service operators lease the malware and infrastructure to affiliates for a revenue share, phishing-as-a-service platforms sell turnkey lure kits with hosting, and infostealer operators dump harvested credentials into subscription channels. Money mule networks and crypto laundering services close the chain by converting stolen value into spendable funds.

Underground forums and Telegram channels host this market. CloudSEK's analysis of France-targeted dark web activity illustrates the compounding effect: monthly underground volume around one country's data grew more than fourfold in two years, driven by credential resale and free leak distribution rather than by any single incident. Law enforcement seizures of major forums disrupt trade briefly, and activity migrates to smaller communities within weeks.

cybercrime as a service economy

Why Cybercrime Keeps Growing

Four structural forces push cybercrime volume upward faster than enforcement scales.

  • Low entry cost: As-a-service tooling turned attacks into purchases, so participation requires a budget rather than a skill set.
  • Anonymity infrastructure: Cryptocurrency, bulletproof hosting, and anonymizing networks separate the offender from the offense at every step.
  • Jurisdictional arbitrage: Operating from non-cooperative countries against victims in wealthy ones keeps arrest probability near zero for high-volume operators.
  • Return on investment: Losses above 20 billion dollars against globally modest conviction counts make cybercrime the rare crime category where economics favor the offender.

Who Commits Cybercrime

Four actor categories drive nearly all activity, with different motives and targets.

  1. Organized criminal groups: Profit-driven syndicates running ransomware franchises, fraud operations, and laundering networks with corporate-style structure.
  2. State-sponsored actors: Government-backed units conducting espionage, prepositioning in critical infrastructure, and stealing currency or IP to fund state objectives.
  3. Hacktivists: Ideologically motivated groups defacing sites and flooding services around political conflicts, occasionally overlapping with the criminal data trade.
  4. Insiders and lone offenders: Employees abusing access, and individuals running scams or harassment campaigns without group infrastructure.

Impact and Cost of Cybercrime

Reported losses understate the real cost, since reporting is voluntary and many organizations absorb incidents silently. Even the reported curve is steep: from 16.6 billion dollars in 2024 to 20.877 billion in 2025, with complaints crossing one million for the first time.

Victim distribution skews old. People aged 60 and above filed more complaints than any other group and lost 7.7 billion dollars, roughly 39% of all losses, a concentration that shapes both criminal targeting and prevention policy.

Non-financial damage compounds the ledger. Hospital ransomware delays care, infrastructure attacks interrupt utilities, stolen trade secrets erode decades of research advantage, and every incident taxes public trust in digital services.

Cybercrime Laws and Jurisdiction

Five legal instruments anchor how the world prosecutes cybercrime, and their gaps explain why arrests lag offenses.

  • Budapest Convention (2001): First international cybercrime treaty, harmonizing offenses and evidence-sharing across 70+ ratifying states, with major non-members limiting its reach.
  • UN Convention against Cybercrime (2024): First comprehensive global treaty, adopted by the General Assembly in December 2024 and opened for signature in Hanoi in October 2025. It creates a 24/7 cooperation network and criminalizes offenses from ransomware to non-consensual intimate imagery.
  • Computer Fraud and Abuse Act: Core US statute since 1986 criminalizing unauthorized access, with state statutes layering on top.
  • GDPR and breach notification regimes: Data protection laws that convert negligent security into regulatory liability, compelling disclosure that makes crime visible.
  • India's IT Act 2000 and DPDP Act 2023: India's framework criminalizing hacking, identity theft, and data offenses, paired with new data-protection duties for organizations.

Jurisdiction remains the structural weakness. An offender in one country, infrastructure in a second, and victims in a third force investigations through mutual legal assistance treaties that move in months while attacks move in minutes. Safe-haven jurisdictions with weak enforcement absorb much of the world's high-volume operations.

How to Report Cybercrime

Reporting cybercrime runs through national channels, and speed matters most for financial fraud, since banks reverse transfers only within narrow windows. Contact the bank first in any money-loss case, then file with the national agency.

Region Agency Channel
United States FBI Internet Crime Complaint Center Complaint portal at ic3.gov
India Indian Cyber Crime Coordination Centre (I4C) National portal cybercrime.gov.in and the 1930 financial fraud helpline
United Kingdom Action Fraud Reporting portal actionfraud.police.uk
European Union National police forces Member-state reporting channels, coordinated through Europol
Anywhere Victim's bank or card issuer Immediate recall request on fraudulent transfers, before any portal filing

How to Prevent Cybercrime

Preventing cybercrime at the organizational level means raising attacker cost across 6 controls, each closing an entry path the types above depend on.

  1. Multi-factor authentication everywhere: Phishing-resistant MFA on email, VPN, and admin accounts neutralizes the stolen credentials that open most intrusions.
  2. Patching on an exploit-informed schedule: Prioritizing actively exploited vulnerabilities closes the openings ransomware affiliates scan for daily.
  3. Email authentication and filtering: SPF, DKIM, and DMARC enforcement plus language-aware filtering blunt the phishing volume that leads every complaint chart.
  4. Verification culture against social engineering: Payment changes and data requests verified through a second channel defeat the social engineering techniques behind business email compromise.
  5. Monitoring and rapid response: Centralized logging with tested response playbooks converts intrusions into contained incidents rather than encrypted networks.
  6. External threat monitoring: Watching criminal forums, leak sites, and Telegram channels for the organization's data, credentials, and brand surfaces attacks during preparation.

How AI Changes Cybercrime

Artificial intelligence entered the official record in 2025, when the FBI tracked AI-referencing complaints for the first time: 22,364 complaints carrying 893 million dollars in losses. Generative tools now write fluent lures in any language, clone voices for authorization fraud, and assemble target research in minutes.

Defenders answer with the same technology, and the deeper treatment of both sides belongs to a dedicated discussion of AI in cybersecurity. What matters for the cybercrime picture is directional: AI lowers the skill floor for offenders exactly as the as-a-service economy lowered the capital floor, and the two compound.

Monitor Cybercrime at Its Source with CloudSEK XVigil

Every stage of the as-a-service economy leaves a visible trace: an access listing naming a company, a stealer log carrying employee credentials, a fraud kit impersonating a brand, a leak post advertising customer data. Traces surface on the forums, marketplaces, and Telegram channels where the trade happens, before the follow-on attack lands.

CloudSEK XVigil monitors those sources continuously for organization-specific exposure, detecting leaked credentials, data leak listings, brand abuse, and access sales that name the enterprise, and prioritizing each finding by exploitability. Detection at the point of trade turns the criminal supply chain's own visibility against it, giving security teams the interval between preparation and execution in which disruption costs defenders least.

FAQs About Cybercrime

Is cybercrime a felony?

It depends: cybercrime is charged as a felony or a misdemeanor based on jurisdiction, financial damage, and intent, with ransomware, large-scale fraud, and espionage prosecuted as felonies almost everywhere.

What is the difference between cybercrime and a cyberattack?

A cyberattack is the technical action against a system, while cybercrime is the legal category covering that attack plus offenses like fraud and harassment that need no intrusion at all.

Who investigates cybercrime cases?

A national agency investigates cybercrime cases in each country: the FBI in the US and I4C in India, with Interpol and Europol coordinating who handles cross-border cases.

What was the first cybercrime in history?

What historians count as the first cybercrime in history was the 1834 French telegraph fraud: the Blanc brothers bribed operators to leak market data, predating computers.

How are cybercriminals caught across borders?

Cybercriminals are caught across borders through mutual legal assistance treaties, joint operations coordinated by Interpol and Europol, infrastructure seizures, and arrests when suspects travel into cooperative jurisdictions.

Does cyber insurance cover cybercrime losses?

Yes, cyber insurance covers many cybercrime losses, including response costs, business interruption, and often ransom payments, while policies exclude prior breaches and increasingly condition payouts on baseline controls.

Related Posts
9 Common Ransomware Attack Vectors in 2026
Ransomware attacks in 2026 can begin through vulnerability exploitation, compromised credentials, brute force, phishing, malware, third-party access, and brokered access.
10 Automotive Cybersecurity Threats Reshaping the Industry in 2026
Automotive cybersecurity in 2026 covers ransomware, supplier compromise, OTA risks, vehicle networks, AI threats, regulations, and attack-path prioritization across OEMs.
7 Best Supply Chain Risk Management Platforms in 2026
Seven supply chain risk management platforms for 2026, covering cyber exposure, supplier screening, risk assessments, analytics, workflows, procurement, and governance.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.