Cybercrime Now Has a Supply Chain — INTERPOL's Cybercrime Expert Group (CyberEX)

INTERPOL's cybercrime experts say the criminal underworld has quietly turned into an industry. Here's what that means for the rest of us.
INTERPOL's Cybercrime Expert Group (CyberEX) has just released its first thematic paper, The Industrialization of Cybercrime, Mapping the Cybercriminal Ecosystem in the Era of AI. The full report is restricted to law enforcement, but a public executive summary lays out the core finding in blunt terms: cybercrime is no longer a collection of clever individuals. It is an economy, with suppliers, customers, specialists, subcontractors and after-sales service.
The paper landed after the CyberEX annual meeting hosted in Hong Kong in early February, held under the theme "Disrupting the Industrialisation of Cybercrime" and chaired by Lam Cheuk-ho, Raymond Lam, the Chief Superintendent who heads the Hong Kong Police Force's Cyber Security and Technology Crime Bureau and currently chairs CyberEX. More than 120 experts from over 30 countries and regions attended.
The simple idea at the heart of it
Think about how a car gets built.
No single person makes a car. One factory makes tyres. Another makes glass. Another makes the seats. Someone else bolts it all together, someone else ships it, someone else sells it, and someone else finances the loan. Because the work is split up, cars can be produced by the million, and you do not need to understand engineering to own one.
That is exactly what has happened to cybercrime. Criminals stopped trying to do everything themselves and started specialising. Each specialist does one thing extremely well and sells that one thing to everybody else.
The industry term for this is crime-as-a-service. In practice, it means a person with money but no technical skill can now assemble a serious cyberattack the way you assemble a meal from a delivery app.
What is actually on the menu
INTERPOL's summary maps the services available at each stage of an attack. It is worth reading slowly, because the completeness of it is the story.

Before the attack, you can rent ready-made malware and ransomware kits. You can buy stolen usernames and passwords, or pay an "access broker" who has already broken into a company and is selling the keys. You can buy tools designed to hide your software from antivirus programs. You can even join criminal training forums where experienced offenders mentor newcomers.
During the attack, there are phishing platforms sold on subscription, deepfake generation offered as a service, "bulletproof" hosting providers who promise to ignore police requests, denial-of-service attacks available by the hour, and forged identity documents to order.
After the attack, the ecosystem takes care of the money and the mess. Stolen data goes to illicit marketplaces. Money-mule networks move the cash. Crypto mixing and tumbling services scramble the trail. Cash-out services turn digital proceeds into spendable money. Some operations even offer legal advice.
Every single step. Available. For rent.
Why this makes the problem so much worse
Three things follow from the division of labour, and each one is bad news.
- It is faster and harder to catch. Specialists are good at their niche. A team assembled from best-in-class services outperforms a generalist working alone, and the attack passes through many hands, leaving investigators with fragments rather than a single trail.
- The barrier to entry has collapsed. You no longer need talent. You need a budget. That means far more offenders, and therefore far more attacks.
- It is spreading beyond "computer crime." The report is clear that this infrastructure is fuelling a much wider range of serious criminality, fraud, human trafficking, and other organised crime. The same money-laundering networks that cash out ransomware payments also cash out the proceeds of scam compounds.
The AI part, and an honest note about hype
Here the INTERPOL summary is refreshingly measured, and I want to underline that, because a lot of commentary in this space is not.
Right now, AI is being used by criminals in limited but real ways. Translating ransom notes. Writing phishing emails in fluent versions of languages the criminal does not speak. Building convincing fake personas for research on targets. Running social engineering at a scale one human could not manage.
That is not science fiction. It is grammar and volume, and it matters, because bad grammar used to be one of the last reliable warning signs an ordinary person could spot. That signal is gone.
In some countries like India, there are public reports on use of AI-assisted malware development and automated hunting for software vulnerabilities.
What is being done about it
Because the ecosystem is the product, the response has to target the ecosystem rather than individual criminals. The framework proposed in the paper rests on four ideas: disrupt the criminal infrastructure that everyone depends on, correlate intelligence across countries and sectors so fragments become pictures, raise the cost of committing cybercrime so the business stops paying, and drive innovation so policing keeps pace with the technology.
The logic is sound. Arresting one ransomware operator is a headline. Taking down the bulletproof hosting provider, the access broker, or the cash-out network that a hundred operators rely on is an actual dent.
What this means for you
If you are not a police officer, the takeaway is simpler than the diagram suggests.
You are unlikely to be targeted because someone chose you. You are much more likely to be caught by an automated, industrial process that is scanning everyone at once, the digital equivalent of a factory rather than a hunter. That changes what protects you.
Turn on two-factor authentication, especially on email, because stolen passwords are a traded commodity and the password alone is no longer a lock. Install updates, because automated exploitation of known flaws is the cheapest attack there is. Stop trusting a message because it sounds professional, and start verifying anything involving money or credentials through a separate channel you chose yourself, a phone number you already have, not one in the message. And treat urgency itself as the warning sign, because rushing you is the one technique every branch of this industry still depends on.
Cybercrime got organised. The rest of us need to as well.
Sources: INTERPOL CyberEX executive summary, "The Industrialization of Cybercrime, Mapping the Cybercriminal Ecosystem in the Era of AI"; Hong Kong Police Force and Hong Kong Government announcements on the CyberEX In-Person Annual Meeting, 2–3 February 2026. The full report is restricted to law enforcement.