Cybercrime moves out of the shadows

Cybercrime is emerging from the dark web, with the actual cumulative cost of cyberattacks in 2024 reaching $9.5trn. This is close to the predicted $10.5trn by 2025, which was initially considered exaggerated. The cost of these economic invasions has risen significantly from $3trn in 2015, making cybercrime a growth industry of apocalyptic proportions.
If cybercrime were seen as an economy in its own right, it would be the third biggest in the world after the US and China. The damage is mounting by the day, with many victim companies attesting to the severity of the issue. For example, South Korean e-commerce platform Coupang took a hit in December 2025 that stole the personal details of nearly 35 million users.
Cyberattacks on Businesses
In 2025, major cybercrime attacks on businesses were dominated by massive cryptocurrency thefts, sophisticated third-party vendor breaches, and disruptive ransomware. A gang was able to halt emergency services across several American states in an attack at OnSolve, a critical risk management provider, in a CodeRED alert system breach.
Hardly a month passes without a damaging and sometimes crippling attack by a wide variety of cybercriminals. These range from computer-savvy youths who think it is fun to government-sponsored agencies engaged in systematic industrial espionage. For instance, according to the Centre for Strategic and International Studies, in December 2025 a Russia-linked group named Electrum knocked out about 30 sites in Poland’s energy grid.
State-Sponsored Cybercrime
State-sponsored cybercrime is highly organised.
Cybercrime investigators say the dark web has become a gigantic pool for the malware, exploit kits, and other tools used to inflict economic mayhem. These weapons have become so powerful that they could disable the economy of a city, state, or even an entire country.
Related: Britain weighs Norway-style wealth fund
The rapid spread of artificial intelligence is blocking some of these attacks, but the economic damage continues to mount. The IMF warns that cumulative losses could reach $23trn by 2027, incurred from direct losses triggered by ransomware, data theft, embezzlement, and fraud, as well as indirect costs such as reputational damage, legal fees, and regulatory fines. Experts from the Brookings Institute also warn that the new wired, always-on brand of criminals will profoundly change the face of online trading and other industries.
No industry is safe from cybercrime. The ingenuity of cybercriminals keeps improving, with one of their favourite scams being ‘CEO fraud’, whereby the criminal poses as the boss by using artificially generated videos and voice to trick an employee into transferring money or disclosing commercially confidential information.
Experts warn that over the next two decades, militancy, terrorism, and organised crime will profoundly change as non-state armed actors adopt many of the same technologies used by conventional armies and everyday society.
The overall consequence is that it will become much harder for traditional law enforcement to police crime that is committed far from where the damage is caused. As experts warn, a handful of individuals are already running automated scams, deepfake identity fraud, and algorithmic phishing, often from locations like basements in distant cities that are hard to detect.
Economic havoc can be caused remotely on a shoestring.