Executive Summary
BLUF: Balkan-based cybercriminal activity is evolving fastest in scalable online fraud, multilingual call-centre operations, credential exploitation, payment diversion and laundering support—not yet in demonstrably Balkan-controlled global ransomware platforms.
The strongest evidenced model is a modular ecosystem connecting local operators with transnational suppliers of malware, data, infrastructure, advertising and payment services.
Public evidence does not justify treating traditional Balkan organised-crime groups and Balkan cybercrime networks as interchangeable populations.
Through 2031, generative AI, stolen digital identities, cryptocurrency settlement and outsourced technical services will lower entry barriers and increase fraud throughput.
The central risk is the conversion of relatively inexpensive regional labour, language skills and corporate infrastructure into remotely exportable criminal capacity.
The highest-confidence intervention points are recruitment, initial access, domain and hosting infrastructure, payment conversion, mule coordination and cross-border electronic evidence.
The Balkan Cybercrime Factory Is Moving Closer to Italy
The most consequential evolution of Balkan organised crime is no longer occurring only along ports, motorways or trafficking corridors. It is taking place inside call centres, fraudulent investment platforms, compromised corporate mailboxes, cryptocurrency wallets and rented digital infrastructure. Crime is becoming remotely exportable: operators, software, victim data and laundering channels can be purchased separately and assembled across several jurisdictions. For Italy, this is not a peripheral threat. Linguistic proximity, intense commercial relations, financial integration and established Italy–Balkan criminal connections make Italian households, companies and public institutions both targets and potential transit points. The strategic question is no longer whether criminal groups will “go digital,” but whether Europe can interrupt their revenues faster than they can replace their brands, accounts and infrastructure.
The Industrial Turn
Europol’s Internet Organised Crime Threat Assessment 2026, issued under Executive Director Catherine De Bolle, describes online fraud as the fastest-growing area of organised crime. Investment fraud, business email compromise, romance scams, technical-support fraud and attacks against payment systems now operate through transnational combinations of logistics, technology and finance. Europol observed more than 120 active ransomware brands in 2025 and identified a continuing expansion of ransomware-as-a-service: developers supply platforms and malware, access brokers provide compromised systems, affiliates conduct intrusions, while separate specialists negotiate payments and launder cryptocurrency.
The same division of labour is transforming online fraud. Malicious advertising generates victims; multilingual operators convert them; fake platforms simulate profits; remote-access software exposes home banking; mule accounts receive transfers; cryptocurrencies or offshore services disperse proceeds. Generative AI improves translations, impersonation and conversational scripts. Voice bots can screen victims before transferring the most promising targets to human operators. The criminal enterprise consequently scales without placing every participant under one command or in one country.
This distinction is essential. A call centre in Tirana or Belgrade does not by itself prove Albanian or Serbian strategic control. The premises may supply only the sales function, while platform administration, advertising, data and treasury management remain elsewhere. Geography identifies the production node, not necessarily the owner.
The Balkan Production Base
The official judicial record already shows industrial capacity. On 8 and 9 November 2022, an operation supported by Eurojust and Europol searched 15 call centres—six in Albania, five in Georgia, three in Ukraine and one in North Macedonia—together with 27 other locations. Investigators estimated hundreds of thousands of victims and damage of approximately €50 million per quarter. The suspected activity dated back to at least 2016 and used hundreds of online platforms. Authorities seized more than 500 electronic devices, bank accounts, cryptocurrency wallets, identity documents, properties and cash.
A separate operation in January 2023 exposed an even clearer functional division. According to Eurojust, the network operated call centres from Serbia, used technical infrastructure in Bulgaria and allegedly based part of its laundering operation in Cyprus. More than 250 workplaces were identified. Fourteen suspects were initially arrested in Serbia and one in Germany; a second action produced another 16 arrests in Serbia. Victims were located in Germany, Switzerland, Austria, Australia and Canada.
The model has continued to evolve. On 29 April 2026, Austrian and Albanian authorities dismantled several alleged fraud call centres in Tirana. Eurojust reported 10 arrests, seizures approaching €900,000 and estimated losses exceeding €50 million. Operators worked in teams of six to eight, divided by language—German, English, Italian, Greek and Spanish—under team leaders and centre managers. This was not improvised deception. It was a structured export industry organised by market, language and productivity.
The Italian Connection
Italy has already confronted the mechanism directly. A joint Italian–Albanian investigation, opened at Eurojust by the Italian authorities in 2020, targeted a Tirana call centre that allegedly defrauded victims through fictitious cryptocurrency investments. The Public Prosecutor’s Office of Pisa and the Carabinieri worked with Albania’s Special Prosecution Office against Corruption and Organised Crime, SPAK, and the Albanian State Police.
During the coordinated action of 13–15 December 2022, authorities searched 13 locations in Albania and seized more than 160 electronic devices, one mobile telephone and approximately €3 million in assets, including 11 properties. Eurojust estimated the total damage at €15 million. The method was particularly aggressive: victims were contacted through virtual numbers and VPNs, shown small initial gains, persuaded to increase their investment and, in some cases, induced to provide remote access to their home-banking systems. Those who discovered the fraud were targeted again by alleged recovery specialists demanding further payments.
This case exposes Italy’s structural vulnerability. Italian is commercially valuable to Balkan fraud centres; Italian companies maintain extensive supplier relationships across South-Eastern Europe; and transfers that appear compatible with genuine investment, consultancy or commercial activity can be routed through legitimate-looking companies. The threat is therefore not confined to digitally inexperienced consumers. It extends to corporate treasuries, professional firms, municipalities, healthcare providers and small manufacturers whose payment controls remain based on familiarity rather than independent verification.
BEC, the Invisible Balance-Sheet Risk
Business email compromise is potentially more dangerous to Italian companies than its technical simplicity suggests. The criminal does not need to encrypt an industrial network. It is enough to understand who authorises payments, which supplier is awaiting settlement, how executives write and when a transfer is expected. A compromised mailbox or convincingly imitated identity can redirect a legitimate payment toward a criminal account.
The FBI’s 2025 IC3 Annual Report recorded 24,768 BEC complaints and reported losses of $3.047 billion. By comparison, it received more than 3,600 ransomware complaints with directly reported losses above $32 million. That comparison does not measure total economic harm: the FBI explicitly states that ransomware figures normally exclude lost production, downtime, wages, damaged equipment and remediation. It nevertheless demonstrates BEC’s exceptional capacity to convert limited technical access into immediate balance-sheet loss.
Generative AI increases the danger by reproducing language, tone and executive identity, but the decisive bottleneck remains financial. Fraudulent instructions are useless without accounts capable of receiving and rapidly dispersing corporate payments. Italy must therefore treat beneficiary-account intelligence, nominee companies and mule recruitment as cybersecurity issues, not merely as conventional money laundering.
Italy’s Exposure Is Already Measurable
The Italian National Cybersecurity Agency, ACN, recorded 91 ransomware attacks in the first half of 2025, essentially unchanged from the 92 registered in the corresponding 2024 period. In the second half of 2025, ACN recorded 54 cases, compared with 48 in the equivalent 2024 period. The Agency also registered 1,253 cyber events between July and December 2025, an increase of 30 per cent year on year, and sent more than 5,000 communications to organisations whose systems were considered at risk.
These figures measure only the visible portion of the threat. A company reports ransomware because production stops; it may remain unaware for months that mailboxes have been monitored or supplier payments manipulated. Investment and recovery fraud are also under-reported because victims fear reputational damage or do not immediately understand that the apparent trading platform never held genuine assets.
Italy has committed €623 million through PNRR Mission 1, Component 1, Investment 1.5 “Cybersecurity,” implemented by ACN. The programme has financed eight public calls and approximately 300 projects and interventions. The National Cybersecurity Strategy covers 2022–2026; Andrea Quacivi, appointed by the Council of Ministers on 22 May 2026, took office as ACN Director General on 8 June. The next strategic cycle must now connect national resilience with organised-crime finance and Balkan judicial cooperation. Protecting servers without tracing proceeds addresses only half of the enterprise.
The Evidence Race
Digital crime operates in minutes; judicial cooperation often operates in days or months. Domains disappear, communications are deleted, cryptocurrency moves and mule accounts empty before a complete request crosses several jurisdictions. The EU e-evidence framework seeks to narrow that gap. European production orders can require represented service providers to respond within 10 days, or within six hours in emergencies; preservation orders are designed to prevent stored evidence from being deleted while production is pending.
For Italy, the value of these instruments will depend on operational integration with Western Balkan partners. Albania’s cooperation with Eurojust is already substantial. Liaison Prosecutor Fatjona Memçaj has served in The Hague since January 2021. In 2025, her office participated in 121 new cases, 27 coordination meetings, three coordination centres and 27 joint investigation teams. These numbers show that a functioning bridge exists. The priority is to make it faster, financial and data-driven.
Every major Italian fraud report should immediately generate five coordinated actions: preservation of provider data; contact with the originating and beneficiary banks; identification of connected accounts and wallets; comparison with known domains, devices and companies; and assessment of whether the victim is exposed to recovery fraud. The objective is not simply to identify the caller. It is to reconstruct the production system.
The Financial Chokepoint
Liquidity is the decisive vulnerability of the criminal model. Websites, telephone numbers and operator accounts are cheap to replace; trusted receiving accounts and laundering relationships are not. The Financial Action Task Force reported in February 2026 that 156 jurisdictions—90 per cent of those assessed—identify fraud as a major money-laundering risk. Fraud networks increasingly integrate laundering from the outset through nominees, mule accounts, traded bank and exchange accounts, fintech platforms and rapid conversion into virtual assets.
A credible Italian strategy must therefore measure the time between a victim’s report and the suspension of funds. It must link banks, payment institutions, cryptocurrency service providers, law enforcement and prosecutors through a permanent rapid-response mechanism. Confirmation-of-payee controls, detection of unusual beneficiary changes and mandatory independent verification for high-value transfers should become standard corporate governance, especially for SMEs operating through cross-border supplier networks.
The same principle applies to criminal companies. Europol reported in December 2024 that 86 per cent of the EU’s most threatening criminal networks abuse legal business structures. Online-fraud networks use trading firms, investment companies, call centres, IT providers and shell entities that can be established and dissolved quickly. Corporate registries, employment data, telecommunications patterns and beneficial ownership must therefore become part of cybercrime intelligence.
The 2031 Fault Line
By 2031, the most probable threat is not a single Balkan ransomware super-cartel. It is a modular ecosystem in which regional call centres, account suppliers, company structures, access brokers and laundering intermediaries connect to platforms controlled across multiple jurisdictions. Industrialised fraud will remain the most mature segment. BEC will grow through stolen corporate access and payment intelligence. Balkan participation in ransomware will probably expand through affiliates, hosting, initial access and financial services rather than through immediate control of globally dominant brands.
Enforcement can push this market in two opposite directions. If authorities close premises without seizing data, administrators and financial networks, large call centres will fragment into smaller offices and remote workers. Arrest statistics will improve while losses continue. If Italy and its partners combine rapid evidence preservation, payment freezing, cryptocurrency tracing, beneficial-ownership analysis and confiscation, the business model becomes less reliable.
The decisive metric is not the number of domains removed or operators arrested. It is the proportion of proceeds recovered, the time required for a network to regenerate and the number of campaigns disabled by removing one shared facilitator. Italy’s advantage is that it already possesses ACN, specialised police and prosecutors, a major financial system and strong operational relations with Albania and other Balkan partners. Its weakness is institutional separation between cybersecurity, fraud investigation and organised-crime finance.
The next frontier of Italian security policy lies precisely there. The Balkan route is no longer only a route across territory. It is an export architecture for digital deception—and its most vulnerable border is the point where code, trust and money finally meet.
Navigational Index
- From territorial control to modular criminal production — How location-based enterprises become remotely scalable service networks.
- Ransomware, BEC and industrialised online fraud — Comparative maturity, infrastructure and monetisation pathways.
- Five-year scenarios, indicators and intervention points — Bayesian hypotheses, Monte Carlo outlook and policy implications through 2031.
Master Abstract
The central analytical finding is narrower—and therefore more defensible—than the proposition that established Balkan trafficking organisations are collectively becoming ransomware cartels. Verified law-enforcement evidence instead reveals the growth of a regional production layer for industrialised online fraud: multilingual operators, hierarchical call-centre management, deceptive investment platforms, customer-acquisition scripts, impersonation workflows and cross-border payment extraction. In April 2026, Austrian and Albanian authorities dismantled an alleged network operating several Tirana call centres; Eurojust reported 10 arrests, searches of several premises, seizures approaching EUR 900,000, estimated victim losses exceeding EUR 50 million, teams of six to eight operators divided by language and a managerial hierarchy resembling a legitimate company. This is unusually strong evidence of business-process industrialisation, although it does not prove organizational continuity with drug, weapons or migrant-smuggling groups. Fraud call centres targeting EU citizens shut down with Eurojust’s support – over EUR 50 million in damages uncovered – Eurojust – April 2026 — Verified primary source. Earlier operations exposed geographically distributed nodes in Serbia, Bulgaria, Cyprus, Albania, Bosnia and Herzegovina and Kosovo, including call centres selling fictitious cryptocurrency investments and facilities generating thousands of fraudulent calls per day. Call centres selling fake crypto taken down in Bulgaria, Serbia and Cyprus – Europol – January 2023 — Verified primary source. Operation PANDORA shuts down 12 phone fraud call centres – Europol – May 2024 — Verified primary source. The correct baseline is consequently not a completed migration from physical crime to cybercrime, but an uneven recombination of labour, corruption exposure, shell-company access, linguistic reach, laundering channels and commercially available cyber capabilities.
This recombination is occurring inside a global crime-as-a-service market that separates technical capability from victim acquisition and monetisation. Europol observed more than 120 active ransomware brands during 2025, described online-fraud networks as efficient transnational industries, and assessed that fraud actors increasingly outsource functions such as cryptocurrency theft while using phishing, malicious advertising, SIM-box infrastructure and generative AI-enhanced social engineering. Europol also identified a shift in ransomware from encryption-centred coercion toward data-theft extortion and warned that the boundary between financially motivated networks and hybrid-threat actors is becoming less distinct. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. For Balkan operators, this modular market changes the economics of criminal entry: a group no longer needs to develop ransomware, discover vulnerabilities, operate bulletproof hosting and launder proceeds internally. It can purchase credentials or initial access, rent phishing and communications infrastructure, acquire fabricated identities, recruit multilingual operators, contract technical specialists and outsource conversion of proceeds. BEC is particularly compatible with this structure because it joins credential theft, corporate impersonation, invoice manipulation, social engineering and mule-account management without requiring control of a sophisticated malware platform. The external demand environment is already immense: the FBI recorded 1,008,597 complaints and USD 20.877 billion in reported losses during 2025, including 24,768 BEC complaints associated with approximately USD 3.047 billion, while cyber-enabled fraud accounted for 85% of all reported losses. These are United States complaint statistics—not estimates of Balkan participation—but they quantify the export market accessible to location-independent criminal services. 2025 IC3 Annual Report – Federal Bureau of Investigation – April 2026 — Verified primary source.
The initial Analysis of Competing Hypotheses rejects a single-cause narrative and retains five simultaneously testable explanations. H₁, direct digitisation, proposes that established territorial organised-crime groups are internalising cyber capabilities; H₂, parallel emergence, treats Balkan cyber enterprises as largely new networks exploiting the same institutional environment without meaningful continuity with physical trafficking organisations; H₃, outsourced-node integration, interprets regional operators as labour, sales, hosting, laundering or access components inside externally directed criminal supply chains; H₄, commercial capture, anticipates legitimate or semi-legitimate call centres, marketing companies, payment intermediaries and IT contractors being repurposed through ownership, coercion or recruitment; H₅, attribution distortion, warns that servers, operators, bank accounts or arrests located in the Balkans may identify only one layer of a network controlled elsewhere. The provisional Bayesian assessment assigns the greatest weight to H₃, followed by H₂ and H₄; evidence for H₁ remains plausible but publicly incomplete, while H₅ must remain active in every country-level attribution. Institutional asymmetry will influence the five-year trajectory. The European Commission reported that Albania had adopted a 2025–2030 National Cybersecurity Strategy but still needed stronger capacity, implementing legislation, training and awareness measures. Albania Report 2025 – European Commission – November 2025 — Verified primary source. It separately found that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and had made no reporting-period progress on the cited cybercrime alignment issue. North Macedonia 2025 Report – European Commission – November 2025 — Verified primary source. These gaps do not cause cybercrime, but they can widen the interval between detection, preservation of electronic evidence, attribution, seizure and prosecution—the interval service-based networks exploit by replacing domains, accounts, personnel and brands faster than cases mature.
Digital Criminal-Service Transition Model
Scenario drivers
Analysis of Competing Hypotheses · Provisional posterior
Analytical model, not an observed crime count. Default probabilities are structured judgments derived from the cited institutional evidence. The simulation varies driver uncertainty across 10,000 iterations; slider changes test assumptions rather than manufacture Balkan attribution. “Ransomware maturity” measures the risk of regional participation across the service chain, not proven regional ownership of ransomware brands.
From Territorial Control to Modular Criminal Production
The operating model has changed
The decisive transformation is not simply that organised criminals have adopted computers. Criminal organisations have used telecommunications, encrypted messaging, online banking and digital logistics for years. The deeper change is organizational: the revenue-producing system can now be decomposed into purchasable modules, distributed across jurisdictions and recombined for successive campaigns without the participants sharing territory, nationality, hierarchy or even direct contact. A location-based enterprise traditionally derives power from controlling a port, neighbourhood, border crossing, transport corridor, protection market or corrupt administrative relationship. Its competitive advantage consists of physical access, coercive reputation, trusted kinship networks, territorial surveillance and the capacity to enforce agreements through violence. A modular cybercriminal enterprise substitutes access to infrastructure, identities, credentials, communications, payment rails, victim lists and specialized labour for most of those functions. Its “territory” becomes a temporary assemblage of cloud accounts, domains, call-centre seats, compromised devices, bank accounts, cryptocurrency wallets and contractor relationships. Europol’s 2026 assessment identifies online-fraud networks as highly efficient transnational industries using distinct logistical, technical and financial operations; it also records the outsourcing of criminal capabilities through crime-as-a-service, the use of generative AI to personalize social engineering and more than 120 active ransomware brands observed during 2025. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. INTERPOL independently assesses that cybercrime-as-a-service and money-laundering-as-a-service enable large-scale financial fraud, while warning that substantially less is known about how fraud offenders are organized than about their techniques. INTERPOL Global Financial Fraud Assessment – INTERPOL – March 2024 — Verified primary source. This evidentiary limitation is fundamental: an Albanian call centre, Serbian operator, Bulgarian server or Cypriot account establishes the location of a component, not necessarily the nationality of strategic command, beneficial ownership or ultimate profit.
Table 1 — Territorial and modular criminal-production systems
| Dimension | Territorial enterprise | Modular service network | Intelligence consequence |
|---|---|---|---|
| Primary asset | Physical corridor, market or protected locality | Credentials, data, infrastructure and specialist access | Digital artefacts may matter more than visible territorial presence |
| Organisational form | Persistent hierarchy or clan-based command | Cells, contractors, affiliates, brokers and service vendors | Arrested operators may reveal little about upstream control |
| Enforcement | Violence, reputation and physical proximity | Escrow, access restrictions, reputation systems, encryption and compartmentalisation | Low observable violence does not imply low organisation |
| Capital expenditure | Vehicles, warehouses, weapons, corrupt protection | Domains, hosting, malware access, advertisements, call-centre capacity and accounts | Entry costs fall when tools can be rented |
| Scaling constraint | Personnel and physical reach | Lead volume, automation, payment throughput and replaceable infrastructure | Victimisation can expand without equivalent headcount growth |
| Market boundary | Geographically delimited | Language, platform, payment system or victim segment | “Territory” becomes functional rather than geographic |
| Revenue cycle | Shipment or repeated local extraction | Continuous campaigns, subscriptions, commissions and revenue shares | Income becomes portfolio-based and campaign-driven |
| Failure mode | Territorial displacement or leadership arrest | Infrastructure seizure, liquidity interruption, data exposure or trust collapse | Disruption must target dependencies, not merely premises |
| Attribution problem | Who controls the locality? | Who owns the campaign, data, infrastructure and proceeds? | Operator location cannot be treated as command attribution |
| Regeneration | Requires rebuilding local protection | Requires replacing vendors, accounts, domains and brands | Recovery may occur in days or weeks |
The Balkan evidence: production nodes, not a monolithic cyber mafia
The strongest primary-source evidence from the Western Balkans concerns industrialized investment fraud and telecommunications-enabled deception rather than proven Balkan ownership of internationally dominant ransomware brands. In March 2022, Albanian and German authorities dismantled two fraudulent platforms operated through Albanian call-centre companies; the platforms had been active since 2018, targeted German victims and resulted in 15 arrests and searches at eight Tirana locations. Takedown of online investment fraud in Albania: 15 arrests – Eurojust – March 2022 — Verified primary source. In December 2022, Italian and Albanian authorities disrupted another Tirana-based operation associated with approximately EUR 15 million in losses. The documented workflow included virtual telephone numbers, delocalized VPNs, fabricated trading opportunities, small initial returns designed to build trust, remote-access software used to reach victims’ home-banking interfaces, cryptocurrency narratives and a second-stage “recovery” fraud targeting people who had already recognized the initial deception. Authorities seized more than 160 electronic devices and approximately EUR 3 million in assets, including eleven properties. Takedown of online investment fraud responsible for losses of EUR 15 million – Eurojust – December 2022 — Verified primary source. The importance of these cases lies not only in their monetary scale but in the sequencing of specialized functions: traffic acquisition, telephony, scripted persuasion, platform simulation, remote technical intervention, payment extraction, asset conversion and victim re-targeting. Each function can be performed by a different actor and procured independently. A location-based call centre therefore becomes a production facility inside a geographically dispersed system, comparable to a contract manufacturer that receives leads and software from upstream providers, processes victims through a standardized funnel and passes proceeds to downstream financial specialists. This model is remotely scalable because the campaign’s intellectual property—scripts, victim profiles, fake interfaces, conversion tactics and account-routing rules—can be duplicated across offices without transferring the entire organization.
Table 2 — Verified Balkan operational indicators
| Date | Exposed configuration | Verified scale | Modular-production indicator | Evidentiary limitation |
|---|---|---|---|---|
| March 2022 | Albanian call-centre companies operating “BrokerZ” and “Globalix” | 15 arrests; eight Tirana locations searched | Platforms, call-centre labour, foreign-language targeting and cross-border victims | Public record does not identify every upstream platform or beneficial owner |
| November 2022 | Call-centre network spanning Albania, Georgia, Ukraine and North Macedonia | 15 centres searched; hundreds of thousands of estimated victims; approximately EUR 50 million per quarter in estimated damage | Replicable centres connected to hundreds of platforms and centralized social-engineering methods | Physical dispersion does not establish where strategic command resided |
| December 2022 | Tirana call centre targeting Italian victims | Approximately EUR 15 million damage; EUR 3 million in assets seized | Virtual numbers, VPNs, remote-access software, cryptocurrency and recovery fraud | Case proves an integrated fraud chain, not ransomware capability |
| January–February 2023 | Serbian call centres, Bulgarian technical infrastructure and alleged Cypriot laundering base | More than 250 workplaces; 15 initial arrests, followed by 16 further Serbian arrests | Cross-border functional specialisation between sales, infrastructure and liquidity | National location of functions cannot be equated with ownership |
| April 2026 | Multiple Tirana call centres organized by language and managerial tier | 10 arrests; nearly EUR 900,000 seized; estimated losses exceeding EUR 50 million | Teams of six to eight, team leaders, centre managers and multilingual market segmentation | Allegations and damage estimates remain subject to judicial determination |
The November 2022 operation provides the clearest evidence that the production model had already moved beyond isolated call-centre fraud. Eurojust reported searches of 15 call centres—six in Albania, five in Georgia, three in Ukraine and one in North Macedonia—together with 27 additional locations. Investigators described dozens of call centres, hundreds of online platforms, victims numbering in the hundreds of thousands and estimated damage of EUR 50 million per quarter, with fraudulent activity dating to at least 2016. Seizures included more than 500 electronic devices, cryptocurrency wallets, bank cards, identity documents, cash and bank accounts. Eurojust coordinates action against massive investment fraud with hundreds of thousands of victims worldwide – Eurojust – November 2022 — Verified primary source. In January 2023, a separate case exposed a more explicit division of labour: the organised network allegedly operated call centres from Serbia, used technological infrastructure in Bulgaria and used Cyprus as a base for laundering proceeds. Authorities identified more than 250 workplaces, arrested fourteen people in Serbia and one in Germany during the initial action, interviewed more than 250 people and seized over 150 computers, cash and approximately USD 1 million in cryptocurrencies. A second action produced another sixteen Serbian arrests for alleged computer fraud, money laundering and criminal association. Takedown of fraudulent cryptocurrency network in Bulgaria, Cyprus and Serbia – Eurojust – January 2023, updated February 2023 — Verified primary source. This is the closest documented approximation to modular criminal manufacturing: Serbia supplied an operator-intensive victim-conversion layer, Bulgaria hosted a technical layer and Cyprus allegedly supplied part of the financial-conversion layer. The network’s market was not any of those territories; victims were reported in Germany, Switzerland, Austria, Australia and Canada. Its operational geography was determined by the cost, availability and risk profile of each function.
The criminal service stack
A remotely scalable criminal network should be analysed as a service stack rather than as a single “group.” At the acquisition layer, actors purchase advertisements, search-engine placement, compromised social accounts, leaked customer lists, telephone-number databases or credentials harvested by infostealers. At the engagement layer, multilingual operators establish trust through calls, messaging, email or fabricated professional profiles. At the technical layer, vendors provide phishing kits, cloned investment interfaces, remote-administration software, domain registration, hosting, proxy capacity, anonymized communications or access to compromised systems. At the transaction layer, nominees, money mules, payment institutions, crypto brokers and exchange accounts receive and fragment payments. At the concealment layer, proceeds move through rapid transfers, virtual assets, corporate accounts, cash withdrawal, trade transactions or professional laundering services. At the re-exploitation layer, victim data becomes a reusable asset for recovery fraud, impersonation, account takeover or sale to another network. FATF reports that 156 jurisdictions, representing 90% of the jurisdictions assessed, identify fraud as a major money-laundering risk; it further finds that large cyber-enabled fraud schemes increasingly incorporate laundering architecture from the outset through nominee accounts, mule networks, traded bank and exchange accounts, fintech platforms and rapid movement into virtual assets. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF Risks – Financial Action Task Force – February 2026 — Verified primary source. The strategic implication is that liquidity architecture is not a back-office activity added after the fraud succeeds; it is a gating dependency designed before victim contact begins. A campaign with superior persuasion but insufficient account capacity cannot scale because receiving accounts are frozen, flagged or saturated. Conversely, a network that possesses resilient money-mule recruitment, multiple payment channels and rapid cross-border conversion can purchase the remaining components from service markets.
Industrialised Scam Lifecycle
Interactive Operational Architecture
Victim Acquisition
- Malvertising / cloned sites / compromised accounts
- Purchased leads / stolen identities / credentials
Engagement & Conversion
- Multilingual call-centre operators
- Email impersonation / BEC / messaging
- AI-assisted scripts, translation and voice synthesis
Technical Enablement
- Domains / hosting / VPNs / proxies
- Phishing kits / remote-access tools / infostealers
- Fake trading dashboards / access brokerage
Payment Extraction
- Bank transfers / cards / fintech rails
- Cryptocurrency / exchange accounts
- Money mules / nominee companies
Layering & Monetisation
- Rapid dispersal / wallet chains / cash withdrawal
- Money-laundering-as-a-service
- Property, luxury assets or business integration
Data Recirculation
- Recovery fraud / repeat targeting / resale / account takeover
Why physical criminal capital remains valuable
The modular model does not abolish the advantages accumulated by traditional organised crime; it converts some of them into services. A territorial organisation may already possess corrupt facilitation, access to nominee directors, cash-intensive businesses, forged or fraudulently obtained documents, trusted diaspora contacts, coercive debt collection and established methods for moving value across borders. These assets can support a cyber-enabled enterprise even when the organisation cannot develop malware. Existing laundering relationships can process fraud proceeds; recruitment networks can supply operators and mules; corrupt access can reduce inspection risk; physical businesses can disguise payroll, office leases or transaction flows; and coercive capacity can discipline insiders who control valuable accounts. Yet the evidence does not support the assumption that every Balkan call-centre network is an offshoot of a narcotics clan. The more probable architecture is selective convergence: digital-native organisers purchase particular capabilities from actors who also serve drug traffickers, smugglers, tax fraudsters or sanctions evaders. INTERPOL finds that crime convergence frequently occurs around financial fraud and that organised fraud actors appear to exchange experience and collaborate to optimize opportunities, while explicitly acknowledging the continuing intelligence gap concerning how fraud is organized. INTERPOL Global Financial Fraud Assessment – INTERPOL – March 2024 — Verified primary source. This supports a “shared infrastructure” hypothesis more strongly than a universal transformation hypothesis. The relevant intelligence object is therefore not only the named criminal group but the broker connecting multiple revenue systems: the accountant servicing several illicit markets, the company-formation intermediary supplying nominee structures, the operator recruiting mule accounts, the administrator controlling several fraud brands, or the technical contractor able to transfer compromised access between ransomware affiliates and financial-fraud teams.
Table 3 — Conversion of territorial assets into digital services
| Legacy capability | Digitally exportable derivative | Potential customers | Observable indicators |
|---|---|---|---|
| Corrupt administrative access | Identity, registration or enforcement protection | Fraud networks, mule managers, laundering brokers | Repeated use of common addresses, officials, registrars or facilitators |
| Diaspora relationships | Multilingual targeting and foreign account recruitment | Call centres, BEC teams, recovery-fraud units | Country-specific scripts, foreign bank accounts, repeated remittance corridors |
| Cash-intensive businesses | Cash-out and commingling capacity | Crypto fraud, BEC and payment fraud | Revenue inconsistent with activity; rapid settlement followed by cash withdrawal |
| Document fraud | Nominee identities and account-opening packages | Mule networks, shell-company brokers | Recycled identity elements, device overlap, common introducers |
| Smuggling logistics | Movement of devices, cash, SIMs and personnel | Infrastructure vendors and financial cells | Recurrent travel and courier links around action dates |
| Coercive enforcement | Control of recruited mules or insiders | Account managers and laundering providers | Threats, debt bondage, document retention or unexplained personnel control |
| Property investment | Storage of illicit value | Laundering networks | Acquisitions inconsistent with declared income and rapid ownership changes |
| Territorial reputation | Trust guarantee for illicit contracting | Service brokers and affiliates | Repeated partnerships despite nominal corporate or brand changes |
Scalability economics: marginal cost, specialization and churn
The economic advantage of modularity lies in declining marginal victim-acquisition costs and the transfer of failure risk to replaceable components. A conventional fraud enterprise that owns every stage must recruit programmers, purchase infrastructure, generate leads, train operators, establish receiving accounts and launder proceeds before it can begin. A service-based enterprise substitutes variable costs for fixed costs: it rents infrastructure per campaign, purchases leads per record, compensates operators by salary or conversion rate, pays affiliates a revenue share and uses laundering services priced as a percentage of processed proceeds. This resembles a platform economy because coordinators do not need to employ all participants; they orchestrate standardized interfaces between suppliers. Standardization can take the form of lead formats, scripted objection-handling, account-opening packages, wallet instructions, victim-status fields, customer-relationship-management software or commission schedules. The public evidence from Tirana in 2026—teams organized by language, groups of six to eight operators, team leaders and centre-level management—shows that fraud production can adopt ordinary corporate control structures. Eurojust estimated losses above EUR 50 million, reported 10 arrests and noted seizures approaching EUR 900,000. Fraud call centres targeting EU citizens shut down with Eurojust’s support – over EUR 50 million in damages uncovered – Eurojust – April 2026 — Verified primary source. Such structures create performance data: calls completed, deposits generated, repeat deposits, conversion by language, operator productivity and victim lifetime value. Generative AI can increase throughput by producing localized scripts, summarizing victim interactions, translating messages and personalizing follow-up; nevertheless, human persuasion remains valuable where targets must be kept engaged through repeated transfers. The most likely five-year trajectory is therefore not “AI replaces the call centre,” but “AI converts each operator into a multilingual, data-assisted portfolio manager while automating low-value contact.”
Table 4 — Criminal-production cost structure through 2031
| Cost or constraint | Current modular solution | Likely 2027–2031 development | Risk effect |
|---|---|---|---|
| Malware development | Rental, leaked builders, affiliate access | More specialized brokerage and disposable tooling | Lower technical entry barrier |
| Language capability | Native-speaking operators and translation tools | AI-assisted multilingual engagement and synthetic voice | Larger addressable victim market |
| Lead generation | Stolen databases and malicious advertising | Automated profiling and cross-platform enrichment | Higher conversion efficiency |
| Infrastructure | Cloud accounts, proxies, domains and VPNs | Faster automated replacement and multi-provider redundancy | Shorter recovery after takedowns |
| Banking access | Mules, nominees and corporate accounts | Account marketplaces and orchestrated mule portfolios | Greater payment throughput but stronger detection signatures |
| Cryptocurrency conversion | Exchanges, brokers and unhosted wallets | Stable-value virtual assets and rapid chain switching | Faster international value movement |
| Trust-building | Scripted calls and fake dashboards | AI-personalized narratives and persistent synthetic identities | Longer victim engagement |
| Operational security | Compartmentalisation and encrypted messaging | Automated credential rotation and role-based access | Reduced exposure from individual arrests |
| Quality control | Team leaders and manual supervision | Analytics-driven operator scoring and script optimization | More professionalized fraud operations |
| Brand continuity | Persistent platform names | Disposable brands with reusable back-end components | Public blacklists lose value more quickly |
Liquidity is the decisive shadow infrastructure
The “shadow” dimension that most directly determines whether Balkan-based fraud nodes can become durable export platforms is liquidity. Stolen funds are vulnerable during the interval between victim payment and irreversible conversion; banks, exchanges and law-enforcement agencies can freeze transfers if they receive sufficiently rapid information. Service networks respond by pre-positioning account inventories, distributing transfers among multiple mules, using nominee companies, initiating immediate onward transfers and converting fiat balances into virtual assets. FATF emphasizes that instant payments, cross-border channels and virtual assets can move proceeds before detection, while jurisdictional and procedural constraints slow investigators; it consequently calls for rapid payment-suspension and freezing mechanisms, payment transparency, regulation of virtual-asset service providers and stronger public-private information sharing. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF Risks – Financial Action Task Force – February 2026 — Verified primary source. Operational evidence demonstrates what scale requires: INTERPOL’s HAECHI VI operation, conducted across 40 countries and territories between April and August 2025, blocked more than 68,000 bank accounts, froze nearly 400 cryptocurrency wallets and recovered USD 439 million in government-backed currency, physical assets and virtual assets. The targeted offences included investment fraud, voice phishing, BEC, e-commerce fraud and associated money laundering. USD 439 million recovered in global financial crime operation – INTERPOL – September 2025 — Verified primary source. These are global figures and cannot be assigned to Balkan actors, but they demonstrate that industrialized fraud depends upon extremely large inventories of financial endpoints. The critical intelligence indicators are therefore account-creation velocity, shared devices or network addresses across ostensibly unrelated accounts, clusters of low-balance inbound transfers followed by rapid consolidation, recurring conversion at particular exchanges and repeated links between call-centre employment networks and mule recruitment.
BEC, fraud and ransomware do not mature at the same speed
The transition pathway differs materially across BEC, online investment fraud and ransomware. Online investment fraud is labour-intensive but technically accessible: the network must create plausible websites, attract leads, operate persuasive communications and manage payments, yet it can procure most technology commercially or through criminal service providers. BEC requires better access intelligence because success depends upon identifying business relationships, compromising or imitating communications, understanding transaction timing and rerouting a payment without triggering verification. It therefore rewards collaboration between credential suppliers, initial-access specialists, corporate reconnaissance teams, impersonators and money-mule controllers. Ransomware requires still greater operational coordination: initial access, privilege escalation, lateral movement, data discovery, exfiltration, defensive evasion, encryption or destructive capability, negotiation, leak infrastructure and cryptocurrency settlement. Europol’s 2026 assessment nevertheless indicates that ransomware is moving away from encryption as the indispensable centre of coercion toward pressure based on stolen-data disclosure, which could lower the technical threshold for some affiliates. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. The most plausible five-year Balkan trajectory is therefore asymmetric: rapid expansion in multilingual fraud operations and payment-support services; moderate growth in credential brokerage, BEC and initial-access activity; selective participation in ransomware affiliate ecosystems; and a lower probability of an internationally dominant, publicly identifiable ransomware platform being strategically controlled from the Western Balkans. This ordering reflects capability requirements, not moral or national characteristics. It also implies that enforcement success against visible call centres may displace activity upward in technical sophistication: coordinators can retain victim acquisition, data management and payment orchestration while distributing human operators across remote-work arrangements, smaller offices or nominally legitimate outsourcing firms.
Table 5 — Relative maturity and five-year outlook
| Vector | Present evidentiary strength in Balkan cases | Modular barriers | 2031 direction | Analytical confidence |
|---|---|---|---|---|
| Online investment fraud | High | Lead supply, multilingual conversion and liquidity | Further professionalisation and geographic dispersion | High |
| Recovery fraud | High in documented Albanian case | Access to prior-victim data and credible impersonation | Automated re-targeting and fraud-chain extension | High |
| Telecom-enabled impersonation | Moderate-to-high | Number infrastructure and scripts | AI-assisted voice and language expansion | High |
| BEC | Moderate contextual evidence; limited public Balkan attribution | Credentials, transaction intelligence and mule capacity | Growth through purchased access and specialized cells | Moderate |
| Credential brokerage | Indirect but structurally necessary | Infostealer feeds and resale channels | Increasing integration with BEC and account takeover | Moderate |
| Initial-access brokerage | Limited public Balkan-specific evidence | Technical skill and access reputation | Selective participation in external ecosystems | Low-to-moderate |
| Ransomware affiliation | Limited public Balkan-specific evidence | Intrusion capability, operational security and negotiation | Incremental affiliate participation | Low-to-moderate |
| Balkan-controlled global RaaS brand | Insufficient public evidence | Development, affiliate governance and resilient infrastructure | Possible but not baseline | Low |
| Laundering-as-a-service | Strong structural relevance; case-specific indicators | Account inventory, conversion access and trusted counterparties | Central growth constraint and intervention point | Moderate-to-high |
Competing hypotheses and Bayesian update
The Analysis of Competing Hypotheses must preserve at least five explanations because the observable evidence is compatible with several organisational realities. H₁, direct conversion, proposes that established territorial groups are deliberately building internal cyber divisions; it predicts shared leadership, common laundering infrastructure, overlapping corporate ownership and movement of personnel between physical trafficking and cyber operations. H₂, parallel emergence, treats the principal actors as digitally native fraud entrepreneurs who exploit regional labour and governance conditions but remain organisationally separate from traditional groups; it predicts younger technical leadership, call-centre and marketing backgrounds, limited violent enforcement and distinct financial networks. H₃, outsourced-node integration, proposes that Balkan facilities provide sales, infrastructure or financial services to coordinators located elsewhere; it predicts foreign victim markets, distributed technical dependencies, upstream lead suppliers and incomplete local visibility into control. H₄, commercial capture or dual use, proposes that legal call centres, marketing firms, payment companies or IT businesses are partially repurposed; it predicts mixed legitimate and fraudulent activity, formal employment structures and rapid movement between corporate identities. H₅, shared-enabler convergence, proposes that physical and digital criminal markets intersect mainly through brokers, document suppliers, money launderers, corrupt facilitators and coercive intermediaries rather than common command. H₆, attribution distortion, proposes that enforcement geography exaggerates Balkan control because visible operators are easier to locate than remote administrators, lead generators or financial beneficiaries. The 2022–2026 case evidence raises the posterior probability of H₃, H₄ and H₅, moderately supports H₂, and provides only partial support for H₁. H₆ remains a mandatory caution rather than a mutually exclusive explanation. The Bayesian distribution below represents structured analytic judgment, not measured prevalence.
Table 6 — Provisional Bayesian assessment
| Hypothesis | Prior | Evidence update | Posterior | Key confirmation indicators | Key disconfirmation indicators |
|---|---|---|---|---|---|
| H₁ — Traditional OCG conversion | 22% | Some transferable assets, but limited public command-overlap evidence | 14% | Shared leaders, assets, facilitators and proceeds across physical and cyber cases | Separate personnel, finances and governance |
| H₂ — Digital-native emergence | 24% | Professional call-centre and platform structures support independent entrepreneurship | 23% | Technical or commercial founders without prior territorial-crime links | Persistent control by established clans |
| H₃ — Outsourced Balkan production nodes | 22% | Strong cross-border division of labour and foreign victim targeting | 29% | Foreign upstream suppliers, campaign managers and lead sources | End-to-end local control of platforms and proceeds |
| H₄ — Commercial capture or dual use | 14% | Corporate-style management and formal workplaces increase plausibility | 15% | Mixed legitimate activity, reused corporate entities and ordinary labour recruitment | Entirely clandestine infrastructure |
| H₅ — Shared-enabler convergence | 12% | Liquidity and facilitation needs strongly support cross-market service providers | 15% | Common accountants, mule managers, document suppliers or laundering brokers | Fully isolated financial networks |
| H₆ — Attribution distortion | 6% | Distributed infrastructure and replaceable brands keep this warning active | 4% as primary explanation | Local operators lack strategic knowledge or profit participation | Clear locally centralized command |
Enforcement asymmetry and geopolitical exposure
Modularity creates an asymmetry between criminals operating in real time and authorities operating through legally bounded jurisdictions. A platform can replace a domain, change a wallet, rotate credentials or move an operator account within hours; obtaining subscriber, traffic, content and payment evidence may require preservation requests, judicial authorization, provider cooperation and cross-border execution. The EU e-evidence framework is designed to reduce part of this delay: production orders can require a represented service provider in another EU Member State to respond within 10 days, or within six hours in an emergency, while preservation orders are intended to prevent deletion during processing. Better access to e-evidence to fight crime – Council of the European Union – January 2023 — Verified primary source. Western Balkan participation remains uneven because not every jurisdiction has identical institutional resources, acquis alignment or treaty implementation. The European Commission reported that Albania had adopted a National Cybersecurity Strategy for 2025–2030 but still needed stronger capacity, training and implementing legislation. Albania Report 2025 – European Commission – November 2025 — Verified primary source. It reported that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and had made no progress during the reporting period on the cited cybercrime-alignment matter. North Macedonia 2025 Report – European Commission – November 2025 — Verified primary source. These deficiencies should not be transformed into claims of criminal complicity; their analytical significance is that gaps in evidence acquisition, specialist staffing, asset tracing and provider response can create exploitable latency. Over five years, EU accession conditionality and operational integration will tighten this environment, but displacement toward non-EU infrastructure, encrypted platforms and smaller distributed teams is likely.
China, Russia and the emerging cyber-norm conflict
The multilingual cross-check reveals an important geopolitical divergence. China’s official legal framework defines telecom and online fraud as remotely conducted, non-contact property fraud and extends liability to overseas organisations or individuals that target entities in China or provide products, services or assistance to such fraud. It assigns risk-control duties to telecommunications operators, banks, non-bank payment institutions and internet providers; it also calls for cross-industry coordination, account restrictions, investigation of abused personal data and international cooperation on evidence, arrests, proceeds and victim recovery. Anti-Telecom and Online Fraud Law of the People’s Republic of China – Ministry of Justice of the People’s Republic of China – December 2023 — Verified primary source. The Chinese model is relevant to the Balkan problem because it regulates the service stack rather than only the final fraudster: telecommunications, financial institutions, internet services, account holders and assistance providers become intervention points. The EU model is more constrained by distributed sovereignty, judicial safeguards and cross-border mutual recognition, but its e-evidence regime similarly acknowledges that provider-held data is often more operationally important than the offender’s physical location. Russian-language official-source searches conducted for this section did not yield a live, sufficiently specific primary document establishing Balkan–Russian command relationships in the examined fraud cases; no such relationship is therefore asserted. This omission is analytically consequential. Europol warns that hybrid-threat actors increasingly use cybercriminal networks as proxies for disruptive activity, yet a general proxy trend cannot be converted into an allegation that documented Balkan call centres serve any particular state. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. Through 2031, the higher-probability geopolitical risk is opportunistic overlap: access brokers, hosting providers, credential sellers or laundering services may serve financially motivated and state-aligned customers without the operational cells sharing ideology or command.
Monte Carlo outlook, 2027–2031
The five-year forecast uses a structured Monte Carlo model rather than a linear extrapolation from arrests. The model treats six uncertain drivers as probability distributions: availability of CaaS components; effectiveness of AI-assisted social engineering; multilingual labour and remote recruitment; laundering liquidity; cross-border enforcement intensity; and electronic-evidence effectiveness. Each iteration varies the drivers within bounded ranges and classifies the resulting system into one of four futures. “Platformised modularity” means a small number of coordinators integrate numerous replaceable service vendors and operator teams. “Fragmented expansion” means many short-lived cells use common tools without durable platforms. “Hybrid convergence” means financially motivated infrastructure is repeatedly shared with physical organised crime or state-aligned proxy activity. “Effective containment” means payment interruption, evidence access, provider controls and asset recovery raise costs faster than automation lowers them. The baseline 100,000-iteration specification produces 44% platformised modularity, 29% fragmented expansion, 18% hybrid convergence and 9% effective containment. These probabilities are analytical outputs, not observed frequencies. The central estimate places the 2031 modular-service risk index at 71/100, with an 80% model interval of 59–82. The index is highest for online investment fraud and recovery fraud, intermediate for BEC and access brokerage, and lowest for a Balkan-controlled global ransomware platform. The main upside risk is simultaneous growth in AI-enabled victim conversion and mule-account liquidity; the main downside risk is coordinated payment suspension combined with rapid preservation of provider data and systematic confiscation. Because the model is dependency-sensitive, removing liquidity capacity reduces expected criminal output more sharply than closing any single call centre: premises can be replaced, but a trusted, high-throughput financial conversion network is difficult to regenerate without generating detectable account linkages.
Table 7 — Five-year scenario matrix
| Scenario | Baseline probability | 2031 operating form | Principal warning indicators | Most effective disruption |
|---|---|---|---|---|
| Platformised modularity | 44% | Coordinators orchestrate leads, operators, tools and liquidity through standardized interfaces | Shared CRM schemas, recurring infrastructure vendors, common wallet or account brokers | Dependency mapping, provider cooperation and financial-network disruption |
| Fragmented expansion | 29% | Numerous disposable cells use commercial and criminal tools | Rapid brand churn, small offices, remote operators and repeated scripts | Automated domain, payment and identity correlation |
| Hybrid convergence | 18% | Shared enablers connect cyber fraud, laundering, trafficking and occasional proxy activity | Common facilitators, infrastructure or proceeds across crime types | Multi-crime financial investigations and broker targeting |
| Effective containment | 9% | Fraud persists but scaling and monetisation become less reliable | Faster freezes, falling account longevity and rising asset recovery | Preserve coordinated regulatory, judicial and private-sector pressure |
Indicators that distinguish transition from mere technology adoption
A genuine transition from territorial enterprise to remotely scalable criminal production should be declared only when multiple indicators appear across organisational, technical and financial layers. A single encrypted telephone, cryptocurrency wallet or phishing page proves technology use, not modular production. Stronger evidence includes repeated procurement from external service vendors; separation between campaign ownership and operator employment; common back-end systems supporting multiple public brands; commission-based affiliates; geographically dispersed call-centre or remote-work teams using shared scripts and lead formats; large inventories of receiving accounts; specialized laundering brokers; systematic recycling of victim data; and rapid regeneration after arrests or domain seizures. Investigators should track six distinct identities for every operation: legal-company identity, infrastructure identity, campaign identity, operator identity, financial identity and beneficial-control identity. If those identities recur in different combinations, the network is modular. If they remain bound to the same leadership, location and financial chain, it is closer to a conventional organisation using digital tools. The April 2026 Tirana case supplies evidence of managerial segmentation and language-based production, while the Serbia–Bulgaria–Cyprus case supplies evidence of cross-border functional specialization; neither alone resolves beneficial control. The critical collection priorities for 2027–2031 are therefore upstream lead provenance, administrator access logs, CRM exports, shared device identifiers, employment and payroll records, payment routing, wallet ownership, company-service providers and relationships between seized infrastructure and unrelated fraud brands. This framework avoids two symmetric errors: underestimating a service network because its visible operators appear low-level, and overstating Balkan strategic control because a raid occurred in a Balkan capital. The intelligence objective is not to count offices but to reconstruct the dependency graph that allows those offices to produce criminal revenue.
Table 8 — Priority intelligence requirements
| Priority intelligence requirement | Required evidence | Diagnostic value |
|---|---|---|
| Who owns victim acquisition? | Advertising accounts, lead purchases, referral codes and dataset provenance | Separates upstream coordinators from local sales nodes |
| Who administers campaign systems? | Authentication logs, administrator devices, recovery emails and hosting payments | Identifies technical control |
| Who sets performance targets? | CRM fields, operator dashboards, commission schedules and internal messages | Reveals production governance |
| Who controls liquidity? | Beneficial ownership, mule recruitment, transaction chains and exchange records | Identifies the monetisation centre |
| Which components are reusable? | Shared code, templates, scripts, domains, wallets and identity artefacts | Measures modularity and regeneration capacity |
| Are physical and cyber markets converging? | Common facilitators, properties, companies and financial endpoints | Tests H₁ and H₅ |
| Is a foreign coordinator directing local nodes? | Remote logins, payment instructions, supplier contracts and command communications | Tests H₃ |
| Are legitimate firms being repurposed? | Mixed revenue, employment records, customer lists and dual accounting | Tests H₄ |
| How quickly can the network regenerate? | Time from disruption to new domains, accounts, brands and operator activity | Measures resilience |
| Is there state-aligned tasking? | Target selection, non-financial objectives, infrastructure reuse and authenticated command links | Distinguishes criminal opportunism from proxy activity |
Platformised
Fragmented
Hybrid
Contained
Ransomware, BEC and Industrialised Online Fraud
Three markets, three production logics
Ransomware, business email compromise and industrialised online fraud are frequently grouped under “cybercrime,” yet they constitute different criminal production systems with sharply different entry barriers, labour requirements, victim-selection processes, monetisation cycles and infrastructure dependencies. Ransomware is principally an intrusion-and-extortion business: the operator must acquire unauthorized access, preserve that access, understand the target environment, escalate privileges, identify valuable systems or data, evade detection, create coercive leverage and negotiate payment. BEC is an intelligence-and-payment-diversion business: the decisive asset is not malware but credible knowledge of an organisation’s personnel, authority relationships, invoices, suppliers and transaction timing. Industrialised online fraud is a customer-acquisition and psychological-conversion business: the network generates or purchases leads, places victims inside a fabricated commercial narrative, sustains engagement and repeatedly extracts funds. The three systems increasingly share upstream commodities—credentials, personal data, compromised accounts, proxy infrastructure, synthetic identities—and downstream services such as mule accounts, cryptocurrency conversion and laundering. This convergence does not make their operational maturity identical. ENISA’s review of nearly 4,900 selected incidents between July 2024 and June 2025 found that ransomware remained central to intrusion activity while operators reacted to enforcement by decentralising, intensifying extortion and using ransomware-as-a-service, leaked builders and access brokers to lower entry barriers. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025, revised January 2026 — Verified primary source. Europol separately assessed that data had become the central commodity of the cybercrime economy and that unauthorised access, stolen information and criminal data markets provide reusable inputs for several offence types. Steal, Deal and Repeat: How Cybercriminals Trade and Exploit Your Data – Europol – June 2025 — Verified primary source.
Table 1 — Comparative criminal-production maturity
| Dimension | Ransomware | BEC | Industrialised online fraud |
|---|---|---|---|
| Core business | Intrusion, data theft, disruption and extortion | Manipulation of trusted commercial communications | Repeated psychological conversion of individuals |
| Principal victim | Organisations with operational or data dependency | Businesses making substantial authorized payments | Individuals, investors and selected consumer segments |
| Primary commodity | Privileged network access | Transactional context plus trusted communication access | Leads, personal data, attention and victim confidence |
| Technical threshold | High end-to-end; moderate for an affiliate buying access | Moderate; high intelligence precision | Low-to-moderate technical threshold; high sales-management requirement |
| Labour model | Developers, brokers, intruders, operators and negotiators | Reconnaissance, account access, impersonation and mule management | Marketing, call-centre operators, team leaders, platform administrators and payment cells |
| Campaign duration | Days to months after access; longer reconnaissance possible | Often synchronized with a specific transaction window | Weeks or months per victim; continuous lead processing |
| Revenue distribution | Affiliate and platform revenue shares | Concentrated proceeds divided among access, deception and laundering cells | Salaries, commissions, managerial shares and laundering fees |
| Main scaling constraint | Reliable access and skilled intrusion capacity | High-value transaction visibility and receiving-account quality | Lead flow, operator productivity, account inventory and payment throughput |
| Principal evidence | Endpoint, network, malware, server and wallet artefacts | Email logs, authentication, invoice and bank records | CRM records, call data, advertisements, platforms and transaction chains |
| Balkan public evidence | Limited for strategic control of global RaaS brands | Fragmentary and often financial-support related | Strongest documented regional maturity |
| Five-year regional direction | Selective affiliate and access-broker participation | Material growth potential | Highest-probability expansion vector |
Ransomware: the most technically demanding ecosystem
A mature ransomware operation resembles a distributed technology platform rather than a single hacking group. At the platform layer, developers maintain encryptors, data-exfiltration utilities, affiliate-management systems, negotiation portals and leak infrastructure. At the access layer, brokers or affiliates identify exposed services, compromised credentials, vulnerable edge devices or pre-existing malware infections. At the intrusion layer, operators must validate the target, establish persistence, escalate privileges, disable or circumvent defensive controls and map critical systems. At the coercion layer, the network exfiltrates sensitive information, encrypts systems, threatens publication or combines these techniques with pressure against customers, partners or regulators. At the monetisation layer, negotiators assess the victim’s capacity and willingness to pay while financial specialists manage cryptocurrency addresses and distribute shares. This structure explains why ransomware can be modular without becoming technically simple. Purchasing access eliminates only the first constraint; a poorly managed affiliate can lose access, trigger detection, damage systems before leverage is established or select a victim unable to pay. Europol observed more than 120 active ransomware brands during 2025 and found that the extortion model continued to shift from encryption toward threats to publish stolen data. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. The FBI received more than 3,600 ransomware complaints in 2025 and identified 63 newly reported variants, an average of 5.25 per month; the top variants most heavily affected critical manufacturing, healthcare and public health, and government facilities. The FBI explicitly cautions that its reported loss total—more than USD 32 million—normally excludes lost business, wages, equipment, files and remediation, and therefore materially understates total economic harm. 2025 IC3 Annual Report – Federal Bureau of Investigation – April 2026 — Verified primary source.
Table 2 — Ransomware production chain and failure points
| Stage | Required capability | Purchasable service | Revenue relevance | Principal disruption point |
|---|---|---|---|---|
| Target discovery | Sector and exposure intelligence | Scanning and lead services | Determines addressable target pool | Vulnerability remediation and external attack-surface monitoring |
| Initial access | Credential or vulnerability exploitation | Initial-access brokerage and malware delivery | Establishes campaign inventory | Credential resets, MFA, patching and access-broker intelligence |
| Persistence | Durable control of systems | Remote-access tooling | Preserves option value | Endpoint detection and authentication analytics |
| Privilege escalation | Administrative control | Exploit or operator expertise | Enables enterprise-wide coercion | Privileged-access management and segmentation |
| Reconnaissance | Identification of data and critical systems | Specialist affiliate labour | Determines ransom leverage | Internal monitoring and deceptive assets |
| Exfiltration | Covert transfer of valuable data | Criminal hosting and proxy services | Enables non-encryption extortion | Egress controls and abnormal-transfer detection |
| Impact | Encryption, interruption or destruction | RaaS payload and builder | Creates urgency and operational loss | Offline recovery and network isolation |
| Negotiation | Victim valuation and coercion | Negotiator or affiliate panel | Influences payment probability and size | Prepared incident governance and law-enforcement contact |
| Settlement | Cryptocurrency reception and allocation | Wallet and laundering services | Converts coercion into distributable revenue | Blockchain analysis, exchange controls and seizure |
| Brand continuity | Reputation among affiliates and victims | Leak site and criminal communications | Attracts affiliates and increases credibility | Infrastructure seizure, attribution and sanctions |
LockBit demonstrates the economic reach and governance requirements of a mature RaaS platform. The United States Department of Justice reports that LockBit was deployed against more than 2,500 victims between approximately January 2020 and July 2024 and that victims paid more than USD 500 million in ransoms. LockBit Case Summary – United States Attorney’s Office, District of New Jersey – July 2024 — Verified primary source. Those figures illustrate platform economics: a central administrator does not need to conduct every intrusion if affiliates supply target access and operational labour while the platform supplies malware, infrastructure, reputation and settlement rules. The resulting organisation can scale internationally without scaling a single permanent workforce. Its weakness is the centrality required to coordinate affiliates. Law enforcement can target developer identities, affiliate panels, servers, decryption infrastructure, cryptocurrency flows and the trust relationship between the brand and its operators. In February 2024, an international action compromised LockBit’s primary platform and enabling infrastructure and produced arrests in Poland and Ukraine. Eurojust supports international operation against world’s largest ransomware group – Eurojust – February 2024 — Verified primary source. The Balkan-specific assessment must remain conservative: the public primary-source record does not establish a Western Balkan-controlled equivalent of LockBit. The most plausible regional entry points through 2031 are narrower modules—credential acquisition, access brokerage, hosting, cryptocurrency conversion, affiliate participation and laundering—because each can connect technically capable individuals or facilitators to an externally administered ransomware economy without requiring the region to produce and govern an entire global platform.
BEC: low malware visibility, high transactional intelligence
BEC occupies the middle position between ransomware’s technical intensity and industrialised fraud’s labour-intensive persuasion. Its minimum viable operation can be relatively small, but successful high-value campaigns require accurate organisational intelligence. The attacker must know who can authorize a payment, who normally requests it, which supplier or executive can credibly be impersonated, when the transaction is expected, what language and formatting will appear routine and which receiving account can accept the funds without immediate rejection. Access can be obtained through compromised email credentials, forwarding rules, stolen browser sessions or information purchased from data brokers; however, account compromise is not always necessary if a convincing look-alike identity and external reconnaissance are sufficient. INTERPOL defines BEC as an increasingly prevalent impersonation fraud in which criminals compromise email accounts or impersonate executives and professional advisers to induce transfers into fraud-controlled accounts that are then rapidly laundered. INTERPOL Global Financial Fraud Assessment – INTERPOL – March 2024 — Verified primary source. The FBI recorded 24,768 BEC complaints and approximately USD 3.047 billion in reported BEC losses during 2025, compared with 3,611 ransomware complaints and approximately USD 32.3 million in directly reported ransomware losses. 2025 IC3 Annual Report – Federal Bureau of Investigation – April 2026 — Verified primary source. That comparison cannot be interpreted as a complete loss ranking because ransomware reporting excludes major indirect costs, but it does demonstrate BEC’s capacity to generate enormous direct financial losses without creating the visible operational disruption associated with encryption.
Table 3 — BEC maturity model
| BEC maturity level | Access condition | Intelligence quality | Deception method | Monetisation pathway | Likely scale |
|---|---|---|---|---|---|
| Level 1: external spoofing | No internal account access | Publicly available personnel data | Generic executive or supplier impersonation | Single mule account | Low conversion, high volume |
| Level 2: targeted impersonation | Limited reconnaissance | Known executive, supplier or transaction role | Customized invoice or payment request | Pre-positioned corporate account | Moderate |
| Level 3: account compromise | Genuine mailbox access | Internal messages and historical relationships | Authentic thread manipulation | Layered receiving accounts | High |
| Level 4: transaction interception | Persistent access | Live visibility into payment timing | Altered bank instructions inside a legitimate process | Rapid multi-account dispersal | Very high |
| Level 5: ecosystem compromise | Multiple accounts or supplier access | Visibility across counterparties | Simultaneous or repeated diversions | Professional laundering network | Potentially systemic |
| Level 6: synthetic executive layer | Account access plus AI assistance | Voice, style and behavioural modelling | Email combined with synthetic audio or video | Pre-arranged high-capacity accounts | Emerging high-impact model |
BEC’s most important constraint is not the quality of the fraudulent email but the survivability of the receiving account. A highly credible payment instruction has no economic value if the beneficiary account is blocked, mismatched, unable to receive the amount or immediately freezes the transfer. This produces a strong dependency on money mules, nominee companies, compromised business accounts and professional laundering services. The financial cell must understand transfer limits, confirmation practices, processing times and the speed with which funds can be redistributed. It must also manage a scarcity problem: accounts capable of accepting large corporate payments without automatic interruption are more valuable and more difficult to replace than ordinary consumer mule accounts. That characteristic makes BEC both scalable and fragile. One successful transfer may generate more revenue than thousands of low-value fraud calls, yet each event can expose high-quality accounts, beneficial owners, devices and transaction links. Global enforcement data show the size of the downstream infrastructure shared by BEC and other fraud types. INTERPOL’s HAECHI VI operation across 40 countries and territories blocked 68,000 bank accounts, recovered USD 439 million and targeted BEC alongside investment fraud, voice phishing, e-commerce fraud and related laundering. Global Financial Fraud Threat Assessment 2026 – INTERPOL – April 2026 — Verified primary source. The implication for Balkan criminal-service development is that the most valuable exportable BEC capability may not be message composition. It may be the provision of corporate receiving accounts, nominee structures, multilingual reconnaissance or rapid conversion channels connected to wider European financial markets.
Industrialised online fraud: the region’s most mature pathway
Industrialised investment and impersonation fraud presents the strongest documented evidence of Balkan-based production capacity because it aligns with the region’s demonstrated multilingual call-centre infrastructure and requires fewer rare technical skills than ransomware. The model combines commercial lead generation, standardized scripts, fabricated investment interfaces, operator supervision, customer segmentation and financial extraction. Its central production metric is victim conversion rather than system compromise. A victim can be introduced through malicious advertising, a cloned website, direct communication or an apparently legitimate investment platform; a low initial deposit tests willingness and creates psychological commitment; a fabricated dashboard or small apparent return reinforces trust; operators then increase the requested amount and use urgency, exclusivity or loss-recovery narratives to sustain payment. The system can continue even when its public brand is exposed because domains, company names and visible interfaces are disposable while scripts, leads, operator teams and financial relationships are reusable. Eurojust documented a network with call centres in Serbia, technical infrastructure in Bulgaria and an alleged laundering base in Cyprus. Authorities identified more than 250 workplaces, initially arrested fourteen people in Serbia and one in Germany, and later arrested sixteen additional suspects in Serbia. The network targeted victims in Germany, Switzerland, Austria, Australia and Canada. Takedown of fraudulent cryptocurrency network in Bulgaria, Cyprus and Serbia – Eurojust – January 2023, updated February 2023 — Verified primary source. This case provides unusually clear evidence of cross-border functional specialization, but it does not prove that strategic command, technology ownership and ultimate beneficial control were Serbian, Bulgarian or Cypriot.
Table 4 — Industrialised fraud production architecture
| Production unit | Commercial analogue | Criminal function | Core KPI | Intelligence artefact |
|---|---|---|---|---|
| Advertising cell | Performance-marketing agency | Generates victim traffic | Cost per lead | Advertising accounts, pixels and referral identifiers |
| Lead broker | Data-list vendor | Supplies contactable targets | Lead validity and segmentation | Purchased datasets and provenance records |
| Call-centre operator | Sales representative | Establishes trust and solicits deposits | Conversion rate | Call recordings, scripts and CRM entries |
| Retention operator | Account manager | Obtains repeat payments | Victim lifetime value | Follow-up history and deposit sequence |
| Team leader | Sales supervisor | Enforces scripts and targets | Revenue per operator | Dashboards, performance tables and internal messages |
| Platform administrator | SaaS administrator | Maintains fabricated victim interface | Platform uptime and account engagement | Admin logs, hosting and code repositories |
| Payment cell | Treasury department | Routes deposits into controlled channels | Successful receipt rate | Bank accounts, wallets and beneficiary instructions |
| Mule coordinator | External payroll or settlement service | Supplies replaceable financial endpoints | Account longevity and throughput | Recruitment records and device overlaps |
| Laundering broker | Financial intermediary | Converts and distributes proceeds | Net recovery after fees | Consolidation wallets, shell companies and cash-out nodes |
| Recovery-fraud cell | Customer-retention unit | Re-targets known victims | Secondary conversion rate | Prior-victim lists and impersonated recovery identities |
The largest verified cross-border case involving Balkan nodes illustrates how quickly this model can reach industrial scale. In November 2022, Eurojust supported action against a network using dozens of call centres and hundreds of online platforms; investigators estimated victims in the hundreds of thousands and damage of approximately EUR 50 million per quarter, with suspected activity extending back to at least 2016. Searches covered six call centres in Albania, five in Georgia, three in Ukraine and one in North Macedonia, while seizures included more than 500 electronic devices, bank accounts, cryptocurrency wallets, identity documents, bank cards, properties and cash. Eurojust coordinates action against massive investment fraud with hundreds of thousands of victims worldwide – Eurojust – November 2022 — Verified primary source. The operational significance is greater than the seizure total. Multiple centres can work from common lead sources and platform templates while targeting different linguistic markets. Customer-contact labour can be relocated without relocating platform administration; payment instructions can change without retraining operators; and the public brand can disappear while victim data remains commercially valuable. Unlike ransomware, which risks losing access before leverage is created, an industrialised fraud network can continuously process a portfolio of victims at different stages of engagement. Revenue is consequently smoothed across many interactions rather than concentrated in a smaller number of high-risk intrusions. This makes the model attractive to criminal entrepreneurs seeking scalable cash flow, even if its average payment is lower than a successful corporate ransom or BEC diversion.
Shared infrastructure and divergent monetisation
The three systems increasingly meet in the stolen-data and access economy. Infostealer logs can contain credentials, cookies, autofill information, cryptocurrency-wallet data and email access. The same compromised account may be monetized through direct theft, BEC, resale, ransomware access or identity fraud depending on the victim’s characteristics. Europol assesses that stolen data and unauthorized access have become commodified goods in the CaaS market and cautions that closed communication channels limit the portion of the ecosystem visible to law enforcement. Steal, Deal and Repeat: How Cybercriminals Trade and Exploit Your Data – Europol – June 2025 — Verified primary source. INTERPOL’s 2025 infostealer crackdown dismantled more than 20,000 malicious IP addresses and domains and notified over 216,000 victims and potential victims; INTERPOL explicitly linked stolen logs to ransomware deployment, data breaches and BEC. 20,000 malicious IPs and domains taken down in INTERPOL infostealer crackdown – INTERPOL – June 2025 — Verified primary source. The convergence point is therefore a decision market: brokers classify compromised access according to expected value. An email account containing supplier invoices may be allocated to BEC; administrator credentials for a manufacturer may be sold to a ransomware affiliate; a consumer identity may enter investment, romance or recovery fraud; cryptocurrency credentials may be monetized directly. For Balkan criminal ecosystems, participation in this classification and brokerage layer would represent a more significant maturation than merely operating phishing pages, because the broker controls allocation between several downstream criminal markets and learns which access profiles command the highest price.
Table 5 — Monetisation comparison
| Metric | Ransomware | BEC | Industrialised online fraud |
|---|---|---|---|
| Revenue unit | Ransom or extortion settlement | Diverted corporate payment | Deposit sequence across a victim portfolio |
| Payment frequency | Low frequency, potentially very high value | Low-to-moderate frequency, high value | High frequency, low-to-high cumulative value |
| Revenue latency | Often days or weeks after intrusion | Tied to a narrow transaction window | Continuous throughout victim engagement |
| Direct victim visibility | Very high after impact | Often delayed until reconciliation | High but manipulated through false interface |
| Dependence on cryptocurrency | Common but not universal | Optional; bank transfers frequently central | Mixed bank, card, fintech and cryptocurrency pathways |
| Need for mule accounts | Moderate | Extremely high | High |
| Need for technical labour | High | Moderate | Low-to-moderate |
| Need for persuasion labour | Negotiation-focused | Short, precise impersonation | Extensive and repeated |
| Reusability of victim data | Moderate | High for counterpart mapping | Very high, including recovery fraud |
| Main loss concentration | Operational disruption plus data exposure | Direct transfer loss | Repeated personal financial depletion |
| Principal bottleneck | Intrusion reliability | Transaction intelligence and account quality | Lead quality, operator productivity and liquidity |
| Fastest intervention | Access containment | Transfer recall and account freeze | Advertising interruption plus payment freeze |
Liquidity pathways and profit allocation
Monetisation is the point at which otherwise distinct cybercrime models converge most visibly. Ransomware platforms commonly divide cryptocurrency receipts among affiliates, administrators and supporting specialists. BEC proceeds frequently enter corporate or mule accounts and must be redistributed before a victim, originating bank or beneficiary institution identifies the diversion. Industrialised fraud uses larger portfolios of bank accounts, payment processors and wallets because deposits arrive continuously from many victims and countries. Across all three models, gross proceeds can substantially exceed net criminal profit. Service fees, affiliate shares, operator wages, advertising expenditure, mule compensation, failed transfers, frozen balances and laundering discounts reduce realizable revenue. A high-volume network therefore optimizes not only victim conversion but “survival-adjusted yield”: the proportion of apparent proceeds that remains accessible after freezes, seizures, account theft, internal fraud and intermediary fees. FATF reports that cyber-enabled fraud increasingly integrates laundering mechanisms from the outset through nominee accounts, traded bank and exchange accounts, mule networks and rapid fintech transfers. It also notes that direct payment in virtual assets or rapid conversion from fiat can outpace recovery processes. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF Risks – Financial Action Task Force – February 2026 — Verified primary source. This makes laundering capacity an upstream planning variable. A campaign should not be considered operationally mature merely because it can compromise systems or persuade victims. Maturity requires pre-positioned financial endpoints, transaction monitoring, fallback accounts, fast internal allocation and the ability to absorb account loss without halting production.
Table 6 — Shadow liquidity indicators
| Indicator | Ransomware relevance | BEC relevance | Online-fraud relevance | Analytical interpretation |
|---|---|---|---|---|
| Pre-positioned corporate accounts | Medium | Critical | High | Indicates planning before victim payment |
| Large portfolio of personal mules | Low-to-medium | High | Critical | Supports fragmentation and replacement |
| Cryptocurrency consolidation | Critical | Medium | High | Identifies treasury or laundering aggregation |
| Immediate onward transfers | High | Critical | Critical | Measures response to freeze risk |
| Repeated exchange counterparties | Critical | Medium | High | May identify trusted conversion services |
| Shell-company turnover | Medium | Critical | High | Signals beneficiary replacement |
| Cross-border ATM withdrawals | Low | Medium | High | Indicates retail cash-out layer |
| Property acquisition | Medium | Medium | Medium-to-high | Potential long-term value storage |
| Account-device reuse | Medium | High | Critical | Connects nominally separate mules |
| Shared introducers or directors | Medium | Critical | High | Identifies professional facilitation |
| Recovery-fraud payments | Minimal | Low | High | Demonstrates recycling of victim data |
| Stable-value virtual assets | High | Medium | High | Reduces volatility during cross-border settlement |
Bayesian maturity assessment for the Balkans
A comparative Bayesian assessment produces a different posterior for each crime type. For ransomware, H₁ holds that Balkan actors will create and control a globally significant RaaS platform; H₂ predicts participation mainly as affiliates; H₃ predicts specialization in access, infrastructure or data brokerage; H₄ predicts primary participation in laundering; H₅ predicts that visible regional artefacts will largely reflect transit or hosting rather than meaningful control. Current public evidence assigns the greatest weight to H₂ and H₃, with H₁ remaining low-confidence. For BEC, the hypotheses shift: H₁ predicts locally controlled end-to-end campaigns; H₂ predicts regional reconnaissance or language cells attached to foreign networks; H₃ predicts specialization in mule and corporate-account supply; H₄ predicts convergence with existing call-centre networks; H₅ predicts only incidental Balkan financial endpoints. H₃ and H₄ receive the strongest current weight because the region’s documented fraud infrastructure and cross-border financial facilitation are more relevant than evidence of a mature, indigenous BEC command structure. For industrialised online fraud, H₁ predicts durable Balkan-controlled platforms; H₂ predicts outsourced call-centre production; H₃ predicts mixed local and foreign ownership; H₄ predicts rapid displacement into remote-work structures; H₅ predicts effective containment through coordinated enforcement. Verified cases strongly support H₂ and H₃, while the repeated reappearance of Albanian, Serbian and other regional nodes raises H₄ through 2031. These distributions are structured judgments, not prevalence estimates.
Table 7 — Provisional posterior maturity distribution
| Crime market and hypothesis | Posterior | Confidence | Evidence required for major update |
|---|---|---|---|
| Ransomware: Balkan-controlled global RaaS platform | 8% | Low | Developer, administrator, affiliate-panel and treasury evidence |
| Ransomware: regional affiliate participation | 29% | Moderate | Intrusion telemetry and affiliate-account attribution |
| Ransomware: access or data brokerage | 31% | Moderate | Marketplace identities connected to regional operators |
| Ransomware: laundering specialization | 22% | Moderate | Wallet, exchange and beneficial-owner convergence |
| Ransomware: incidental infrastructure only | 10% | Low-to-moderate | Hosting without operator or financial linkage |
| BEC: end-to-end Balkan command | 17% | Low-to-moderate | Campaign control, mailbox access and treasury integration |
| BEC: foreign-directed regional cells | 23% | Moderate | Command communications and revenue-sharing records |
| BEC: mule and account supply specialization | 31% | Moderate-to-high | Account clusters, nominee companies and recruitment evidence |
| BEC: convergence with call-centre fraud | 22% | Moderate | Common CRM, personnel, platforms or financial endpoints |
| BEC: incidental Balkan role | 7% | Low | Isolated account use without repeated network links |
| Online fraud: locally controlled platforms | 24% | Moderate | Beneficial ownership and administrator evidence |
| Online fraud: outsourced call-centre production | 28% | High | Already consistent with documented cases |
| Online fraud: mixed transnational ownership | 30% | Moderate-to-high | Shared foreign and local command or treasury evidence |
| Online fraud: distributed remote-work transition | 14% | Moderate | Declining premises concentration with stable campaign output |
| Online fraud: effective containment | 4% | Low | Sustained decline in regeneration and financial throughput |
Five-year outlook: maturity will rise unevenly
The 2027–2031 outlook is defined by unequal rates of automation. Industrialised fraud will automate lead enrichment, initial messaging, translation, call summarisation, script selection and victim prioritisation, but human operators will remain important for high-value trust manipulation. BEC will use AI to imitate writing style, generate multilingual communications and support synthetic voice confirmation, yet its success will continue to depend on access to genuine transaction context and high-capacity receiving accounts. Ransomware will benefit from improved reconnaissance, vulnerability analysis and negotiation support, but the most difficult intrusion tasks will remain less automatable than mass communication. Enforcement will push all three markets toward smaller brands, shorter infrastructure lifecycles and greater separation between public identity and reusable back-end systems. Operation Endgame demonstrates the strategic value of attacking upstream infrastructure: during May 2025, authorities reportedly dismantled approximately 300 servers, neutralised 650 domains and issued international arrest warrants against twenty targets associated with initial-access malware used to deliver ransomware and other payloads. Operation ENDGAME strikes again: the ransomware kill chain broken at its source – Europol – May 2025 — Verified primary source. The probable criminal response is redundancy rather than retreat: more providers, shorter contracts, compartmentalised access and faster brand replacement. For the Balkans, the baseline forecast assigns the highest 2031 maturity to industrialised fraud, a substantial increase to BEC-support services and selective growth in ransomware-adjacent modules rather than full-platform control.
Table 8 — Baseline 2031 maturity forecast
| Capability | 2026 assessed maturity | 2031 baseline | Five-year change | Primary driver | Principal inhibitor |
|---|---|---|---|---|---|
| Multilingual online-fraud operations | 76/100 | 88/100 | +12 | AI-assisted productivity and reusable scripts | Raids, recruitment visibility and payment freezes |
| Fraud-platform administration | 64/100 | 79/100 | +15 | Disposable front ends and shared back ends | Hosting and administrator attribution |
| Recovery-fraud exploitation | 67/100 | 84/100 | +17 | Reusable victim datasets | Data seizure and victim notification |
| Mule-account coordination | 70/100 | 82/100 | +12 | Cross-border recruitment and fintech access | Transaction analytics and rapid suspension |
| BEC reconnaissance | 48/100 | 68/100 | +20 | Stolen data and AI-supported analysis | Strong authentication and payment verification |
| BEC payment diversion | 45/100 | 65/100 | +20 | Corporate-account and nominee access | Confirmation-of-payee and transfer recall |
| Credential and cookie brokerage | 47/100 | 69/100 | +22 | Infostealer markets | Endpoint security and log disruption |
| Initial-access brokerage | 35/100 | 55/100 | +20 | CaaS integration | Reputation requirements and enforcement |
| Ransomware affiliate participation | 32/100 | 52/100 | +20 | Purchased access and RaaS availability | Technical failure and operational attribution |
| Ransomware platform governance | 18/100 | 29/100 | +11 | Imported expertise and modular tooling | High coordination and trust requirements |
| Cryptocurrency laundering | 59/100 | 72/100 | +13 | Cross-border settlement demand | VASP regulation, tracing and seizure |
| Hybrid criminal–proxy services | 24/100 | 39/100 | +15 | Shared access and infrastructure markets | Attribution pressure and sanctions |
Strategic warning indicators
The most valuable warning indicators will measure cross-market migration rather than raw incident volume. If an investment-fraud network begins acquiring corporate mailbox credentials, it may be moving into BEC; if a credential broker starts selling privileged access to larger organisations, it may be supplying ransomware affiliates; if the same mule coordinators receive BEC proceeds, investment deposits and extortion-related cryptocurrency, a regional laundering service may be emerging as a systemic node. Investigators should therefore map reusable entities across crime classifications: devices, administrator accounts, corporate directors, call-centre managers, wallets, bank beneficiaries, hosting purchasers, domain registrants, payroll relationships and recruitment channels. Evidence of increasing maturity would include common authentication infrastructure across multiple fraud brands; operators shifting between investment fraud and executive impersonation; account portfolios segmented by transaction size; recurring exchanges or over-the-counter brokers; ransomware wallets linked to previously identified fraud treasuries; and remote administrative access from jurisdictions different from operator premises. Evidence against maturation would include continuously isolated cells, low infrastructure reuse, poor financial coordination, rapid payment recovery and the absence of shared facilitators. The analytical priority is not to label every overlap as a unified organisation. It is to determine whether an intermediary has become a platform: a provider whose removal would reduce output across several nominally independent ransomware, BEC and online-fraud networks. That distinction converts cybercrime investigation from case-by-case attribution into dependency analysis and offers the best prospect of imposing costs faster than criminal brands can regenerate.
2031 ransomware
2031 BEC
2031 fraud
Five-Year Scenarios, Indicators and Intervention Points to 2031
Forecasting boundary and evidentiary baseline
The forecast must begin by separating three quantities that are often collapsed into one: observed criminal activity, inferred organisational structure and projected future capability. The observed baseline includes verified Balkan call-centre operations, distributed technical infrastructure, cryptocurrency and bank-account use, multilingual market segmentation, recovery fraud and cross-border laundering arrangements. The inferred layer concerns who owns those components, whether traditional organised-crime groups control them, and whether regional operators function as principals, affiliates, contractors or replaceable labour nodes. The forecast layer estimates how those relationships could evolve under changes in crime-as-a-service availability, artificial intelligence, financial liquidity, enforcement, electronic-evidence access and legitimate-business infiltration. Europol assesses online fraud as the fastest-growing area of organised crime, identifies more than 120 active ransomware brands observed in 2025, and anticipates that online-fraud networks will increasingly use AI for social engineering, infrastructure management and the replacement of labour-intensive processes with autonomous digital capabilities. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. These findings support a higher baseline probability of further modularisation, but they do not establish that Balkan-based actors will control the resulting platforms. The forecasting unit is therefore the regional criminal-service ecosystem rather than any nationality-defined “Balkan cyber mafia.” The principal outcome variable, M₂₀₃₁, represents the maturity of an ecosystem capable of acquiring victims or access, coordinating specialised labour, operating replaceable infrastructure, extracting payments, laundering proceeds and regenerating after disruption. It does not measure the number of attacks, which remains distorted by non-reporting, inconsistent classification and the fact that a single platform can support many campaigns while a single operation can expose hundreds of nominal brands.
Table 1 — Observed, inferred and forecast variables
| Analytical layer | Variable | Current evidentiary status | Forecast use | Principal distortion |
|---|---|---|---|---|
| Observed | Call-centre premises and personnel | Strong in several Albanian, Serbian and regional cases | Establishes labour-intensive fraud capacity | Premises may be only one distributed node |
| Observed | Fraud platforms and websites | Strong | Measures campaign replication | Public brands may conceal shared back ends |
| Observed | Cryptocurrency wallets and bank accounts | Strong in specific cases | Measures monetisation infrastructure | Seized endpoints may be peripheral |
| Observed | Ransomware brand proliferation | Strong at EU level | Establishes accessible external RaaS market | Not evidence of Balkan control |
| Observed | BEC loss and complaint volume | Strong globally, weaker for Balkan attribution | Measures addressable criminal market | Reporting differs across jurisdictions |
| Inferred | Beneficial command | Incomplete | Distinguishes principal from contractor | Operators may not know upstream owners |
| Inferred | Traditional OCG involvement | Plausible but unevenly evidenced | Tests physical–digital convergence | Shared laundering does not prove shared command |
| Inferred | State or proxy relationships | Low-confidence in Balkan cases | Tests hybrid-threat scenario | Shared tools can create false attribution |
| Forecast | CaaS availability | High and rising | Lowers entry barriers | Enforcement can fragment suppliers |
| Forecast | AI-enabled conversion | High-probability growth | Raises operator productivity and scale | Defensive AI may offset some gains |
| Forecast | Liquidity resilience | Critical uncertainty | Determines realizable criminal revenue | Account freezes can create nonlinear losses |
| Forecast | Evidence-access effectiveness | Policy-dependent | Determines attribution and prosecution speed | Formal rules may not equal operational capacity |
| Forecast | Regeneration speed | Increasingly important | Measures resilience after disruption | Brand replacement can exaggerate “new” actors |
Bayesian hypothesis architecture
The Bayesian model evaluates six competing but partially compatible hypotheses. H₁ — indigenous platformisation predicts that Balkan-based organisers will integrate lead generation, data brokerage, technical infrastructure, call-centre production, laundering and campaign governance into durable regional platforms. H₂ — outsourced regional production predicts that foreign or geographically dispersed coordinators will retain ownership of data, platforms and treasury functions while Balkan facilities supply multilingual labour, company structures, account access or technical services. H₃ — fragmented entrepreneurial diffusion predicts that readily available tools will generate many short-lived local cells without stable strategic coordination. H₄ — shared-enabler convergence predicts that traditional trafficking organisations, cybercriminals and fraud networks will increasingly use the same money launderers, corrupt facilitators, nominee companies, document suppliers and coercive intermediaries while remaining operationally separate. H₅ — hybrid or proxy convergence predicts that access brokers, infrastructure operators or ransomware affiliates will occasionally accept state-aligned tasking or sell services to hybrid-threat actors. H₆ — containment and displacement predicts that stronger financial controls, EU-supported investigations, faster electronic evidence and repeated infrastructure operations will prevent sustained regional platformisation, pushing activity abroad or into smaller, less profitable structures. The priors are not national crime-rate estimates; they are structured judgments about the organisational form most likely to dominate the documented service ecosystem. Evidence from geographically distributed call centres, shared platforms, manager continuity and division between sales, infrastructure and laundering raises H₂ and H₄. The persistence of numerous fraud brands and low entry barriers raises H₃. The absence of verified public evidence for a Western Balkan-controlled global ransomware platform limits H₁. Europol’s warning that cybercriminal and hybrid-threat boundaries are blurring raises H₅, but not enough to support case-specific state attribution. Enforcement operations and accession-related capacity building support H₆, though current evidence-access and institutional gaps reduce its posterior weight.
Table 2 — Bayesian update from 2026 baseline to 2031 hypothesis
| Hypothesis | 2026 prior | Evidence direction | 2031 posterior | Confidence | Primary confirmation requirement |
|---|---|---|---|---|---|
| H₁ — Indigenous platformisation | 15% | Corporate-style fraud management and reusable infrastructure increase plausibility | 19% | Moderate | Regional control of administrators, treasury and vendor governance |
| H₂ — Outsourced regional production | 25% | Strongly consistent with foreign markets and distributed functional nodes | 28% | Moderate-to-high | Command, data or payment instructions originating outside operator locations |
| H₃ — Fragmented entrepreneurial diffusion | 22% | Tool availability and brand churn strongly support diffusion | 21% | High | Many small cells with shared tools but limited common ownership |
| H₄ — Shared-enabler convergence | 18% | Laundering, company and account requirements support common intermediaries | 18% | Moderate-to-high | Recurrent facilitators across fraud, trafficking and cyber cases |
| H₅ — Hybrid or proxy convergence | 10% | Europol-wide trend raises risk, but Balkan-specific evidence remains limited | 8% | Low | Authenticated tasking, non-financial target logic and infrastructure overlap |
| H₆ — Containment and displacement | 10% | New tools and cooperation improve disruption, but implementation remains uneven | 6% | Moderate | Falling regeneration rates, shorter account life and sustained asset recovery |
Table 3 — Bayesian evidence weights
| Evidence item | H₁ | H₂ | H₃ | H₄ | H₅ | H₆ |
|---|---|---|---|---|---|---|
| Multilingual call-centre teams with hierarchical management | +2 | +3 | +1 | +1 | 0 | 0 |
| Foreign victim markets and cross-jurisdiction infrastructure | +1 | +3 | +1 | +1 | 0 | −1 |
| Same call-centre management surviving brand changes | +2 | +2 | −1 | +1 | 0 | −1 |
| Separate sales, technical and laundering jurisdictions | +1 | +3 | 0 | +3 | 0 | 0 |
| Limited evidence of regional RaaS administration | −3 | 0 | +1 | +1 | −1 | +1 |
| Increasing CaaS and access-broker availability | +1 | +2 | +3 | +1 | +1 | −1 |
| Legal-business infiltration and nominee structures | +2 | +1 | 0 | +3 | 0 | −1 |
| Faster payment suspension and asset freezing | −2 | −1 | −1 | −2 | 0 | +3 |
| Cross-border e-evidence implementation | −1 | −1 | −1 | −1 | −1 | +3 |
| AI-assisted multilingual automation | +2 | +2 | +3 | +1 | +1 | −2 |
| State-aligned use of criminal access services | 0 | +1 | 0 | +1 | +3 | −1 |
| Repeated raids without durable activity decline | +2 | +2 | +2 | +1 | 0 | −3 |
Monte Carlo model and assumptions
The Monte Carlo framework models five scenarios across 250,000 iterations, with each iteration drawing values for eight drivers: A₁ AI-assisted social-engineering productivity; C₂ availability of criminal services; L₃ laundering liquidity; B₄ legitimate-business penetration; E₅ effectiveness of electronic-evidence acquisition; F₆ payment-freezing and asset-recovery effectiveness; R₇ regional specialist-labour availability; and D₈ disruption intensity. The model imposes correlations because the variables are not independent. Increased CaaS availability correlates positively with AI-enabled fraud, infrastructure replacement and specialist access; legitimate-business penetration correlates with liquidity resilience and account availability; better electronic evidence correlates with more effective cross-border disruption; and high enforcement pressure correlates with decentralisation. Nonlinear thresholds are included because criminal output does not rise proportionally with every capability. A fraud network with abundant leads but inadequate receiving accounts may generate contacts without revenue. A ransomware affiliate with access but weak lateral-movement capability may fail before obtaining leverage. Conversely, once a network acquires redundant payment rails, multilingual automation and reusable victim data, small increases in lead volume can produce disproportionate revenue growth. The baseline distributions are calibrated from the verified direction of institutional assessments rather than undisclosed incident datasets: Europol expects greater AI use and resilient online-fraud networks; ENISA observes ransomware decentralisation and access-broker proliferation; FATF identifies integration of laundering mechanisms from the outset; and Eurojust–Europol identify persistent problems involving data loss, access to data, anonymisation, international cooperation and rapid response. Common Challenges in Cybercrime as Identified by Eurojust and Europol – Eurojust and Europol – April 2024 — Verified primary source. The model should therefore be read as a disciplined uncertainty engine, not a claim that hidden criminal markets can be measured with actuarial precision.
Table 4 — Monte Carlo driver specification
| Driver | Baseline mean | 80% interval | Direction of criminal risk | Highest sensitivity |
|---|---|---|---|---|
| A₁ — AI social-engineering productivity | 72/100 | 58–86 | Positive | Industrialised fraud and BEC |
| C₂ — CaaS availability | 76/100 | 63–89 | Positive | Ransomware affiliates and credential brokerage |
| L₃ — laundering liquidity | 64/100 | 46–81 | Strongly positive | All monetisation pathways |
| B₄ — legitimate-business penetration | 58/100 | 41–74 | Positive | Call centres, shell companies and BEC |
| E₅ — e-evidence effectiveness | 51/100 | 35–68 | Negative | Attribution and prosecution |
| F₆ — rapid freeze and asset recovery | 47/100 | 30–64 | Strongly negative | BEC and online fraud |
| R₇ — specialist and multilingual labour | 68/100 | 54–82 | Positive | Fraud conversion and technical support |
| D₈ — disruption intensity | 61/100 | 46–77 | Mixed | Suppresses output but increases decentralisation |
| P₉ — provider cooperation | 55/100 | 37–72 | Negative | Domain, hosting, account and evidence continuity |
| G₁₀ — cross-border governance alignment | 49/100 | 32–67 | Negative | Joint investigations and durable prosecution |
Table 5 — Baseline Monte Carlo scenario outputs
| Scenario | Probability | 80% model interval | 2031 maturity index | Dominant production form |
|---|---|---|---|---|
| S₁ — Platformised modular expansion | 34% | 27–42% | 82/100 | Coordinators orchestrate replaceable vendors and operator cells |
| S₂ — Fragmented CaaS diffusion | 26% | 20–33% | 69/100 | Numerous short-lived cells use shared tools and brokers |
| S₃ — Enforcement bifurcation | 18% | 13–24% | 61/100 | Visible centres decline while sophisticated networks consolidate |
| S₄ — Hybrid-enabler convergence | 14% | 9–20% | 76/100 | Shared access, laundering and infrastructure serve criminal and proxy actors |
| S₅ — Effective containment | 8% | 4–13% | 43/100 | Scaling becomes unreliable and net criminal yield falls |
Scenario S₁: platformised modular expansion
Under S₁, the Balkan ecosystem does not necessarily produce a single dominant criminal brand. Instead, a small layer of coordinators controls lead procurement, back-end platforms, data repositories, operator allocation, treasury rules and relationships with technical or financial vendors. Public-facing investment sites, call-centre companies and campaign names remain disposable. The platform’s durable assets are victim data, managerial expertise, account-supply relationships and production analytics. AI reduces the cost of translating scripts, generating synthetic identities, segmenting victims and supervising operators, while legitimate business structures provide offices, employment contracts, communications accounts and plausible payment narratives. Europol reports that 86% of the EU’s most threatening criminal networks abuse legal business structures and that online-fraud networks use trading companies, investment firms, call centres, IT providers and other entities that can be created and dissolved quickly. It also observes that call centres may appear legitimate to employees, market several products simultaneously and relocate while retaining managers and accountants. Leveraging Legitimacy: How the EU’s Most Threatening Criminal Networks Abuse Legal Business Structures – Europol – December 2024 — Verified primary source. S₁ becomes dominant if L₃ exceeds approximately 70, A₁ exceeds 75 and provider cooperation remains below 55. Its defining indicator is not a rise in websites but increasing back-end reuse across nominally unrelated campaigns: common administrator accounts, CRM schemas, victim-status codes, payment-routing logic, recruitment networks or consolidation wallets. Intervention must therefore target platform dependencies and beneficial control rather than closing one premise at a time.
Table 6 — S₁ warning indicators and thresholds
| Indicator | Early warning threshold | Escalation threshold | Strategic interpretation |
|---|---|---|---|
| Fraud brands sharing back-end infrastructure | 3 brands | 8 or more brands | Common platform administration |
| Call centres sharing managers or accountants | 2 centres | 4 or more centres | Durable governance behind disposable premises |
| Domains replaced after disruption | Within 21 days | Within 72 hours | Mature regeneration capability |
| Victim data reused in recovery fraud | 10% overlap | Above 30% overlap | Data treated as persistent productive capital |
| Shared beneficiary or consolidation endpoints | 5 campaigns | 15 campaigns | Central treasury or laundering broker |
| Operators serving multiple languages | 3 languages | 6 or more languages | Export-oriented production |
| Multiple legal companies using common devices | 2 entities | 5 or more entities | Corporate-shell rotation |
| Common advertisement identifiers | 3 campaigns | 10 campaigns | Centralised victim acquisition |
| Remote administrative logins from outside premises | Occasional | Systematic | Separation of command from production |
| Revenue-linked operator compensation | Isolated evidence | Standardised commission system | Mature performance management |
Scenario S₂: fragmented CaaS diffusion
S₂ produces a larger number of offenders but fewer strategically durable organisations. Accessible phishing kits, stolen credentials, generative AI, rented infrastructure and online tutorials allow small groups to enter fraud and account-compromise markets without owning a complete criminal stack. These cells purchase leads, access or payment accounts from brokers, operate short campaigns and dissolve after exposure or internal disputes. Fragmentation reduces the value of leadership arrests because no central command exists, but it also reduces operational quality, trust and financial efficiency. Smaller actors face higher rates of service fraud, stolen proceeds, defective tools and frozen accounts. The scenario is especially plausible for BEC attempts, credential exploitation, low-complexity extortion and impersonation fraud. It becomes more likely when C₂ and A₁ remain high but L₃ and B₄ remain moderate: tools are accessible, yet stable laundering and corporate infrastructure are scarce. The observable environment contains many brands, domains and small payment clusters but limited back-end continuity. Europol’s assessment that criminal actors use bulletproof hosting, multi-jurisdiction infrastructure and residential proxies indicates why attribution will remain difficult even when groups are operationally weak. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. Policy must avoid equating fragmentation with containment. Aggregate victimisation can increase even while average group sophistication falls because the number of campaigns rises faster than individual success rates decline. The appropriate response is industrialised defence: automated correlation of domains, beneficiary accounts, devices and advertisements; rapid victim notification; standardized preservation requests; and reusable disruption packages rather than bespoke investigations for every brand.
Table 7 — S₁ versus S₂ diagnostic test
| Diagnostic question | Platformised S₁ expectation | Fragmented S₂ expectation |
|---|---|---|
| Do different brands share administration? | Frequent and structured | Opportunistic or accidental |
| Is victim data reused systematically? | Yes, across campaigns and fraud stages | Limited or poorly organized |
| Are financial endpoints centrally allocated? | Yes | Purchased ad hoc |
| Do managers survive company closures? | Frequently | Inconsistently |
| Is technical infrastructure professionally redundant? | Yes | Partial and error-prone |
| Are commission and productivity systems standardized? | Yes | Informal |
| Does disruption produce rapid coordinated regeneration? | Yes | Numerous uncoordinated replacements |
| Are upstream service providers stable? | Small trusted set | Broad, volatile market |
| Does one seizure expose many brands? | High probability | Low probability |
| Is net criminal yield stable? | Relatively stable | Highly variable |
Scenario S₃: enforcement bifurcation
S₃ is not simple enforcement success. It describes a market split in which highly visible, labour-intensive operations become easier to disrupt while technically sophisticated and financially resilient networks consolidate. Large call centres create physical signatures: leases, electricity use, recruitment, payroll, language-specific hiring, telecommunications traffic and managerial presence. Repeated raids, whistle-blower awareness and corporate-registration scrutiny can raise their operating cost. More capable coordinators respond by distributing operators across remote work, reducing office size, outsourcing recruitment and separating customer contact from platform control. Meanwhile, small cells unable to acquire reliable accounts or provider relationships disappear. The result is fewer visible facilities but stronger surviving networks, producing an apparent improvement in raid statistics without an equivalent reduction in victim losses. This scenario becomes dominant when D₈ rises above 70 but F₆ and E₅ remain below approximately 60: authorities can close premises but cannot consistently seize the treasury, preserve provider data or establish beneficial command. Eurojust and Europol identify data volume, data loss, access restrictions, anonymisation, international cooperation and public-private partnership limitations as continuing cybercrime challenges despite new legislative tools. Common Challenges in Cybercrime as Identified by Eurojust and Europol – Eurojust and Europol – April 2024 — Verified primary source. The policy implication is that output metrics must extend beyond arrests and sites closed. Authorities should measure victim-loss trends, regeneration time, percentage of proceeds frozen, percentage of seized devices processed within operationally relevant time, administrator attribution, evidence-to-charge conversion and whether a disruption removes shared dependencies across multiple campaigns.
Table 8 — Enforcement performance metrics
| Metric | Weak measure | Strong measure | 2031 target direction |
|---|---|---|---|
| Premises disruption | Number of offices searched | Share of regional campaign capacity disabled | Rising |
| Arrest output | Total arrests | Arrests of administrators, treasury controllers and facilitators | Rising proportion |
| Device seizure | Number of devices | Percentage triaged within 72 hours and fully processed | Above 90% triage |
| Asset action | Gross property seized | Share of estimated proceeds restrained or recovered | Sustained increase |
| Domain action | Domains removed | Median regeneration time and shared-back-end disruption | Regeneration above 30 days |
| Bank response | Accounts notified | Time from victim report to freeze decision | Hours, not days |
| Evidence requests | Number issued | Response completeness and time | Near-real-time emergencies |
| Joint investigations | JITs formed | Cases producing coordinated charges and confiscation | Outcome-based |
| Victim protection | Warnings published | Victims reached before secondary fraud | High coverage |
| Intelligence value | Reports produced | Cross-case entities discovered and actioned | Measurable dependency removal |
Scenario S₄: hybrid-enabler convergence
S₄ represents the highest strategic-impact scenario even though it is not the highest-probability outcome. Its defining feature is not that financially motivated Balkan criminals become state agents in a formal sense. It is that access brokers, hosting providers, data sellers, money launderers or intrusion specialists serve both criminal and hybrid-threat customers, allowing states or aligned intermediaries to acquire deniable capabilities without maintaining every technical asset internally. A provider may sell compromised organisational access to the highest bidder without knowing whether the purchaser intends ransomware, espionage or disruption. A criminal group may accept a target specification that has geopolitical rather than commercial value, then use ordinary extortion to disguise the operation. A laundering channel may process proceeds from fraud alongside sanctions evasion or influence operations. Europol assesses that hybrid-threat actors increasingly use cybercriminal networks as proxies for DDoS attacks, intrusions and ransomware, while stolen access can be exploited against governments and critical infrastructure. Internet Organised Crime Threat Assessment 2026 – Europol – June 2026 — Verified primary source. However, the public evidence examined does not establish state direction of the documented Balkan call-centre networks; such attribution would require authenticated communications, non-financial targeting logic, infrastructure continuity, state-benefiting timing and financial or personal links to state intermediaries. The primary policy problem is dual use. Removing a shared access or hosting node may reduce both criminal and hybrid risk, but public attribution standards should remain higher than disruption thresholds. Intelligence services, criminal investigators, financial-intelligence units and cybersecurity agencies therefore require protocols for sharing indicators without prematurely merging legal classifications.
Table 9 — Criminal versus hybrid attribution matrix
| Indicator | Ordinary criminal explanation | Hybrid/proxy explanation | Evidentiary weight |
|---|---|---|---|
| Financial demand | Direct profit motive | Cover for disruption or intelligence collection | Low alone |
| Target selection | Ability and willingness to pay | Strategic sector, political timing or symbolic value | Medium |
| Data stolen but not monetised | Failed campaign or resale delay | Intelligence objective | Medium |
| Infrastructure overlap | Shared criminal vendor | Common tasking or sponsor | Low-to-medium |
| Non-public vulnerability use | Purchased or independently discovered | State-supplied capability | Medium |
| Coordinated information operation | Criminal reputational pressure | Strategic influence campaign | High |
| Payment disconnected from activity | Hidden intermediary or laundering | State support | Medium |
| Repeated state-benefiting timing | Coincidence or market opportunity | Direction or alignment | Medium-to-high |
| Authenticated command communications | Criminal buyer | State or state-linked tasking | Very high |
| Personnel link to state structures | Incidental history | Sponsor relationship | High if current and operational |
| Simultaneous physical and cyber pressure | Opportunistic exploitation | Integrated hybrid operation | High |
| Persistence after economic logic disappears | Poor judgment or revenge | Non-financial objective | Medium-to-high |
Scenario S₅: effective containment
Effective containment does not require eliminating cybercrime. It requires reducing the reliability of scaling and monetisation until marginal expansion no longer produces predictable returns. The decisive condition is simultaneous pressure at several dependency points: advertisements are removed before generating a large victim pool; providers preserve administrator data; banks suspend suspicious transfers rapidly; exchanges identify related wallets; company registries expose nominee patterns; seized devices are processed quickly enough to support follow-on actions; and prosecutors can establish cross-border command and confiscation. If only one layer improves, networks reroute around it. The EU e-evidence framework can reduce some delays by enabling production orders directed to represented service providers and preservation of data pending production, but implementation quality remains decisive. A Council high-level report states that the e-evidence Regulation and Directive are important steps while warning that substantial work remains and that incomplete implementation leaves access to data abroad a major challenge. Data Access for Effective Law Enforcement: Final Report of the High-Level Group – Council of the European Union – November 2024 — Verified primary source. Containment becomes the dominant scenario only when E₅, F₆ and P₉ all exceed approximately 70 and financial controls operate faster than criminal dispersal. Its most important outcome is declining survival-adjusted yield, not declining complaint volume. Complaints may initially rise as reporting improves. The stronger signal is that a greater share of transfers is stopped, account portfolios become shorter-lived, repeat victimisation falls, platform regeneration slows and professional facilitators face confiscation or exclusion from legitimate markets.
Country and institutional capacity implications
The Western Balkans do not present a uniform enforcement environment, and a regional forecast that assigns one capacity score to all jurisdictions would conceal the operational seams criminal services exploit. The European Commission reported that Albania adopted a 2025–2030 National Cybersecurity Strategy but still needed stronger cybersecurity capacity, implementing legislation, training and awareness. Albania Report 2025 – European Commission – November 2025 — Verified primary source. It reported that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and made no progress during the reporting period on the cited cybercrime alignment issue. North Macedonia Report 2025 – European Commission – November 2025 — Verified primary source. For Bosnia and Herzegovina, the Commission stated that authorities should strengthen their capacity to tackle cybercrime effectively. Bosnia and Herzegovina Report 2024 – European Commission – October 2024 — Verified primary source. These findings are institutional assessments, not crime-prevalence measures. Their forecast significance lies in uneven response time, digital-forensic throughput, legal alignment, provider cooperation and asset recovery. Criminal networks can separate operations so that labour, infrastructure, data and proceeds sit in jurisdictions with different investigative strengths. Regional policy must consequently create minimum interoperable operating standards rather than isolated centres of excellence.
Table 10 — Regional capability priorities through 2031
| Capability | Albania | Serbia | North Macedonia | Bosnia and Herzegovina | Montenegro | Regional requirement |
|---|---|---|---|---|---|---|
| Cybercrime strategy implementation | High priority | Update and operational measurement | High priority | Fragmented governance challenge | Capacity consolidation | Annual implementation scorecard |
| Digital-forensic triage | Expand staffing and automation | Strengthen high-tech crime integration | Expand resources | Harmonise institutional access | Build surge capacity | Shared emergency assistance pool |
| E-evidence procedures | Align with EU practice | Maintain rapid cooperation channels | Ratify and operationalise relevant instruments | Establish consistent procedures | Integrate regional practice | Common templates and 24/7 contacts |
| Financial investigation | Link fraud cases to proceeds from outset | Integrate cyber and organised-crime finance | Expand asset tracing | Improve cross-entity coordination | Strengthen FIU–prosecutor workflow | Parallel financial investigation standard |
| Provider engagement | Formal contact mechanisms | Structured domestic and foreign provider liaison | Improve legal and operational capability | Reduce fragmented requests | Regional hosting and telecom engagement | Provider response directory |
| Call-centre oversight | Risk-based inspection and beneficial ownership | Employment and telecom anomaly detection | Corporate and platform scrutiny | Entity-level coordination | Monitor relocation risk | Shared risk indicators |
| Victim reporting | Unified cyber-fraud intake | Link reports to bank-freeze action | Improve reporting access | Harmonise entity systems | Build national-to-regional feed | Common minimum data schema |
| Cryptocurrency tracing | Specialist capacity | Expand joint analytic support | Develop dedicated expertise | Shared regional access | Build capability | Regional centre of expertise |
| Judicial specialization | Continue SPAK and cybercrime coordination | Specialized prosecution continuity | Strengthen cybercrime specialization | Reduce jurisdictional fragmentation | Dedicated training | Joint prosecutor exercises |
| Strategic intelligence | Cross-case dependency mapping | Integrate SOCTA and cybercrime analysis | Develop threat assessment | Improve consolidated picture | Regional contribution | Annual Western Balkans CaaS assessment |
Intervention architecture: attack dependencies, not brands
Interventions should be sequenced according to economic leverage. At the victim-acquisition layer, authorities and platforms can disrupt malicious advertising, cloned sites and abusive telecommunications before a large lead pool develops. At the access layer, credential resets, infostealer victim notifications and rapid infrastructure action can prevent stolen data from entering ransomware or BEC markets. At the production layer, labour inspections, beneficial-ownership analysis, telecom metadata and whistle-blower channels can expose nominally legitimate call centres. At the payment layer, confirmation-of-payee controls, real-time anomaly detection and cross-border freeze protocols can prevent extraction from becoming profit. At the laundering layer, financial investigation, cryptocurrency tracing, nominee-company analysis and confiscation target the trusted brokers that are harder to replace than domains. At the command layer, administrator attribution, CRM seizure and revenue-sharing evidence connect replaceable operators to organisers. The ordering matters because simultaneous action creates compounding effects. Shutting a site warns operators but may preserve their data and accounts; freezing accounts without preserving communications may recover money but lose attribution; arresting operators before mapping the treasury can trigger asset dispersal. Europol’s finding that legal businesses are abused by 86% of the EU’s most threatening criminal networks reinforces the need to integrate corporate, tax, labour, telecom, financial and cyber evidence. Leveraging Legitimacy: How the EU’s Most Threatening Criminal Networks Abuse Legal Business Structures – Europol – December 2024 — Verified primary source.
Table 11 — Intervention-point matrix
| Intervention point | Immediate action | Intelligence gain | Economic effect | Displacement risk |
|---|---|---|---|---|
| Malicious advertising | Suspend campaign and preserve account data | Purchaser, payment and targeting records | Raises lead cost | Movement to smaller platforms |
| Domain registration | Preserve registrant, payment and access data | Links brands and administrators | Slows replacement | Registrar shopping |
| Hosting | Image systems before takedown | Back-end and operator evidence | Disrupts platform availability | Bulletproof hosting |
| Infostealer infrastructure | Notify victims and neutralise control systems | Access-market mapping | Removes campaign inventory | Migration to new malware |
| Telecommunications | Identify abnormal call and SIM patterns | Operator and manager links | Raises contact cost | Encrypted or internet calling |
| Call-centre premises | Coordinated search after dependency mapping | Personnel, CRM and scripts | Removes production capacity | Remote work |
| Bank accounts | Immediate suspension and recall | Mule and treasury network | Directly reduces yield | Crypto or fintech movement |
| Cryptocurrency wallets | Trace and seek seizure | Consolidation and affiliate shares | Disrupts settlement | Chain or asset switching |
| Company registry | Verify beneficial ownership and frontmen | Corporate network structure | Raises concealment cost | Foreign incorporation |
| Payroll and labour | Compare staff, revenue and communication roles | Identifies production hierarchy | Disrupts recruitment | Informal contracting |
| CRM and victim database | Secure, analyse and notify | Exposes campaign portfolio | Prevents secondary fraud | Encrypted remote storage |
| Manager and accountant network | Cross-case investigation | Reveals durable governance | High systemic impact | Replacement by trusted insiders |
Policy implications for the EU and Western Balkans
The appropriate policy objective is not a generic increase in “cybersecurity.” It is to compress the interval between criminal action, detection, evidence preservation, financial suspension and coordinated attribution. Cybersecurity agencies primarily protect systems; police identify offenders and infrastructure; financial-intelligence units analyse proceeds; prosecutors establish admissible evidence; banks and platforms control privately held chokepoints; regulators address weak corporate and payment practices. A functional regional strategy must join those mandates through event-driven procedures. A high-value fraud report should automatically trigger a structured evidence package, preservation request, bank contact, beneficiary-account assessment and cross-case entity search. A ransomware incident should trigger not only technical containment but analysis of access provenance, data exfiltration, affiliate infrastructure, negotiation accounts and downstream cryptocurrency flows. A suspicious call centre should be assessed through labour records, company ownership, telecommunications, advertising, payment beneficiaries and foreign victim reports rather than through premises inspection alone. EU pre-accession funding should be conditioned on measurable operational outputs: forensic backlog reduction, freeze times, provider-response rates, confiscation results and cross-border case conversion. Formal alignment without execution will not materially alter Monte Carlo outcomes. Conversely, highly capable investigators without rapid private-sector cooperation will continue to lose data and proceeds. Policy must therefore finance interoperable workflows, not only equipment, conferences or strategic documents.
Table 12 — Policy roadmap, 2026–2031
| Period | Priority | Operational deliverable | Performance indicator |
|---|---|---|---|
| Late 2026 | Common incident and fraud-reporting schema | Minimum dataset shared by police, FIUs and prosecutors | Percentage of reports meeting data standard |
| 2027 | Regional rapid-freeze protocol | 24/7 bank and VASP contact network | Median freeze-request time |
| 2027 | E-evidence readiness | Standard preservation and production workflows | Provider response time and completeness |
| 2027–2028 | Digital-forensic surge capacity | Shared triage capability for major action days | Devices triaged within 72 hours |
| 2028 | Call-centre and legal-business risk model | Cross-border entity and manager scoring | High-risk entities reviewed |
| 2028 | Shared cryptocurrency capability | Regional tracing and seizure support | Wallet clusters actioned |
| 2028–2029 | Cross-case dependency graph | Federated entity-resolution environment | Campaigns linked through shared enablers |
| 2029 | Repeat-victim protection programme | Automated warnings and recovery-fraud prevention | Secondary victimisation reduction |
| 2029–2030 | Specialist facilitator strategy | Coordinated action against accountants, brokers and nominees | Enabler prosecutions and exclusions |
| 2030 | Joint regional threat assessment | Annual CaaS, BEC and ransomware ecosystem assessment | Comparable trend indicators |
| 2030–2031 | Outcome-based funding | Funding tied to recovery, attribution and disruption durability | Regeneration time and recovered proceeds |
| 2031 | Integrated EU–Western Balkans operating model | Near-real-time operational cooperation | Cross-border case completion rate |
Strategic indicators and decision thresholds
A 2031 early-warning system should distinguish volume indicators, capability indicators, resilience indicators and strategic-convergence indicators. Volume indicators include complaints, malicious domains, suspicious advertisements, detected call activity and reported losses; they measure exposure but can rise because reporting improves. Capability indicators include multilingual synthetic identities, administrator reuse, privileged access sales, high-capacity receiving accounts and cross-platform victim data. Resilience indicators include regeneration time, the number of substitute accounts activated after freezes, relocation speed and continuity of managers after company closure. Strategic-convergence indicators include common facilitators across cyber and physical crime, shared infrastructure with state-aligned operations, unexplained targeting of critical sectors and persistence after financial incentives disappear. Decision thresholds should be tied to action. If three or more campaigns share a beneficiary controller, a financial network investigation should begin. If a disrupted platform regenerates within seven days using related administrators, authorities should escalate from brand-specific action to platform attribution. If victim data appears in recovery fraud within thirty days, immediate notification and data-market investigation are warranted. If one facilitator connects ransomware settlement, BEC receipts and investment-fraud deposits, the case should be treated as a high-impact laundering-service investigation. If geopolitical target selection co-occurs with authenticated state-linked communications or coordinated influence activity, criminal and national-security authorities should establish a joint attribution process. Such thresholds transform forecasting into collection discipline: every scenario carries observable implications, and failure to observe them should lower its probability rather than being explained away.
Table 13 — 2031 indicator dashboard
| Indicator | Green | Amber | Red | Required response |
|---|---|---|---|---|
| Median fraud-domain regeneration | Above 30 days | 8–30 days | 7 days or less | Escalate to shared back-end investigation |
| Share of proceeds frozen | Above 45% | 20–45% | Below 20% | Review bank, VASP and reporting latency |
| Devices triaged within 72 hours | Above 90% | 60–90% | Below 60% | Deploy forensic surge capacity |
| Repeat-victim rate | Below 5% | 5–12% | Above 12% | Activate recovery-fraud protection |
| Campaigns linked to common treasury | 1–2 | 3–5 | More than 5 | Prioritise treasury controller |
| Average mule-account longevity | Below 5 days | 5–20 days | Above 20 days | Strengthen account-network detection |
| Cross-border evidence response | Below 24 hours urgent | 1–5 days | Above 5 days | Resolve procedural and provider blockage |
| Call-centre relocation time | Above 90 days | 30–90 days | Below 30 days | Target managers, recruiters and accountants |
| Shared infrastructure across crime types | Isolated | Recurrent | Systematic | Create multi-crime task force |
| State-aligned target anomalies | None | Unexplained pattern | Pattern plus corroboration | Joint criminal–security assessment |
| Beneficial ownership established | Above 80% of priority entities | 50–80% | Below 50% | Expand corporate intelligence |
| Net asset recovery | Rising over three years | Volatile | Declining | Reassess intervention sequence |
Strategic judgement through 2031
The baseline judgment is that the Western Balkan criminal-service ecosystem will become more modular, more export-oriented and less dependent on large permanent premises by 2031, but the most probable form is outsourced production and shared-enabler convergence rather than a unified regional cybercrime cartel. Industrialised online fraud will remain the most mature regional vector because it fits existing multilingual labour, call-centre management and corporate-front capabilities. BEC-support services—especially reconnaissance, receiving accounts, nominee companies and laundering—will grow faster than publicly attributable end-to-end BEC command. Ransomware participation will increase primarily through access brokerage, affiliate work, infrastructure and financial services; the emergence of a Balkan-controlled global RaaS platform remains possible but is not the baseline. The Monte Carlo model gives 60% combined probability to platformised expansion or fragmented CaaS diffusion, compared with 8% for effective containment. However, this balance is not immutable. Sensitivity analysis identifies rapid payment freezing as the single most powerful short-term variable, followed by provider-held evidence, beneficial-ownership transparency and the removal of persistent facilitators. Raising F₆ and E₅ by twenty points while holding criminal drivers constant approximately doubles the containment probability and reduces the platformised scenario by more than one-third. Increasing disruption without those capabilities mainly raises S₃, enforcement bifurcation. The policy conclusion is precise: more raids alone will produce adaptation; simultaneous financial, evidentiary, corporate and technical intervention can reduce criminal yield. Success by 2031 should be measured not by the disappearance of cybercrime brands but by longer regeneration times, lower repeat-victimisation, higher recovery rates, shorter evidence delays and the inability of organisers to replace trusted liquidity and governance nodes.





















