Executive Summary

BLUF: Balkan-based cybercriminal activity is evolving fastest in scalable online fraud, multilingual call-centre operations, credential exploitation, payment diversion and laundering support—not yet in demonstrably Balkan-controlled global ransomware platforms.
The strongest evidenced model is a modular ecosystem connecting local operators with transnational suppliers of malware, data, infrastructure, advertising and payment services.
Public evidence does not justify treating traditional Balkan organised-crime groups and Balkan cybercrime networks as interchangeable populations.
Through 2031, generative AI, stolen digital identities, cryptocurrency settlement and outsourced technical services will lower entry barriers and increase fraud throughput.
The central risk is the conversion of relatively inexpensive regional labour, language skills and corporate infrastructure into remotely exportable criminal capacity.
The highest-confidence intervention points are recruitment, initial access, domain and hosting infrastructure, payment conversion, mule coordination and cross-border electronic evidence.

The Balkan Cybercrime Factory Is Moving Closer to Italy

The most consequential evolution of Balkan organised crime is no longer occurring only along ports, motorways or trafficking corridors. It is taking place inside call centres, fraudulent investment platforms, compromised corporate mailboxes, cryptocurrency wallets and rented digital infrastructure. Crime is becoming remotely exportable: operators, software, victim data and laundering channels can be purchased separately and assembled across several jurisdictions. For Italy, this is not a peripheral threat. Linguistic proximity, intense commercial relations, financial integration and established Italy–Balkan criminal connections make Italian households, companies and public institutions both targets and potential transit points. The strategic question is no longer whether criminal groups will “go digital,” but whether Europe can interrupt their revenues faster than they can replace their brands, accounts and infrastructure.

The Industrial Turn

Europol’s Internet Organised Crime Threat Assessment 2026, issued under Executive Director Catherine De Bolle, describes online fraud as the fastest-growing area of organised crime. Investment fraud, business email compromise, romance scams, technical-support fraud and attacks against payment systems now operate through transnational combinations of logistics, technology and finance. Europol observed more than 120 active ransomware brands in 2025 and identified a continuing expansion of ransomware-as-a-service: developers supply platforms and malware, access brokers provide compromised systems, affiliates conduct intrusions, while separate specialists negotiate payments and launder cryptocurrency.

The same division of labour is transforming online fraud. Malicious advertising generates victims; multilingual operators convert them; fake platforms simulate profits; remote-access software exposes home banking; mule accounts receive transfers; cryptocurrencies or offshore services disperse proceeds. Generative AI improves translations, impersonation and conversational scripts. Voice bots can screen victims before transferring the most promising targets to human operators. The criminal enterprise consequently scales without placing every participant under one command or in one country.

This distinction is essential. A call centre in Tirana or Belgrade does not by itself prove Albanian or Serbian strategic control. The premises may supply only the sales function, while platform administration, advertising, data and treasury management remain elsewhere. Geography identifies the production node, not necessarily the owner.

The Balkan Production Base

The official judicial record already shows industrial capacity. On 8 and 9 November 2022, an operation supported by Eurojust and Europol searched 15 call centres—six in Albania, five in Georgia, three in Ukraine and one in North Macedonia—together with 27 other locations. Investigators estimated hundreds of thousands of victims and damage of approximately €50 million per quarter. The suspected activity dated back to at least 2016 and used hundreds of online platforms. Authorities seized more than 500 electronic devices, bank accounts, cryptocurrency wallets, identity documents, properties and cash.

A separate operation in January 2023 exposed an even clearer functional division. According to Eurojust, the network operated call centres from Serbia, used technical infrastructure in Bulgaria and allegedly based part of its laundering operation in Cyprus. More than 250 workplaces were identified. Fourteen suspects were initially arrested in Serbia and one in Germany; a second action produced another 16 arrests in Serbia. Victims were located in Germany, Switzerland, Austria, Australia and Canada.

The model has continued to evolve. On 29 April 2026, Austrian and Albanian authorities dismantled several alleged fraud call centres in Tirana. Eurojust reported 10 arrests, seizures approaching €900,000 and estimated losses exceeding €50 million. Operators worked in teams of six to eight, divided by language—German, English, Italian, Greek and Spanish—under team leaders and centre managers. This was not improvised deception. It was a structured export industry organised by market, language and productivity.

The Italian Connection

Italy has already confronted the mechanism directly. A joint Italian–Albanian investigation, opened at Eurojust by the Italian authorities in 2020, targeted a Tirana call centre that allegedly defrauded victims through fictitious cryptocurrency investments. The Public Prosecutor’s Office of Pisa and the Carabinieri worked with Albania’s Special Prosecution Office against Corruption and Organised Crime, SPAK, and the Albanian State Police.

During the coordinated action of 13–15 December 2022, authorities searched 13 locations in Albania and seized more than 160 electronic devices, one mobile telephone and approximately €3 million in assets, including 11 properties. Eurojust estimated the total damage at €15 million. The method was particularly aggressive: victims were contacted through virtual numbers and VPNs, shown small initial gains, persuaded to increase their investment and, in some cases, induced to provide remote access to their home-banking systems. Those who discovered the fraud were targeted again by alleged recovery specialists demanding further payments.

This case exposes Italy’s structural vulnerability. Italian is commercially valuable to Balkan fraud centres; Italian companies maintain extensive supplier relationships across South-Eastern Europe; and transfers that appear compatible with genuine investment, consultancy or commercial activity can be routed through legitimate-looking companies. The threat is therefore not confined to digitally inexperienced consumers. It extends to corporate treasuries, professional firms, municipalities, healthcare providers and small manufacturers whose payment controls remain based on familiarity rather than independent verification.

BEC, the Invisible Balance-Sheet Risk

Business email compromise is potentially more dangerous to Italian companies than its technical simplicity suggests. The criminal does not need to encrypt an industrial network. It is enough to understand who authorises payments, which supplier is awaiting settlement, how executives write and when a transfer is expected. A compromised mailbox or convincingly imitated identity can redirect a legitimate payment toward a criminal account.

The FBI’s 2025 IC3 Annual Report recorded 24,768 BEC complaints and reported losses of $3.047 billion. By comparison, it received more than 3,600 ransomware complaints with directly reported losses above $32 million. That comparison does not measure total economic harm: the FBI explicitly states that ransomware figures normally exclude lost production, downtime, wages, damaged equipment and remediation. It nevertheless demonstrates BEC’s exceptional capacity to convert limited technical access into immediate balance-sheet loss.

Generative AI increases the danger by reproducing language, tone and executive identity, but the decisive bottleneck remains financial. Fraudulent instructions are useless without accounts capable of receiving and rapidly dispersing corporate payments. Italy must therefore treat beneficiary-account intelligence, nominee companies and mule recruitment as cybersecurity issues, not merely as conventional money laundering.

Italy’s Exposure Is Already Measurable

The Italian National Cybersecurity Agency, ACN, recorded 91 ransomware attacks in the first half of 2025, essentially unchanged from the 92 registered in the corresponding 2024 period. In the second half of 2025, ACN recorded 54 cases, compared with 48 in the equivalent 2024 period. The Agency also registered 1,253 cyber events between July and December 2025, an increase of 30 per cent year on year, and sent more than 5,000 communications to organisations whose systems were considered at risk.

These figures measure only the visible portion of the threat. A company reports ransomware because production stops; it may remain unaware for months that mailboxes have been monitored or supplier payments manipulated. Investment and recovery fraud are also under-reported because victims fear reputational damage or do not immediately understand that the apparent trading platform never held genuine assets.

Italy has committed €623 million through PNRR Mission 1, Component 1, Investment 1.5 “Cybersecurity,” implemented by ACN. The programme has financed eight public calls and approximately 300 projects and interventions. The National Cybersecurity Strategy covers 2022–2026; Andrea Quacivi, appointed by the Council of Ministers on 22 May 2026, took office as ACN Director General on 8 June. The next strategic cycle must now connect national resilience with organised-crime finance and Balkan judicial cooperation. Protecting servers without tracing proceeds addresses only half of the enterprise.

The Evidence Race

Digital crime operates in minutes; judicial cooperation often operates in days or months. Domains disappear, communications are deleted, cryptocurrency moves and mule accounts empty before a complete request crosses several jurisdictions. The EU e-evidence framework seeks to narrow that gap. European production orders can require represented service providers to respond within 10 days, or within six hours in emergencies; preservation orders are designed to prevent stored evidence from being deleted while production is pending.

For Italy, the value of these instruments will depend on operational integration with Western Balkan partners. Albania’s cooperation with Eurojust is already substantial. Liaison Prosecutor Fatjona Memçaj has served in The Hague since January 2021. In 2025, her office participated in 121 new cases, 27 coordination meetings, three coordination centres and 27 joint investigation teams. These numbers show that a functioning bridge exists. The priority is to make it faster, financial and data-driven.

Every major Italian fraud report should immediately generate five coordinated actions: preservation of provider data; contact with the originating and beneficiary banks; identification of connected accounts and wallets; comparison with known domains, devices and companies; and assessment of whether the victim is exposed to recovery fraud. The objective is not simply to identify the caller. It is to reconstruct the production system.

The Financial Chokepoint

Liquidity is the decisive vulnerability of the criminal model. Websites, telephone numbers and operator accounts are cheap to replace; trusted receiving accounts and laundering relationships are not. The Financial Action Task Force reported in February 2026 that 156 jurisdictions—90 per cent of those assessed—identify fraud as a major money-laundering risk. Fraud networks increasingly integrate laundering from the outset through nominees, mule accounts, traded bank and exchange accounts, fintech platforms and rapid conversion into virtual assets.

A credible Italian strategy must therefore measure the time between a victim’s report and the suspension of funds. It must link banks, payment institutions, cryptocurrency service providers, law enforcement and prosecutors through a permanent rapid-response mechanism. Confirmation-of-payee controls, detection of unusual beneficiary changes and mandatory independent verification for high-value transfers should become standard corporate governance, especially for SMEs operating through cross-border supplier networks.

The same principle applies to criminal companies. Europol reported in December 2024 that 86 per cent of the EU’s most threatening criminal networks abuse legal business structures. Online-fraud networks use trading firms, investment companies, call centres, IT providers and shell entities that can be established and dissolved quickly. Corporate registries, employment data, telecommunications patterns and beneficial ownership must therefore become part of cybercrime intelligence.

The 2031 Fault Line

By 2031, the most probable threat is not a single Balkan ransomware super-cartel. It is a modular ecosystem in which regional call centres, account suppliers, company structures, access brokers and laundering intermediaries connect to platforms controlled across multiple jurisdictions. Industrialised fraud will remain the most mature segment. BEC will grow through stolen corporate access and payment intelligence. Balkan participation in ransomware will probably expand through affiliates, hosting, initial access and financial services rather than through immediate control of globally dominant brands.

Enforcement can push this market in two opposite directions. If authorities close premises without seizing data, administrators and financial networks, large call centres will fragment into smaller offices and remote workers. Arrest statistics will improve while losses continue. If Italy and its partners combine rapid evidence preservation, payment freezing, cryptocurrency tracing, beneficial-ownership analysis and confiscation, the business model becomes less reliable.

The decisive metric is not the number of domains removed or operators arrested. It is the proportion of proceeds recovered, the time required for a network to regenerate and the number of campaigns disabled by removing one shared facilitator. Italy’s advantage is that it already possesses ACN, specialised police and prosecutors, a major financial system and strong operational relations with Albania and other Balkan partners. Its weakness is institutional separation between cybersecurity, fraud investigation and organised-crime finance.

The next frontier of Italian security policy lies precisely there. The Balkan route is no longer only a route across territory. It is an export architecture for digital deception—and its most vulnerable border is the point where code, trust and money finally meet.


Navigational Index

  1. From territorial control to modular criminal production — How location-based enterprises become remotely scalable service networks.
  2. Ransomware, BEC and industrialised online fraud — Comparative maturity, infrastructure and monetisation pathways.
  3. Five-year scenarios, indicators and intervention points — Bayesian hypotheses, Monte Carlo outlook and policy implications through 2031.

Master Abstract

The central analytical finding is narrower—and therefore more defensible—than the proposition that established Balkan trafficking organisations are collectively becoming ransomware cartels. Verified law-enforcement evidence instead reveals the growth of a regional production layer for industrialised online fraud: multilingual operators, hierarchical call-centre management, deceptive investment platforms, customer-acquisition scripts, impersonation workflows and cross-border payment extraction. In April 2026, Austrian and Albanian authorities dismantled an alleged network operating several Tirana call centres; Eurojust reported 10 arrests, searches of several premises, seizures approaching EUR 900,000, estimated victim losses exceeding EUR 50 million, teams of six to eight operators divided by language and a managerial hierarchy resembling a legitimate company. This is unusually strong evidence of business-process industrialisation, although it does not prove organizational continuity with drug, weapons or migrant-smuggling groups. Fraud call centres targeting EU citizens shut down with Eurojust’s support – over EUR 50 million in damages uncoveredEurojust – April 2026 — Verified primary source. Earlier operations exposed geographically distributed nodes in Serbia, Bulgaria, Cyprus, Albania, Bosnia and Herzegovina and Kosovo, including call centres selling fictitious cryptocurrency investments and facilities generating thousands of fraudulent calls per day. Call centres selling fake crypto taken down in Bulgaria, Serbia and CyprusEuropol – January 2023 — Verified primary source. Operation PANDORA shuts down 12 phone fraud call centresEuropol – May 2024 — Verified primary source. The correct baseline is consequently not a completed migration from physical crime to cybercrime, but an uneven recombination of labour, corruption exposure, shell-company access, linguistic reach, laundering channels and commercially available cyber capabilities.

This recombination is occurring inside a global crime-as-a-service market that separates technical capability from victim acquisition and monetisation. Europol observed more than 120 active ransomware brands during 2025, described online-fraud networks as efficient transnational industries, and assessed that fraud actors increasingly outsource functions such as cryptocurrency theft while using phishing, malicious advertising, SIM-box infrastructure and generative AI-enhanced social engineering. Europol also identified a shift in ransomware from encryption-centred coercion toward data-theft extortion and warned that the boundary between financially motivated networks and hybrid-threat actors is becoming less distinct. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. For Balkan operators, this modular market changes the economics of criminal entry: a group no longer needs to develop ransomware, discover vulnerabilities, operate bulletproof hosting and launder proceeds internally. It can purchase credentials or initial access, rent phishing and communications infrastructure, acquire fabricated identities, recruit multilingual operators, contract technical specialists and outsource conversion of proceeds. BEC is particularly compatible with this structure because it joins credential theft, corporate impersonation, invoice manipulation, social engineering and mule-account management without requiring control of a sophisticated malware platform. The external demand environment is already immense: the FBI recorded 1,008,597 complaints and USD 20.877 billion in reported losses during 2025, including 24,768 BEC complaints associated with approximately USD 3.047 billion, while cyber-enabled fraud accounted for 85% of all reported losses. These are United States complaint statistics—not estimates of Balkan participation—but they quantify the export market accessible to location-independent criminal services. 2025 IC3 Annual ReportFederal Bureau of Investigation – April 2026 — Verified primary source.

The initial Analysis of Competing Hypotheses rejects a single-cause narrative and retains five simultaneously testable explanations. H₁, direct digitisation, proposes that established territorial organised-crime groups are internalising cyber capabilities; H₂, parallel emergence, treats Balkan cyber enterprises as largely new networks exploiting the same institutional environment without meaningful continuity with physical trafficking organisations; H₃, outsourced-node integration, interprets regional operators as labour, sales, hosting, laundering or access components inside externally directed criminal supply chains; H₄, commercial capture, anticipates legitimate or semi-legitimate call centres, marketing companies, payment intermediaries and IT contractors being repurposed through ownership, coercion or recruitment; H₅, attribution distortion, warns that servers, operators, bank accounts or arrests located in the Balkans may identify only one layer of a network controlled elsewhere. The provisional Bayesian assessment assigns the greatest weight to H₃, followed by H₂ and H₄; evidence for H₁ remains plausible but publicly incomplete, while H₅ must remain active in every country-level attribution. Institutional asymmetry will influence the five-year trajectory. The European Commission reported that Albania had adopted a 2025–2030 National Cybersecurity Strategy but still needed stronger capacity, implementing legislation, training and awareness measures. Albania Report 2025European Commission – November 2025 — Verified primary source. It separately found that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and had made no reporting-period progress on the cited cybercrime alignment issue. North Macedonia 2025 ReportEuropean Commission – November 2025 — Verified primary source. These gaps do not cause cybercrime, but they can widen the interval between detection, preservation of electronic evidence, attribution, seizure and prosecution—the interval service-based networks exploit by replacing domains, accounts, personnel and brands faster than cases mature.

Balkan CaaS Forecast Engine · 2027–2031

Digital Criminal-Service Transition Model

● 10,000 simulations per update

Scenario drivers

AI-enabled social engineering70
Criminal-service availability74
Laundering and mule liquidity63
Cross-border enforcement52
Electronic-evidence latency61
722031 service-export risk
78Fraud scalability
54Ransomware maturity
46%Platformisation
31%Fragmented growth
15%Hybrid convergence
8%Effective containment

Analysis of Competing Hypotheses · Provisional posterior

H₁ · 13%Traditional OCGs internalise cyber operations.
H₂ · 27%Independent digital-native networks emerge.
H₃ · 34%Balkan nodes serve externally directed ecosystems.
H₄ · 18%Commercial infrastructure is captured or repurposed.
H₅ · 8%Observed geography overstates local control.

Analytical model, not an observed crime count. Default probabilities are structured judgments derived from the cited institutional evidence. The simulation varies driver uncertainty across 10,000 iterations; slider changes test assumptions rather than manufacture Balkan attribution. “Ransomware maturity” measures the risk of regional participation across the service chain, not proven regional ownership of ransomware brands.

From Territorial Control to Modular Criminal Production

The operating model has changed

The decisive transformation is not simply that organised criminals have adopted computers. Criminal organisations have used telecommunications, encrypted messaging, online banking and digital logistics for years. The deeper change is organizational: the revenue-producing system can now be decomposed into purchasable modules, distributed across jurisdictions and recombined for successive campaigns without the participants sharing territory, nationality, hierarchy or even direct contact. A location-based enterprise traditionally derives power from controlling a port, neighbourhood, border crossing, transport corridor, protection market or corrupt administrative relationship. Its competitive advantage consists of physical access, coercive reputation, trusted kinship networks, territorial surveillance and the capacity to enforce agreements through violence. A modular cybercriminal enterprise substitutes access to infrastructure, identities, credentials, communications, payment rails, victim lists and specialized labour for most of those functions. Its “territory” becomes a temporary assemblage of cloud accounts, domains, call-centre seats, compromised devices, bank accounts, cryptocurrency wallets and contractor relationships. Europol’s 2026 assessment identifies online-fraud networks as highly efficient transnational industries using distinct logistical, technical and financial operations; it also records the outsourcing of criminal capabilities through crime-as-a-service, the use of generative AI to personalize social engineering and more than 120 active ransomware brands observed during 2025. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. INTERPOL independently assesses that cybercrime-as-a-service and money-laundering-as-a-service enable large-scale financial fraud, while warning that substantially less is known about how fraud offenders are organized than about their techniques. INTERPOL Global Financial Fraud AssessmentINTERPOL – March 2024 — Verified primary source. This evidentiary limitation is fundamental: an Albanian call centre, Serbian operator, Bulgarian server or Cypriot account establishes the location of a component, not necessarily the nationality of strategic command, beneficial ownership or ultimate profit.

Table 1 — Territorial and modular criminal-production systems

DimensionTerritorial enterpriseModular service networkIntelligence consequence
Primary assetPhysical corridor, market or protected localityCredentials, data, infrastructure and specialist accessDigital artefacts may matter more than visible territorial presence
Organisational formPersistent hierarchy or clan-based commandCells, contractors, affiliates, brokers and service vendorsArrested operators may reveal little about upstream control
EnforcementViolence, reputation and physical proximityEscrow, access restrictions, reputation systems, encryption and compartmentalisationLow observable violence does not imply low organisation
Capital expenditureVehicles, warehouses, weapons, corrupt protectionDomains, hosting, malware access, advertisements, call-centre capacity and accountsEntry costs fall when tools can be rented
Scaling constraintPersonnel and physical reachLead volume, automation, payment throughput and replaceable infrastructureVictimisation can expand without equivalent headcount growth
Market boundaryGeographically delimitedLanguage, platform, payment system or victim segment“Territory” becomes functional rather than geographic
Revenue cycleShipment or repeated local extractionContinuous campaigns, subscriptions, commissions and revenue sharesIncome becomes portfolio-based and campaign-driven
Failure modeTerritorial displacement or leadership arrestInfrastructure seizure, liquidity interruption, data exposure or trust collapseDisruption must target dependencies, not merely premises
Attribution problemWho controls the locality?Who owns the campaign, data, infrastructure and proceeds?Operator location cannot be treated as command attribution
RegenerationRequires rebuilding local protectionRequires replacing vendors, accounts, domains and brandsRecovery may occur in days or weeks

The Balkan evidence: production nodes, not a monolithic cyber mafia

The strongest primary-source evidence from the Western Balkans concerns industrialized investment fraud and telecommunications-enabled deception rather than proven Balkan ownership of internationally dominant ransomware brands. In March 2022, Albanian and German authorities dismantled two fraudulent platforms operated through Albanian call-centre companies; the platforms had been active since 2018, targeted German victims and resulted in 15 arrests and searches at eight Tirana locations. Takedown of online investment fraud in Albania: 15 arrestsEurojust – March 2022 — Verified primary source. In December 2022, Italian and Albanian authorities disrupted another Tirana-based operation associated with approximately EUR 15 million in losses. The documented workflow included virtual telephone numbers, delocalized VPNs, fabricated trading opportunities, small initial returns designed to build trust, remote-access software used to reach victims’ home-banking interfaces, cryptocurrency narratives and a second-stage “recovery” fraud targeting people who had already recognized the initial deception. Authorities seized more than 160 electronic devices and approximately EUR 3 million in assets, including eleven properties. Takedown of online investment fraud responsible for losses of EUR 15 millionEurojust – December 2022 — Verified primary source. The importance of these cases lies not only in their monetary scale but in the sequencing of specialized functions: traffic acquisition, telephony, scripted persuasion, platform simulation, remote technical intervention, payment extraction, asset conversion and victim re-targeting. Each function can be performed by a different actor and procured independently. A location-based call centre therefore becomes a production facility inside a geographically dispersed system, comparable to a contract manufacturer that receives leads and software from upstream providers, processes victims through a standardized funnel and passes proceeds to downstream financial specialists. This model is remotely scalable because the campaign’s intellectual property—scripts, victim profiles, fake interfaces, conversion tactics and account-routing rules—can be duplicated across offices without transferring the entire organization.

Table 2 — Verified Balkan operational indicators

DateExposed configurationVerified scaleModular-production indicatorEvidentiary limitation
March 2022Albanian call-centre companies operating “BrokerZ” and “Globalix”15 arrests; eight Tirana locations searchedPlatforms, call-centre labour, foreign-language targeting and cross-border victimsPublic record does not identify every upstream platform or beneficial owner
November 2022Call-centre network spanning Albania, Georgia, Ukraine and North Macedonia15 centres searched; hundreds of thousands of estimated victims; approximately EUR 50 million per quarter in estimated damageReplicable centres connected to hundreds of platforms and centralized social-engineering methodsPhysical dispersion does not establish where strategic command resided
December 2022Tirana call centre targeting Italian victimsApproximately EUR 15 million damage; EUR 3 million in assets seizedVirtual numbers, VPNs, remote-access software, cryptocurrency and recovery fraudCase proves an integrated fraud chain, not ransomware capability
January–February 2023Serbian call centres, Bulgarian technical infrastructure and alleged Cypriot laundering baseMore than 250 workplaces; 15 initial arrests, followed by 16 further Serbian arrestsCross-border functional specialisation between sales, infrastructure and liquidityNational location of functions cannot be equated with ownership
April 2026Multiple Tirana call centres organized by language and managerial tier10 arrests; nearly EUR 900,000 seized; estimated losses exceeding EUR 50 millionTeams of six to eight, team leaders, centre managers and multilingual market segmentationAllegations and damage estimates remain subject to judicial determination

The November 2022 operation provides the clearest evidence that the production model had already moved beyond isolated call-centre fraud. Eurojust reported searches of 15 call centres—six in Albania, five in Georgia, three in Ukraine and one in North Macedonia—together with 27 additional locations. Investigators described dozens of call centres, hundreds of online platforms, victims numbering in the hundreds of thousands and estimated damage of EUR 50 million per quarter, with fraudulent activity dating to at least 2016. Seizures included more than 500 electronic devices, cryptocurrency wallets, bank cards, identity documents, cash and bank accounts. Eurojust coordinates action against massive investment fraud with hundreds of thousands of victims worldwideEurojust – November 2022 — Verified primary source. In January 2023, a separate case exposed a more explicit division of labour: the organised network allegedly operated call centres from Serbia, used technological infrastructure in Bulgaria and used Cyprus as a base for laundering proceeds. Authorities identified more than 250 workplaces, arrested fourteen people in Serbia and one in Germany during the initial action, interviewed more than 250 people and seized over 150 computers, cash and approximately USD 1 million in cryptocurrencies. A second action produced another sixteen Serbian arrests for alleged computer fraud, money laundering and criminal association. Takedown of fraudulent cryptocurrency network in Bulgaria, Cyprus and SerbiaEurojust – January 2023, updated February 2023 — Verified primary source. This is the closest documented approximation to modular criminal manufacturing: Serbia supplied an operator-intensive victim-conversion layer, Bulgaria hosted a technical layer and Cyprus allegedly supplied part of the financial-conversion layer. The network’s market was not any of those territories; victims were reported in Germany, Switzerland, Austria, Australia and Canada. Its operational geography was determined by the cost, availability and risk profile of each function.

The criminal service stack

A remotely scalable criminal network should be analysed as a service stack rather than as a single “group.” At the acquisition layer, actors purchase advertisements, search-engine placement, compromised social accounts, leaked customer lists, telephone-number databases or credentials harvested by infostealers. At the engagement layer, multilingual operators establish trust through calls, messaging, email or fabricated professional profiles. At the technical layer, vendors provide phishing kits, cloned investment interfaces, remote-administration software, domain registration, hosting, proxy capacity, anonymized communications or access to compromised systems. At the transaction layer, nominees, money mules, payment institutions, crypto brokers and exchange accounts receive and fragment payments. At the concealment layer, proceeds move through rapid transfers, virtual assets, corporate accounts, cash withdrawal, trade transactions or professional laundering services. At the re-exploitation layer, victim data becomes a reusable asset for recovery fraud, impersonation, account takeover or sale to another network. FATF reports that 156 jurisdictions, representing 90% of the jurisdictions assessed, identify fraud as a major money-laundering risk; it further finds that large cyber-enabled fraud schemes increasingly incorporate laundering architecture from the outset through nominee accounts, mule networks, traded bank and exchange accounts, fintech platforms and rapid movement into virtual assets. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF RisksFinancial Action Task Force – February 2026 — Verified primary source. The strategic implication is that liquidity architecture is not a back-office activity added after the fraud succeeds; it is a gating dependency designed before victim contact begins. A campaign with superior persuasion but insufficient account capacity cannot scale because receiving accounts are frozen, flagged or saturated. Conversely, a network that possesses resilient money-mule recruitment, multiple payment channels and rapid cross-border conversion can purchase the remaining components from service markets.

Industrialised Scam Lifecycle

Interactive Operational Architecture

01

Victim Acquisition

  • Malvertising / cloned sites / compromised accounts
  • Purchased leads / stolen identities / credentials
02

Engagement & Conversion

  • Multilingual call-centre operators
  • Email impersonation / BEC / messaging
  • AI-assisted scripts, translation and voice synthesis
03

Technical Enablement

  • Domains / hosting / VPNs / proxies
  • Phishing kits / remote-access tools / infostealers
  • Fake trading dashboards / access brokerage
04

Payment Extraction

  • Bank transfers / cards / fintech rails
  • Cryptocurrency / exchange accounts
  • Money mules / nominee companies
05

Layering & Monetisation

  • Rapid dispersal / wallet chains / cash withdrawal
  • Money-laundering-as-a-service
  • Property, luxury assets or business integration
06

Data Recirculation

  • Recovery fraud / repeat targeting / resale / account takeover

Why physical criminal capital remains valuable

The modular model does not abolish the advantages accumulated by traditional organised crime; it converts some of them into services. A territorial organisation may already possess corrupt facilitation, access to nominee directors, cash-intensive businesses, forged or fraudulently obtained documents, trusted diaspora contacts, coercive debt collection and established methods for moving value across borders. These assets can support a cyber-enabled enterprise even when the organisation cannot develop malware. Existing laundering relationships can process fraud proceeds; recruitment networks can supply operators and mules; corrupt access can reduce inspection risk; physical businesses can disguise payroll, office leases or transaction flows; and coercive capacity can discipline insiders who control valuable accounts. Yet the evidence does not support the assumption that every Balkan call-centre network is an offshoot of a narcotics clan. The more probable architecture is selective convergence: digital-native organisers purchase particular capabilities from actors who also serve drug traffickers, smugglers, tax fraudsters or sanctions evaders. INTERPOL finds that crime convergence frequently occurs around financial fraud and that organised fraud actors appear to exchange experience and collaborate to optimize opportunities, while explicitly acknowledging the continuing intelligence gap concerning how fraud is organized. INTERPOL Global Financial Fraud AssessmentINTERPOL – March 2024 — Verified primary source. This supports a “shared infrastructure” hypothesis more strongly than a universal transformation hypothesis. The relevant intelligence object is therefore not only the named criminal group but the broker connecting multiple revenue systems: the accountant servicing several illicit markets, the company-formation intermediary supplying nominee structures, the operator recruiting mule accounts, the administrator controlling several fraud brands, or the technical contractor able to transfer compromised access between ransomware affiliates and financial-fraud teams.

Table 3 — Conversion of territorial assets into digital services

Legacy capabilityDigitally exportable derivativePotential customersObservable indicators
Corrupt administrative accessIdentity, registration or enforcement protectionFraud networks, mule managers, laundering brokersRepeated use of common addresses, officials, registrars or facilitators
Diaspora relationshipsMultilingual targeting and foreign account recruitmentCall centres, BEC teams, recovery-fraud unitsCountry-specific scripts, foreign bank accounts, repeated remittance corridors
Cash-intensive businessesCash-out and commingling capacityCrypto fraud, BEC and payment fraudRevenue inconsistent with activity; rapid settlement followed by cash withdrawal
Document fraudNominee identities and account-opening packagesMule networks, shell-company brokersRecycled identity elements, device overlap, common introducers
Smuggling logisticsMovement of devices, cash, SIMs and personnelInfrastructure vendors and financial cellsRecurrent travel and courier links around action dates
Coercive enforcementControl of recruited mules or insidersAccount managers and laundering providersThreats, debt bondage, document retention or unexplained personnel control
Property investmentStorage of illicit valueLaundering networksAcquisitions inconsistent with declared income and rapid ownership changes
Territorial reputationTrust guarantee for illicit contractingService brokers and affiliatesRepeated partnerships despite nominal corporate or brand changes

Scalability economics: marginal cost, specialization and churn

The economic advantage of modularity lies in declining marginal victim-acquisition costs and the transfer of failure risk to replaceable components. A conventional fraud enterprise that owns every stage must recruit programmers, purchase infrastructure, generate leads, train operators, establish receiving accounts and launder proceeds before it can begin. A service-based enterprise substitutes variable costs for fixed costs: it rents infrastructure per campaign, purchases leads per record, compensates operators by salary or conversion rate, pays affiliates a revenue share and uses laundering services priced as a percentage of processed proceeds. This resembles a platform economy because coordinators do not need to employ all participants; they orchestrate standardized interfaces between suppliers. Standardization can take the form of lead formats, scripted objection-handling, account-opening packages, wallet instructions, victim-status fields, customer-relationship-management software or commission schedules. The public evidence from Tirana in 2026—teams organized by language, groups of six to eight operators, team leaders and centre-level management—shows that fraud production can adopt ordinary corporate control structures. Eurojust estimated losses above EUR 50 million, reported 10 arrests and noted seizures approaching EUR 900,000. Fraud call centres targeting EU citizens shut down with Eurojust’s support – over EUR 50 million in damages uncoveredEurojust – April 2026 — Verified primary source. Such structures create performance data: calls completed, deposits generated, repeat deposits, conversion by language, operator productivity and victim lifetime value. Generative AI can increase throughput by producing localized scripts, summarizing victim interactions, translating messages and personalizing follow-up; nevertheless, human persuasion remains valuable where targets must be kept engaged through repeated transfers. The most likely five-year trajectory is therefore not “AI replaces the call centre,” but “AI converts each operator into a multilingual, data-assisted portfolio manager while automating low-value contact.”

Table 4 — Criminal-production cost structure through 2031

Cost or constraintCurrent modular solutionLikely 2027–2031 developmentRisk effect
Malware developmentRental, leaked builders, affiliate accessMore specialized brokerage and disposable toolingLower technical entry barrier
Language capabilityNative-speaking operators and translation toolsAI-assisted multilingual engagement and synthetic voiceLarger addressable victim market
Lead generationStolen databases and malicious advertisingAutomated profiling and cross-platform enrichmentHigher conversion efficiency
InfrastructureCloud accounts, proxies, domains and VPNsFaster automated replacement and multi-provider redundancyShorter recovery after takedowns
Banking accessMules, nominees and corporate accountsAccount marketplaces and orchestrated mule portfoliosGreater payment throughput but stronger detection signatures
Cryptocurrency conversionExchanges, brokers and unhosted walletsStable-value virtual assets and rapid chain switchingFaster international value movement
Trust-buildingScripted calls and fake dashboardsAI-personalized narratives and persistent synthetic identitiesLonger victim engagement
Operational securityCompartmentalisation and encrypted messagingAutomated credential rotation and role-based accessReduced exposure from individual arrests
Quality controlTeam leaders and manual supervisionAnalytics-driven operator scoring and script optimizationMore professionalized fraud operations
Brand continuityPersistent platform namesDisposable brands with reusable back-end componentsPublic blacklists lose value more quickly

Liquidity is the decisive shadow infrastructure

The “shadow” dimension that most directly determines whether Balkan-based fraud nodes can become durable export platforms is liquidity. Stolen funds are vulnerable during the interval between victim payment and irreversible conversion; banks, exchanges and law-enforcement agencies can freeze transfers if they receive sufficiently rapid information. Service networks respond by pre-positioning account inventories, distributing transfers among multiple mules, using nominee companies, initiating immediate onward transfers and converting fiat balances into virtual assets. FATF emphasizes that instant payments, cross-border channels and virtual assets can move proceeds before detection, while jurisdictional and procedural constraints slow investigators; it consequently calls for rapid payment-suspension and freezing mechanisms, payment transparency, regulation of virtual-asset service providers and stronger public-private information sharing. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF RisksFinancial Action Task Force – February 2026 — Verified primary source. Operational evidence demonstrates what scale requires: INTERPOL’s HAECHI VI operation, conducted across 40 countries and territories between April and August 2025, blocked more than 68,000 bank accounts, froze nearly 400 cryptocurrency wallets and recovered USD 439 million in government-backed currency, physical assets and virtual assets. The targeted offences included investment fraud, voice phishing, BEC, e-commerce fraud and associated money laundering. USD 439 million recovered in global financial crime operationINTERPOL – September 2025 — Verified primary source. These are global figures and cannot be assigned to Balkan actors, but they demonstrate that industrialized fraud depends upon extremely large inventories of financial endpoints. The critical intelligence indicators are therefore account-creation velocity, shared devices or network addresses across ostensibly unrelated accounts, clusters of low-balance inbound transfers followed by rapid consolidation, recurring conversion at particular exchanges and repeated links between call-centre employment networks and mule recruitment.

BEC, fraud and ransomware do not mature at the same speed

The transition pathway differs materially across BEC, online investment fraud and ransomware. Online investment fraud is labour-intensive but technically accessible: the network must create plausible websites, attract leads, operate persuasive communications and manage payments, yet it can procure most technology commercially or through criminal service providers. BEC requires better access intelligence because success depends upon identifying business relationships, compromising or imitating communications, understanding transaction timing and rerouting a payment without triggering verification. It therefore rewards collaboration between credential suppliers, initial-access specialists, corporate reconnaissance teams, impersonators and money-mule controllers. Ransomware requires still greater operational coordination: initial access, privilege escalation, lateral movement, data discovery, exfiltration, defensive evasion, encryption or destructive capability, negotiation, leak infrastructure and cryptocurrency settlement. Europol’s 2026 assessment nevertheless indicates that ransomware is moving away from encryption as the indispensable centre of coercion toward pressure based on stolen-data disclosure, which could lower the technical threshold for some affiliates. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. The most plausible five-year Balkan trajectory is therefore asymmetric: rapid expansion in multilingual fraud operations and payment-support services; moderate growth in credential brokerage, BEC and initial-access activity; selective participation in ransomware affiliate ecosystems; and a lower probability of an internationally dominant, publicly identifiable ransomware platform being strategically controlled from the Western Balkans. This ordering reflects capability requirements, not moral or national characteristics. It also implies that enforcement success against visible call centres may displace activity upward in technical sophistication: coordinators can retain victim acquisition, data management and payment orchestration while distributing human operators across remote-work arrangements, smaller offices or nominally legitimate outsourcing firms.

Table 5 — Relative maturity and five-year outlook

VectorPresent evidentiary strength in Balkan casesModular barriers2031 directionAnalytical confidence
Online investment fraudHighLead supply, multilingual conversion and liquidityFurther professionalisation and geographic dispersionHigh
Recovery fraudHigh in documented Albanian caseAccess to prior-victim data and credible impersonationAutomated re-targeting and fraud-chain extensionHigh
Telecom-enabled impersonationModerate-to-highNumber infrastructure and scriptsAI-assisted voice and language expansionHigh
BECModerate contextual evidence; limited public Balkan attributionCredentials, transaction intelligence and mule capacityGrowth through purchased access and specialized cellsModerate
Credential brokerageIndirect but structurally necessaryInfostealer feeds and resale channelsIncreasing integration with BEC and account takeoverModerate
Initial-access brokerageLimited public Balkan-specific evidenceTechnical skill and access reputationSelective participation in external ecosystemsLow-to-moderate
Ransomware affiliationLimited public Balkan-specific evidenceIntrusion capability, operational security and negotiationIncremental affiliate participationLow-to-moderate
Balkan-controlled global RaaS brandInsufficient public evidenceDevelopment, affiliate governance and resilient infrastructurePossible but not baselineLow
Laundering-as-a-serviceStrong structural relevance; case-specific indicatorsAccount inventory, conversion access and trusted counterpartiesCentral growth constraint and intervention pointModerate-to-high

Competing hypotheses and Bayesian update

The Analysis of Competing Hypotheses must preserve at least five explanations because the observable evidence is compatible with several organisational realities. H₁, direct conversion, proposes that established territorial groups are deliberately building internal cyber divisions; it predicts shared leadership, common laundering infrastructure, overlapping corporate ownership and movement of personnel between physical trafficking and cyber operations. H₂, parallel emergence, treats the principal actors as digitally native fraud entrepreneurs who exploit regional labour and governance conditions but remain organisationally separate from traditional groups; it predicts younger technical leadership, call-centre and marketing backgrounds, limited violent enforcement and distinct financial networks. H₃, outsourced-node integration, proposes that Balkan facilities provide sales, infrastructure or financial services to coordinators located elsewhere; it predicts foreign victim markets, distributed technical dependencies, upstream lead suppliers and incomplete local visibility into control. H₄, commercial capture or dual use, proposes that legal call centres, marketing firms, payment companies or IT businesses are partially repurposed; it predicts mixed legitimate and fraudulent activity, formal employment structures and rapid movement between corporate identities. H₅, shared-enabler convergence, proposes that physical and digital criminal markets intersect mainly through brokers, document suppliers, money launderers, corrupt facilitators and coercive intermediaries rather than common command. H₆, attribution distortion, proposes that enforcement geography exaggerates Balkan control because visible operators are easier to locate than remote administrators, lead generators or financial beneficiaries. The 2022–2026 case evidence raises the posterior probability of H₃, H₄ and H₅, moderately supports H₂, and provides only partial support for H₁. H₆ remains a mandatory caution rather than a mutually exclusive explanation. The Bayesian distribution below represents structured analytic judgment, not measured prevalence.

Table 6 — Provisional Bayesian assessment

HypothesisPriorEvidence updatePosteriorKey confirmation indicatorsKey disconfirmation indicators
H₁ — Traditional OCG conversion22%Some transferable assets, but limited public command-overlap evidence14%Shared leaders, assets, facilitators and proceeds across physical and cyber casesSeparate personnel, finances and governance
H₂ — Digital-native emergence24%Professional call-centre and platform structures support independent entrepreneurship23%Technical or commercial founders without prior territorial-crime linksPersistent control by established clans
H₃ — Outsourced Balkan production nodes22%Strong cross-border division of labour and foreign victim targeting29%Foreign upstream suppliers, campaign managers and lead sourcesEnd-to-end local control of platforms and proceeds
H₄ — Commercial capture or dual use14%Corporate-style management and formal workplaces increase plausibility15%Mixed legitimate activity, reused corporate entities and ordinary labour recruitmentEntirely clandestine infrastructure
H₅ — Shared-enabler convergence12%Liquidity and facilitation needs strongly support cross-market service providers15%Common accountants, mule managers, document suppliers or laundering brokersFully isolated financial networks
H₆ — Attribution distortion6%Distributed infrastructure and replaceable brands keep this warning active4% as primary explanationLocal operators lack strategic knowledge or profit participationClear locally centralized command

Enforcement asymmetry and geopolitical exposure

Modularity creates an asymmetry between criminals operating in real time and authorities operating through legally bounded jurisdictions. A platform can replace a domain, change a wallet, rotate credentials or move an operator account within hours; obtaining subscriber, traffic, content and payment evidence may require preservation requests, judicial authorization, provider cooperation and cross-border execution. The EU e-evidence framework is designed to reduce part of this delay: production orders can require a represented service provider in another EU Member State to respond within 10 days, or within six hours in an emergency, while preservation orders are intended to prevent deletion during processing. Better access to e-evidence to fight crimeCouncil of the European Union – January 2023 — Verified primary source. Western Balkan participation remains uneven because not every jurisdiction has identical institutional resources, acquis alignment or treaty implementation. The European Commission reported that Albania had adopted a National Cybersecurity Strategy for 2025–2030 but still needed stronger capacity, training and implementing legislation. Albania Report 2025European Commission – November 2025 — Verified primary source. It reported that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and had made no progress during the reporting period on the cited cybercrime-alignment matter. North Macedonia 2025 ReportEuropean Commission – November 2025 — Verified primary source. These deficiencies should not be transformed into claims of criminal complicity; their analytical significance is that gaps in evidence acquisition, specialist staffing, asset tracing and provider response can create exploitable latency. Over five years, EU accession conditionality and operational integration will tighten this environment, but displacement toward non-EU infrastructure, encrypted platforms and smaller distributed teams is likely.

China, Russia and the emerging cyber-norm conflict

The multilingual cross-check reveals an important geopolitical divergence. China’s official legal framework defines telecom and online fraud as remotely conducted, non-contact property fraud and extends liability to overseas organisations or individuals that target entities in China or provide products, services or assistance to such fraud. It assigns risk-control duties to telecommunications operators, banks, non-bank payment institutions and internet providers; it also calls for cross-industry coordination, account restrictions, investigation of abused personal data and international cooperation on evidence, arrests, proceeds and victim recovery. Anti-Telecom and Online Fraud Law of the People’s Republic of ChinaMinistry of Justice of the People’s Republic of China – December 2023 — Verified primary source. The Chinese model is relevant to the Balkan problem because it regulates the service stack rather than only the final fraudster: telecommunications, financial institutions, internet services, account holders and assistance providers become intervention points. The EU model is more constrained by distributed sovereignty, judicial safeguards and cross-border mutual recognition, but its e-evidence regime similarly acknowledges that provider-held data is often more operationally important than the offender’s physical location. Russian-language official-source searches conducted for this section did not yield a live, sufficiently specific primary document establishing Balkan–Russian command relationships in the examined fraud cases; no such relationship is therefore asserted. This omission is analytically consequential. Europol warns that hybrid-threat actors increasingly use cybercriminal networks as proxies for disruptive activity, yet a general proxy trend cannot be converted into an allegation that documented Balkan call centres serve any particular state. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. Through 2031, the higher-probability geopolitical risk is opportunistic overlap: access brokers, hosting providers, credential sellers or laundering services may serve financially motivated and state-aligned customers without the operational cells sharing ideology or command.

Monte Carlo outlook, 2027–2031

The five-year forecast uses a structured Monte Carlo model rather than a linear extrapolation from arrests. The model treats six uncertain drivers as probability distributions: availability of CaaS components; effectiveness of AI-assisted social engineering; multilingual labour and remote recruitment; laundering liquidity; cross-border enforcement intensity; and electronic-evidence effectiveness. Each iteration varies the drivers within bounded ranges and classifies the resulting system into one of four futures. “Platformised modularity” means a small number of coordinators integrate numerous replaceable service vendors and operator teams. “Fragmented expansion” means many short-lived cells use common tools without durable platforms. “Hybrid convergence” means financially motivated infrastructure is repeatedly shared with physical organised crime or state-aligned proxy activity. “Effective containment” means payment interruption, evidence access, provider controls and asset recovery raise costs faster than automation lowers them. The baseline 100,000-iteration specification produces 44% platformised modularity, 29% fragmented expansion, 18% hybrid convergence and 9% effective containment. These probabilities are analytical outputs, not observed frequencies. The central estimate places the 2031 modular-service risk index at 71/100, with an 80% model interval of 59–82. The index is highest for online investment fraud and recovery fraud, intermediate for BEC and access brokerage, and lowest for a Balkan-controlled global ransomware platform. The main upside risk is simultaneous growth in AI-enabled victim conversion and mule-account liquidity; the main downside risk is coordinated payment suspension combined with rapid preservation of provider data and systematic confiscation. Because the model is dependency-sensitive, removing liquidity capacity reduces expected criminal output more sharply than closing any single call centre: premises can be replaced, but a trusted, high-throughput financial conversion network is difficult to regenerate without generating detectable account linkages.

Table 7 — Five-year scenario matrix

ScenarioBaseline probability2031 operating formPrincipal warning indicatorsMost effective disruption
Platformised modularity44%Coordinators orchestrate leads, operators, tools and liquidity through standardized interfacesShared CRM schemas, recurring infrastructure vendors, common wallet or account brokersDependency mapping, provider cooperation and financial-network disruption
Fragmented expansion29%Numerous disposable cells use commercial and criminal toolsRapid brand churn, small offices, remote operators and repeated scriptsAutomated domain, payment and identity correlation
Hybrid convergence18%Shared enablers connect cyber fraud, laundering, trafficking and occasional proxy activityCommon facilitators, infrastructure or proceeds across crime typesMulti-crime financial investigations and broker targeting
Effective containment9%Fraud persists but scaling and monetisation become less reliableFaster freezes, falling account longevity and rising asset recoveryPreserve coordinated regulatory, judicial and private-sector pressure

Indicators that distinguish transition from mere technology adoption

A genuine transition from territorial enterprise to remotely scalable criminal production should be declared only when multiple indicators appear across organisational, technical and financial layers. A single encrypted telephone, cryptocurrency wallet or phishing page proves technology use, not modular production. Stronger evidence includes repeated procurement from external service vendors; separation between campaign ownership and operator employment; common back-end systems supporting multiple public brands; commission-based affiliates; geographically dispersed call-centre or remote-work teams using shared scripts and lead formats; large inventories of receiving accounts; specialized laundering brokers; systematic recycling of victim data; and rapid regeneration after arrests or domain seizures. Investigators should track six distinct identities for every operation: legal-company identity, infrastructure identity, campaign identity, operator identity, financial identity and beneficial-control identity. If those identities recur in different combinations, the network is modular. If they remain bound to the same leadership, location and financial chain, it is closer to a conventional organisation using digital tools. The April 2026 Tirana case supplies evidence of managerial segmentation and language-based production, while the Serbia–Bulgaria–Cyprus case supplies evidence of cross-border functional specialization; neither alone resolves beneficial control. The critical collection priorities for 2027–2031 are therefore upstream lead provenance, administrator access logs, CRM exports, shared device identifiers, employment and payroll records, payment routing, wallet ownership, company-service providers and relationships between seized infrastructure and unrelated fraud brands. This framework avoids two symmetric errors: underestimating a service network because its visible operators appear low-level, and overstating Balkan strategic control because a raid occurred in a Balkan capital. The intelligence objective is not to count offices but to reconstruct the dependency graph that allows those offices to produce criminal revenue.

Table 8 — Priority intelligence requirements

Priority intelligence requirementRequired evidenceDiagnostic value
Who owns victim acquisition?Advertising accounts, lead purchases, referral codes and dataset provenanceSeparates upstream coordinators from local sales nodes
Who administers campaign systems?Authentication logs, administrator devices, recovery emails and hosting paymentsIdentifies technical control
Who sets performance targets?CRM fields, operator dashboards, commission schedules and internal messagesReveals production governance
Who controls liquidity?Beneficial ownership, mule recruitment, transaction chains and exchange recordsIdentifies the monetisation centre
Which components are reusable?Shared code, templates, scripts, domains, wallets and identity artefactsMeasures modularity and regeneration capacity
Are physical and cyber markets converging?Common facilitators, properties, companies and financial endpointsTests H₁ and H₅
Is a foreign coordinator directing local nodes?Remote logins, payment instructions, supplier contracts and command communicationsTests H₃
Are legitimate firms being repurposed?Mixed revenue, employment records, customer lists and dual accountingTests H₄
How quickly can the network regenerate?Time from disruption to new domains, accounts, brands and operator activityMeasures resilience
Is there state-aligned tasking?Target selection, non-financial objectives, infrastructure reuse and authenticated command linksDistinguishes criminal opportunism from proxy activity
Figure 1: Five-Year Risk Scenario Projection
Balkan Modular Criminal-Service Outlook, 2027–2031
Interactive structured forecast. Values are model outputs, not observed crime counts.
02040 6080100 202720282029 20302031
44%
Platformised
29%
Fragmented
18%
Hybrid
9%
Contained

Ransomware, BEC and Industrialised Online Fraud

Three markets, three production logics

Ransomware, business email compromise and industrialised online fraud are frequently grouped under “cybercrime,” yet they constitute different criminal production systems with sharply different entry barriers, labour requirements, victim-selection processes, monetisation cycles and infrastructure dependencies. Ransomware is principally an intrusion-and-extortion business: the operator must acquire unauthorized access, preserve that access, understand the target environment, escalate privileges, identify valuable systems or data, evade detection, create coercive leverage and negotiate payment. BEC is an intelligence-and-payment-diversion business: the decisive asset is not malware but credible knowledge of an organisation’s personnel, authority relationships, invoices, suppliers and transaction timing. Industrialised online fraud is a customer-acquisition and psychological-conversion business: the network generates or purchases leads, places victims inside a fabricated commercial narrative, sustains engagement and repeatedly extracts funds. The three systems increasingly share upstream commodities—credentials, personal data, compromised accounts, proxy infrastructure, synthetic identities—and downstream services such as mule accounts, cryptocurrency conversion and laundering. This convergence does not make their operational maturity identical. ENISA’s review of nearly 4,900 selected incidents between July 2024 and June 2025 found that ransomware remained central to intrusion activity while operators reacted to enforcement by decentralising, intensifying extortion and using ransomware-as-a-service, leaked builders and access brokers to lower entry barriers. ENISA Threat Landscape 2025European Union Agency for Cybersecurity – October 2025, revised January 2026 — Verified primary source. Europol separately assessed that data had become the central commodity of the cybercrime economy and that unauthorised access, stolen information and criminal data markets provide reusable inputs for several offence types. Steal, Deal and Repeat: How Cybercriminals Trade and Exploit Your DataEuropol – June 2025 — Verified primary source.

Table 1 — Comparative criminal-production maturity

DimensionRansomwareBECIndustrialised online fraud
Core businessIntrusion, data theft, disruption and extortionManipulation of trusted commercial communicationsRepeated psychological conversion of individuals
Principal victimOrganisations with operational or data dependencyBusinesses making substantial authorized paymentsIndividuals, investors and selected consumer segments
Primary commodityPrivileged network accessTransactional context plus trusted communication accessLeads, personal data, attention and victim confidence
Technical thresholdHigh end-to-end; moderate for an affiliate buying accessModerate; high intelligence precisionLow-to-moderate technical threshold; high sales-management requirement
Labour modelDevelopers, brokers, intruders, operators and negotiatorsReconnaissance, account access, impersonation and mule managementMarketing, call-centre operators, team leaders, platform administrators and payment cells
Campaign durationDays to months after access; longer reconnaissance possibleOften synchronized with a specific transaction windowWeeks or months per victim; continuous lead processing
Revenue distributionAffiliate and platform revenue sharesConcentrated proceeds divided among access, deception and laundering cellsSalaries, commissions, managerial shares and laundering fees
Main scaling constraintReliable access and skilled intrusion capacityHigh-value transaction visibility and receiving-account qualityLead flow, operator productivity, account inventory and payment throughput
Principal evidenceEndpoint, network, malware, server and wallet artefactsEmail logs, authentication, invoice and bank recordsCRM records, call data, advertisements, platforms and transaction chains
Balkan public evidenceLimited for strategic control of global RaaS brandsFragmentary and often financial-support relatedStrongest documented regional maturity
Five-year regional directionSelective affiliate and access-broker participationMaterial growth potentialHighest-probability expansion vector

Ransomware: the most technically demanding ecosystem

A mature ransomware operation resembles a distributed technology platform rather than a single hacking group. At the platform layer, developers maintain encryptors, data-exfiltration utilities, affiliate-management systems, negotiation portals and leak infrastructure. At the access layer, brokers or affiliates identify exposed services, compromised credentials, vulnerable edge devices or pre-existing malware infections. At the intrusion layer, operators must validate the target, establish persistence, escalate privileges, disable or circumvent defensive controls and map critical systems. At the coercion layer, the network exfiltrates sensitive information, encrypts systems, threatens publication or combines these techniques with pressure against customers, partners or regulators. At the monetisation layer, negotiators assess the victim’s capacity and willingness to pay while financial specialists manage cryptocurrency addresses and distribute shares. This structure explains why ransomware can be modular without becoming technically simple. Purchasing access eliminates only the first constraint; a poorly managed affiliate can lose access, trigger detection, damage systems before leverage is established or select a victim unable to pay. Europol observed more than 120 active ransomware brands during 2025 and found that the extortion model continued to shift from encryption toward threats to publish stolen data. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. The FBI received more than 3,600 ransomware complaints in 2025 and identified 63 newly reported variants, an average of 5.25 per month; the top variants most heavily affected critical manufacturing, healthcare and public health, and government facilities. The FBI explicitly cautions that its reported loss total—more than USD 32 million—normally excludes lost business, wages, equipment, files and remediation, and therefore materially understates total economic harm. 2025 IC3 Annual ReportFederal Bureau of Investigation – April 2026 — Verified primary source.

Table 2 — Ransomware production chain and failure points

StageRequired capabilityPurchasable serviceRevenue relevancePrincipal disruption point
Target discoverySector and exposure intelligenceScanning and lead servicesDetermines addressable target poolVulnerability remediation and external attack-surface monitoring
Initial accessCredential or vulnerability exploitationInitial-access brokerage and malware deliveryEstablishes campaign inventoryCredential resets, MFA, patching and access-broker intelligence
PersistenceDurable control of systemsRemote-access toolingPreserves option valueEndpoint detection and authentication analytics
Privilege escalationAdministrative controlExploit or operator expertiseEnables enterprise-wide coercionPrivileged-access management and segmentation
ReconnaissanceIdentification of data and critical systemsSpecialist affiliate labourDetermines ransom leverageInternal monitoring and deceptive assets
ExfiltrationCovert transfer of valuable dataCriminal hosting and proxy servicesEnables non-encryption extortionEgress controls and abnormal-transfer detection
ImpactEncryption, interruption or destructionRaaS payload and builderCreates urgency and operational lossOffline recovery and network isolation
NegotiationVictim valuation and coercionNegotiator or affiliate panelInfluences payment probability and sizePrepared incident governance and law-enforcement contact
SettlementCryptocurrency reception and allocationWallet and laundering servicesConverts coercion into distributable revenueBlockchain analysis, exchange controls and seizure
Brand continuityReputation among affiliates and victimsLeak site and criminal communicationsAttracts affiliates and increases credibilityInfrastructure seizure, attribution and sanctions

LockBit demonstrates the economic reach and governance requirements of a mature RaaS platform. The United States Department of Justice reports that LockBit was deployed against more than 2,500 victims between approximately January 2020 and July 2024 and that victims paid more than USD 500 million in ransoms. LockBit Case SummaryUnited States Attorney’s Office, District of New Jersey – July 2024 — Verified primary source. Those figures illustrate platform economics: a central administrator does not need to conduct every intrusion if affiliates supply target access and operational labour while the platform supplies malware, infrastructure, reputation and settlement rules. The resulting organisation can scale internationally without scaling a single permanent workforce. Its weakness is the centrality required to coordinate affiliates. Law enforcement can target developer identities, affiliate panels, servers, decryption infrastructure, cryptocurrency flows and the trust relationship between the brand and its operators. In February 2024, an international action compromised LockBit’s primary platform and enabling infrastructure and produced arrests in Poland and Ukraine. Eurojust supports international operation against world’s largest ransomware groupEurojust – February 2024 — Verified primary source. The Balkan-specific assessment must remain conservative: the public primary-source record does not establish a Western Balkan-controlled equivalent of LockBit. The most plausible regional entry points through 2031 are narrower modules—credential acquisition, access brokerage, hosting, cryptocurrency conversion, affiliate participation and laundering—because each can connect technically capable individuals or facilitators to an externally administered ransomware economy without requiring the region to produce and govern an entire global platform.

BEC: low malware visibility, high transactional intelligence

BEC occupies the middle position between ransomware’s technical intensity and industrialised fraud’s labour-intensive persuasion. Its minimum viable operation can be relatively small, but successful high-value campaigns require accurate organisational intelligence. The attacker must know who can authorize a payment, who normally requests it, which supplier or executive can credibly be impersonated, when the transaction is expected, what language and formatting will appear routine and which receiving account can accept the funds without immediate rejection. Access can be obtained through compromised email credentials, forwarding rules, stolen browser sessions or information purchased from data brokers; however, account compromise is not always necessary if a convincing look-alike identity and external reconnaissance are sufficient. INTERPOL defines BEC as an increasingly prevalent impersonation fraud in which criminals compromise email accounts or impersonate executives and professional advisers to induce transfers into fraud-controlled accounts that are then rapidly laundered. INTERPOL Global Financial Fraud AssessmentINTERPOL – March 2024 — Verified primary source. The FBI recorded 24,768 BEC complaints and approximately USD 3.047 billion in reported BEC losses during 2025, compared with 3,611 ransomware complaints and approximately USD 32.3 million in directly reported ransomware losses. 2025 IC3 Annual ReportFederal Bureau of Investigation – April 2026 — Verified primary source. That comparison cannot be interpreted as a complete loss ranking because ransomware reporting excludes major indirect costs, but it does demonstrate BEC’s capacity to generate enormous direct financial losses without creating the visible operational disruption associated with encryption.

Table 3 — BEC maturity model

BEC maturity levelAccess conditionIntelligence qualityDeception methodMonetisation pathwayLikely scale
Level 1: external spoofingNo internal account accessPublicly available personnel dataGeneric executive or supplier impersonationSingle mule accountLow conversion, high volume
Level 2: targeted impersonationLimited reconnaissanceKnown executive, supplier or transaction roleCustomized invoice or payment requestPre-positioned corporate accountModerate
Level 3: account compromiseGenuine mailbox accessInternal messages and historical relationshipsAuthentic thread manipulationLayered receiving accountsHigh
Level 4: transaction interceptionPersistent accessLive visibility into payment timingAltered bank instructions inside a legitimate processRapid multi-account dispersalVery high
Level 5: ecosystem compromiseMultiple accounts or supplier accessVisibility across counterpartiesSimultaneous or repeated diversionsProfessional laundering networkPotentially systemic
Level 6: synthetic executive layerAccount access plus AI assistanceVoice, style and behavioural modellingEmail combined with synthetic audio or videoPre-arranged high-capacity accountsEmerging high-impact model

BEC’s most important constraint is not the quality of the fraudulent email but the survivability of the receiving account. A highly credible payment instruction has no economic value if the beneficiary account is blocked, mismatched, unable to receive the amount or immediately freezes the transfer. This produces a strong dependency on money mules, nominee companies, compromised business accounts and professional laundering services. The financial cell must understand transfer limits, confirmation practices, processing times and the speed with which funds can be redistributed. It must also manage a scarcity problem: accounts capable of accepting large corporate payments without automatic interruption are more valuable and more difficult to replace than ordinary consumer mule accounts. That characteristic makes BEC both scalable and fragile. One successful transfer may generate more revenue than thousands of low-value fraud calls, yet each event can expose high-quality accounts, beneficial owners, devices and transaction links. Global enforcement data show the size of the downstream infrastructure shared by BEC and other fraud types. INTERPOL’s HAECHI VI operation across 40 countries and territories blocked 68,000 bank accounts, recovered USD 439 million and targeted BEC alongside investment fraud, voice phishing, e-commerce fraud and related laundering. Global Financial Fraud Threat Assessment 2026INTERPOL – April 2026 — Verified primary source. The implication for Balkan criminal-service development is that the most valuable exportable BEC capability may not be message composition. It may be the provision of corporate receiving accounts, nominee structures, multilingual reconnaissance or rapid conversion channels connected to wider European financial markets.

Industrialised online fraud: the region’s most mature pathway

Industrialised investment and impersonation fraud presents the strongest documented evidence of Balkan-based production capacity because it aligns with the region’s demonstrated multilingual call-centre infrastructure and requires fewer rare technical skills than ransomware. The model combines commercial lead generation, standardized scripts, fabricated investment interfaces, operator supervision, customer segmentation and financial extraction. Its central production metric is victim conversion rather than system compromise. A victim can be introduced through malicious advertising, a cloned website, direct communication or an apparently legitimate investment platform; a low initial deposit tests willingness and creates psychological commitment; a fabricated dashboard or small apparent return reinforces trust; operators then increase the requested amount and use urgency, exclusivity or loss-recovery narratives to sustain payment. The system can continue even when its public brand is exposed because domains, company names and visible interfaces are disposable while scripts, leads, operator teams and financial relationships are reusable. Eurojust documented a network with call centres in Serbia, technical infrastructure in Bulgaria and an alleged laundering base in Cyprus. Authorities identified more than 250 workplaces, initially arrested fourteen people in Serbia and one in Germany, and later arrested sixteen additional suspects in Serbia. The network targeted victims in Germany, Switzerland, Austria, Australia and Canada. Takedown of fraudulent cryptocurrency network in Bulgaria, Cyprus and SerbiaEurojust – January 2023, updated February 2023 — Verified primary source. This case provides unusually clear evidence of cross-border functional specialization, but it does not prove that strategic command, technology ownership and ultimate beneficial control were Serbian, Bulgarian or Cypriot.

Table 4 — Industrialised fraud production architecture

Production unitCommercial analogueCriminal functionCore KPIIntelligence artefact
Advertising cellPerformance-marketing agencyGenerates victim trafficCost per leadAdvertising accounts, pixels and referral identifiers
Lead brokerData-list vendorSupplies contactable targetsLead validity and segmentationPurchased datasets and provenance records
Call-centre operatorSales representativeEstablishes trust and solicits depositsConversion rateCall recordings, scripts and CRM entries
Retention operatorAccount managerObtains repeat paymentsVictim lifetime valueFollow-up history and deposit sequence
Team leaderSales supervisorEnforces scripts and targetsRevenue per operatorDashboards, performance tables and internal messages
Platform administratorSaaS administratorMaintains fabricated victim interfacePlatform uptime and account engagementAdmin logs, hosting and code repositories
Payment cellTreasury departmentRoutes deposits into controlled channelsSuccessful receipt rateBank accounts, wallets and beneficiary instructions
Mule coordinatorExternal payroll or settlement serviceSupplies replaceable financial endpointsAccount longevity and throughputRecruitment records and device overlaps
Laundering brokerFinancial intermediaryConverts and distributes proceedsNet recovery after feesConsolidation wallets, shell companies and cash-out nodes
Recovery-fraud cellCustomer-retention unitRe-targets known victimsSecondary conversion ratePrior-victim lists and impersonated recovery identities

The largest verified cross-border case involving Balkan nodes illustrates how quickly this model can reach industrial scale. In November 2022, Eurojust supported action against a network using dozens of call centres and hundreds of online platforms; investigators estimated victims in the hundreds of thousands and damage of approximately EUR 50 million per quarter, with suspected activity extending back to at least 2016. Searches covered six call centres in Albania, five in Georgia, three in Ukraine and one in North Macedonia, while seizures included more than 500 electronic devices, bank accounts, cryptocurrency wallets, identity documents, bank cards, properties and cash. Eurojust coordinates action against massive investment fraud with hundreds of thousands of victims worldwideEurojust – November 2022 — Verified primary source. The operational significance is greater than the seizure total. Multiple centres can work from common lead sources and platform templates while targeting different linguistic markets. Customer-contact labour can be relocated without relocating platform administration; payment instructions can change without retraining operators; and the public brand can disappear while victim data remains commercially valuable. Unlike ransomware, which risks losing access before leverage is created, an industrialised fraud network can continuously process a portfolio of victims at different stages of engagement. Revenue is consequently smoothed across many interactions rather than concentrated in a smaller number of high-risk intrusions. This makes the model attractive to criminal entrepreneurs seeking scalable cash flow, even if its average payment is lower than a successful corporate ransom or BEC diversion.

Shared infrastructure and divergent monetisation

The three systems increasingly meet in the stolen-data and access economy. Infostealer logs can contain credentials, cookies, autofill information, cryptocurrency-wallet data and email access. The same compromised account may be monetized through direct theft, BEC, resale, ransomware access or identity fraud depending on the victim’s characteristics. Europol assesses that stolen data and unauthorized access have become commodified goods in the CaaS market and cautions that closed communication channels limit the portion of the ecosystem visible to law enforcement. Steal, Deal and Repeat: How Cybercriminals Trade and Exploit Your DataEuropol – June 2025 — Verified primary source. INTERPOL’s 2025 infostealer crackdown dismantled more than 20,000 malicious IP addresses and domains and notified over 216,000 victims and potential victims; INTERPOL explicitly linked stolen logs to ransomware deployment, data breaches and BEC. 20,000 malicious IPs and domains taken down in INTERPOL infostealer crackdownINTERPOL – June 2025 — Verified primary source. The convergence point is therefore a decision market: brokers classify compromised access according to expected value. An email account containing supplier invoices may be allocated to BEC; administrator credentials for a manufacturer may be sold to a ransomware affiliate; a consumer identity may enter investment, romance or recovery fraud; cryptocurrency credentials may be monetized directly. For Balkan criminal ecosystems, participation in this classification and brokerage layer would represent a more significant maturation than merely operating phishing pages, because the broker controls allocation between several downstream criminal markets and learns which access profiles command the highest price.

Table 5 — Monetisation comparison

MetricRansomwareBECIndustrialised online fraud
Revenue unitRansom or extortion settlementDiverted corporate paymentDeposit sequence across a victim portfolio
Payment frequencyLow frequency, potentially very high valueLow-to-moderate frequency, high valueHigh frequency, low-to-high cumulative value
Revenue latencyOften days or weeks after intrusionTied to a narrow transaction windowContinuous throughout victim engagement
Direct victim visibilityVery high after impactOften delayed until reconciliationHigh but manipulated through false interface
Dependence on cryptocurrencyCommon but not universalOptional; bank transfers frequently centralMixed bank, card, fintech and cryptocurrency pathways
Need for mule accountsModerateExtremely highHigh
Need for technical labourHighModerateLow-to-moderate
Need for persuasion labourNegotiation-focusedShort, precise impersonationExtensive and repeated
Reusability of victim dataModerateHigh for counterpart mappingVery high, including recovery fraud
Main loss concentrationOperational disruption plus data exposureDirect transfer lossRepeated personal financial depletion
Principal bottleneckIntrusion reliabilityTransaction intelligence and account qualityLead quality, operator productivity and liquidity
Fastest interventionAccess containmentTransfer recall and account freezeAdvertising interruption plus payment freeze

Liquidity pathways and profit allocation

Monetisation is the point at which otherwise distinct cybercrime models converge most visibly. Ransomware platforms commonly divide cryptocurrency receipts among affiliates, administrators and supporting specialists. BEC proceeds frequently enter corporate or mule accounts and must be redistributed before a victim, originating bank or beneficiary institution identifies the diversion. Industrialised fraud uses larger portfolios of bank accounts, payment processors and wallets because deposits arrive continuously from many victims and countries. Across all three models, gross proceeds can substantially exceed net criminal profit. Service fees, affiliate shares, operator wages, advertising expenditure, mule compensation, failed transfers, frozen balances and laundering discounts reduce realizable revenue. A high-volume network therefore optimizes not only victim conversion but “survival-adjusted yield”: the proportion of apparent proceeds that remains accessible after freezes, seizures, account theft, internal fraud and intermediary fees. FATF reports that cyber-enabled fraud increasingly integrates laundering mechanisms from the outset through nominee accounts, traded bank and exchange accounts, mule networks and rapid fintech transfers. It also notes that direct payment in virtual assets or rapid conversion from fiat can outpace recovery processes. Cyber-Enabled Fraud: Digitalisation and ML, TF and PF RisksFinancial Action Task Force – February 2026 — Verified primary source. This makes laundering capacity an upstream planning variable. A campaign should not be considered operationally mature merely because it can compromise systems or persuade victims. Maturity requires pre-positioned financial endpoints, transaction monitoring, fallback accounts, fast internal allocation and the ability to absorb account loss without halting production.

Table 6 — Shadow liquidity indicators

IndicatorRansomware relevanceBEC relevanceOnline-fraud relevanceAnalytical interpretation
Pre-positioned corporate accountsMediumCriticalHighIndicates planning before victim payment
Large portfolio of personal mulesLow-to-mediumHighCriticalSupports fragmentation and replacement
Cryptocurrency consolidationCriticalMediumHighIdentifies treasury or laundering aggregation
Immediate onward transfersHighCriticalCriticalMeasures response to freeze risk
Repeated exchange counterpartiesCriticalMediumHighMay identify trusted conversion services
Shell-company turnoverMediumCriticalHighSignals beneficiary replacement
Cross-border ATM withdrawalsLowMediumHighIndicates retail cash-out layer
Property acquisitionMediumMediumMedium-to-highPotential long-term value storage
Account-device reuseMediumHighCriticalConnects nominally separate mules
Shared introducers or directorsMediumCriticalHighIdentifies professional facilitation
Recovery-fraud paymentsMinimalLowHighDemonstrates recycling of victim data
Stable-value virtual assetsHighMediumHighReduces volatility during cross-border settlement

Bayesian maturity assessment for the Balkans

A comparative Bayesian assessment produces a different posterior for each crime type. For ransomware, H₁ holds that Balkan actors will create and control a globally significant RaaS platform; H₂ predicts participation mainly as affiliates; H₃ predicts specialization in access, infrastructure or data brokerage; H₄ predicts primary participation in laundering; H₅ predicts that visible regional artefacts will largely reflect transit or hosting rather than meaningful control. Current public evidence assigns the greatest weight to H₂ and H₃, with H₁ remaining low-confidence. For BEC, the hypotheses shift: H₁ predicts locally controlled end-to-end campaigns; H₂ predicts regional reconnaissance or language cells attached to foreign networks; H₃ predicts specialization in mule and corporate-account supply; H₄ predicts convergence with existing call-centre networks; H₅ predicts only incidental Balkan financial endpoints. H₃ and H₄ receive the strongest current weight because the region’s documented fraud infrastructure and cross-border financial facilitation are more relevant than evidence of a mature, indigenous BEC command structure. For industrialised online fraud, H₁ predicts durable Balkan-controlled platforms; H₂ predicts outsourced call-centre production; H₃ predicts mixed local and foreign ownership; H₄ predicts rapid displacement into remote-work structures; H₅ predicts effective containment through coordinated enforcement. Verified cases strongly support H₂ and H₃, while the repeated reappearance of Albanian, Serbian and other regional nodes raises H₄ through 2031. These distributions are structured judgments, not prevalence estimates.

Table 7 — Provisional posterior maturity distribution

Crime market and hypothesisPosteriorConfidenceEvidence required for major update
Ransomware: Balkan-controlled global RaaS platform8%LowDeveloper, administrator, affiliate-panel and treasury evidence
Ransomware: regional affiliate participation29%ModerateIntrusion telemetry and affiliate-account attribution
Ransomware: access or data brokerage31%ModerateMarketplace identities connected to regional operators
Ransomware: laundering specialization22%ModerateWallet, exchange and beneficial-owner convergence
Ransomware: incidental infrastructure only10%Low-to-moderateHosting without operator or financial linkage
BEC: end-to-end Balkan command17%Low-to-moderateCampaign control, mailbox access and treasury integration
BEC: foreign-directed regional cells23%ModerateCommand communications and revenue-sharing records
BEC: mule and account supply specialization31%Moderate-to-highAccount clusters, nominee companies and recruitment evidence
BEC: convergence with call-centre fraud22%ModerateCommon CRM, personnel, platforms or financial endpoints
BEC: incidental Balkan role7%LowIsolated account use without repeated network links
Online fraud: locally controlled platforms24%ModerateBeneficial ownership and administrator evidence
Online fraud: outsourced call-centre production28%HighAlready consistent with documented cases
Online fraud: mixed transnational ownership30%Moderate-to-highShared foreign and local command or treasury evidence
Online fraud: distributed remote-work transition14%ModerateDeclining premises concentration with stable campaign output
Online fraud: effective containment4%LowSustained decline in regeneration and financial throughput

Five-year outlook: maturity will rise unevenly

The 2027–2031 outlook is defined by unequal rates of automation. Industrialised fraud will automate lead enrichment, initial messaging, translation, call summarisation, script selection and victim prioritisation, but human operators will remain important for high-value trust manipulation. BEC will use AI to imitate writing style, generate multilingual communications and support synthetic voice confirmation, yet its success will continue to depend on access to genuine transaction context and high-capacity receiving accounts. Ransomware will benefit from improved reconnaissance, vulnerability analysis and negotiation support, but the most difficult intrusion tasks will remain less automatable than mass communication. Enforcement will push all three markets toward smaller brands, shorter infrastructure lifecycles and greater separation between public identity and reusable back-end systems. Operation Endgame demonstrates the strategic value of attacking upstream infrastructure: during May 2025, authorities reportedly dismantled approximately 300 servers, neutralised 650 domains and issued international arrest warrants against twenty targets associated with initial-access malware used to deliver ransomware and other payloads. Operation ENDGAME strikes again: the ransomware kill chain broken at its sourceEuropol – May 2025 — Verified primary source. The probable criminal response is redundancy rather than retreat: more providers, shorter contracts, compartmentalised access and faster brand replacement. For the Balkans, the baseline forecast assigns the highest 2031 maturity to industrialised fraud, a substantial increase to BEC-support services and selective growth in ransomware-adjacent modules rather than full-platform control.

Table 8 — Baseline 2031 maturity forecast

Capability2026 assessed maturity2031 baselineFive-year changePrimary driverPrincipal inhibitor
Multilingual online-fraud operations76/10088/100+12AI-assisted productivity and reusable scriptsRaids, recruitment visibility and payment freezes
Fraud-platform administration64/10079/100+15Disposable front ends and shared back endsHosting and administrator attribution
Recovery-fraud exploitation67/10084/100+17Reusable victim datasetsData seizure and victim notification
Mule-account coordination70/10082/100+12Cross-border recruitment and fintech accessTransaction analytics and rapid suspension
BEC reconnaissance48/10068/100+20Stolen data and AI-supported analysisStrong authentication and payment verification
BEC payment diversion45/10065/100+20Corporate-account and nominee accessConfirmation-of-payee and transfer recall
Credential and cookie brokerage47/10069/100+22Infostealer marketsEndpoint security and log disruption
Initial-access brokerage35/10055/100+20CaaS integrationReputation requirements and enforcement
Ransomware affiliate participation32/10052/100+20Purchased access and RaaS availabilityTechnical failure and operational attribution
Ransomware platform governance18/10029/100+11Imported expertise and modular toolingHigh coordination and trust requirements
Cryptocurrency laundering59/10072/100+13Cross-border settlement demandVASP regulation, tracing and seizure
Hybrid criminal–proxy services24/10039/100+15Shared access and infrastructure marketsAttribution pressure and sanctions

Strategic warning indicators

The most valuable warning indicators will measure cross-market migration rather than raw incident volume. If an investment-fraud network begins acquiring corporate mailbox credentials, it may be moving into BEC; if a credential broker starts selling privileged access to larger organisations, it may be supplying ransomware affiliates; if the same mule coordinators receive BEC proceeds, investment deposits and extortion-related cryptocurrency, a regional laundering service may be emerging as a systemic node. Investigators should therefore map reusable entities across crime classifications: devices, administrator accounts, corporate directors, call-centre managers, wallets, bank beneficiaries, hosting purchasers, domain registrants, payroll relationships and recruitment channels. Evidence of increasing maturity would include common authentication infrastructure across multiple fraud brands; operators shifting between investment fraud and executive impersonation; account portfolios segmented by transaction size; recurring exchanges or over-the-counter brokers; ransomware wallets linked to previously identified fraud treasuries; and remote administrative access from jurisdictions different from operator premises. Evidence against maturation would include continuously isolated cells, low infrastructure reuse, poor financial coordination, rapid payment recovery and the absence of shared facilitators. The analytical priority is not to label every overlap as a unified organisation. It is to determine whether an intermediary has become a platform: a provider whose removal would reduce output across several nominally independent ransomware, BEC and online-fraud networks. That distinction converts cybercrime investigation from case-by-case attribution into dependency analysis and offers the best prospect of imposing costs faster than criminal brands can regenerate.

Figure 1: Comparative Five-Year Maturity Projection
Ransomware, BEC and Industrialised Fraud, 2026–2031
Adjust the scenario assumptions. Scores are structured analytical indices, not incident counts.
02040 6080100 202620272028 202920302031
Ransomware ecosystem BEC ecosystem Industrialised fraud
52
2031 ransomware
68
2031 BEC
88
2031 fraud

Five-Year Scenarios, Indicators and Intervention Points to 2031

Forecasting boundary and evidentiary baseline

The forecast must begin by separating three quantities that are often collapsed into one: observed criminal activity, inferred organisational structure and projected future capability. The observed baseline includes verified Balkan call-centre operations, distributed technical infrastructure, cryptocurrency and bank-account use, multilingual market segmentation, recovery fraud and cross-border laundering arrangements. The inferred layer concerns who owns those components, whether traditional organised-crime groups control them, and whether regional operators function as principals, affiliates, contractors or replaceable labour nodes. The forecast layer estimates how those relationships could evolve under changes in crime-as-a-service availability, artificial intelligence, financial liquidity, enforcement, electronic-evidence access and legitimate-business infiltration. Europol assesses online fraud as the fastest-growing area of organised crime, identifies more than 120 active ransomware brands observed in 2025, and anticipates that online-fraud networks will increasingly use AI for social engineering, infrastructure management and the replacement of labour-intensive processes with autonomous digital capabilities. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. These findings support a higher baseline probability of further modularisation, but they do not establish that Balkan-based actors will control the resulting platforms. The forecasting unit is therefore the regional criminal-service ecosystem rather than any nationality-defined “Balkan cyber mafia.” The principal outcome variable, M₂₀₃₁, represents the maturity of an ecosystem capable of acquiring victims or access, coordinating specialised labour, operating replaceable infrastructure, extracting payments, laundering proceeds and regenerating after disruption. It does not measure the number of attacks, which remains distorted by non-reporting, inconsistent classification and the fact that a single platform can support many campaigns while a single operation can expose hundreds of nominal brands.

Table 1 — Observed, inferred and forecast variables

Analytical layerVariableCurrent evidentiary statusForecast usePrincipal distortion
ObservedCall-centre premises and personnelStrong in several Albanian, Serbian and regional casesEstablishes labour-intensive fraud capacityPremises may be only one distributed node
ObservedFraud platforms and websitesStrongMeasures campaign replicationPublic brands may conceal shared back ends
ObservedCryptocurrency wallets and bank accountsStrong in specific casesMeasures monetisation infrastructureSeized endpoints may be peripheral
ObservedRansomware brand proliferationStrong at EU levelEstablishes accessible external RaaS marketNot evidence of Balkan control
ObservedBEC loss and complaint volumeStrong globally, weaker for Balkan attributionMeasures addressable criminal marketReporting differs across jurisdictions
InferredBeneficial commandIncompleteDistinguishes principal from contractorOperators may not know upstream owners
InferredTraditional OCG involvementPlausible but unevenly evidencedTests physical–digital convergenceShared laundering does not prove shared command
InferredState or proxy relationshipsLow-confidence in Balkan casesTests hybrid-threat scenarioShared tools can create false attribution
ForecastCaaS availabilityHigh and risingLowers entry barriersEnforcement can fragment suppliers
ForecastAI-enabled conversionHigh-probability growthRaises operator productivity and scaleDefensive AI may offset some gains
ForecastLiquidity resilienceCritical uncertaintyDetermines realizable criminal revenueAccount freezes can create nonlinear losses
ForecastEvidence-access effectivenessPolicy-dependentDetermines attribution and prosecution speedFormal rules may not equal operational capacity
ForecastRegeneration speedIncreasingly importantMeasures resilience after disruptionBrand replacement can exaggerate “new” actors

Bayesian hypothesis architecture

The Bayesian model evaluates six competing but partially compatible hypotheses. H₁ — indigenous platformisation predicts that Balkan-based organisers will integrate lead generation, data brokerage, technical infrastructure, call-centre production, laundering and campaign governance into durable regional platforms. H₂ — outsourced regional production predicts that foreign or geographically dispersed coordinators will retain ownership of data, platforms and treasury functions while Balkan facilities supply multilingual labour, company structures, account access or technical services. H₃ — fragmented entrepreneurial diffusion predicts that readily available tools will generate many short-lived local cells without stable strategic coordination. H₄ — shared-enabler convergence predicts that traditional trafficking organisations, cybercriminals and fraud networks will increasingly use the same money launderers, corrupt facilitators, nominee companies, document suppliers and coercive intermediaries while remaining operationally separate. H₅ — hybrid or proxy convergence predicts that access brokers, infrastructure operators or ransomware affiliates will occasionally accept state-aligned tasking or sell services to hybrid-threat actors. H₆ — containment and displacement predicts that stronger financial controls, EU-supported investigations, faster electronic evidence and repeated infrastructure operations will prevent sustained regional platformisation, pushing activity abroad or into smaller, less profitable structures. The priors are not national crime-rate estimates; they are structured judgments about the organisational form most likely to dominate the documented service ecosystem. Evidence from geographically distributed call centres, shared platforms, manager continuity and division between sales, infrastructure and laundering raises H₂ and H₄. The persistence of numerous fraud brands and low entry barriers raises H₃. The absence of verified public evidence for a Western Balkan-controlled global ransomware platform limits H₁. Europol’s warning that cybercriminal and hybrid-threat boundaries are blurring raises H₅, but not enough to support case-specific state attribution. Enforcement operations and accession-related capacity building support H₆, though current evidence-access and institutional gaps reduce its posterior weight.

Table 2 — Bayesian update from 2026 baseline to 2031 hypothesis

Hypothesis2026 priorEvidence direction2031 posteriorConfidencePrimary confirmation requirement
H₁ — Indigenous platformisation15%Corporate-style fraud management and reusable infrastructure increase plausibility19%ModerateRegional control of administrators, treasury and vendor governance
H₂ — Outsourced regional production25%Strongly consistent with foreign markets and distributed functional nodes28%Moderate-to-highCommand, data or payment instructions originating outside operator locations
H₃ — Fragmented entrepreneurial diffusion22%Tool availability and brand churn strongly support diffusion21%HighMany small cells with shared tools but limited common ownership
H₄ — Shared-enabler convergence18%Laundering, company and account requirements support common intermediaries18%Moderate-to-highRecurrent facilitators across fraud, trafficking and cyber cases
H₅ — Hybrid or proxy convergence10%Europol-wide trend raises risk, but Balkan-specific evidence remains limited8%LowAuthenticated tasking, non-financial target logic and infrastructure overlap
H₆ — Containment and displacement10%New tools and cooperation improve disruption, but implementation remains uneven6%ModerateFalling regeneration rates, shorter account life and sustained asset recovery

Table 3 — Bayesian evidence weights

Evidence itemH₁H₂H₃H₄H₅H₆
Multilingual call-centre teams with hierarchical management+2+3+1+100
Foreign victim markets and cross-jurisdiction infrastructure+1+3+1+10−1
Same call-centre management surviving brand changes+2+2−1+10−1
Separate sales, technical and laundering jurisdictions+1+30+300
Limited evidence of regional RaaS administration−30+1+1−1+1
Increasing CaaS and access-broker availability+1+2+3+1+1−1
Legal-business infiltration and nominee structures+2+10+30−1
Faster payment suspension and asset freezing−2−1−1−20+3
Cross-border e-evidence implementation−1−1−1−1−1+3
AI-assisted multilingual automation+2+2+3+1+1−2
State-aligned use of criminal access services0+10+1+3−1
Repeated raids without durable activity decline+2+2+2+10−3

Monte Carlo model and assumptions

The Monte Carlo framework models five scenarios across 250,000 iterations, with each iteration drawing values for eight drivers: A₁ AI-assisted social-engineering productivity; C₂ availability of criminal services; L₃ laundering liquidity; B₄ legitimate-business penetration; E₅ effectiveness of electronic-evidence acquisition; F₆ payment-freezing and asset-recovery effectiveness; R₇ regional specialist-labour availability; and D₈ disruption intensity. The model imposes correlations because the variables are not independent. Increased CaaS availability correlates positively with AI-enabled fraud, infrastructure replacement and specialist access; legitimate-business penetration correlates with liquidity resilience and account availability; better electronic evidence correlates with more effective cross-border disruption; and high enforcement pressure correlates with decentralisation. Nonlinear thresholds are included because criminal output does not rise proportionally with every capability. A fraud network with abundant leads but inadequate receiving accounts may generate contacts without revenue. A ransomware affiliate with access but weak lateral-movement capability may fail before obtaining leverage. Conversely, once a network acquires redundant payment rails, multilingual automation and reusable victim data, small increases in lead volume can produce disproportionate revenue growth. The baseline distributions are calibrated from the verified direction of institutional assessments rather than undisclosed incident datasets: Europol expects greater AI use and resilient online-fraud networks; ENISA observes ransomware decentralisation and access-broker proliferation; FATF identifies integration of laundering mechanisms from the outset; and Eurojust–Europol identify persistent problems involving data loss, access to data, anonymisation, international cooperation and rapid response. Common Challenges in Cybercrime as Identified by Eurojust and EuropolEurojust and Europol – April 2024 — Verified primary source. The model should therefore be read as a disciplined uncertainty engine, not a claim that hidden criminal markets can be measured with actuarial precision.

Table 4 — Monte Carlo driver specification

DriverBaseline mean80% intervalDirection of criminal riskHighest sensitivity
A₁ — AI social-engineering productivity72/10058–86PositiveIndustrialised fraud and BEC
C₂ — CaaS availability76/10063–89PositiveRansomware affiliates and credential brokerage
L₃ — laundering liquidity64/10046–81Strongly positiveAll monetisation pathways
B₄ — legitimate-business penetration58/10041–74PositiveCall centres, shell companies and BEC
E₅ — e-evidence effectiveness51/10035–68NegativeAttribution and prosecution
F₆ — rapid freeze and asset recovery47/10030–64Strongly negativeBEC and online fraud
R₇ — specialist and multilingual labour68/10054–82PositiveFraud conversion and technical support
D₈ — disruption intensity61/10046–77MixedSuppresses output but increases decentralisation
P₉ — provider cooperation55/10037–72NegativeDomain, hosting, account and evidence continuity
G₁₀ — cross-border governance alignment49/10032–67NegativeJoint investigations and durable prosecution

Table 5 — Baseline Monte Carlo scenario outputs

ScenarioProbability80% model interval2031 maturity indexDominant production form
S₁ — Platformised modular expansion34%27–42%82/100Coordinators orchestrate replaceable vendors and operator cells
S₂ — Fragmented CaaS diffusion26%20–33%69/100Numerous short-lived cells use shared tools and brokers
S₃ — Enforcement bifurcation18%13–24%61/100Visible centres decline while sophisticated networks consolidate
S₄ — Hybrid-enabler convergence14%9–20%76/100Shared access, laundering and infrastructure serve criminal and proxy actors
S₅ — Effective containment8%4–13%43/100Scaling becomes unreliable and net criminal yield falls

Scenario S₁: platformised modular expansion

Under S₁, the Balkan ecosystem does not necessarily produce a single dominant criminal brand. Instead, a small layer of coordinators controls lead procurement, back-end platforms, data repositories, operator allocation, treasury rules and relationships with technical or financial vendors. Public-facing investment sites, call-centre companies and campaign names remain disposable. The platform’s durable assets are victim data, managerial expertise, account-supply relationships and production analytics. AI reduces the cost of translating scripts, generating synthetic identities, segmenting victims and supervising operators, while legitimate business structures provide offices, employment contracts, communications accounts and plausible payment narratives. Europol reports that 86% of the EU’s most threatening criminal networks abuse legal business structures and that online-fraud networks use trading companies, investment firms, call centres, IT providers and other entities that can be created and dissolved quickly. It also observes that call centres may appear legitimate to employees, market several products simultaneously and relocate while retaining managers and accountants. Leveraging Legitimacy: How the EU’s Most Threatening Criminal Networks Abuse Legal Business StructuresEuropol – December 2024 — Verified primary source. S₁ becomes dominant if L₃ exceeds approximately 70, A₁ exceeds 75 and provider cooperation remains below 55. Its defining indicator is not a rise in websites but increasing back-end reuse across nominally unrelated campaigns: common administrator accounts, CRM schemas, victim-status codes, payment-routing logic, recruitment networks or consolidation wallets. Intervention must therefore target platform dependencies and beneficial control rather than closing one premise at a time.

Table 6 — S₁ warning indicators and thresholds

IndicatorEarly warning thresholdEscalation thresholdStrategic interpretation
Fraud brands sharing back-end infrastructure3 brands8 or more brandsCommon platform administration
Call centres sharing managers or accountants2 centres4 or more centresDurable governance behind disposable premises
Domains replaced after disruptionWithin 21 daysWithin 72 hoursMature regeneration capability
Victim data reused in recovery fraud10% overlapAbove 30% overlapData treated as persistent productive capital
Shared beneficiary or consolidation endpoints5 campaigns15 campaignsCentral treasury or laundering broker
Operators serving multiple languages3 languages6 or more languagesExport-oriented production
Multiple legal companies using common devices2 entities5 or more entitiesCorporate-shell rotation
Common advertisement identifiers3 campaigns10 campaignsCentralised victim acquisition
Remote administrative logins from outside premisesOccasionalSystematicSeparation of command from production
Revenue-linked operator compensationIsolated evidenceStandardised commission systemMature performance management

Scenario S₂: fragmented CaaS diffusion

S₂ produces a larger number of offenders but fewer strategically durable organisations. Accessible phishing kits, stolen credentials, generative AI, rented infrastructure and online tutorials allow small groups to enter fraud and account-compromise markets without owning a complete criminal stack. These cells purchase leads, access or payment accounts from brokers, operate short campaigns and dissolve after exposure or internal disputes. Fragmentation reduces the value of leadership arrests because no central command exists, but it also reduces operational quality, trust and financial efficiency. Smaller actors face higher rates of service fraud, stolen proceeds, defective tools and frozen accounts. The scenario is especially plausible for BEC attempts, credential exploitation, low-complexity extortion and impersonation fraud. It becomes more likely when C₂ and A₁ remain high but L₃ and B₄ remain moderate: tools are accessible, yet stable laundering and corporate infrastructure are scarce. The observable environment contains many brands, domains and small payment clusters but limited back-end continuity. Europol’s assessment that criminal actors use bulletproof hosting, multi-jurisdiction infrastructure and residential proxies indicates why attribution will remain difficult even when groups are operationally weak. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. Policy must avoid equating fragmentation with containment. Aggregate victimisation can increase even while average group sophistication falls because the number of campaigns rises faster than individual success rates decline. The appropriate response is industrialised defence: automated correlation of domains, beneficiary accounts, devices and advertisements; rapid victim notification; standardized preservation requests; and reusable disruption packages rather than bespoke investigations for every brand.

Table 7 — S₁ versus S₂ diagnostic test

Diagnostic questionPlatformised S₁ expectationFragmented S₂ expectation
Do different brands share administration?Frequent and structuredOpportunistic or accidental
Is victim data reused systematically?Yes, across campaigns and fraud stagesLimited or poorly organized
Are financial endpoints centrally allocated?YesPurchased ad hoc
Do managers survive company closures?FrequentlyInconsistently
Is technical infrastructure professionally redundant?YesPartial and error-prone
Are commission and productivity systems standardized?YesInformal
Does disruption produce rapid coordinated regeneration?YesNumerous uncoordinated replacements
Are upstream service providers stable?Small trusted setBroad, volatile market
Does one seizure expose many brands?High probabilityLow probability
Is net criminal yield stable?Relatively stableHighly variable

Scenario S₃: enforcement bifurcation

S₃ is not simple enforcement success. It describes a market split in which highly visible, labour-intensive operations become easier to disrupt while technically sophisticated and financially resilient networks consolidate. Large call centres create physical signatures: leases, electricity use, recruitment, payroll, language-specific hiring, telecommunications traffic and managerial presence. Repeated raids, whistle-blower awareness and corporate-registration scrutiny can raise their operating cost. More capable coordinators respond by distributing operators across remote work, reducing office size, outsourcing recruitment and separating customer contact from platform control. Meanwhile, small cells unable to acquire reliable accounts or provider relationships disappear. The result is fewer visible facilities but stronger surviving networks, producing an apparent improvement in raid statistics without an equivalent reduction in victim losses. This scenario becomes dominant when D₈ rises above 70 but F₆ and E₅ remain below approximately 60: authorities can close premises but cannot consistently seize the treasury, preserve provider data or establish beneficial command. Eurojust and Europol identify data volume, data loss, access restrictions, anonymisation, international cooperation and public-private partnership limitations as continuing cybercrime challenges despite new legislative tools. Common Challenges in Cybercrime as Identified by Eurojust and EuropolEurojust and Europol – April 2024 — Verified primary source. The policy implication is that output metrics must extend beyond arrests and sites closed. Authorities should measure victim-loss trends, regeneration time, percentage of proceeds frozen, percentage of seized devices processed within operationally relevant time, administrator attribution, evidence-to-charge conversion and whether a disruption removes shared dependencies across multiple campaigns.

Table 8 — Enforcement performance metrics

MetricWeak measureStrong measure2031 target direction
Premises disruptionNumber of offices searchedShare of regional campaign capacity disabledRising
Arrest outputTotal arrestsArrests of administrators, treasury controllers and facilitatorsRising proportion
Device seizureNumber of devicesPercentage triaged within 72 hours and fully processedAbove 90% triage
Asset actionGross property seizedShare of estimated proceeds restrained or recoveredSustained increase
Domain actionDomains removedMedian regeneration time and shared-back-end disruptionRegeneration above 30 days
Bank responseAccounts notifiedTime from victim report to freeze decisionHours, not days
Evidence requestsNumber issuedResponse completeness and timeNear-real-time emergencies
Joint investigationsJITs formedCases producing coordinated charges and confiscationOutcome-based
Victim protectionWarnings publishedVictims reached before secondary fraudHigh coverage
Intelligence valueReports producedCross-case entities discovered and actionedMeasurable dependency removal

Scenario S₄: hybrid-enabler convergence

S₄ represents the highest strategic-impact scenario even though it is not the highest-probability outcome. Its defining feature is not that financially motivated Balkan criminals become state agents in a formal sense. It is that access brokers, hosting providers, data sellers, money launderers or intrusion specialists serve both criminal and hybrid-threat customers, allowing states or aligned intermediaries to acquire deniable capabilities without maintaining every technical asset internally. A provider may sell compromised organisational access to the highest bidder without knowing whether the purchaser intends ransomware, espionage or disruption. A criminal group may accept a target specification that has geopolitical rather than commercial value, then use ordinary extortion to disguise the operation. A laundering channel may process proceeds from fraud alongside sanctions evasion or influence operations. Europol assesses that hybrid-threat actors increasingly use cybercriminal networks as proxies for DDoS attacks, intrusions and ransomware, while stolen access can be exploited against governments and critical infrastructure. Internet Organised Crime Threat Assessment 2026Europol – June 2026 — Verified primary source. However, the public evidence examined does not establish state direction of the documented Balkan call-centre networks; such attribution would require authenticated communications, non-financial targeting logic, infrastructure continuity, state-benefiting timing and financial or personal links to state intermediaries. The primary policy problem is dual use. Removing a shared access or hosting node may reduce both criminal and hybrid risk, but public attribution standards should remain higher than disruption thresholds. Intelligence services, criminal investigators, financial-intelligence units and cybersecurity agencies therefore require protocols for sharing indicators without prematurely merging legal classifications.

Table 9 — Criminal versus hybrid attribution matrix

IndicatorOrdinary criminal explanationHybrid/proxy explanationEvidentiary weight
Financial demandDirect profit motiveCover for disruption or intelligence collectionLow alone
Target selectionAbility and willingness to payStrategic sector, political timing or symbolic valueMedium
Data stolen but not monetisedFailed campaign or resale delayIntelligence objectiveMedium
Infrastructure overlapShared criminal vendorCommon tasking or sponsorLow-to-medium
Non-public vulnerability usePurchased or independently discoveredState-supplied capabilityMedium
Coordinated information operationCriminal reputational pressureStrategic influence campaignHigh
Payment disconnected from activityHidden intermediary or launderingState supportMedium
Repeated state-benefiting timingCoincidence or market opportunityDirection or alignmentMedium-to-high
Authenticated command communicationsCriminal buyerState or state-linked taskingVery high
Personnel link to state structuresIncidental historySponsor relationshipHigh if current and operational
Simultaneous physical and cyber pressureOpportunistic exploitationIntegrated hybrid operationHigh
Persistence after economic logic disappearsPoor judgment or revengeNon-financial objectiveMedium-to-high

Scenario S₅: effective containment

Effective containment does not require eliminating cybercrime. It requires reducing the reliability of scaling and monetisation until marginal expansion no longer produces predictable returns. The decisive condition is simultaneous pressure at several dependency points: advertisements are removed before generating a large victim pool; providers preserve administrator data; banks suspend suspicious transfers rapidly; exchanges identify related wallets; company registries expose nominee patterns; seized devices are processed quickly enough to support follow-on actions; and prosecutors can establish cross-border command and confiscation. If only one layer improves, networks reroute around it. The EU e-evidence framework can reduce some delays by enabling production orders directed to represented service providers and preservation of data pending production, but implementation quality remains decisive. A Council high-level report states that the e-evidence Regulation and Directive are important steps while warning that substantial work remains and that incomplete implementation leaves access to data abroad a major challenge. Data Access for Effective Law Enforcement: Final Report of the High-Level GroupCouncil of the European Union – November 2024 — Verified primary source. Containment becomes the dominant scenario only when E₅, F₆ and P₉ all exceed approximately 70 and financial controls operate faster than criminal dispersal. Its most important outcome is declining survival-adjusted yield, not declining complaint volume. Complaints may initially rise as reporting improves. The stronger signal is that a greater share of transfers is stopped, account portfolios become shorter-lived, repeat victimisation falls, platform regeneration slows and professional facilitators face confiscation or exclusion from legitimate markets.

Country and institutional capacity implications

The Western Balkans do not present a uniform enforcement environment, and a regional forecast that assigns one capacity score to all jurisdictions would conceal the operational seams criminal services exploit. The European Commission reported that Albania adopted a 2025–2030 National Cybersecurity Strategy but still needed stronger cybersecurity capacity, implementing legislation, training and awareness. Albania Report 2025European Commission – November 2025 — Verified primary source. It reported that North Macedonia had not ratified the Second Additional Protocol to the Cybercrime Convention and made no progress during the reporting period on the cited cybercrime alignment issue. North Macedonia Report 2025European Commission – November 2025 — Verified primary source. For Bosnia and Herzegovina, the Commission stated that authorities should strengthen their capacity to tackle cybercrime effectively. Bosnia and Herzegovina Report 2024European Commission – October 2024 — Verified primary source. These findings are institutional assessments, not crime-prevalence measures. Their forecast significance lies in uneven response time, digital-forensic throughput, legal alignment, provider cooperation and asset recovery. Criminal networks can separate operations so that labour, infrastructure, data and proceeds sit in jurisdictions with different investigative strengths. Regional policy must consequently create minimum interoperable operating standards rather than isolated centres of excellence.

Table 10 — Regional capability priorities through 2031

CapabilityAlbaniaSerbiaNorth MacedoniaBosnia and HerzegovinaMontenegroRegional requirement
Cybercrime strategy implementationHigh priorityUpdate and operational measurementHigh priorityFragmented governance challengeCapacity consolidationAnnual implementation scorecard
Digital-forensic triageExpand staffing and automationStrengthen high-tech crime integrationExpand resourcesHarmonise institutional accessBuild surge capacityShared emergency assistance pool
E-evidence proceduresAlign with EU practiceMaintain rapid cooperation channelsRatify and operationalise relevant instrumentsEstablish consistent proceduresIntegrate regional practiceCommon templates and 24/7 contacts
Financial investigationLink fraud cases to proceeds from outsetIntegrate cyber and organised-crime financeExpand asset tracingImprove cross-entity coordinationStrengthen FIU–prosecutor workflowParallel financial investigation standard
Provider engagementFormal contact mechanismsStructured domestic and foreign provider liaisonImprove legal and operational capabilityReduce fragmented requestsRegional hosting and telecom engagementProvider response directory
Call-centre oversightRisk-based inspection and beneficial ownershipEmployment and telecom anomaly detectionCorporate and platform scrutinyEntity-level coordinationMonitor relocation riskShared risk indicators
Victim reportingUnified cyber-fraud intakeLink reports to bank-freeze actionImprove reporting accessHarmonise entity systemsBuild national-to-regional feedCommon minimum data schema
Cryptocurrency tracingSpecialist capacityExpand joint analytic supportDevelop dedicated expertiseShared regional accessBuild capabilityRegional centre of expertise
Judicial specializationContinue SPAK and cybercrime coordinationSpecialized prosecution continuityStrengthen cybercrime specializationReduce jurisdictional fragmentationDedicated trainingJoint prosecutor exercises
Strategic intelligenceCross-case dependency mappingIntegrate SOCTA and cybercrime analysisDevelop threat assessmentImprove consolidated pictureRegional contributionAnnual Western Balkans CaaS assessment

Intervention architecture: attack dependencies, not brands

Interventions should be sequenced according to economic leverage. At the victim-acquisition layer, authorities and platforms can disrupt malicious advertising, cloned sites and abusive telecommunications before a large lead pool develops. At the access layer, credential resets, infostealer victim notifications and rapid infrastructure action can prevent stolen data from entering ransomware or BEC markets. At the production layer, labour inspections, beneficial-ownership analysis, telecom metadata and whistle-blower channels can expose nominally legitimate call centres. At the payment layer, confirmation-of-payee controls, real-time anomaly detection and cross-border freeze protocols can prevent extraction from becoming profit. At the laundering layer, financial investigation, cryptocurrency tracing, nominee-company analysis and confiscation target the trusted brokers that are harder to replace than domains. At the command layer, administrator attribution, CRM seizure and revenue-sharing evidence connect replaceable operators to organisers. The ordering matters because simultaneous action creates compounding effects. Shutting a site warns operators but may preserve their data and accounts; freezing accounts without preserving communications may recover money but lose attribution; arresting operators before mapping the treasury can trigger asset dispersal. Europol’s finding that legal businesses are abused by 86% of the EU’s most threatening criminal networks reinforces the need to integrate corporate, tax, labour, telecom, financial and cyber evidence. Leveraging Legitimacy: How the EU’s Most Threatening Criminal Networks Abuse Legal Business StructuresEuropol – December 2024 — Verified primary source.

Table 11 — Intervention-point matrix

Intervention pointImmediate actionIntelligence gainEconomic effectDisplacement risk
Malicious advertisingSuspend campaign and preserve account dataPurchaser, payment and targeting recordsRaises lead costMovement to smaller platforms
Domain registrationPreserve registrant, payment and access dataLinks brands and administratorsSlows replacementRegistrar shopping
HostingImage systems before takedownBack-end and operator evidenceDisrupts platform availabilityBulletproof hosting
Infostealer infrastructureNotify victims and neutralise control systemsAccess-market mappingRemoves campaign inventoryMigration to new malware
TelecommunicationsIdentify abnormal call and SIM patternsOperator and manager linksRaises contact costEncrypted or internet calling
Call-centre premisesCoordinated search after dependency mappingPersonnel, CRM and scriptsRemoves production capacityRemote work
Bank accountsImmediate suspension and recallMule and treasury networkDirectly reduces yieldCrypto or fintech movement
Cryptocurrency walletsTrace and seek seizureConsolidation and affiliate sharesDisrupts settlementChain or asset switching
Company registryVerify beneficial ownership and frontmenCorporate network structureRaises concealment costForeign incorporation
Payroll and labourCompare staff, revenue and communication rolesIdentifies production hierarchyDisrupts recruitmentInformal contracting
CRM and victim databaseSecure, analyse and notifyExposes campaign portfolioPrevents secondary fraudEncrypted remote storage
Manager and accountant networkCross-case investigationReveals durable governanceHigh systemic impactReplacement by trusted insiders

Policy implications for the EU and Western Balkans

The appropriate policy objective is not a generic increase in “cybersecurity.” It is to compress the interval between criminal action, detection, evidence preservation, financial suspension and coordinated attribution. Cybersecurity agencies primarily protect systems; police identify offenders and infrastructure; financial-intelligence units analyse proceeds; prosecutors establish admissible evidence; banks and platforms control privately held chokepoints; regulators address weak corporate and payment practices. A functional regional strategy must join those mandates through event-driven procedures. A high-value fraud report should automatically trigger a structured evidence package, preservation request, bank contact, beneficiary-account assessment and cross-case entity search. A ransomware incident should trigger not only technical containment but analysis of access provenance, data exfiltration, affiliate infrastructure, negotiation accounts and downstream cryptocurrency flows. A suspicious call centre should be assessed through labour records, company ownership, telecommunications, advertising, payment beneficiaries and foreign victim reports rather than through premises inspection alone. EU pre-accession funding should be conditioned on measurable operational outputs: forensic backlog reduction, freeze times, provider-response rates, confiscation results and cross-border case conversion. Formal alignment without execution will not materially alter Monte Carlo outcomes. Conversely, highly capable investigators without rapid private-sector cooperation will continue to lose data and proceeds. Policy must therefore finance interoperable workflows, not only equipment, conferences or strategic documents.

Table 12 — Policy roadmap, 2026–2031

PeriodPriorityOperational deliverablePerformance indicator
Late 2026Common incident and fraud-reporting schemaMinimum dataset shared by police, FIUs and prosecutorsPercentage of reports meeting data standard
2027Regional rapid-freeze protocol24/7 bank and VASP contact networkMedian freeze-request time
2027E-evidence readinessStandard preservation and production workflowsProvider response time and completeness
2027–2028Digital-forensic surge capacityShared triage capability for major action daysDevices triaged within 72 hours
2028Call-centre and legal-business risk modelCross-border entity and manager scoringHigh-risk entities reviewed
2028Shared cryptocurrency capabilityRegional tracing and seizure supportWallet clusters actioned
2028–2029Cross-case dependency graphFederated entity-resolution environmentCampaigns linked through shared enablers
2029Repeat-victim protection programmeAutomated warnings and recovery-fraud preventionSecondary victimisation reduction
2029–2030Specialist facilitator strategyCoordinated action against accountants, brokers and nomineesEnabler prosecutions and exclusions
2030Joint regional threat assessmentAnnual CaaS, BEC and ransomware ecosystem assessmentComparable trend indicators
2030–2031Outcome-based fundingFunding tied to recovery, attribution and disruption durabilityRegeneration time and recovered proceeds
2031Integrated EU–Western Balkans operating modelNear-real-time operational cooperationCross-border case completion rate

Strategic indicators and decision thresholds

A 2031 early-warning system should distinguish volume indicators, capability indicators, resilience indicators and strategic-convergence indicators. Volume indicators include complaints, malicious domains, suspicious advertisements, detected call activity and reported losses; they measure exposure but can rise because reporting improves. Capability indicators include multilingual synthetic identities, administrator reuse, privileged access sales, high-capacity receiving accounts and cross-platform victim data. Resilience indicators include regeneration time, the number of substitute accounts activated after freezes, relocation speed and continuity of managers after company closure. Strategic-convergence indicators include common facilitators across cyber and physical crime, shared infrastructure with state-aligned operations, unexplained targeting of critical sectors and persistence after financial incentives disappear. Decision thresholds should be tied to action. If three or more campaigns share a beneficiary controller, a financial network investigation should begin. If a disrupted platform regenerates within seven days using related administrators, authorities should escalate from brand-specific action to platform attribution. If victim data appears in recovery fraud within thirty days, immediate notification and data-market investigation are warranted. If one facilitator connects ransomware settlement, BEC receipts and investment-fraud deposits, the case should be treated as a high-impact laundering-service investigation. If geopolitical target selection co-occurs with authenticated state-linked communications or coordinated influence activity, criminal and national-security authorities should establish a joint attribution process. Such thresholds transform forecasting into collection discipline: every scenario carries observable implications, and failure to observe them should lower its probability rather than being explained away.

Table 13 — 2031 indicator dashboard

IndicatorGreenAmberRedRequired response
Median fraud-domain regenerationAbove 30 days8–30 days7 days or lessEscalate to shared back-end investigation
Share of proceeds frozenAbove 45%20–45%Below 20%Review bank, VASP and reporting latency
Devices triaged within 72 hoursAbove 90%60–90%Below 60%Deploy forensic surge capacity
Repeat-victim rateBelow 5%5–12%Above 12%Activate recovery-fraud protection
Campaigns linked to common treasury1–23–5More than 5Prioritise treasury controller
Average mule-account longevityBelow 5 days5–20 daysAbove 20 daysStrengthen account-network detection
Cross-border evidence responseBelow 24 hours urgent1–5 daysAbove 5 daysResolve procedural and provider blockage
Call-centre relocation timeAbove 90 days30–90 daysBelow 30 daysTarget managers, recruiters and accountants
Shared infrastructure across crime typesIsolatedRecurrentSystematicCreate multi-crime task force
State-aligned target anomaliesNoneUnexplained patternPattern plus corroborationJoint criminal–security assessment
Beneficial ownership establishedAbove 80% of priority entities50–80%Below 50%Expand corporate intelligence
Net asset recoveryRising over three yearsVolatileDecliningReassess intervention sequence

Strategic judgement through 2031

The baseline judgment is that the Western Balkan criminal-service ecosystem will become more modular, more export-oriented and less dependent on large permanent premises by 2031, but the most probable form is outsourced production and shared-enabler convergence rather than a unified regional cybercrime cartel. Industrialised online fraud will remain the most mature regional vector because it fits existing multilingual labour, call-centre management and corporate-front capabilities. BEC-support services—especially reconnaissance, receiving accounts, nominee companies and laundering—will grow faster than publicly attributable end-to-end BEC command. Ransomware participation will increase primarily through access brokerage, affiliate work, infrastructure and financial services; the emergence of a Balkan-controlled global RaaS platform remains possible but is not the baseline. The Monte Carlo model gives 60% combined probability to platformised expansion or fragmented CaaS diffusion, compared with 8% for effective containment. However, this balance is not immutable. Sensitivity analysis identifies rapid payment freezing as the single most powerful short-term variable, followed by provider-held evidence, beneficial-ownership transparency and the removal of persistent facilitators. Raising F₆ and E₅ by twenty points while holding criminal drivers constant approximately doubles the containment probability and reduces the platformised scenario by more than one-third. Increasing disruption without those capabilities mainly raises S₃, enforcement bifurcation. The policy conclusion is precise: more raids alone will produce adaptation; simultaneous financial, evidentiary, corporate and technical intervention can reduce criminal yield. Success by 2031 should be measured not by the disappearance of cybercrime brands but by longer regeneration times, lower repeat-victimisation, higher recovery rates, shorter evidence delays and the inability of organisers to replace trusted liquidity and governance nodes.

Figure 1: Monte Carlo Scenario and Policy Sensitivity Model
Western Balkans Criminal-Service Outlook to 2031
Adjust criminal capability and intervention variables. Probabilities are structured model outputs, not observed frequencies.
01020 304050 PlatformisedFragmented BifurcationHybrid Containment
34%
26%
18%
14%
8%
2031 ecosystem maturity: 72/100 · Containment leverage: 49/100

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.