INTERPOL: Phishing, Ransomware and AI-Enabled Scams Surge Across Asia-Pacific
INTERPOL’s latest assessment for 2025/2026 reveals a steep uptick in cybercriminal activity throughout Asia and the South Pacific, a trend the agency links to fast-moving digital adoption, wider internet access, emerging technologies, transnational criminal networks and uneven levels of cybersecurity preparedness.
The report-titled the 2025/2026 Asia and South Pacific Cyberthreat Assessment-identifies phishing as the single most pervasive and costly cyber threat in the region. Roughly one-third of countries covered by the study logged more than 10,000 phishing incidents between January 2024 and March 2025, and more than half of INTERPOL’s member nations reported that cybercrime represented at least 30% of all recorded criminal activity nationwide.
Neal Jetton, INTERPOL’s Cybercrime Director, warned that offenders are increasingly exploiting artificial intelligence, ransomware-as-a-service offerings and sophisticated social-engineering methods at scale. He stressed that as digital services proliferate across the region, improving operational collaboration, sharing intelligence and bolstering cyber resilience are critical to protecting people and essential systems.
The report highlights a marked rise in ransomware assaults alongside AI-driven fraud and deepfake-enabled schemes, including scams where attackers impersonate corporate leaders to authorize fraudulent transfers. INTERPOL estimates the region suffered in excess of 135,000 ransomware-related incidents in 2024, with the real estate, manufacturing and financial services sectors bearing the brunt of these attacks.
Investigators also documented the growing professionalisation of scam operations run by transnational organised crime groups in nations such as Cambodia, Laos, Myanmar and the Philippines. These networks have established large-scale scam facilities-frequently using coerced labour-to operate investment and romance frauds that target victims worldwide after cultivating friendly or intimate relationships.
INTERPOL notes that organised criminal networks in Myanmar, Cambodia and Laos have deployed deepfake content as part of ‘romance-baiting’ campaigns, combining AI-generated personas with targeted social engineering. The agency attributes roughly $37 billion in regional cybercrime losses to these kinds of operations.
Other notable patterns uncovered in the assessment include a rise in banking trojans and information-stealing malware, which ranked as the region’s second-most common category of cyber offence. Malware families such as RedLine, Lumma, LokiBot, Negasteal and ZBot were among the most frequently observed strains.
On user behavior, the report found that about 5.5 people per 1,000 in the Asia and South Pacific region clicked on phishing links each month-almost double the global average of 2.9 per 1,000. Network disruption attacks also climbed sharply: distributed denial-of-service (DDoS) incidents increased by 92% in 2024 compared with the prior year.
System intrusions were implicated in roughly 80% of all data breaches during 2024. The assessment also documents the malicious use of deepfake technology for sexual exploitation, coercion and blackmail. Attackers continue to exploit misconfigured systems, weak encryption schemes, insecure APIs and poor monitoring practices to penetrate corporate networks.
Ransomware operators have taken to leveraging organisations’ regulatory and compliance obligations as leverage during extortion attempts, amplifying pressure on victims to pay to avoid reputational and legal fallout.
In response to these trends, INTERPOL says regional law enforcement partners are intensifying coordinated actions-backed by the organisation-including takedowns of criminal infrastructure, joint investigations, specialised training programs and policy work aimed at strengthening cyber resilience across the Asia-Pacific.