INTERPOL Flags Sharp Rise in Phishing, Ransomware and AI Scams Across Asia-Pacific

A new INTERPOL assessment maps a region where cybercrime is outpacing defensive capacity, with phishing leading the volume charts and ransomware crews exploiting the gap.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
INTERPOL Flags Sharp Rise in Phishing, Ransomware and AI Scams Across Asia-Pacific
Share

Key points

  • INTERPOL's 2025/2026 Asia and South Pacific Cyberthreat Assessment Report documents a "dramatic increase" in cybercrime across the region.
  • Phishing is the most widespread vector, feeding credential theft that ransomware affiliates convert into network access.
  • AI-enabled fraud is the fastest-growing category, with deepfakes and large language models automating scam operations.
  • A maturity gap between advanced economies and Pacific Island states gives criminal groups a structural routing advantage.
  • INTERPOL is pushing wider participation in its Operation Synergia takedowns and broader intelligence sharing.

What does the INTERPOL report actually say?

Phishing tops the list. INTERPOL calls it the region's most widespread vector, used as a standalone fraud play and as the entry point for heavier intrusions. The assessment ties phishing to credential theft feeding initial access brokers, who sell footholds to ransomware affiliates. That supply chain is now firmly entrenched across Southeast Asia and the Pacific.

Ransomware remains the highest-impact category. Operators are tailoring ransom demands to local economic conditions, and smaller Pacific nations, where incident response capacity is thin, are increasingly hit by groups that previously focused on Western targets. INTERPOL doesn't name specific crews in the public summary, but the techniques track with affiliates of the major Russian-speaking ransomware-as-a-service brands still dominating leak-site activity. We've been following those crews closely: our June piece tracing 'The Gentlemen' RaaS to an Izhevsk operator shows how quickly a competitive affiliate split can rocket a new crew up the victim count charts.

Should you worry about AI-enabled fraud?

Yes, especially if you operate in a multilingual environment. INTERPOL points to deepfake-driven business email compromise and voice-cloned executive impersonation, alongside generative AI used to mass-produce phishing lures in local languages. That last capability matters: a region with hundreds of dialects previously offered genuine friction against foreign scam operations. That friction is eroding. Pig-butchering investment fraud, much of it run out of scam compounds across the region, is increasingly automated with large language models handling early conversational grooming.

Why does the maturity gap matter?

It's structural, not incidental. Singapore, Japan and Australia have national CERTs, mandatory breach reporting and active law enforcement cyber units. Many Pacific Island states have none of those. Criminal groups route infrastructure through the weaker jurisdictions and target victims in the wealthier ones. Our earlier reporting on anonymized infrastructure touching 94% of incidents makes the same point from the defender's side: even well-resourced SOCs can't always answer who's on the other end of a connection.

Common questions

What is ransomware-as-a-service?

Ransomware-as-a-service, or RaaS, is a criminal business model where a core developer team builds and maintains ransomware code and leases it to affiliates, who carry out the actual attacks and split the ransom proceeds with the developers.

What is pig-butchering fraud?

Pig-butchering is a long-con investment scam where operators build a relationship with a target over weeks or months before steering them into a fake trading platform and stealing their funds.

Where can I read the full INTERPOL report?

The full assessment is available through INTERPOL's cybercrime portal.

Whether member states fund the response at the scale the numbers demand is the open question. INTERPOL is pushing for expanded participation in its Operation Synergia line of takedowns, but coordination frameworks only work if smaller jurisdictions have the capacity to act on what they're shared. Right now, many don't.

© 2026 Threat Vectr