Crime-as-a-Service lowers entry barriers to cybercrime world
Europol report sheds light on the rise of the Crime-as-a-Service business model
Europol Cyber Crime Centre (EC3) has sounded the alarm over the rise of the Crime-as-a-Service business model, and how it's lowering the barriers to entry into the world of cybercrime.
According to the organisation's 2014 Internet Organised Crime Threat Assessment (iOCTA), the model allows cybercriminals to develop sophisticated malicious products and services before selling them on to the less experienced to use via the "digital underground" world.
As a result, it's getting easier for less technically-minded criminals to engage with cybercrime, putting companies at even bigger risk.
"In a simplified business model, a cybercriminal's toolkit may include malicious software, supporting infrastructure, stolen personal and financial data and the means to monetise their criminal gains," the report states.
"With every aspect of this toolkit available to purchase or hire as a service, it is relatively easy for cybercrime initiates lacking experience and technical skills to launch cyber attacks not only of a scale highly disproportionate to their ability but for a price similarly disproportionate to the potential damage."
Many of these transactions take place on the "Dark Net", which the report states has fuelled evolution of cybercrime in recent years.
Cecilia Malmstrm, EU commissioner for Home Affairs, said almost anyone can become a cybercriminal these days, thanks to the proliferation of the anonymous and hidden internet.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"This put an even increasingly pressure on law enforcement authorities to keep up," she said.
"We need to use our new knowledge of house organised crime operates online to launch more transactional operations. We need to ensure that investigations into payment card fraud and online child abuse don't stop at national borders," Malmstrm added.
Professor Alan Woodward from the University of Surrey, who co-authored the report, added: "If agencies fail to mobilise to meet the threats highlighted in this report then organised cybercrime will gain the upper hand.
"However, if agencies work together, across borders, then we can use modern technologies to catch criminals, rather giving them a platform for ever more innovative forms of crime."
Caroline Donnelly was the news and analysis editor of IT Pro. Previously, she worked as a reporter at several B2B publications, including UK channel magazine CRN, and as features writer for local weekly newspaper, The Slough and Windsor Observer. She studied Medical Biochemistry at the University of Leicester and completed a Postgraduate Diploma in Magazine Journalism at PMA Training in 2006.
-
Pure DC reveals plans for 550MW data center campus in FinlandNews The Seinäjoki site is designed specifically for AI and machine learning workloads, according to Pure DC
-
Could the memory shortages be the making of the channel?Industry Insights Partners will need to offer purchasing options, intelligent refresh and lifecycle management
-
Startup founders lament 'regulatory friction' despite EU simplification effortsNews Entrepreneurs are spending a fortune on compliance, and it’s forcing some to consider relocating
-
AWS says cloud market gatekeeper designation risks ‘deterring European investment and innovation’ as EU regulators plot competition crackdownNews Gatekeeper designation under the legislation would force AWS and Microsoft to make concessions
-
‘This closes a gap that has caused real uncertainty in the market’: Changes to EU AI Act implementation deadlines welcomed by industryNews New implementation deadlines for the EU AI Act could help remove “genuine friction” for European companies
-
European Commission approves data flows with UK for another six yearsNews The European Commission says the UK can have seamless data flows for another six years despite recent rule changes
-
Three things you need to know about the EU Data Act ahead of this week's big compliance deadlineNews A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack.
-
The second enforcement deadline for the EU AI Act is approaching – here’s what businesses need to know about the General-Purpose AI Code of PracticeNews General-purpose AI model providers will face heightened scrutiny
-
Meta isn’t playing ball with the EU on the AI ActNews Europe is 'heading down the wrong path on AI', according to Meta, with the company accusing the EU of overreach
-
‘Confusing for developers and bad for users’: Apple launches appeal over ‘unprecedented’ EU fineNews Apple is pushing back against new app store rules imposed by the European Commission, suggesting a €500m fine is a step too far.