Emerging cybercrime threats encompass the novel forms of digitally mediated criminal activity that are developing at the frontier of technological innovation, driven by advances in artificial intelligence, the expansion of the Internet of Things, the maturation of cryptocurrency ecosystems, the evolution of deepfake and synthetic media capabilities, and the anticipated disruptive potential of quantum computing. Within Cyber Criminology, the study of emerging threats requires scholars and practitioners to look beyond the current threat landscape and anticipate how technological development will create new criminal opportunities, transform existing offense categories, and challenge the legal, investigative, and preventive frameworks designed for an earlier generation of digital crime. Europol’s Internet Organised Crime Threat Assessment, the FBI’s annual Internet Crime Report, and the World Economic Forum’s Global Risks Report have each identified technology-enabled crime evolution as a defining concern for the coming decade. This article examines the major categories of emerging cybercrime threats, assesses their potential scale and consequence, and considers the policy and institutional responses necessary to address threats that do not yet fully exist within the broader field of Criminology.
Introduction
The history of cybercrime is a history of criminal adaptation to technological change. Each major technological development — personal computing, the internet, mobile devices, social media, cloud computing, cryptocurrency — has generated new criminal opportunities that offenders have exploited faster than legal and institutional frameworks could respond. The current wave of emerging technologies represents a particularly consequential inflection point because the technologies involved — artificial intelligence, ubiquitous sensing, quantum computing — do not merely create new tools for existing criminal activities but have the potential to transform the fundamental dynamics of offense and defense in ways that favor attackers.
The challenge of addressing emerging threats is inherently speculative. Predictions about future cybercrime must extrapolate from current technological trajectories and criminal behavior patterns, acknowledging uncertainty about both the pace of technological development and the creativity of criminal adaptation. The history of cybercrime prediction includes both prescient warnings (the anticipation of ransomware as a major threat before its full emergence) and unfulfilled alarms (the persistent prediction of catastrophic cyberterrorism that has not materialized). The most productive approach treats emerging threat assessment not as prediction but as preparation: identifying the technological capabilities that could enable new forms of criminal activity, assessing the vulnerability of current defensive frameworks to those capabilities, and developing adaptive responses that can be scaled as threats materialize.
Artificial Intelligence and Criminal Applications
AI-Enhanced Social Engineering and Fraud
The application of artificial intelligence to social engineering and fraud represents the most immediately consequential emerging threat, as large language models, voice cloning technologies, and video generation capabilities dramatically lower the skill and effort required to produce convincing deceptive communications. Before the current generation of AI tools, effective spear phishing required human effort to research targets, craft personalized messages, and maintain convincing correspondence. Generative AI enables the automated production of phishing messages that are grammatically flawless, contextually relevant, and personalized at a scale that was previously impossible — transforming spear phishing from a labor-intensive targeted operation into a mass-production capability.
Voice cloning technology, which can produce convincing reproductions of a specific person’s voice from as little as three seconds of sample audio, has already been deployed in fraud operations. A widely reported 2024 incident involved a Hong Kong-based financial worker who transferred approximately $25 million after participating in a video conference in which deepfake technology was used to impersonate multiple senior executives of the worker’s company. While this incident was exceptional in its scale, it illustrates the potential for AI-generated impersonation to defeat the verification practices — including voice recognition and video confirmation — that organizations rely on to authenticate high-value transactions. The FBI has issued warnings about the increasing use of AI-generated voice and video in business email compromise and romance fraud schemes, advising organizations to develop verification protocols that do not rely solely on the apparent identity of the communicating party.
The automation of fraud through AI-powered chatbots represents a further evolution. Romance scam operations, which traditionally required human operators to manage individual victim relationships, can be partially or fully automated using conversational AI that maintains emotionally engaging dialogue across dozens of simultaneous conversations. The scalability of AI-driven fraud operations threatens to increase both the volume and the sophistication of social engineering attacks, potentially overwhelming the detection capabilities of both technical security systems and human judgment.
AI-Generated Malware and Vulnerability Discovery
Beyond social engineering, AI tools have demonstrated capabilities relevant to the technical dimensions of cybercrime, including the generation of malicious code, the discovery of software vulnerabilities, and the automation of attack processes. Research has shown that large language models can generate functional malware code, adapt existing malware to evade specific detection signatures, and produce exploit code for known vulnerabilities — capabilities that lower the skill threshold for technically sophisticated attacks. While current AI models implement safety guardrails that are intended to prevent the generation of malicious content, these guardrails are imperfect and can be circumvented through prompt engineering, jailbreaking techniques, or the use of open-source models that lack safety restrictions.
The potential for AI to accelerate vulnerability discovery is particularly concerning for defenders. Automated fuzzing — the systematic testing of software with unexpected inputs to identify exploitable flaws — has been enhanced by machine learning techniques that can target testing more efficiently than random approaches. The prospect of AI systems that can independently discover zero-day vulnerabilities — flaws unknown to the software vendor — and generate working exploits would dramatically shift the offense-defense balance by expanding the supply of exploitable vulnerabilities faster than the patching process can remediate them. The Defense Advanced Research Projects Agency (DARPA) has conducted research programs exploring both the offensive and defensive applications of AI to vulnerability discovery, recognizing that the technology will be applied by both sides of the cybersecurity equation.
The defensive applications of AI — anomaly detection, automated incident response, predictive threat intelligence — provide a partial counterbalance to the offensive applications. AI-powered security tools can analyze network traffic patterns, identify behavioral anomalies, and respond to detected threats at machine speed, potentially matching the acceleration that AI provides to attackers. The resulting dynamic is an AI-versus-AI arms race in which the effectiveness of both offense and defense continuously evolves, with the net impact on cybercrime levels depending on the relative pace of innovation on each side.
Deepfakes and Synthetic Media
Criminal Applications of Deepfake Technology
Deepfake technology — the use of machine learning to generate synthetic images, audio, and video that convincingly depict real people saying or doing things they did not actually say or do — creates criminal applications across multiple offense categories. Deepfake video and audio can be used for financial fraud (impersonating executives to authorize transactions), identity theft (defeating biometric verification systems that rely on facial or voice recognition), nonconsensual pornography (generating synthetic intimate imagery of real individuals), extortion (creating fabricated compromising content as the basis for threats), and disinformation (producing apparently authentic video of public figures making statements they never made).
The production of nonconsensual deepfake pornography has emerged as a significant harm, particularly targeting women and public figures. The accessibility of face-swapping applications and open-source deepfake tools has democratized the production of synthetic intimate imagery, enabling individuals without technical expertise to generate convincing content depicting any person whose photographs are publicly available. While several states have enacted legislation specifically addressing deepfake pornography and the federal DEFIANCE Act has been proposed to create a federal civil cause of action, the legal framework remains incomplete and enforcement is complicated by the difficulty of identifying anonymous creators and the ease of distributing content across multiple platforms and jurisdictions.
The potential for deepfake technology to undermine trust in digital evidence represents a systemic threat that extends beyond any individual criminal application. If convincing synthetic media can be produced cheaply and distributed widely, the evidentiary value of digital recordings — video, audio, photographs — is diminished across the entire criminal justice system. The “liar’s dividend” described by Chesney and Citron (2019) refers to the phenomenon in which the existence of deepfake technology enables guilty parties to dismiss authentic evidence as fabricated, creating doubt about the reliability of digital evidence even when it is genuine. The development of content authentication technologies — digital watermarking, cryptographic provenance tracking, AI-based deepfake detection — provides a partial response but faces the fundamental challenge that detection technology must continually evolve to keep pace with improving generation technology.
Implications for Identity Verification and Authentication
The improving quality of deepfake audio and video threatens the biometric authentication systems that an increasing number of financial institutions, government agencies, and technology companies rely on for identity verification. Facial recognition systems, voice biometric authentication, and video-based identity verification (used for remote account opening and KYC compliance) are all potentially vulnerable to spoofing through synthetic media that replicates the biometric characteristics of the authorized user. Research has demonstrated that current deepfake technology can defeat some commercial facial recognition and liveness detection systems, though the arms race between spoofing and anti-spoofing technologies continues.
The implications for the financial sector are particularly acute. Banks and financial technology companies have invested heavily in biometric authentication as a security enhancement over password-based systems, and the vulnerability of these systems to deepfake attacks threatens to undermine a substantial security investment. The response requires multi-layered authentication approaches that do not depend on any single biometric modality — combining facial recognition with behavioral biometrics, device fingerprinting, location analysis, and challenge-response protocols that are more resistant to synthetic media attacks. The broader trajectory suggests that the “something you are” authentication factor (biometrics) may become less reliable as deepfake technology improves, shifting security emphasis back toward “something you have” (cryptographic keys, hardware tokens) and “something you know” (though knowledge-based authentication has its own well-documented weaknesses).
Internet of Things and Expanded Attack Surfaces
IoT Vulnerabilities and Criminal Exploitation
The proliferation of Internet of Things devices — estimated at over 15 billion globally and projected to exceed 30 billion by 2030 — creates an expanding attack surface characterized by devices that often lack the security features of traditional computing platforms. IoT devices including smart home systems, industrial sensors, medical devices, connected vehicles, and municipal infrastructure frequently run minimal operating systems, use default or hardcoded credentials, receive infrequent or no security updates, and lack the processing capacity to support encryption and other security controls. These characteristics make IoT devices attractive targets for criminal exploitation and potential vectors for attacks against the networks to which they are connected.
The Mirai botnet of 2016 demonstrated the aggregate threat that compromised IoT devices can pose when coordinated at scale. By exploiting default credentials on security cameras, routers, and digital video recorders, the Mirai malware assembled a botnet capable of generating DDoS attacks exceeding one terabit per second — volumes sufficient to disrupt major internet infrastructure. Subsequent IoT botnets have expanded the range of targeted devices and the sophistication of their exploitation techniques, and the IoT device population continues to grow faster than the security standards and update mechanisms necessary to protect it.
The criminal exploitation of IoT extends beyond botnet recruitment. Smart home devices can be compromised for surveillance — accessing security cameras, smart speakers, and connected baby monitors to monitor occupants without their knowledge. Connected medical devices, including insulin pumps and cardiac pacemakers, have demonstrated vulnerabilities that could theoretically be exploited to cause physical harm, though no confirmed criminal exploitation of medical device vulnerabilities has been documented. Connected vehicle systems present similar concerns: researchers have demonstrated the ability to remotely compromise vehicle control systems, and the increasing autonomy of vehicle systems expands the potential consequences of successful exploitation.
Smart City and Critical Infrastructure Risks
The deployment of IoT technology in urban infrastructure — traffic management systems, water treatment facilities, electrical grids, emergency services networks — creates critical infrastructure vulnerabilities that combine the security weaknesses of IoT devices with the consequence severity of essential service disruption. Smart city systems aggregate data from thousands of sensors and actuators to optimize urban services, creating interdependencies that can transform the compromise of one system into cascading failures across multiple services.
The cybersecurity of operational technology (OT) systems — the industrial control systems that manage physical processes in manufacturing, energy, water, and transportation — has emerged as a distinct concern at the intersection of IoT and critical infrastructure security. OT systems were historically isolated from internet-connected networks (“air-gapped”), but the convergence of IT and OT networks for efficiency and monitoring purposes has exposed OT systems to cyber threats that they were not designed to withstand. The CISA has identified OT security as a national priority and has published sector-specific guidance addressing the unique security requirements of industrial control environments, but the pace of OT digitization continues to outpace the development and deployment of effective security controls.
Cryptocurrency Evolution and Financial Crime
Decentralized Finance and Novel Exploitation
The rapid development of decentralized finance (DeFi) protocols — financial services built on blockchain technology that operate without centralized intermediaries — has created novel criminal exploitation opportunities that existing legal and regulatory frameworks are poorly equipped to address. DeFi protocols enable lending, borrowing, trading, and insurance functions through automated smart contracts that execute transactions according to predefined rules without human intervention. The total value locked in DeFi protocols has fluctuated between $40 billion and $180 billion, representing a substantial pool of assets governed by code rather than institutional controls.
The exploitation of DeFi protocols has produced billions of dollars in losses through multiple attack vectors. Smart contract vulnerabilities — coding errors in the automated programs that govern DeFi transactions — have been exploited to drain funds from lending platforms, liquidity pools, and decentralized exchanges. Flash loan attacks exploit the ability to borrow large amounts of cryptocurrency without collateral for a single transaction block, using the borrowed funds to manipulate prices on decentralized exchanges and extract profit through arbitrage before repaying the loan within the same transaction. Governance attacks exploit the voting mechanisms through which some DeFi protocols are managed, using temporarily acquired voting tokens to pass proposals that redirect protocol funds to the attacker.
The legal characterization of DeFi exploitation remains unsettled. When an attacker exploits a flaw in a smart contract’s code to withdraw funds that the code’s logic permits — even if the withdrawal contradicts the protocol developers’ intent — the question of whether the conduct constitutes “unauthorized access” or “theft” depends on how legal concepts developed for human-mediated transactions are applied to automated systems. The SEC, CFTC, and DOJ have pursued enforcement actions against DeFi actors under existing securities, commodities, and wire fraud statutes, but the application of these statutes to novel DeFi structures is contested and will require further judicial development.
Privacy Coins and Regulatory Evasion
The development of privacy-focused cryptocurrencies — Monero, Zcash, and Dash among the most prominent — presents escalating challenges for law enforcement cryptocurrency investigation. Unlike Bitcoin, whose transaction history is publicly recorded and analytically traceable, privacy coins employ cryptographic techniques that obscure sender, receiver, and transaction amount information. Monero’s combination of ring signatures (which mix a transaction with decoy transactions), stealth addresses (which generate one-time addresses for each transaction), and RingCT (which conceals transaction amounts) creates a level of transaction privacy that significantly complicates analytical tracing.
The law enforcement and regulatory response to privacy coins has varied across jurisdictions. Japan, South Korea, and several other countries have banned or restricted the trading of privacy coins on regulated exchanges. The U.S. approach has been more targeted, with the IRS commissioning research into Monero tracing capabilities and the Treasury Department’s FinCEN proposing rules that would require reporting of cryptocurrency transactions involving mixing services. The effectiveness of these measures depends on the technical feasibility of tracing privacy coin transactions — a question that remains actively debated among cryptographers and law enforcement analysts — and on the extent to which criminals migrate from regulated to unregulated exchange platforms in response to tightened oversight.
Quantum Computing Threats
Cryptographic Vulnerability
Quantum computing, while still in its early developmental stages, presents a long-term threat to the cryptographic foundations on which digital security depends. Current public-key cryptographic systems — including RSA, elliptic curve cryptography, and Diffie-Hellman key exchange — derive their security from mathematical problems that are computationally infeasible for classical computers to solve. Shor’s algorithm, developed in 1994, demonstrated that a sufficiently powerful quantum computer could solve these problems efficiently, potentially rendering current encryption standards obsolete.
The timeline for the emergence of cryptographically relevant quantum computers is uncertain but has narrowed as quantum hardware development has accelerated. NIST’s Post-Quantum Cryptography Standardization Project, which has been developing and evaluating quantum-resistant cryptographic algorithms since 2016, released its first set of post-quantum standards in 2024 — reflecting the institutional assessment that the transition to quantum-resistant cryptography should begin now even though the quantum threat has not yet materialized. The “harvest now, decrypt later” threat — in which adversaries collect encrypted data today with the expectation of decrypting it when quantum computers become available — adds urgency to the cryptographic transition, as sensitive data encrypted with current algorithms may be vulnerable to future decryption.
Criminal Implications Beyond Cryptographic Breaking
The criminal implications of quantum computing extend beyond the direct breaking of encryption. Quantum-enabled password cracking could render current password hashing algorithms vulnerable, potentially exposing the stored credential databases that are already frequent targets of data breaches. Quantum attacks against blockchain protocols — specifically against the elliptic curve cryptography that secures cryptocurrency wallets — could enable the theft of cryptocurrency at a scale that would destabilize digital financial markets. The potential exploitation of quantum computing resources for criminal purposes — whether through the compromise of quantum computing infrastructure or through the criminal use of commercially available quantum services — represents a further threat vector that the cybersecurity community is beginning to model.
However, the practical timeline for these threats remains long relative to the more immediate threats posed by AI and IoT vulnerabilities. Current quantum computers lack the qubit count and error correction capabilities necessary for cryptographically relevant computation, and estimates of when these capabilities will emerge range from the late 2020s to the 2040s depending on the assumptions employed. The risk of overhyping quantum threats at the expense of attention to current challenges is a concern that threat assessment frameworks must balance against the long lead times required for cryptographic transition — organizations that wait until quantum threats are imminent to begin their transition to post-quantum algorithms may find that the transition cannot be completed in time.
Autonomous Systems and Criminal Exploitation
Drones, Autonomous Vehicles, and Robotics
The increasing deployment of autonomous and semi-autonomous systems — drones, self-driving vehicles, robotic process automation, autonomous weapons — creates new categories of criminal exploitation that existing legal frameworks were not designed to address. Drones have already been used for criminal purposes including drug smuggling across prison walls and international borders, surveillance of potential burglary targets, and disruption of airport operations. The increasing payload capacity, range, and autonomy of commercial drones expand their potential criminal utility, and the difficulty of attributing drone operations to specific individuals complicates investigation and prosecution.
Autonomous vehicle technology presents both a potential attack target and a potential criminal tool. The compromise of autonomous vehicle systems could be used to cause traffic disruption, facilitate vehicle theft, or — in worst-case scenarios — cause physical harm. The use of autonomous vehicles as delivery platforms for criminal operations (drug delivery, stolen goods transport) would exploit the difficulty of attributing a vehicle’s activities to a specific human operator. While these scenarios remain largely theoretical, the automotive industry’s investment in cybersecurity and the development of vehicle security standards reflect the recognition that autonomous systems will attract criminal attention as they become more prevalent and capable.
Legal Frameworks and Attribution Challenges
The legal and regulatory frameworks for autonomous systems are developing but remain immature relative to the pace of technological deployment. The FAA’s drone regulations, NHTSA’s autonomous vehicle guidelines, and various state-level legislative initiatives address operational safety but have not fully anticipated the criminal exploitation dimensions that emerging capabilities will create. When a drone is used to deliver contraband into a correctional facility, existing statutes may address the delivery of prohibited items but not the specific use of autonomous technology to accomplish it — a gap that creates both prosecutorial challenges and sentencing inconsistencies.
The attribution problem for autonomous system crime is particularly acute. A drone recovered after a criminal operation may yield forensic evidence — serial numbers, flight logs, controller pairing data — that links it to a specific operator, but commercially available drones can be modified to remove identifying features, and the physical separation between the operator and the autonomous agent complicates the establishment of criminal responsibility. The integration of autonomous systems into the criminal justice system’s analytical framework — understanding how they can be used as both tools and targets of crime — represents a necessary evolution in criminological thinking that parallels the earlier integration of computers and the internet into crime analysis.
Conclusion
Emerging cybercrime threats represent the next generation of digital criminal challenges that the American criminal justice system and the global cybersecurity community must prepare to address. The most immediate threats — AI-enhanced social engineering, deepfake-enabled fraud and impersonation, and the exploitation of expanding IoT attack surfaces — are already materializing and require urgent adaptation of defensive capabilities, legal frameworks, and investigative techniques. Longer-term threats — quantum computing’s potential to undermine cryptographic security, the criminal exploitation of autonomous systems, and the evolution of decentralized financial technologies — demand anticipatory investment in research, standards development, and institutional capacity that may not produce visible returns for years.
The overarching challenge is institutional adaptability: the capacity of legal systems, law enforcement agencies, regulatory bodies, and technology companies to evolve their practices at a pace that matches the technological change driving criminal innovation. The history of cybercrime suggests that this adaptability will be imperfect — new threats will materialize before frameworks are fully prepared to address them — but that sustained investment in research, workforce development, international cooperation, and adaptive governance can narrow the gap between criminal exploitation and institutional response.
References
- Ajder, H., Patrini, G., Cavalli, F., & Cullen, L. (2019). The state of deepfakes: Landscape, threats, and impact. Sensity (formerly Deeptrace).
- Caldwell, M., Andrews, J. T. A., Tanay, T., & Griffin, L. D. (2020). AI-enabled future crime. Crime Science, 9(1), 14. https://doi.org/10.1186/s40163-020-00123-8
- Chainalysis. (2024). The 2024 crypto crime report. https://www.chainalysis.com/blog/crypto-crime-2024/
- Chesney, R., & Citron, D. K. (2019). Deep fakes: A looming challenge for privacy, democracy, and national security. California Law Review, 107(6), 1753–1819. https://doi.org/10.15779/Z38RV0D15J
- Cybersecurity and Infrastructure Security Agency. (2023). Cross-sector cybersecurity performance goals. U.S. Department of Homeland Security.
- Europol. (2024). Internet Organised Crime Threat Assessment (IOCTA) 2024. European Union Agency for Law Enforcement Cooperation.
- Federal Bureau of Investigation. (2024). Internet Crime Complaint Center 2023 annual report. U.S. Department of Justice.
- Guembe, B., Azeta, A., Misra, S., Osamor, V. C., Fernandez-Sanz, L., & Pospelova, V. (2022). The emerging threat of AI-driven cyber attacks: A review. Applied Artificial Intelligence, 36(1), 2037254. https://doi.org/10.1080/08839514.2022.2037254
- King, T. C., Aggarwal, N., Taddeo, M., & Floridi, L. (2020). Artificial intelligence crime: An interdisciplinary analysis of foreseeable threats and solutions. Science and Engineering Ethics, 26(1), 89–120. https://doi.org/10.1007/s11948-018-00081-0
- National Institute of Standards and Technology. (2024). Post-quantum cryptography standardization. U.S. Department of Commerce. https://csrc.nist.gov/projects/post-quantum-cryptography
- National Security Commission on Artificial Intelligence. (2021). Final report. https://www.nscai.gov/2021-final-report/
- Nguyen, T. T., Nguyen, Q. V. H., Nguyen, C. M., Nguyen, D., Nguyen, D. T., & Nahavandi, S. (2022). Deep learning for deepfakes creation and detection: A survey. Computer Vision and Image Understanding, 223, 103525. https://doi.org/10.1016/j.cviu.2022.103525
- Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
- Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
- World Economic Forum. (2024). Global risks report 2024. https://www.weforum.org/reports/global-risks-report-2024/
- Yar, M., & Steinmetz, K. F. (2019). Cybercrime and society (3rd ed.). SAGE Publications.
- Zetter, K. (2014). Countdown to zero day: Stuxnet and the launch of the world’s first digital weapon. Crown.
- Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., & Zhou, Y. (2017). Understanding the Mirai botnet. Proceedings of the 26th USENIX Security Symposium (pp. 1093–1110).
- Holt, T. J., & Bossler, A. M. (2016). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
- Bernstein, D. J., & Lange, T. (2017). Post-quantum cryptography. Nature, 549(7671), 188–194. https://doi.org/10.1038/nature23461
Related Articles
- Artificial Intelligence and Crime
- Cybercrime Typologies
- Cryptocurrency and Crime
- Cybercrime and the Dark Web
- Digital Criminology and Public Policy