The World Is Rewriting the Rules Against Cyber-Enabled Transnational Crime

Maj. Vineet Kumar and Isharth Kumar
Maj. Vineet Kumar and Isharth Kumar
Founder & Global President, CyberPeace and Isharth Kumar (Intern) CyberPeace
PUBLISHED ON
Aug 19, 2026
10

Introduction

For two decades, cybercrime enforcement was built around a simple assumption: criminals hide behind screens, but they still operate mostly within reachable borders. That assumption has collapsed. Today's fraud economy runs through industrial-scale scam compounds in Myanmar and Cambodia, laundering networks spanning a dozen jurisdictions, and trafficked labour forced to defraud victims thousands of miles away. INTERPOL's own trend reporting has tracked victims from more than 60 countries pulled into scam operations that now stretch well beyond Southeast Asia into Africa, the Gulf, and Latin America. Global losses from this activity are estimated in the hundreds of billions of dollars annually, and the networks rebuild faster than any single government can dismantle them.

A Threat That Outran the Old Playbook

The mismatch is the real story behind a wave of policy moves in 2025 and 2026. The August 12, 2026 U.S. National Security Presidential Memorandum authorising vetted private companies to conduct government-supervised offensive cyber operations against transnational criminal organisations is one data point in that wave, not the whole story. Washington's move sits alongside a broader, still-unfinished experiment: can the international system build cooperative machinery fast enough to match a threat that treats borders as an inconvenience rather than a barrier?

Three Tracks of International Response

Three distinct but overlapping tracks have emerged.

The treaty: The most consequential recent development is the UN Convention against Cybercrime, adopted by the General Assembly in December 2024 and opened for signature in Hanoi in October 2025, where 71 states and the EU signed on. It is the first comprehensive global treaty addressing cybercrime and cross-border evidence sharing, building on the older Budapest Convention framework that has anchored cooperation since 2004. The Hanoi Convention needs 40 ratifications to enter into force; as of mid-2026, only three states (Qatar, Azerbaijan, and Vietnam) had ratified it, and human rights groups continue to warn that its broad scope could be used by authoritarian governments to justify surveillance and cross-border data requests dressed up as cybercrime cooperation. The treaty's fate will hinge on a Conference of States Parties process now being negotiated, where democracies are pushing for genuine multi-stakeholder oversight rather than a rubber stamp.

The operational track: While treaty diplomacy moves slowly, police-to-police cooperation has scaled up dramatically. INTERPOL's Operation First Light, now an annual standing initiative, illustrates the trajectory: its 2026 iteration spanned January to April, generated over 5,800 arrests and roughly $293 million in intercepted funds, and made heavy use of the Global Rapid Intervention of Payments mechanism to freeze illicit transfers before they disappeared into crypto wallets. A parallel operation led by Dubai Police with the FBI and Chinese authorities dismantled nine pig-butchering compounds across Myanmar, Indonesia, Cambodia, and Thailand, seizing more than $701 million. In Europe, Europol's EMPACT framework has entered a new 2026–2029 cycle, deepening ties with Frontex, Eurojust, and regional partners like Ameripol and the EL PACTTO programme in Latin America, effectively building a lattice of standing coordination bodies rather than one-off task forces. These operations demonstrate real capacity, but they also expose the "whack-a-mole" problem: raided compounds in Myanmar's Myawaddy region simply relocated, reconnected via satellite internet, and resumed operations within weeks, according to regional reporting.

The public-private track: This is where the U.S. memorandum fits into a genuinely global pattern rather than standing alone. The United Kingdom's 2026–2029 Fraud Strategy centres on a £31 million Online Crime Centre, opening in 2026, that fuses data from the National Crime Agency, the intelligence community, and private partners across banking, telecoms, and technology into a single coordination hub building on existing arrangements like Stop Scams UK, where telecom operators and banks already share suspicious SIM and account data in near real time. In the U.S., a June 2026 joint action involving the Justice Department, Meta, Microsoft, Google, Apple, and Coinbase froze $3.8 billion in cryptocurrency and disrupted 1.4 million fraud-linked accounts, showing that platform cooperation can move faster than formal treaty processes. Singapore has positioned itself as a hub for this model too, anchoring the Global Anti-Scam Alliance, which now includes ASEAN's own foundation as a member, bringing governments, banks, and tech platforms into shared intelligence loops. What distinguishes the U.S. memorandum is that it goes a step further than data-sharing: it authorises companies to take disruptive technical action, not just contribute intelligence, under a legal theory that folds them into the government's own authority under the Computer Fraud and Abuse Act's law-enforcement exception.

Where the System Still Breaks Down

Despite this activity, structural gaps, like jurisdiction, are the deepest ones. Scam compounds deliberately locate in special economic zones and border regions precisely because territorial control there is contested or weak, leaving no single government with clean authority to act. ASEAN's own policy work acknowledges that nearly every stage of the regional scam value chain crosses at least one border, which is why the bloc has shifted toward standing coordination bodies like its Working Group on Anti-Online Scams rather than relying on bilateral requests.

Attribution and accountability lag behind operational tempo. Financial intelligence and blockchain analytics have improved enforcement precision, but identifying the human traffickers and financiers sitting above front-line scam operators remains slow, uneven, and dependent on political will in host countries.

Governance of the newer public-private authorities is also unsettled. Human rights advocates flag that expanding both the Hanoi Convention's surveillance-adjacent powers and unilateral hack-back authorities like the U.S. memorandum could, without careful oversight, blur the line between fighting organised fraud and enabling broader digital overreach. The U.S. memorandum's own guardrails, which are a ban on operations causing serious injury or rising to a use of force, mandatory federal sign-off, and a $1 million forfeitable bond, reflect an awareness of that risk, but its implementing procedures remain classified, and comparable transparency gaps exist in several other national programs.

The Emerging Consensus

What's notable is not any single instrument but the convergence: nearly every serious national or regional response now combines the same three ingredients deeper platform and financial-sector data sharing, standing multilateral operational coordination, and a cautious expansion of what non-state actors are permitted to do. The countries and blocs making the fastest progress, from the UK's Online Crime Centre to INTERPOL's payment-interdiction tools to ASEAN's regional information-sharing arrangement, are the ones treating cyber-enabled transnational crime as a persistent infrastructure problem rather than a series of discrete crimes to be prosecuted after the fact. Whether that convergence produces durable results or simply better-coordinated whack-a-mole will depend on the unglamorous work still ahead: ratifying treaties, writing classified rulebooks, and building the cross-border trust that lets financial and technical data move as fast as the criminals do.

Conclusion 

Transnational cybercrime has outgrown fragmented national enforcement. The emerging combination of international treaties, operational cooperation, and public-private partnerships offers a stronger response, but serious gaps in jurisdiction, accountability, and oversight remain. Ultimately, success will depend on whether states can build cooperation and safeguards capable of matching criminals’ speed, adaptability, and global reach.

Sources

PUBLISHED ON
Aug 19, 2026
Category
TAGS
No items found.

Related Blogs