Back to Insights
Threats5 min read30 July 2026

Southeast Asia's Cyber-Fraud Industry Now Costs the World Up to $114 Billion a Year

A 2026 UN threat assessment reveals how cryptocurrency, AI deepfakes, and satellite internet turned regional scam compounds into a global criminal service economy that no single government can shut down.

t2s
train2secure NewsdeskSecurity awareness team
A wide-angle photoreal editorial scene shot at dusk over a dense Southeast Asian city skyline, with rows of nondescript

The United Nations Office on Drugs and Crime has placed a price tag on Southeast Asia's industrialised fraud networks: between $88 billion and $114 billion in economic damage for 2025 alone, making this one of the largest organised-crime industries on the planet.

That number is not a projection. It reflects documented fraud losses, money laundered through parallel financial systems, and broader harm to governance across the region. The UNODC Transnational Organized Crime Threat Assessment for Southeast Asia 2026 describes an industry so structurally mature it operates less like a criminal network and more like a distributed services sector.

How did this industry get so large so fast?

Criminal compounds in Myanmar, once centred at locations including KK Park and Shwe Kokko, were never permanently dismantled. When authorities applied pressure, operators moved. New compounds opened in Cambodia, Laos, and beyond, often rebuilt within weeks.

The result is a franchise-style model. Patrick Dannacher, chief executive of Indonesian information-security firm ITSEC Asia, describes the structure plainly: "Different groups specialise in different pieces, stolen data, malware, hosting infrastructure, recruitment and laundering, and monetise each piece independently. That's closer to a service industry than a single criminal operation."

Workers are trafficked into these compounds from more than 80 countries. Many are coerced at gunpoint into running scam call centres and romance-fraud operations targeting victims on every continent.

What technology is powering the operation?

Four tools, used in combination, turned a regional problem into a global one.

Cryptocurrency came first. The TRON blockchain, a fast and low-fee network, combined with Tether (a dollar-pegged digital coin), gave criminal operators a parallel banking system with limited regulatory visibility. Scam-related cryptocurrency inflows more than doubled in a single year, rising from $9.8 billion in 2024 to $22 billion in 2025.

Telegram-based criminal marketplaces followed. Platforms including Huione Guarantee and Xinbi Guarantee function as open storefronts where vendors advertise money laundering, stolen identity data, and fraud-as-a-service tools. Those platforms processed over $53 billion in transaction flows in 2025, up from roughly $6 billion in 2022.

Generative AI lowered the skill barrier to near zero. Xue Yin Peh, a senior intelligence analyst at blockchain-analysis firm Chainalysis, notes that these marketplaces openly advertise AI-powered deepfake tools capable of impersonating real individuals in live video calls. Voice cloning and AI-written social-engineering scripts are standard catalogue items.

Satellite internet services, Starlink among them, cut criminal operators' dependence on local telecoms infrastructure, removing one of the few technical levers available to law enforcement.

TechnologyCriminal applicationDocumented scale (2025)
TRON / TetherCross-border laundering, payments$22 billion in scam-related inflows
Telegram marketplacesFraud tools, stolen data, laundering services$53 billion in transaction flows
Generative AIDeepfakes, voice cloning, phishing scriptsOpenly advertised on criminal platforms
Satellite internetBypassing local telecoms monitoringActive across compound networks
Forced labourStaffing scam centresWorkers from 80+ countries

Why can't law enforcement shut it down?

Corruption is the structural answer, not an incidental one. The UNODC assessment characterises corruption inside local governments as a permanent feature of this criminal economy, not an occasional failure. Where criminal revenues represent a meaningful share of national economic output, operators gain leverage over officials that enforcement operations cannot easily overcome.

Peh of Chainalysis captures the cascade of harm: "A single scam operation can simultaneously destroy individual victims' savings, exploit trafficked workers through forced labour, launder proceeds through global financial infrastructure, and in certain instances, undermine governance and the rule of law."

When police move, criminal networks relocate. The cycle repeats.

Which controls failed, and what should defenders learn?

This is not purely a law-enforcement problem. These networks reach into everyday inboxes, investment apps, and dating platforms used by ordinary employees worldwide. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches involved a human element, and the fraud compounds described in the UNODC assessment are optimised to exploit exactly that vulnerability at industrial scale.

The primary control failure here is not technical. It is social engineering at a scope and sophistication that outpaces traditional awareness training. Romance-fraud scripts have been refined over years of iteration. Investment-scam lures are now A/B tested across thousands of simultaneous targets. AI-generated video impersonating a known contact or executive bypasses the gut-check that most people rely on when deciding whether to trust a message.

Security-awareness practitioners observe this consistently in live training programmes: staff recognise generic phishing templates far more readily than they recognise contextual, relationship-based manipulation. A message that arrives after weeks of warm, apparently personal contact does not trigger the same alarm as an unexpected email from a stranger. That gap between awareness of phishing and awareness of long-game social engineering is where these criminal networks operate.

Organisations that run regular, scenario-based awareness training which includes romance-fraud patterns, fake investment platforms, and impersonation via video or voice, give employees a practical mental model for exactly these situations.

A second control failure is the absence of verified reporting channels. Many employees who suspect they have been targeted, or who have already handed over credentials or funds, do not report the incident immediately because they feel embarrassed or fear blame. Reducing that friction, through clear, no-blame reporting processes, is a measurable organisational control.

A third failure is identity verification in financial workflows. Deepfake video and cloned audio mean that seeing and hearing a person is no longer a reliable verification method. Out-of-band confirmation, calling a known number rather than replying to the contact that initiated the request, must become standard practice before any funds movement or credential change is authorised.

What should individuals watch for right now?

These operations target every continent. Any unsolicited message offering unusually high investment returns, a romantic relationship that quickly steers toward financial requests, or a remote-work opportunity with exceptional pay should be treated as suspicious until independently verified.

Verify any financial platform through official regulatory registries before transferring money. If a job offer abroad requires surrendering a passport, contact national police immediately. Peh's summary at Chainalysis is worth repeating: a single operation can destroy individual savings, exploit forced labour, and corrode institutions simultaneously. The personal and systemic harms are inseparable.

For organisations managing staff who travel to Southeast Asia or who engage with international contacts in high-risk sectors, reviewing your security training programme for social-engineering scenarios specific to this threat pattern is a practical next step.

How to prepare your staff before the next deepfake call arrives

  • Run scenario-based training that includes romance fraud, fake investment platforms, and AI-generated impersonation, not just standard phishing simulations.
  • Establish clear, no-blame incident-reporting processes so staff act quickly when something feels wrong, rather than staying silent out of embarrassment.
  • Introduce out-of-band verification as a mandatory step before any funds movement or credential change, regardless of how convincing the request appears.

Train2Secure's awareness programmes include social-engineering scenarios built around exactly these threat patterns, so your team recognises long-game manipulation, not just obvious phishing.

Start free, no card required

Frequently asked questions

How much did Southeast Asian cyber-fraud networks cost the world in 2025?

The UNODC Transnational Organized Crime Threat Assessment for Southeast Asia 2026 estimates total economic damage at between $88 billion and $114 billion for 2025, covering fraud losses, laundered funds, and harm to governance.

How are criminal fraud compounds using AI against ordinary people?

Fraud networks now openly advertise AI-powered deepfake tools on Telegram-based marketplaces, allowing operators to impersonate known contacts or executives in live video calls and use voice cloning to make scam communications appear genuine.

Why has law enforcement struggled to dismantle these fraud networks?

The UNODC identifies corruption inside local governments as a structural feature of the criminal economy; when authorities apply pressure in one location, operators relocate and rebuild elsewhere, often within weeks.

What should an employee do if they suspect they have been targeted by a fraud operation?

Report the contact immediately through your organisation's incident channel without delay, do not transfer any funds or credentials, and verify any financial request by calling a known, pre-established number rather than replying to the suspicious contact.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress