Law enforcement agencies can no longer keep up. This is probably the main lesson to be drawn from Europol’s latest annual report, which assesses the threat of online organized crime over the past year. The accelerating pace of cybercrime presents progressively sophisticated threats to society, with harmful implications both online and offline,” the European criminal police agency stresses in the introduction to its 43-page document. This “introduces additional challenges for law enforcement, which must overcome the widening “velocity gap.”
Authorities have reason to be concerned: the rise of artificial intelligence is not only benefiting businesses, but also criminals of all kinds, who now use it extensively to carry out increasingly elaborate attacks. To do so, they do not use the mainstream models we know, such as ChatGPT, Gemini or Claude—they create (or buy access to) malicious language models designed to “remove any ethical constraints and filters” of existing AIs. Models resold on the dark web are thus tweaked so that they can provide complete guides on how to carry out online fraud, or on how to set up infrastructures enabling the evasion of authorities, among other things.
AI, master of scams
AI is particularly prolific in three areas. The first is none other than online fraud. According to Europol, the most seasoned scammers tend to combine their gigantic “SIM farms” (these apartments where thousands of SIM cards are hidden, used to anonymously send millions of scam SMS messages and calls) with AI-generated content.
In this way, they manage to redirect their victims via SMS to fake websites created by AI, which look exactly like government sites—the corrupted models drawing on website source codes to replicate them effectively. Beyond these fake sites, there are rising cases of AI-assisted identity theft, particularly when scammers seek to impersonate bank advisers or police officers.
The second area is, unsurprisingly, ransomware, malicious software that blocks access to personal or corporate data in order to force their owners to pay a ransom. New hackers no longer hesitate to assemble their ransomware by exploiting AI, which readily provides them with code. Artificial intelligence also enables them to adapt to different security protocols. Europol identified no fewer than 120 active ransomware groups in 2025, an unprecedented number.
Entire communities of pedophiles
The third area where AI excels? The generation of child sexual abuse (CSAM) material. Pedophiles are increasingly asking malicious models to create, for their personal deviance, images depicting children being sexually abused. There are two main types of AI-generated CSAM, either fully synthetic or partially synthetic. The latter is usually generated with image-to-image models that are able to modify existing images and produce AI-altered CSAM,” Europol specifies.
The agency adds in its report that many web developers and other AI specialists sell their technical skills to the highest bidder. Once paid, they then feed malicious models with child sexual abuse material (by having them draw on image banks filled with images of children), or provide ready-to-use prompts capable of instantly generating highly specific content. In order to overcome content moderation and obtain accurate results, AI-generated CSAM is often produced in offline models trained with authentic sexual abuse material.”
These criminal contents are shared within vast online communities. The criminal police agency cites the example of a community run by a 28-year-old suspect, frequented by 1,500 individuals from 29 different countries skilled in artificial intelligence. The community had set up a paid subscription allowing each member to access AI-generated child sexual abuse content. The site manager was arrested in 2024 in Denmark, and further operations in 2025 led to the identification of 273 suspects worldwide.
Another community, for its part, is still active: “The Com,” which operates several sites on the dark web. Mainly composed of children and teenagers aged 8 to 17, recruited by adults on certain networks and online video games, these sites promote all types of violence against children and encourage members to post photos of themselves naked or engaging in sexual acts. Some engage in criminal activities for money or in search of belonging to the community, Europol explains. Once sensitive information and compromising images are shared by the victim, criminals use them to force the child to produce more sexual content or to commit violent acts. Despite the seriousness of these acts, the “The Com” network manages to evade authorities by constantly moving its activities between different digital spaces and on encrypted communication channels, according to Europol.
Another platform mentioned is Kidflix. It was a streaming platform on the dark web, dismantled by law enforcement in 2025. Between 2021 and its shutdown, this platform, which offered users free, “premium” and “administrator” accounts, recorded 1.8 million users and 80,000 child sexual abuse videos uploaded. With a basic account, users only had access to previews or low-quality videos. To obtain full access to the site, users had to be active on the platform (uploading videos, likes, comments). In doing so, users earned digital coins, called ‘candies,’ and after accumulating a certain amount, they obtained a premium account. The second option was to pay in cryptocurrencies, Europol explains.
International coalition of hackers
It must be said that cryptocurrencies remain the preferred means of payment for cybercriminals of all kinds, despite significant market fluctuations in 2025. To offset this, hackers have deployed large-scale “cryptocurrency drainers”: tricked into downloading them, crypto holders who fall victim see their digital wallets emptied instantly.
Beyond the multiplication of such attacks, authorities have observed a new phenomenon in cybercriminal circles: the formation of coalitions among international hackers. In August 2025, three formidable hacking groups (Scattered Spider, Lapsus$ and the ShinyHunters) officially announced that they had joined forces on the dark web. They are notably known for having respectively targeted U.S. healthcare providers, major firms such as Microsoft and Samsung, or for having siphoned off one billion customer records from Salesforce. In September 2025, three other groups (LockBit, Qilin and DragonForce) also sealed a partnership.
It is worth noting that despite raids and dismantling operations by law enforcement worldwide, illegal dark web platforms remain just as active. While major platforms show some signs of contraction, with a reduced “average lifespan,” their users no longer hesitate to move to smaller and more specialized platforms.
Europol also cites the case of Archetyp Market, a platform dismantled in June 2025. Before its closure, it had hosted 600,000 users worldwide, and its transaction volume had exceeded €250 million since its creation in 2020, thanks to the mass sale of fentanyl and other opioids. Shortly after its dismantling, Abacus Market and MGM Grand also shut down. But a new marketplace, named BlackOps, was launched shortly afterward in July 2025, Europol notes. Immediately, this new site offered 41,942 items and reached 63,979 listings by the end of November 2025. Proof, if any were needed, that cybercriminals unfortunately remain one step ahead of international law enforcement.





