Europol’s IOCTA 2025 shows how stolen data has become a core commodity in cybercrime, fueling fraud, account takeovers, extortion, and access brokering across dark web forums and encrypted channels. The report highlights the growing impact of infostealers, ClickFix, vishing, and generative AI, while also noting major law enforcement disruptions to Lumma, LabHost, Cracked, and Nulled. #Europol #IOCTA2025 #Lumma #LabHost #Cracked #Nulled #ClickFix #Infostealers
Keypoints
- Typical annual report structure: These reports usually begin with key findings and an executive overview, followed by an introduction that frames the threat landscape, a methodology section explaining data sources and limitations, thematic analytical chapters, a discussion section covering broader implications, and a conclusions section outlining policy and operational priorities.
- Key findings section: IOCTA 2025 centers on data theft as a major threat, showing that compromised data is both a target and a tradable asset, while social engineering, initial access brokering, and data brokerage remain central to the criminal ecosystem.
- Introduction and scope: The report argues that digitalization, AI, and crime-as-a-service are accelerating the scale and efficiency of cybercrime, with stolen data increasingly used for fraud, extortion, espionage, child sexual exploitation, and attacks on critical systems.
- Methodology: Europol based the assessment on EC3-supported cases, operational expert interviews, Advisory Group input, open-source intelligence, and other Europol threat analysis products, while noting that much of the ecosystem remains hidden in closed channels.
- What criminals are after: The report identifies credentials, accounts, personal information, remote access services, payment data, and browser/session artifacts as high-value targets because they enable account takeovers, lateral movement, impersonation, and further compromise.
- Data as a target: Stolen data is used for ransomware, espionage, financial theft, and reputational harm, especially when it belongs to businesses, governments, or users with sensitive records.
- Data as a means: Personal data is used to profile victims, improve fraud narratives, support business email compromise, facilitate identity theft, and intensify coercion in child sexual exploitation and romance fraud cases.
- Data as a commodity: Stolen information is routinely resold on underground markets, forums, and encrypted messaging channels, including credentials, credit cards, breached datasets, and access to compromised systems.
- Access acquisition methods: Criminals combine phishing, infostealers, malspam, malvertising, SEO poisoning, malicious apps, browser extensions, and exploit kits to harvest credentials and session data.
- Infostealer trend: Infostealers are emphasized as a key malware category because they steal credentials, tokens, cookies, and device fingerprints, enabling authenticated access and helping criminals bypass security controls.
- Operation Endgame / Lumma: Europol and Microsoft supported action against the Lumma infostealer ecosystem in 2025; Microsoft identified more than 394,000 Windows computers infected globally by Lumma.
- ClickFix and vishing: ClickFix social engineering is becoming more popular, tricking users into executing malicious commands, while vishing and spoofing services are increasingly used to obtain credentials and deliver malicious payloads.
- GenAI and LLM abuse: Generative AI is improving phishing quality, localization, personalization, and scalability, with LLM-generated phishing shown to achieve much higher click-through rates than human-written messages in cited research.
- System vulnerability exploitation: Threat actors also target unpatched public-facing infrastructure, e-commerce sites, VPNs, web apps, and payment environments through CVEs, digital skimming, replay attacks, MitM attacks, brute force, BIN attacks, and session hijacking.
- Actor landscape: The report describes a flexible criminal ecosystem in which data brokers, initial access brokers, ransomware affiliates, fraud actors, and hybrid threat actors reuse the same stolen assets in different ways.
- Initial Access Broker market: IAB activity reportedly surged in 2024, with the price of advertised access increasing by almost 50%, showing strong demand for compromised corporate access.
- Platform specialization: Underground markets are becoming more specialized, with some focusing on card data, others on access credentials or breached logs, while encrypted apps increasingly serve as negotiation and sales channels.
- Fraud-related commodities: Automated vending carts, card-testing services, phishing-kits, exploit kits, and OpSec manuals are widely sold to support payment fraud and credential theft.
- LabHost disruption: Europol helped disrupt LabHost, a phishing-as-a-service platform that exposed at least 40,000 phishing domains and had about 10,000 users worldwide.
- Access brokering and resale: Access listings may be sold in bulk or auctioned, and the same stolen data can be resold multiple times, creating repeated victimization and layered abuse.
- Data broker behavior: Vendors increasingly move between forums and E2EE channels to diversify revenue, preserve resilience against takedowns, and build reputation through listings and reputation systems.
- Forum reputation economy: Trust, status, deposits, reviews, and moderator roles are central to underground commerce, because buyers want reliable access and sellers need credibility to move high-value goods.
- Cracked and Nulled takedown: The report highlights the January 2025 disruption of Cracked and Nulled, two massive cybercrime forums that hosted stolen data, cybercrime tools, and AI-based attack utilities; Cracked had over 4 million users and Nulled more than 5 million.
- Open society risks: The report argues that abundant public data and voluntary sharing increase connectivity but also expose children and vulnerable people to grooming, profiling, doxxing, and exploitation.
- E2EE and investigative challenges: Criminal use of end-to-end encrypted apps reduces visibility for investigators and limits access to content, leaving metadata retention and lawful access as major policy pressure points.
- AI-enabled abuse and supply-chain risk: The discussion warns that criminals are abusing biometrics, deepfakes, adversarial fingerprints, and slopsquatting, where AI hallucinated package names are weaponized to contaminate software supply chains.
- Overall trend: The major takeaway is that cybercrime is becoming more modular, commercialized, and resilient, with data, access, malware, and trust all traded as interchangeable assets across a distributed criminal economy.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)