Fraud-as-a-Service: Why Blaming Victims Protects the Enablers

The listing could belong to any mid-market software company. There is a tiered pricing table. There is a changelog documenting the latest release, with bug fixes and a note about improved output quality. There is a refund policy, a customer-support handle that answers within hours, and testimonials from satisfied users describing exactly how much money the product helped them make. There is even a free trial. The only detail that does not fit the template of a legitimate software-as-a-service business is the product itself. What is being sold, on a subscription that costs less than a premium music streaming plan, is the ability to defraud strangers at industrial scale, personalised to each victim's job, location, and financial behaviour, generated on demand by a large language model whose safety training has been deliberately stripped away.

This is the shape of a shift that cybersecurity researchers have taken to calling Fraud-as-a-Service, and it is the subject of a July 2026 investigation by the Times of India and the specialist Indian cybercrime outlet The420.in. The investigation documented a fully commercialised ecosystem of criminal AI tools, sold through Telegram channels and dark-web marketplaces under names such as FraudGPT, WormGPT, EvilGPT, and DarkBard, packaged with the exact conveniences that made legitimate cloud software so successful: version updates, service tiers, live support, and an interface requiring no technical skill. The story is not that fraud has become possible. Fraud has always been possible. The story is that the practical barrier to committing sophisticated, personalised, AI-assisted fraud has collapsed to the price of a subscription, and that the people who built the supply chain have organised it to look, feel, and bill exactly like the legitimate technology industry it preys upon.

The important questions follow from that collapse rather than from the mere existence of the tools. If anyone with a payment method and an internet connection can now rent a fraud capability that a few years ago required real expertise and criminal connections, who ends up bearing the cost of that democratisation? And what structural changes to the technical, regulatory, or financial infrastructure would actually interrupt the supply chain, rather than repeating the tired official advice that potential victims should simply be more careful?

A Product History Written on Telegram

The commercial lineage of these tools is unusually well documented for a criminal industry, because it was advertised in public. In July 2023, a threat actor operating under the handle CanadianKingpin12 began promoting FraudGPT across underground forums and Telegram, marketing it as an all-in-one offensive toolkit for writing malicious code, building scam pages, and composing convincing fraudulent messages with, in the seller's phrasing, no boundaries. Netenrich analysts, who first surfaced the listing, reported a price of around 200 dollars per month or roughly 1,700 dollars per year, and a seller claiming several thousand confirmed sales. The same actor advertised a small family of related products, including DarkBERT and DarkBard, the latter a criminal counterpart to Google's Bard chatbot. WormGPT, its better-known sibling, had emerged slightly earlier and was built on an open-source model fine-tuned for business email compromise, the category of attack in which a fraudster impersonates a supplier or executive to redirect a payment.

What distinguishes the 2026 picture from that 2023 debut is maturation. The early tools were crude, expensive, and frequently scams in their own right, with sellers vanishing after taking a subscriber's cryptocurrency. The ecosystem The420.in describes has professionalised. It now offers custom dashboards from which a subscriber can orchestrate campaigns, ingesting parsed consumer datasets and generating thousands of unique phishing emails, texts, and voice-call scripts tailored to a target's profession, geography, and recent transactions. Capability that once had to be built in-house is now rented by the month, maintained by someone else, and delivered through an interface simple enough that the buyer need not understand what happens underneath. The criminal underground did not invent this model. It copied it, faithfully, down to the customer-support ethos.

The pricing reported in the investigation reflects that copying. A basic subscription is said to start at around 20 dollars per month and to include AI-generated phishing templates personalised to the victim, while a tier at around 160 dollars per month is described as bundling deepfake tools capable of defeating the identity checks banks and exchanges use to onboard customers. These figures should be read as reporting from the investigation rather than as independently audited prices, and they sit alongside the higher, historically documented FraudGPT rates. The tools are getting cheaper, easier, and more capable at once, precisely the trajectory that turned software from a specialist craft into a mass-market utility.

What Twenty Dollars Actually Buys

To treat a twenty-dollar phishing subscription as a novelty of the dark web that produces slightly better spam badly understates what has changed, and the misunderstanding matters because it shapes the defensive advice issued in response.

The old defensive folklore held that phishing could be spotted by its tells: clumsy grammar, generic greetings, obvious mismatches between a message and the organisation it claimed to represent. Those tells were artefacts of scale. A fraudster writing in a second language and blasting one template to a hundred thousand addresses produced text a careful reader could catch. Generative models dissolve that trade-off between scale and quality. KnowBe4, examining phishing emails detected between September 2024 and February 2025, found that 82.6 per cent contained AI-generated content, a jump the firm put at more than fifty per cent year on year; its April 2026 research put the figure at 86 per cent. The movement between those two readings is itself evidence of a share still climbing towards saturation rather than one that spiked and settled. The same research finds AI-written lures achieving markedly higher engagement than their human-written predecessors, with native-level grammar, appropriate register, and cultural context on demand. The advice to look for bad spelling is now advice to look for a weakness the attacker has already engineered away.

Personalisation is the second and more consequential capability. A message that references a target's actual employer, job title, city, and a plausible recent transaction is not a marginal improvement on generic spam; it is a different weapon, one that historically required either a skilled operator or a manual research effort that did not scale. The subscription model automates that research and folds it into the generation step, so that each of ten thousand recipients receives a lure calibrated to them individually. The most alarming tier reaches into the machinery of identity itself. Deepfake tools that fabricate a convincing identity-verification video are marketed as a way to defeat the know-your-customer checks meant to stop criminals opening accounts. That turns fraud from an act of persuasion into an act of impersonation at the infrastructure level, letting an attacker manufacture the accounts through which stolen money is received and laundered. The barrier that collapsed was never only the barrier to writing a convincing email. It was the barrier to industrialising every stage of the fraud pipeline, from the first message to the mule account that receives the proceeds.

The Evidence That This Is Cause, Not Coincidence

It is one thing to observe that criminal AI tools exist and that fraud is rising, and quite another to establish that the former is scaling the latter; sceptics reasonably ask whether the tools are hype layered over crime that would have happened anyway. The most rigorous attempt to answer that question is an academic paper catalogued on the arXiv preprint server under the identifier 2505.23733 and titled Unintentional Consequences: Generative AI Use for Cybercrime, whose authors, Truong Jack Luu and Binny M. Samuel, treat the public release of ChatGPT at the end of November 2022 as a natural experiment.

The researchers took two large real-world abuse datasets: more than 464 million malicious IP-address reports from AbuseIPDB, and 281,115 cryptocurrency scam reports from Chainabuse. They then treated the arrival of a powerful, publicly accessible generative model as a shock, and estimated the counterfactual trajectory of reported abuse had the model not been released. They found statistically significant increases in reported malicious activity after the shock across both datasets, including an immediate rise of over 1.12 million weekly malicious IP reports and roughly 722 additional weekly cryptocurrency scam reports, with sustained rather than transient growth in the crypto-scam series. The paper's conceptual contribution is a mechanism rather than a mere correlation. Generative AI, the authors argue, both creates new action possibilities for offenders and magnifies pre-existing malicious intent, by lowering the expertise required and raising the efficiency of each attack. Commoditisation does not create new criminals from nothing so much as it removes the friction that previously kept marginal offenders out and capped the output of committed ones.

Set against the market data, the mechanism becomes legible. Chainalysis, whose annual crypto-crime reports are among the most cited in the field, found that cryptocurrency scams received at least 14 billion dollars on-chain in 2025, up sharply from prior years, and projected the final figure could exceed 17 billion as more illicit addresses are identified. Crucially, the firm reported that scams with on-chain links to AI service providers generated on average about 3.2 million dollars per operation, roughly four and a half times more than scams without such links, and that the average scam payment more than tripled year on year. Europol's Internet Organised Crime Threat Assessment for 2026, published in April under the subtitle The evolving threat landscape: how encryption, proxies and AI are expanding cybercrime, reached a complementary conclusion in plainer language. Cybercriminals no longer need technical skills to succeed, because crime-as-a-service platforms supply everything from stolen data to step-by-step fraud tutorials. What the current edition adds is a measure of tempo: a widening velocity gap between law enforcement and offenders who use AI to automate attacks, personalise scams, and compress the time needed to launch an operation. Europol's word for the shift is industrialisation, and it notes that the dark web's marketplaces and forums have shown remarkable resilience despite sustained enforcement pressure. The commoditisation is not a projection. It is being measured.

The Country Where the Bill Arrived First

If the abstraction of a global fraud supply chain needs a concrete ledger, India provides one, which is why the original investigation is Indian. The country's Ministry of Home Affairs reported that cybercrime cases rose roughly 24 per cent in 2025, with reported losses of about 22,495 crore rupees, roughly 2.7 billion dollars, spread across more than 28 lakh, or 2.8 million, complaints. Investment-related frauds dominated, accounting for around 76 per cent of the total financial loss, with fake trading applications, Ponzi structures, crypto traps, and messaging-group schemes on Telegram and WhatsApp draining accounts within days.

India is an instructive case precisely because it built, faster than almost anywhere, the two conditions that AI-enabled fraud exploits. The first is instant, irrevocable payment. The Unified Payments Interface, the real-time rails that made digital payments ubiquitous across Indian daily life, moves money in seconds, without the settlement delay that elsewhere occasionally gives a defrauded victim or an alert bank a window to intervene. The second is a vast population newly brought online, transacting in dozens of languages, for whom the old visual tells of a scam were never reliable guides in the first place. Personalised, fluent, native-language lures generated by a subscription tool are not a marginal threat in that environment; they are a precision instrument aimed at its softest point. The Indian Cyber Crime Coordination Centre has leaned on the countermeasure available to it, assembling a registry of suspected criminal identifiers shared with banks; lenders contributed millions of suspect identifiers and mule-account flags, helping block fraudulent transactions worth thousands of crore. That is meaningful defensive work. It is also, revealingly, downstream work, aimed at catching the money after the fraud has already been manufactured, because the manufacturing happens on infrastructure that sits well outside any single national regulator's reach.

Where the Losses Actually Land

Who bears the cost of this democratisation has, until recently, had an uncomfortable default answer: the victim, alone. The prevailing model in most jurisdictions treated an authorised push payment, one the account holder was tricked into approving themselves, as the customer's responsibility, on the reasoning that the bank had followed instructions. The fraud, in this framing, was a personal misfortune, and the official response was educational. Be vigilant. Verify before you pay. Hang up and call back.

That default is regressive in a specific and under-examined way. When the cost of a systemic failure is assigned to whoever happened to be standing where it struck, the burden falls hardest on those least able to model the threat, and the data bears this out. The United States Federal Bureau of Investigation's Internet Crime Complaint Center recorded almost 21 billion dollars in reported losses for 2025, a 26 per cent rise on the previous year, across 1,008,597 complaints, the first time the centre has passed a million in a single year. Investment fraud, much of it involving cryptocurrency, remained the largest single loss category at 8.65 billion dollars. It is the distribution beneath those totals that makes the point. People aged sixty and over filed 201,266 complaints and lost 7.7 billion dollars, more than any other age group, their losses up around 59 per cent on 2024 against a 37 per cent rise in their complaint count, which is what happens when each attempt is better aimed rather than merely more numerous. That cohort filed a fifth of all complaints and absorbed 37 per cent of all losses, averaging 38,501 dollars each against an all-ages average of 20,699. The 2025 report also introduced AI-related as a formal crime descriptor for the first time, logging over 22,000 complaints and nearly 900 million dollars in losses. The pattern is the industrialisation thesis made human, and the bureau has now begun to measure it directly. When personalised, fluent, emotionally calibrated fraud can be produced for pennies and aimed at millions, the people it reaches are not a representative cross-section who failed a vigilance test. They are disproportionately the old, the isolated, the financially anxious, and the newly connected, selected because the tooling makes selecting them cheap.

Telling that population to be more careful is not merely inadequate; it is an implicit policy choice about where to place the cost. It leaves the loss with the person who has the least capacity to prevent it and the least ability to absorb it, while asking nothing of the parties that operate the infrastructure through which the fraud flows: the model providers whose systems were bent to the task, the platforms hosting the marketplaces, the payment rails moving the money, and the exchanges converting it into something untraceable. The current answer was never neutral. It was a liability regime that happened to spare the enablers, and it is that regime, rather than the credulity of victims, that the structural interventions worth discussing are designed to rewrite.

Making the Enabler Pay

The most instructive experiment in shifting that liability is British, and it has now been evaluated. On 7 October 2024, the United Kingdom became the first country to impose a mandatory reimbursement requirement for authorised push payment fraud. Under rules set by the Payment Systems Regulator, banks and payment firms must reimburse most victims of APP scams, up to a limit of 85,000 pounds, with the cost split evenly between the institution that sent the payment and the one that received it. By making the receiving bank liable for half of every reimbursement, that fifty-fifty split creates a direct financial incentive for institutions to police the mule accounts through which fraud proceeds are collected, a part of the chain that previously bore almost no consequence for its role.

The logic is the ordinary economics of externalities. When the cost of fraud sits entirely with victims, every other party in the chain has an incentive to shift the risk onward and invest as little as possible in stopping it. Reassign that cost to the institutions best placed to detect and interrupt the flow, and they suddenly have a reason to build the controls they had long treated as optional. The predictable industry objection, that mandatory reimbursement invites opportunistic claims and could even subsidise fraud, has to be managed through carve-outs for first-party fraud and gross negligence.

Until this month, that reasoning had to be taken largely on trust. On 1 July 2026 the Payment Systems Regulator published an independent evaluation of the scheme's first year, and its findings are the empirical payoff for the argument. The policy was estimated to have cut APP fraud losses by 73 million pounds a year and to have reduced the number of APP scams by nearly 35,000, with losses sent over Faster Payments falling around 21 per cent following implementation. Of the money lost to APP scams and claimed back from a payment firm, 88 per cent was returned to victims, against 66 per cent in the equivalent period of 2023/24. Overall reimbursement rates rose from 54 to 65 per cent; for claims within the policy's scope, firms now reimburse 97 per cent, settling around 84 per cent of claims within five days and 97 per cent within 35 days. The predicted surge in opportunistic claiming did not materialise in the first year's evidence. That matters most, because it distinguishes relocating a cost from reducing one: liability moved onto the enablers did not shuffle the bill around the system, it produced measurably less fraud, which is what should happen when the party best placed to prevent something finally becomes the party that pays. The regime continues under new management, HM Treasury's April 2026 package consolidating the Payment Systems Regulator into the Financial Conduct Authority.

That reimbursement mandate did not arrive alone, and its companion measure illustrates how liability and technical control reinforce one another. Confirmation of Payee, the account-name-checking service Britain required its largest banks to adopt from 2020, now covers well over ninety-nine per cent of Faster Payments and CHAPS transactions after successive expansions, according to the regulator. It verifies, before a payment is sent, that the name on the destination account matches the name the payer believes they are paying, closing off a category of impersonation on which many scams depend. On its own, a name check is easily circumvented by a determined criminal. Paired with a reimbursement rule that gives banks a reason to act on the signals it produces, it becomes part of a system in which the enablers, rather than the victims, carry the cost of failure and therefore have a reason to prevent it.

Choking the Money at the Off-Ramp

Liability rules interrupt the fraud where it touches the regulated banking system. A great deal of it, however, is designed precisely to avoid that system, routing proceeds through cryptocurrency, and especially through stablecoins, the dollar-pegged tokens that have become the preferred settlement layer of online crime. Chainalysis has reported that stablecoins now account for the majority of illicit on-chain value, which makes the mechanisms for controlling them a second, distinct chokepoint in the supply chain, and one with a surprising property: some stablecoins can be frozen at the point of issuance.

The clearest demonstration is the T3 Financial Crime Unit, a partnership launched in September 2024 between the stablecoin issuer Tether, the TRON blockchain network, and the blockchain-analytics firm TRM Labs. Because Tether can freeze its own tokens at the issuer level, a flagged wallet can be immobilised on-chain, in a way that has no equivalent in the cash economy. The unit has frozen more than 450 million dollars in illicit crypto since its launch, a figure Tether reconfirmed in May 2026, working with law enforcement across 23 jurisdictions and, in some cases, executing freezes within 24 hours of a request; it intercepted 43.9 per cent more illicit proceeds in 2025 than in the year before. The Financial Action Task Force, which sets global anti-money-laundering standards, has cited the arrangement as a model of public-private disruption. The same capability that privacy advocates rightly find troubling, a private issuer able to freeze funds on demand, is also the single most effective lever yet demonstrated for stopping fraud proceeds mid-flight.

The more durable structural intervention sits at the conversion points, the on-ramps and off-ramps where crypto meets conventional money. Fraud proceeds are only useful once converted into spendable currency, and that conversion overwhelmingly happens at exchanges, which are increasingly regulated financial institutions subject to know-your-customer and anti-money-laundering obligations. Rigorously enforced identity checks at those chokepoints do more to interrupt the supply chain than any amount of consumer education, because they attack the economics of the enterprise: fraud that cannot be cashed out is fraud that does not pay. This is why the deepfake KYC-bypass tier matters so much. Criminals are investing in defeating identity verification precisely because it is one of the few controls that genuinely threatens their business model, and that investment is itself confirmation that the chokepoint works.

The Fight Over the Model Layer

Upstream of the money sits the capability itself, the model that writes the lure and fabricates the verification video, and this is where interventions are least mature and most contested. The uncomfortable fact is that the tools sold under names such as WormGPT are frequently not exotic bespoke systems but ordinary open or leaked models with their safety training removed, wrapped in a friendly interface. That makes the model layer a genuine point of leverage and a genuinely hard problem at once.

For the major commercial providers, the relevant control is the robustness of guardrails against jailbreaking, the practice of coaxing a model into producing content its policies forbid. Every serious frontier developer now invests heavily in refusal training and adversarial testing, and the effectiveness of that work determines whether a criminal can simply use a mainstream model rather than a specialist criminal one. But guardrails on hosted models do nothing about the parallel ecosystem of open-weight models that can be downloaded, fine-tuned, and stripped of safety behaviour on a subscriber's own hardware, outside any provider's control. That is the unresolved tension at the centre of AI governance: the same openness that democratises beneficial capability also democratises the criminal kind, and no purely technical fix reconciles the two.

The intervention with the most regulatory momentum targets output rather than the model, through provenance. The Coalition for Content Provenance and Authenticity, an open standard backed by Adobe, Microsoft, the BBC, and others, attaches cryptographically signed metadata to a media file, recording who created it, with what tools, and whether AI was involved, a tamper-evident record known as Content Credentials. The European Union has given the approach legal teeth. Under Article 50 of its AI Act, whose transparency obligations become applicable from 2 August 2026, deployers who use AI to create deepfakes must disclose that the content is artificially generated, and the Commission's draft Code of Practice explicitly points to C2PA-style marking as the mechanism. That date survived a deregulatory round. The Digital Omnibus on AI, adopted by the European Parliament on 16 June 2026 and by the Council on 29 June, postponed the Act's high-risk obligations, pushing Annex III to 2 December 2027 and Annex I to 2 August 2028, but left the Article 50 transparency duties on their original timetable. The one exception is narrow: the watermarking and machine-readable-marking requirement under Article 50(2) applies from 2 December 2026 for systems already on the market at 2 August 2026. Deepfake disclosure and provenance marking, in other words, were among the few duties judged too important to delay.

The limitations are equally clear. Provenance is a voluntary declaration that a criminal will simply decline to make, watermarks can be degraded, and social platforms routinely strip metadata on upload. A provenance standard does not stop a fraudster generating a fake KYC video. What it does, if adoption becomes widespread, is invert the default, allowing verification systems to treat unsigned or unverifiable media with suspicion rather than credulity, which raises the cost and lowers the yield of synthetic impersonation. That is a supply-chain intervention, aimed at the value the tool produces rather than at scolding the person it targets.

The Platform That Blinked

Between the model and the money sits distribution, and for the Fraud-as-a-Service economy the channel of choice has been Telegram, whose encrypted messaging, large public channels, and long-standing reluctance to moderate made it an ideal marketplace. What happened to that channel is the clearest illustration that platform behaviour is a policy variable rather than a fixed feature of the internet.

In August 2024, French authorities arrested Telegram's co-founder Pavel Durov at an airport near Paris and subsequently indicted him on charges that included complicity in the distribution of illegal content and in organised criminal activity conducted through the platform, on the theory that its refusal to cooperate had made it a haven for fraud and worse. The investigation remains open as of July 2026, with no trial date set, Durov questioned for a fourth time this month and still rejecting the charges. Whatever the eventual legal outcome, the operational effect was immediate. Within weeks, Telegram revised its policy to state that it would hand over users' IP addresses and phone numbers to authorities in response to valid legal requests, extending cooperation from the narrow category of terrorism to fraud and other cybercrime. Reporting on the platform's transparency data showed fulfilled law-enforcement requests rising steeply in the months that followed. A platform that had positioned non-cooperation as a principle discovered, under sufficient legal pressure on an individual, that cooperation was possible after all.

The marketplaces on which criminal tools are sold are not forces of nature; they are operated by identifiable entities that respond to incentives, and the incentives can be changed. Coordinated takedowns of dark-web markets impose real if temporary costs, fragmenting communities and eroding the trust on which any marketplace depends. Europol's finding that those marketplaces have nonetheless proved remarkably resilient is the honest qualifier: the costs are real, and they are also absorbed. Sustained legal pressure on the platforms that knowingly host criminal commerce, and on the intermediaries that process payments for them, attacks the distribution layer of the supply chain directly. None of this eliminates the underground. It raises the friction, and friction, restored to a system that has spent a decade removing it, is precisely the point.

Interrupting a Supply Chain Rather Than Scolding Its Victims

Assemble the parts and a picture emerges very different from the individualised, be-careful framing that has dominated the public response to fraud. What the Times of India investigation described is not a wave of cleverer criminals but a supply chain, with distinct and separable stages: a model layer that manufactures the capability, a distribution layer that sells it, a targeting layer that finds and personalises the victims, and a settlement layer that collects and launders the proceeds. Each stage has a chokepoint. Each chokepoint has at least one demonstrated intervention. And every one of those interventions places the cost of prevention on an enabler with the leverage to act, rather than on a victim with none.

Seen this way, the choice a society faces is not between accepting fraud and achieving the impossible task of making millions of individuals immune to personalised deception. It is a choice about where in the chain to concentrate pressure. The British reimbursement mandate, with a first-year evaluation now behind it, demonstrates that liability can be relocated onto financial institutions, that they respond by building controls, and that the fraud itself measurably falls as a result. The T3 freezing mechanism and exchange-level identity checks demonstrate that the settlement layer can be squeezed, which is why criminals are paying to defeat it. The EU AI Act's provenance requirements demonstrate that the output of the tools can be made costlier to weaponise. The pressure applied to Telegram demonstrates that the distribution layer bends when the legal cost of hosting crime rises high enough. None of these is sufficient alone. Fraud will migrate to whichever stage is left unguarded, which is why a piecemeal, single-lever response fails and why the interventions have to be understood as a system answering a system.

The deeper point is one about honesty in assigning cost. For as long as the losses from AI-enabled fraud are treated as the private misfortune of the people unlucky enough to be targeted, the enablers face no bill and therefore build no defences, and the externality flows downhill to the old, the isolated, and the newly connected. The technologies that could interrupt the supply chain already exist and are, in places, already working. What has been missing is the decision to make the parties who profit from the infrastructure carry the cost of its abuse, rather than leaving that cost with whoever happened to open the message. A subscription that turns anyone into a fraudster is a market signal. It says the friction that once protected people has been engineered out, deliberately and for profit. Restoring that friction, at the model, the marketplace, the payment rail, and the off-ramp, is the work. Advising the target to be more careful is what a society does instead of the work.

References and Sources

  1. The420.in, “Renting the Exploits: How Fraud-as-a-Service Platforms Turned Digital Crime Into a Subscription Business,” July 2026. https://the420.in/fraud-as-a-service-cybercrime-subscription-business-ai-phishing/
  2. The420.in, “Fraud at the Speed of UPI: How AI Is Supercharging India's Cybercrime Boom,” 2026. https://the420.in/ai-fraud-real-time-digital-payments-india-cybercrime/
  3. Netenrich / SecureOps, “FraudGPT: The Villain Avatar of ChatGPT,” 2023. https://www.secureops.com/blog/ai-attacks-fraudgpt
  4. Dark Reading, “'FraudGPT' Malicious Chatbot Now for Sale on Dark Web,” 2023. https://www.darkreading.com/threat-intelligence/fraudgpt-malicious-chatbot-for-sale-dark-web
  5. Huntress, “What Is WormGPT?” Cybersecurity 101. https://www.huntress.com/cybersecurity-101/topic/wormgpt
  6. KnowBe4, “KnowBe4 Research Finds 86% of Phishing Attacks are AI Driven,” April 2026. https://www.knowbe4.com/press/knowbe4-research-finds-86-of-phishing-attacks-are-ai-driven
  7. Truong Jack Luu and Binny M. Samuel, “Unintentional Consequences: Generative AI Use for Cybercrime,” arXiv preprint 2505.23733, revised December 2025. https://arxiv.org/abs/2505.23733
  8. Chainalysis, “2026 Crypto Crime Report: Scams,” 2026. https://www.chainalysis.com/blog/crypto-scams-2026/
  9. Infosecurity Magazine, “Impersonation Fraud Drives Record $17bn in Crypto Losses,” 2026. https://www.infosecurity-magazine.com/news/impersonation-fraud-record-17bn/
  10. Europol, “Internet Organised Crime Threat Assessment (IOCTA) 2026 — The evolving threat landscape: how encryption, proxies and AI are expanding cybercrime,” 28 April 2026. https://www.europol.europa.eu/cms/sites/default/files/documents/IOCTA-2026.pdf
  11. The Print, “Cybercrime saw 24% spike in 2025. Indians lost Rs 22,495 crore, mainly in investment scams,” 2026. https://theprint.in/india/cybercrime-saw-24-spike-in-2025-indians-lost-rs-22495-crore-mainly-in-investment-scams/2859930/
  12. Insights on India, “Cybercrime in India 2025: 24% Spike, ₹22,495 Crore Lost,” 21 February 2026. https://www.insightsonindia.com/2026/02/21/cybercrime-in-india/
  13. Federal Bureau of Investigation, “Cryptocurrency and AI Scams Bilk Americans of Billions” (2025 IC3 Annual Report), April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  14. Internet Crime Complaint Center, “2025 IC3 Annual Report” (PDF). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  15. Payment Systems Regulator, “Consolidated policy statement: APP scams reimbursement requirement (PS25/5),” May 2025. https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf
  16. Payment Systems Regulator, “One year on: Impact of APP reimbursement on victims,” 1 July 2026. https://www.psr.org.uk/news-and-updates/latest-news/news/one-year-on-impact-of-app-reimbursement-on-victims/
  17. A&O Shearman, “The UK's Authorised Push Payment (APP) Fraud Reimbursement Scheme.” https://www.aoshearman.com/en/insights/ao-shearman-on-fintech-and-digital-assets/the-uks-authorised-push-payment-app-fraud-reimbursement-scheme
  18. Payment Systems Regulator, “Anti-fraud tool Confirmation of Payee expanded to hundreds of more firms.” https://www.psr.org.uk/news-and-updates/latest-news/news/anti-fraud-tool-confirmation-of-payee-expanded-to-hundreds-of-more-firms/
  19. TRM Labs, “T3 Financial Crime Unit: A Model for Public-private Disruption in the Age of Stablecoins.” https://www.trmlabs.com/resources/blog/t3-financial-crime-unit-a-model-for-public-private-disruption-in-the-age-of-stablecoins
  20. Tether, “$450 Million Frozen And Counting: T3 Financial Crime Unit Continues Global Crackdown on Illicit Crypto Flows.” https://tether.io/news/450-million-frozen-and-counting-t3-financial-crime-unit-continues-global-crackdown-on-illicit-crypto-flows/
  21. European Union, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems,” EU AI Act. https://artificialintelligenceact.eu/article/50/
  22. Greenberg Traurig LLP, “Deepfakes, Chatbots, AI-Generated Text: European Commission Details Transparency Obligations Under the AI Act,” June 2026. https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act
  23. Coalition for Content Provenance and Authenticity, “C2PA and Content Credentials Explainer 2.2,” 22 April 2025. https://spec.c2pa.org/specifications/specifications/2.2/explainer/_attachments/Explainer.pdf
  24. Wikipedia, “Arrest and indictment of Pavel Durov,” 2024. https://en.wikipedia.org/wiki/Arrest_and_indictment_of_Pavel_Durov
  25. Dark Reading, “Sharing of Telegram User Data Surges After CEO Arrest,” 2025. https://www.darkreading.com/cybersecurity-operations/sharing-telegram-user-data-surged-after-ceo-arrest

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...