Crime-as-a-Service lowers entry barriers to cybercrime world
Europol report sheds light on the rise of the Crime-as-a-Service business model

Europol Cyber Crime Centre (EC3) has sounded the alarm over the rise of the Crime-as-a-Service business model, and how it's lowering the barriers to entry into the world of cybercrime.
According to the organisation's 2014 Internet Organised Crime Threat Assessment (iOCTA), the model allows cybercriminals to develop sophisticated malicious products and services before selling them on to the less experienced to use via the "digital underground" world.
As a result, it's getting easier for less technically-minded criminals to engage with cybercrime, putting companies at even bigger risk.
"In a simplified business model, a cybercriminal's toolkit may include malicious software, supporting infrastructure, stolen personal and financial data and the means to monetise their criminal gains," the report states.
"With every aspect of this toolkit available to purchase or hire as a service, it is relatively easy for cybercrime initiates lacking experience and technical skills to launch cyber attacks not only of a scale highly disproportionate to their ability but for a price similarly disproportionate to the potential damage."
Many of these transactions take place on the "Dark Net", which the report states has fuelled evolution of cybercrime in recent years.
Cecilia Malmstrm, EU commissioner for Home Affairs, said almost anyone can become a cybercriminal these days, thanks to the proliferation of the anonymous and hidden internet.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"This put an even increasingly pressure on law enforcement authorities to keep up," she said.
"We need to use our new knowledge of house organised crime operates online to launch more transactional operations. We need to ensure that investigations into payment card fraud and online child abuse don't stop at national borders," Malmstrm added.
Professor Alan Woodward from the University of Surrey, who co-authored the report, added: "If agencies fail to mobilise to meet the threats highlighted in this report then organised cybercrime will gain the upper hand.
"However, if agencies work together, across borders, then we can use modern technologies to catch criminals, rather giving them a platform for ever more innovative forms of crime."
-
Third time lucky? Microsoft finally begins roll-out of controversial Recall feature
News The Windows Recall feature has been plagued by setbacks and backlash from security professionals
By Emma Woollacott Published
-
The UK government wants quantum technology out of the lab and in the hands of enterprises
News The UK government has unveiled plans to invest £121 million in quantum computing projects in an effort to drive real-world applications and adoption rates.
By Emma Woollacott Published
-
‘Europe could do it, but it's chosen not to do it’: Eric Schmidt thinks EU regulation will stifle AI innovation – but Britain has a huge opportunity
News Former Google CEO Eric Schmidt believes EU AI regulation is hampering innovation in the region and placing enterprises at a disadvantage.
By Ross Kelly Published
-
The EU just shelved its AI liability directive
News The European Commission has scrapped plans to introduce the AI Liability Directive aimed at protecting consumers from harmful AI systems.
By Ross Kelly Published
-
A big enforcement deadline for the EU AI Act just passed – here's what you need to know
News The first set of compliance deadlines for the EU AI Act passed on the 2nd of February, and enterprises are urged to ramp up preparations for future deadlines.
By George Fitzmaurice Last updated
-
EU agrees amendments to Cyber Solidarity Act in bid to create ‘cyber shield’ for member states
News The EU’s Cyber Solidarity Act will provide new mechanisms for authorities to bolster union-wide security practices
By Emma Woollacott Published
-
The EU's 'long-arm' regulatory approach could create frosty US environment for European tech firms
Analysis US tech firms are throwing their toys out of the pram over the EU’s Digital Markets Act, but will this come back to bite European companies?
By Solomon Klappholz Published
-
EU AI Act risks collapse if consensus not reached, experts warn
Analysis Industry stakeholders have warned the EU AI Act could stifle innovation ahead of a crunch decision
By Ross Kelly Published
-
Three quarters of UK firms unprepared for NIS2 regulations, study finds
News Senior management can be held personally liable for non-compliance under NIS2 rules
By Ross Kelly Published
-
US-UK data bridge: Everything you need to know
News The US-UK data bridge will ease the complexity of transatlantic data transfers
By Ross Kelly Published