Login
Sign Up
Woofun AI reports that the United Nations Office on Drugs and Crime (UNODC) released its 'TOCTA 2026' assessment, titled 'Assessment of Transnational Organized Crime Threats in Southeast Asia,' in Bangkok on July 21, revealing that cyber fraud losses across East Asia, Southeast Asia, Australia, and New Zealand are projected to range from $88.3 billion to $114.1 billion in 2025. This figure represents a tripling of the estimated losses from 2023, which stood between $18 billion and $37 billion, with cryptocurrencies identified as the foundational financial infrastructure enabling this criminal economy. The upper bound of the 2025 estimate exceeds the GDP of several Southeast Asian nations, while even the lower bound of $88.
3 billion is 2.4 times higher than the peak estimates for 2023. Geographically, East Asia accounted for approximately 71% of these losses, whereas Australia and New Zealand contributed between 15.8% and 20.2%, and Southeast Asia itself accounted for 8.4% to 13.2%. Despite being a smaller share of total losses, Southeast Asia serves as the operational hub for these activities, with victims spanning the entire Asia-Pacific region and beyond. According to a separate assessment by the Treasury, Americans alone lost over $10 billion to fraud originating in Southeast Asia in 2024, highlighting the global reach of these networks.
The financial architecture of this crime syndicate relies heavily on USDT operating on the TRON chain, favored for its speed, low fees, and anonymity.
Woofun AI data shows that stablecoins accounted for 84% of all global illegal crypto transactions by 2025, with a single cryptocurrency service provider in the Mekong River basin processing between $49 billion and $64 billion in transactions between 2021 and 2024. This entity remains the largest of its kind in the Asia-Pacific region. Beyond centralized providers, decentralized networks known as CMLNs (Chinese: 洗钱网络) have expanded rapidly, processing $16.1 billion in illegal crypto assets through 1,799 active wallets in 2025.
These networks utilize cross-chain bridges, DeFi protocols, and mixers to layer money laundering operations. The barrier to entry has lowered significantly, with DeFi money laundering kits available for a few hundred dollars, capable of automatically splitting funds, performing cross-chain transfers, and obfuscating transaction trails. This technological accessibility has democratized the ability to launder large sums, making it difficult for traditional financial monitoring systems to track the flow of illicit funds.
National case studies illustrate the surging impact of these crimes across the region. In Thailand, cybercrime cases exploded from fewer than 20,000 in 2023 to over 380,000 in 2025, resulting in total losses exceeding $700 million. Malaysia experienced cyber fraud losses of approximately $730 million in 2025, double the previous year’s figure, with the number of cases surging by 87% to over 66,000. Singapore saw fraud losses reach $822 million in 2024, a 70.6% year-on-year increase, before dropping to $686 million in 2025 following legislative interventions.
These figures underscore the varying degrees of vulnerability and response effectiveness across different jurisdictions. While Singapore’s legislative measures appear to have had a temporary dampening effect, the overall trend in the region remains upward, with Thailand and Malaysia facing particularly severe escalations in both case volume and financial impact. The disparity in losses and case numbers highlights the need for coordinated regional responses rather than isolated national efforts.
The operational model of these criminal networks has evolved into a highly industrialized structure, described by Delphine Schantz, UNODC’s representative for Southeast Asia and the Pacific, as corporate franchising. This model features specialized teams handling money laundering, human trafficking, smuggling, and data theft, all sharing common financial and logistics infrastructure.
The organization is stratified into four tiers: a strategic leadership layer comprising overseas leaders and asset managers; an operational management layer responsible for regional coordination and maintaining corrupt relationships; a workforce consisting of recruiters, technicians, and coerced laborers; and a network of accomplices including lawyers, underground bank operators, cryptocurrency exchangers, and corrupt officials. At least 300,000 people are trapped in fraud parks across Southeast Asia, while another 6 million are involved in the broader criminal support ecosystem.
Victims from at least 80 countries and regions are lured to these parks through fake job advertisements, after which they are deprived of their freedom and forced to engage in cyber fraud. Data from Thailand’s anti-fraud center in 2025 indicates that the country identified 13,195 individuals from 83 countries through its national referral mechanism, with 4,407 confirmed as victims of human trafficking. Conditions in these parks are brutal; new arrivals have their passports and phones confiscated, undergo medical checks such as blood tests, and are confined to dormitory areas surrounded by barbed wire and military checkpoints.
Whistleblowers from the K99 Triumph City park reported being beaten and electrocuted, illustrating the extreme coercion employed to maintain control.
Recruitment networks have expanded globally, extending to transit hubs in Asia, the Middle East, and Africa, with advertisements now targeting job seekers in Europe and North America. These ads specifically seek individuals who speak German, French, Spanish, Italian, Dutch, Polish, Swedish, Norwegian, and English, reflecting a strategic effort to target victims from diverse linguistic backgrounds.
Criminal networks are also expanding into South America and Africa, with Asian criminal groups establishing physical fraud centers in South America and recruiting workers who speak Spanish and Portuguese. These groups have formed partnerships with local drug trafficking organizations, leveraging existing illicit infrastructure to facilitate their operations. This global expansion demonstrates the adaptability and resilience of these networks, which are able to exploit vulnerabilities in different regions and integrate with local criminal ecosystems to sustain their growth.
Technological evolution has further empowered these criminal enterprises, with the deployment of AI-driven deepfake and automated fraud systems. Malvertising incidents increased by 42% year-on-year in 2025, with criminals using legitimate advertising networks to distribute malware to large numbers of users. Previous reports by the United Nations News Agency have indicated that deepfake and voice cloning technologies have become weapons used in organized fraud. Screenshots of fraud recruitment advertisements claiming 'Collaborate sincerely to recruit insiders from public security agencies' have also appeared, suggesting an attempt to infiltrate law enforcement.
Criminal gangs utilize Starlink’s portability and independence from national telecommunications networks to maintain operations in remote areas such as Myanmar and Laos, allowing them to continue functioning even when local governments cut off traditional internet access. The Sulu-Sulawesi sea route, connecting Indonesia, Malaysia, and the Philippines, is used to transport technical equipment, including low-earth orbit satellite devices. ClickFix social engineering attacks surged by 517% in the first half of 2025, with organizations affiliated with the Lazarus Group adapting this technique into a variant called ClickFake Interview, targeting professionals in the cryptocurrency industry through fake recruitment processes.
48% of cybersecurity professionals consider Agentic AI—AI systems capable of independently planning, executing, and adjusting multi-step attacks—the biggest threat vector in 2026. The number of AI service providers in the guarantee market grew at an average annual rate of 1,900% between 2021 and 2024, generating $375.9 million in revenue from cryptocurrencies in 2024 alone.
Enforcement actions have intensified, but challenges remain. Within the first three months of its establishment, the Scam Center Strike Force of the DOJ’s Fraud Center seized $580 million in cryptocurrency. Cambodia arrested Chen Zhi, a key figure in a fraud network, and carried out one of the largest Bitcoin seizures in the country’s history. On the day the report was released, Thailand announced deeper cooperation with the U.S. FBI to combat global fraud networks.
In April 2026, the Treasury’s OFAC imposed sanctions on Cambodian Senator Kok An and his K99 group, along with Rithy Raksmei and 26 other individuals and entities, for using fraud parks to exploit forced labor from human trafficking victims in digital asset investment fraud and romance scams. Thailand’s Anti-Money Laundering Office (AMLO) and civil courts had previously issued temporary freezes on Kok An’s associated assets, valued at 13.07 billion Thai baht (approximately $407 million).
In February 2025, the Lazarus Group, linked to North Korea, stole around $1.5 billion in ETH from the cryptocurrency exchange Bybit and laundered it using the THORChain cross-chain protocol. Wallet drainer attacks stole $494 million in 2024, a 67% increase year-on-year, with over 300,000 wallets targeted. Special operations in Myanmar and Laos destroyed some fraud parks, but criminal networks quickly migrated to areas with weaker law enforcement.
Systemic challenges persist, as noted by Inshik Sim, UNODC’s chief analyst, who warned that the scale and complexity of the criminal economy are exceeding the design limits of existing response mechanisms. Criminal organizations’ ability to create their own stablecoins, build blockchain networks, and develop encrypted communication platforms means that freezing mechanisms—currently the main financial intervention tool used by the international community—may be becoming ineffective. Delphine Schantz believes that law enforcement agencies need to shift from targeting individual criminal acts to systematically tracking and seizing criminal proceeds, while extending regulatory frameworks to the underlying blockchain infrastructure rather than relying solely on cooperation with individual stablecoin issuers.
This shift requires a fundamental rethinking of how global regulation addresses decentralized financial technologies and the illicit uses to which they are put.
The existing response mechanisms are fundamentally limited by their design, which fails to account for the adaptive nature of these criminal networks. The international community and law enforcement agencies must move beyond addressing individual criminal acts and instead focus on dismantling the broader infrastructure that supports these operations. Regulatory frameworks need to be extended to cover the underlying blockchain infrastructure, ensuring that stablecoin issuers and other key players are held accountable for their role in facilitating illicit activities. Without such a paradigm shift, the growth of Southeast Asia’s crypto fraud empire will likely continue, posing an increasing threat to global economic security.