Skip to main content
Category: Predicate Offenses

Cybercrime

Also known as: Cyber Crime, Computer Crime
Simply put

Cybercrime is illegal activity that targets or makes use of computers, computer networks, or internet-connected devices. Common examples include identity theft, phishing, malware, hacking, and social engineering. It can involve using technology as the tool to commit an offense, or making the technology itself the target of the offense.

Formal definition

Cybercrime refers to criminal activity that either targets or uses a computer, a computer network, or a networked device, encompassing offenses in which technology is the instrument of the crime and those in which it is the object. Recognized categories include hacking, malware, identity theft, social engineering, phishing, and software piracy (the unauthorized reproduction or distribution of software). The definition here is descriptive and drawn from general and law-enforcement sources rather than from a single harmonized statutory instrument; the precise legal elements, offense classifications, and reporting mechanisms vary by jurisdiction and should be confirmed against the applicable national framework (for example, national cybercrime reporting portals and the mandates of investigative agencies).

Why it matters

Cybercrime sits at the intersection of predicate offending and money laundering, making it a central concern for AML and financial crime compliance functions. Offenses such as identity theft, phishing, and malware can generate illicit proceeds that criminals then seek to move through the financial system, and the same techniques are frequently used to compromise customer accounts, defeat authentication controls, and facilitate fraud. Because technology can serve either as the instrument of an offense or as its target, cybercrime blurs the line between the underlying criminal act and the financial flows that follow it.

For obliged entities, the significance is operational as well as legal. Compromised credentials, account takeover, and social-engineering schemes can result in transactions that appear legitimate on their face but originate from criminal activity, complicating customer due diligence, transaction monitoring, and suspicious activity detection. The proceeds of cybercrime may need to be identified and reported through the applicable suspicious activity or suspicious transaction reporting regime, and firms may face both regulatory expectations and reputational exposure where controls fail to detect the illicit use of their systems.

It is important to note that cybercrime is a descriptive typology rather than a single harmonized offense. The precise legal elements, classifications, and reporting mechanisms vary by jurisdiction, and detection of a suspicious pattern or a compromised account does not by itself establish that a crime has occurred. Firms should confirm specific obligations against the applicable national framework, including any national cybercrime reporting portals and the mandates of relevant investigative agencies.

Who it's relevant to

Compliance Officers
Compliance officers need to understand cybercrime as a potential predicate to money laundering and as a driver of fraud and account compromise. Proceeds of cybercrime may need to be identified and, where suspicion arises, reported through the applicable suspicious activity or suspicious transaction reporting regime. The specific obligations and reporting channels vary by jurisdiction and should be confirmed against the applicable national framework.
Financial Intelligence Analysts
Analysts assessing transaction patterns and alerts may encounter activity linked to identity theft, phishing, account takeover, or malware-enabled fraud. Recognizing how technology can be either the tool or the target of an offense helps in interpreting anomalies, though a suspicious pattern alone does not establish that a crime has occurred.
Investigators
Investigators handling matters with a cyber dimension work within jurisdiction-specific structures, including national cybercrime reporting portals and the mandates of designated investigative agencies. Because offense classifications and legal elements differ across regimes, investigators should confirm the applicable framework for any given matter.
Legal and Risk Professionals
Legal and risk professionals should treat cybercrime as a descriptive typology rather than a single harmonized offense. The precise legal elements and reporting mechanisms vary by jurisdiction, and specific requirements should be validated against the relevant national legislation and the mandates of the applicable authorities.

Inside Cybercrime

Predicate offence dimension
Cybercrime is frequently a predicate offence generating illicit proceeds that subsequently require laundering. In many jurisdictions cyber-dependent and cyber-enabled offences fall within the scope of predicate offences for money laundering, though the exact list of predicate offences varies by regime and should be confirmed against the applicable law.
Cyber-dependent versus cyber-enabled offences
A commonly drawn distinction: cyber-dependent crimes (such as hacking, malware deployment, and denial-of-service attacks) can only be committed using computers or networks, whereas cyber-enabled crimes (such as online fraud, phishing, and business email compromise) are traditional offences facilitated at scale by technology. The precise categorisation may differ across jurisdictions and enforcement bodies.
Laundering of cyber-derived proceeds
Proceeds from cybercrime are typically moved through the conceptual placement, layering, and integration stages, often using mechanisms such as money mules, virtual assets, and rapid cross-border transfers. This staged model is a conceptual framework, not a legal test for establishing an offence.
Obliged entity monitoring obligations
Financial institutions and other obliged entities are generally expected to detect, deter, and manage risks associated with cyber-derived funds through transaction monitoring, customer due diligence, and suspicious activity reporting. The specific obligations attach only to entities within scope of the relevant regime (for example, under the US Bank Secrecy Act and FinCEN rules, the UK Money Laundering Regulations, or the EU AML framework) and are not identical across jurisdictions.
Virtual asset and VASP relevance
Cybercrime proceeds are often channelled through virtual assets, bringing virtual asset service providers into focus. The FATF Recommendations set standards (not binding law) addressing virtual assets and VASPs, but domestic implementation and definitions vary and should be checked against local regulation.
Reporting and intelligence outputs
Suspected laundering of cybercrime proceeds may trigger a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) depending on the jurisdiction's terminology and framework. Such a filing reports suspicion and does not itself establish that any wrongdoing has occurred.

Common questions

Answers to the questions practitioners most commonly ask about Cybercrime.

Is cybercrime the same thing as cyber-enabled money laundering?
No. These are related but distinct concepts. Cybercrime broadly refers to offences committed using or against computer systems and networks, which may generate criminal proceeds. Cyber-enabled money laundering refers to the use of digital tools, channels, or infrastructure to place, layer, or integrate proceeds that may originate from cybercrime or from other predicate offences. Cybercrime can be a predicate offence that generates illicit funds, while money laundering concerns the subsequent handling of proceeds; conflating the two obscures the point at which AML obligations typically attach. The specific predicate offences and their treatment vary by jurisdiction and should be confirmed against applicable law.
Does detecting a cybercrime-related transaction pattern prove that a customer has committed a crime?
No. Typologies and red flags associated with cybercrime are indicators used to detect and manage risk, not proof of criminality. An alert, a match, or the identification of a suspicious pattern reflects a compliance judgment that a transaction or behaviour warrants further review, and in many jurisdictions may support the filing of a suspicious activity or suspicious transaction report. Whether an actual offence has occurred is a matter for criminal investigation and adjudication by the relevant authorities, and a compliance filing does not itself establish wrongdoing. Red flag lists should also not be treated as exhaustive.
How should an obliged entity incorporate cybercrime typologies into its transaction monitoring?
Cybercrime typologies are generally integrated as part of a risk-based approach, informing monitoring scenarios, thresholds, and behavioural indicators calibrated to the entity's products, channels, and customer base. Because typologies evolve and are not exhaustive, they are typically reviewed and updated periodically against emerging guidance from bodies such as FATF, national financial intelligence units, and applicable regulators. Monitoring outputs are indicators for further review rather than determinations of criminality, and calibration should be documented to reflect the specific obligations of the applicable regime.
What role does customer due diligence play in managing cybercrime-related risk?
Customer due diligence measures help an obliged entity understand who its customer is, the nature and purpose of the relationship, and the expected pattern of activity, which supports detection of anomalies that may be associated with cybercrime proceeds. Where higher risk is identified, enhanced due diligence may be applied to obtain additional information or scrutiny. CDD is a measure to detect, deter, and mitigate risk rather than a guarantee against misuse, and the precise scope and triggers for standard versus enhanced measures vary by jurisdiction and should be confirmed against the applicable regulation.
When may a suspicious activity or suspicious transaction report be warranted in a suspected cybercrime scenario?
A report is generally warranted when an obliged entity forms the relevant suspicion or knowledge, or meets the reporting threshold defined under its applicable regime, in relation to funds or transactions that may involve proceeds of crime. Terminology and triggers differ by jurisdiction: some regimes use the term suspicious activity report while others use suspicious transaction report, and the standard for filing may be framed as knowledge, suspicion, or reasonable grounds. The specific threshold, timing, and recipient authority should be confirmed against the applicable law, and filing reflects a compliance obligation rather than a finding of guilt.
How can a compliance function keep its cybercrime controls current as methods evolve?
Controls are typically kept current through periodic risk assessment, review of guidance and typologies published by relevant bodies, and updates to monitoring scenarios, staff training, and escalation procedures. Because cybercrime methods change and no single control eliminates financial crime risk, many programmes treat control maintenance as an ongoing process aligned to the risk-based approach rather than a one-time exercise. The frequency and specific requirements for review may be prescribed differently across regimes and should be confirmed against the applicable regulation or supervisory expectations.

Common misconceptions

Cybercrime is a distinct, standalone AML category with its own single global definition.
There is no single universally binding definition of cybercrime. It is generally treated as a source of predicate offences and its scope, categorisation, and treatment differ across regimes; practitioners should rely on the definitions in the applicable law rather than assume uniformity.
Detecting cyber-derived funds or filing a report demonstrates that a crime has been committed.
Alerts, screening matches, and SAR/STR filings reflect suspicion or risk indicators, not proof of criminality. Establishing a cybercrime or money laundering offence is a matter for the criminal-law process, which is separate from the compliance reporting function.
Strong cybersecurity controls or a single AML tool will prevent cybercrime-related laundering.
Controls such as monitoring, screening, and due diligence are measures to detect, deter, and mitigate risk; no single control guarantees prevention or eliminates financial crime risk. Effective management typically relies on layered, risk-based measures rather than any one safeguard.

Best practices

Adopt a risk-based approach that assesses exposure to cyber-derived proceeds across customers, products, and channels, and calibrate monitoring and due diligence accordingly rather than relying on any single control.
Confirm the specific predicate offence list, thresholds, and reporting terminology (SAR versus STR) against the regime applicable to your entity, recognising that these vary across the FATF standards, EU, US BSA/FinCEN, and UK frameworks.
Incorporate virtual asset and VASP-related typologies into monitoring where relevant, while verifying local implementation of virtual asset requirements against applicable regulation.
Treat typologies and red flags for cyber-derived funds (such as money mule activity or rapid cross-border transfers) as indicators to investigate, not as exhaustive lists or as proof of wrongdoing.
Coordinate compliance, fraud, and information-security functions so that intelligence on cyber-enabled and cyber-dependent offences informs AML monitoring, while keeping the compliance reporting role distinct from any criminal-law determination.
Document the rationale for filings and escalations clearly, ensuring reports convey suspicion accurately without implying that a match or alert establishes criminal conduct.