Cybercrime has evolved into a complex, borderless ecosystem that blends financial crime, technical intrusion, and geopolitical tension. While high-profile arrests and takedowns frequently make headlines, the broader picture of how law enforcement worldwide is responding to cybercrime has remained fragmented—until now.
A new large-scale analysis sheds light on this scattered fight. Drawing from 418 publicly announced law enforcement actions between 2021 and mid-2025, the research offers one of the most comprehensive open-source views to date of who is being targeted, what crimes are prioritized, and how authorities are responding.
Building a Global View of Cyber Enforcement
The dataset was compiled and validated by threat intelligence teams at Orange Cyberdefense, using official law enforcement announcements and reputable media reports. Each case was manually enriched with contextual details, including the type of crime addressed, enforcement actions taken, and demographic information on identified offenders where available.
Rather than focusing on isolated operations, the analysis aggregates global activity to identify patterns—revealing how cybercrime enforcement has matured into a coordinated, multi-layered effort involving governments, international coalitions, and private-sector partners.
The Crimes Law Enforcement Targets Most
The data shows a clear hierarchy in enforcement priorities. Cyber extortion, including ransomware, dominates global law enforcement activity, making it the most frequently addressed criminal act. Close behind are malware distribution and unauthorized system intrusion, reflecting continued focus on the technical foundations that enable large-scale cybercrime.
Authorities are also targeting the broader cybercrime ecosystem. Actions against criminal infrastructure providers, dark web marketplaces, and fraud networks highlight an effort to disrupt not only attackers, but also the services that sustain them. Meanwhile, increased attention to cryptocurrency misuse, money laundering, and stolen data trafficking signals growing recognition of the financial backbone behind cyber operations.
While financial motivation remains central, researchers note that the line between profit-driven cybercrime and politically influenced activity has blurred, particularly in response to global geopolitical developments.
Arrests, Takedowns, and Sanctions: How Authorities Respond
Arrests account for the largest share of enforcement actions, representing nearly one-third of all reported activity. This underscores law enforcement’s continued emphasis on individual accountability. Takedowns and formal charges together form another major portion, reflecting efforts to dismantle criminal infrastructure while advancing cases through the judicial system.
Other measures—such as sentences, seizures, and economic sanctions—demonstrate a broader enforcement toolkit. Notably, sanctions have increased steadily in recent years, especially in cases tied to cyber espionage and state-aligned operations, where traditional arrests may not be feasible.
Takedowns are most commonly associated with dark web platforms and malware infrastructure, often involving international coordination and highly visible actions designed to disrupt operations and deter future activity.
Who Leads the Global Cybercrime Fight?
The United States emerges as the most active player, appearing as the primary participant in nearly 45% of all documented actions. Agencies such as the Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) dominate the enforcement landscape, reflecting both capacity and transparency in public reporting.
Outside the U.S., a strong second tier includes Germany, the United Kingdom, the Netherlands, France, Spain, Ukraine, and Russia. European coordination through Europol and Eurojust plays a critical role in cross-border operations, while multinational task forces—often listed simply as “international” or “European”—underscore the collaborative nature of modern cyber enforcement.
Private organizations also play a pivotal role. Across the dataset, 74 distinct private-sector entities were identified as contributors, highlighting the growing importance of public-private partnerships in investigations, infrastructure takedowns, and attribution efforts.
What the Data Reveals About Cybercriminals
Demographic analysis offers insight into who is committing cybercrime—at least among cases that result in public enforcement actions. The majority of identified offenders fall between the ages of 18 and 44, with the 35–44 age group representing the largest share.
Younger offenders tend to engage more in technically exploratory activities such as hacking and DDoS attacks, while older cohorts are more frequently linked to ransomware, malware operations, cyber espionage, and money laundering—crimes that often require greater resources and coordination.
Nationality data, while inherently limited in a digital world, shows a strong concentration among a small number of countries. Russian nationals account for the largest single group, followed by offenders identified as American, Chinese, Ukrainian, and North Korean. Researchers caution that reporting bias and jurisdictional transparency heavily influence these figures.
A More Visible—but Still Incomplete—Global Response
Taken together, the findings illustrate a cybercrime enforcement landscape that is more active, diverse, and international than ever before. Law enforcement agencies are no longer focused solely on arrests; they are combining prosecutions, infrastructure disruption, sanctions, and collaboration with private companies to counter increasingly sophisticated threats.
At the same time, the research highlights ongoing challenges. Public reporting remains uneven across regions, younger offenders are underrepresented due to legal protections, and many operations occur behind the scenes without disclosure.
Still, the trend is clear: cybercrime is no longer treated as a niche or secondary issue. It is now a core law enforcement priority—one that requires badges, bytes, and, increasingly, coordinated global pressure to keep pace with an evolving threat landscape.