As of 2026-07-21 22:37 UTC, a new United Nations Office on Drugs and Crime assessment puts 2025 scam losses across East Asia, Southeast Asia, Australia, and New Zealand at $88.3 billion to $114.1 billion. The primary assessment, corroborated by Associated Press and Reuters reports on Tuesday, places that range inside a wider finding: criminal groups are combining fraud, trafficking, data harvesting, underground banking, and money laundering through shared services that travel more easily than any one scam compound.[1][2][9]
The number is enormous. It is also an estimate, not a count of cash found in raids, criminal profit, or every victim worldwide.
The report's more useful warning is therefore about movement. UNODC says enforcement pressure has not dismantled the underlying infrastructure but has displaced and dispersed it: operations have downsized or relocated around established hubs, while the criminal model has separately expanded toward Timor-Leste, Pacific Island states, and parts of Africa. The immediate decision is whether governments, banks, telecoms, platforms, and investigators keep scoring visible raids—or start measuring whether the network can still recruit people, reach victims, and move stolen money afterward.[1][2][9]
What Changed—and How Confidently We Know It
| Time and source | Finding | Confidence boundary |
|---|---|---|
| July 21, 2026 — new UNODC assessment, corroborated by AP and Reuters | Estimated 2025 scam losses in the covered Asia-Pacific economies were $88.3–114.1 billion. People from at least 80 countries and territories have been identified in Mekong-region scam compounds, and recruitment adverts are reaching beyond Asian-language labour pools.[1][2][9] | High on what the report states; bounded on precision. The primary assessment is now accessible and calls the loss figures informed approximations rather than exact measurements. National definitions and reporting data are inconsistent.[9] |
| October 2024 — UNODC's previous regional assessment | For 2023, UNODC estimated $18–37 billion in victim losses across 12 East and Southeast Asian economies by adjusting reported losses for estimated reporting rates. A separate labour-based model put annual criminal proceeds at $27.4–36.5 billion.[3] | High on the published method; low on direct comparability. The old figures use different geographies and measure either victim loss or proceeds. They cannot be subtracted from the new range to claim a clean growth rate. |
| September 2025 — UNODC technology brief | Scam operations already used bulk messaging, autodialling, fake account interfaces, AI-assisted impersonation, and deepfake video or voice tools. Automation often finds and routes targets before a human operator takes over.[4] | High that these methods have been documented; uncertain on prevalence. Case studies prove capability, not the share of all scams using it. Reuters describes agentic AI as an expected next step in the new assessment, not a measured 2025 baseline.[2] |
| June 23, 2026 — U.S. Treasury action | Treasury sanctioned nine people and 26 entities linked to the Prince Group network, while U.S. authorities targeted infrastructure associated with Huione Group. Treasury said earlier coordinated actions had prompted property seizures, arrests, and asset freezes in other jurisdictions.[7] | High on what the government did; allegations remain attributed. A designation or asset action is not, by itself, a final criminal judgment or proof that replacement infrastructure cannot appear. |
The distinction between loss, revenue, and assets matters. A victim-loss estimate asks how much targets were deprived of. A revenue or proceeds estimate asks how much criminal operators generated. A seizure figure records what authorities controlled. Those quantities overlap, but they are not interchangeable. Adding them together would double-count; comparing them without matching countries, years, and reporting assumptions would create a false trend.[3]
A Compound Is a Workplace, Not the Whole Business
The scam-centre image is physically powerful: guarded buildings, rows of devices, dormitories, and people held under coercion. That physical system is real. Using a different evidence base from the new UNODC assessment, a 2026 report from the Office of the UN High Commissioner for Human Rights says recent credible estimates put the scam workforce at at least 300,000 people from 66 countries, while stressing that poor screening makes detailed counts difficult. OHCHR also warns that trafficked workers can be misidentified as criminals when authorities raid a site.[6]
That workforce number is an estimate, not a census, and it should not be added to the new dollar range. It establishes the second victim population inside the business model: people recruited with deceptive job offers, confined, abused, and compelled to target a first population of victims online.[6]
The visible compound is only one layer. UNODC's 2024 assessment described a service market around it: data brokers supply leads; software vendors provide scam pages and malware; recruiters source labour; communications services reach targets; money-mule and underground-banking networks move funds; high-risk virtual-asset services obscure the trail. Multiple operators can rent space or buy pieces of that stack without owning the whole chain.[3]
That modular structure explains why a demolition, power cut, or mass arrest can be both worthwhile and insufficient. It may release people, preserve evidence, interrupt active campaigns, and raise operating costs. But if the lead lists, administrators, beneficial owners, payment routes, domain infrastructure, recruiters, and corrupt protection survive, another location can reconnect to the service layer.
INTERPOL's June 2026 regional assessment reinforces the scale of the operating environment: phishing was the most widely reported cyberthreat among participating countries, while organized networks were increasingly using AI and sophisticated social engineering. It also found that fragmented enforcement and weaker legislation left some jurisdictions especially exposed.[5]
This is why “enforcement pressure is dispersing the network” is not an argument against raids. It is an argument for following what moves.
What the $88.3–114.1 Billion Range Can—and Cannot—Decide
The range can set a risk order. Even its low end says online scamming is not a niche consumer-protection problem. It joins financial crime, labour trafficking, telecom abuse, platform integrity, corruption, and cross-border policing in one operational file.[1][2][9]
It cannot rank each country's exposure with precision. The new assessment starts with officially reported losses and divides by an estimated share of victims who report. Depending on local data, UNODC uses a country's own victimization survey, derives a rate from reported cases and estimated victimizations, or applies regional reporting-rate bounds where no national survey exists. The answer is sensitive to both loss records and reporting assumptions; UNODC also notes inconsistent national definitions.[9]
Nor does a bigger geographic total prove that the same underlying market grew by the same proportion. The new scope explicitly includes Australia and New Zealand, while the 2023 loss model covered 12 East and Southeast Asian jurisdictions. Without a like-for-like series holding geography, definitions, and reporting-rate methods constant, the responsible statement is “a much larger current risk envelope,” not “losses rose by X percent.”[3][9]
The AI claim needs the same discipline. UNODC has documented real-time face and voice manipulation, automated outreach, translation, and fake-platform tooling in regional cases.[4] Reuters reports that the new assessment expects criminals to adopt more autonomous, agentic systems for victim selection, social engineering, cryptocurrency theft, and laundering.[2] Observed tools belong in today's controls. Agentic end-to-end operation belongs in threat planning, not in a claim that the future has already arrived everywhere.
Decision Impact: 24 Hours, 7 Days, 30 Days
Next 24 hours — banks, platforms, telecoms, and newsrooms: treat the new range as an escalation signal, not a precise forecast for any one institution. Preserve the lower and upper bounds, label the geography, and stop translating “losses” into “criminal profit.” Fraud teams should review whether an incident handoff connects account, device, phone, domain, wallet, recruitment, and trafficking indicators rather than closing each as a separate ticket.
Next 7 days — UNODC and national authorities: pair the report PDF with a stable landing page and publish machine-readable country inputs, reporting-rate assumptions, coverage dates, currency treatment, and overlap controls. National anti-scam centres should disclose whether they can send and receive rapid freeze requests across borders outside business hours. The Stimson Center's July review finds that several regional centres already coordinate domestically, but legal fragmentation and uneven cross-border mechanisms still create an accountability gap.[8]
Next 30 days — enforcement and oversight bodies: add outcome measures to raid totals. At minimum, report people screened and protected as potential trafficking victims; organizers and facilitators identified; domains, SIM infrastructure, bank accounts, and wallets disabled; value frozen and returned; time from victim report to freeze request; corruption cases opened; and whether the same network reappears elsewhere. Treasury's June action shows the network-level model—targeting leaders, investors, front companies, and payment infrastructure—but its durability has to be measured after designation day.[7]
Three Paths From Here
Base case — disruption produces continued dispersion. Large compounds become riskier, so operators split across villas, smaller offices, and new jurisdictions while buying the same recruitment, data, communications, and laundering services. Trigger: raids continue, yet linked domains, wallets, recruitment adverts, and scripts reappear quickly in new countries.[1][2][3][9]
Upside case — financial and victim-protection systems outrun relocation. Rapid cross-border freezes make stolen funds harder to settle; coordinated investigations identify service providers and beneficial owners; trafficked workers are screened and protected rather than automatically prosecuted; platforms and telecoms remove reusable infrastructure. Trigger: falling median freeze times, higher recovery rates, fewer repeat-linked accounts, and sustained victim identification across successive operations.[6][7][8]
Downside case — automation makes fragmentation cheaper. Multilingual AI outreach, synthetic identities, and real-time impersonation reduce the labour and location footprint needed for each campaign, while corrupt protection and weak regulation keep offering new landing zones. Trigger: more campaigns share technical fingerprints but use smaller teams, shorter-lived accounts, more languages, and a wider spread of jurisdictions.[2][4][5]
Action Checklist—and the Invalidation Test
- For investigators: map the service chain before the site is cleared. Preserve devices and account relationships, but also trace recruiters, landlords, corporate owners, payment intermediaries, domain registrars, telecom infrastructure, and officials alleged to provide protection.
- For banks and crypto services: make a live fraud report capable of triggering a rapid hold and a cross-border escalation. Track time-to-freeze and money returned, not only alerts generated.
- For platforms and telecoms: cluster campaigns across languages, identities, devices, domains, and payment destinations. A removed account is an input; slower network regeneration is the outcome.
- For governments: screen people found in compounds individually for trafficking and forced criminality, with interpreters, legal access, safe referral, and non-punishment safeguards where applicable.[6]
- For readers: treat unexpected investment, romance, authority, or emergency contact as unverified until it survives a second channel that the sender did not provide. Do not install an app, move a conversation, or send money merely because a video or voice appears authentic.[4]
- Invalidation condition: revise this report's displacement thesis if transparent, like-for-like data show that coordinated enforcement produces a sustained fall in victim losses, recruitment, active infrastructure, and cross-border reappearance—not just a rise in raids or arrests. An official crosswalk that makes the new range directly comparable with the 2023 baseline would also justify recalculating the trend.
The new UN figure should command attention, but it should not become a scoreboard detached from its method. The harder test begins after the doors of a compound open: whether people are protected, money stops moving, the service chain breaks, and the same operation fails to reconnect somewhere else.
Sources
- Associated Press, “International criminal groups use technology to expand in and beyond Asia, UN report says” (July 21, 2026) — independent report on the new UNODC assessment, its loss range, criminal convergence, compound displacement, and source page for the documentary cover photograph.
- Poppy McPherson, Reuters via Internazionale, “Crime gangs snare more than $88 billion in scams in Asia-Pacific, UN says” (July 21, 2026) — independent wire account of geographic coverage, recruitment reach, jurisdiction shopping, corruption, and the report's agentic-AI warning.
- United Nations Office on Drugs and Crime, Transnational Organized Crime and the Convergence of Cyber-Enabled Fraud, Underground Banking and Technological Innovation in Southeast Asia: A Shifting Threat Landscape (October 2024) — primary regional assessment, 2023 estimation methods, service-layer model, and displacement analysis.
- United Nations Office on Drugs and Crime, Emerging Threats: The Intersection of Criminal and Technological Innovation in the Use of Automation and Artificial Intelligence in the Cybercrime Landscape of Southeast Asia (September 2025) — primary technical brief on automated outreach, fake platforms, deepfakes, and human handoffs.
- INTERPOL, “New INTERPOL report highlights escalating cyber threats across Asia and South Pacific” (June 17, 2026) — regional law-enforcement assessment of phishing prevalence, organized threats, AI use, and national capacity gaps.
- Office of the UN High Commissioner for Human Rights, “A Wicked Problem”: Seeking Human Rights-Based Solutions to Trafficking into Cyber Scam Operations in South-East Asia (2026) — primary human-rights report on workforce estimates, forced criminality, victim screening, and protection principles.
- U.S. Department of the Treasury, “Treasury Further Dismantles Overseas Scam Operations Targeting Americans” (June 23, 2026) — official record of sanctions, financial restrictions, infrastructure seizure, and attributed allegations concerning the Prince and Huione networks.
- Allison Pytlak, Courtney Weatherby, and Kathleen Scoggin, “The Accountability Gap—Tackling Cyber Fraud Across Legal Frameworks,” Stimson Center (July 10, 2026) — independent policy analysis of national anti-scam centres, cross-border legal fragmentation, sanctions, victim protection, and coordination design.
- United Nations Office on Drugs and Crime, An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for South-East Asia (July 2026) — primary current assessment, including the 2025 scam-loss method and range, recruitment reach, network convergence, and enforcement-displacement findings.