---
title: Five Things We Can Learn from the Latest Europol/NCA Reports
description: Two reports from Europol and NCA about cybercrime
image: https://insights.comforte.com/hubfs/comforte%20AG_Europol_10.08.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![comforte AG - Five Things We Can Learn from the Latest Europol/NCA Reports](https://insights.comforte.com/hubfs/comforte%20AG_Europol_10.08.png)](https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l Aug 10, 2023 l [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Five Things We Can Learn from the Latest Europol/NCA Reports

The front line in the war on cybercrime can be an unrelenting place. Those tasked with bringing cyber-criminals to heel work long hours for relatively low pay. But they also offer an arguably unique insight into the cybercrime landscape which we can all learn from. Two new reports from the European Union and the UK are a great example.

Both Europol’s [*Internet organised crime threat assessment 2023*](https://www.europol.europa.eu/cms/sites/default/files/documents/IOCTA%202023%20-%20EN.pdf) and the National Crime Agency (NCA)’s [National Strategic Assessment](https://www.nationalcrimeagency.gov.uk/news/director-general-graeme-biggar-launches-national-strategic-assessment) reports have one thing in common: they emphasize the criticality of data to the cybercrime economy.

## Five takeaways

Here’s what we can learn from the reports, in greater detail:

**1- Data is the main commodity of the cybercrime economy**

Stolen data is both bought for and produced by various cyber-attack types, Europol says. It could be log-ins which enable hackers to hijack employee or customer accounts. It could be personally identifiable information (PII) that can be leveraged for use in fraud (see below). It could be trade secrets sold to the highest bidder. It could be customer or corporate information held to ransom by extortionists. It could even be highly sensitive personal information that sextortionists try to use for blackmail.

Europol also warns that the type of stolen data available on criminal markets is changing. It is no longer only static data such as card details, but increasingly “is compiled of a number of datapoints retrieved from victims’ malware-infected devices.” Whatever type it is, it needs to be better protected.

**2- Data theft is fuelling a fraud epidemic**

While data is the main commodity of the cybercrime economy in general, it’s driving a particular surge in fraud. NCA director general, Graeme Biggar, warns that fraud now accounts for over 40% of all crime in the UK, with three-quarters of adults targeted by scammers in 2022—many of them online.

“The internet has enabled fraud to be undertaken at scale, anonymously, and from overseas,” he says.

The data fuelling this fraud is typically PII, financial details and logins. It could be phished directly from victims, but often it’s breached *en masse* from corporate data stores. The inability of organizations to keep this under lock and key ultimately has a devastating impact on downstream victims, through no fault of their own. If this data were protected in the first instance, the impact could be significantly reduced.

**3- The same victims are often targeted multiple times**

No organization is 100% breach proof. But following an incident, a victim corporation could be forgiven for thinking the worst is over. They would be wrong. According to Europol, cyber-criminals are increasingly victimizing the same company multiple times. This happens because internet access brokers (IABs), who sell access to corporate networks, usually do so to multiple attack groups. That means the same credentials or vulnerability exploits may be used by multiple threat groups. This makes it more important than ever that organizations focus security first on data protection.

**4- The cybercrime supply chain is well established**

The cybercrime economy is [estimated to be worth](https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/#:~:text=Cybersecurity%20Ventures%20expects%20global%20cybercrime,%243%20trillion%20USD%20in%202015.) trillions annually today. That doesn’t happen by accident. As Europol explains, it’s a product of a well-oiled machine comprised of many moving parts—professional criminals with discrete specialisms. These range from the aforementioned IABs to malware developers, providers of “crypters” designed to hide malware, bulletproof hosters and sellers of counter-antivirus (CAV) services. They all congregate around cybercrime forums and marketplaces.

“Fraud and cybercrime are enabled by criminal marketplaces, where you can buy hacked personal data, victim lists, accesses, and capabilities. All these professional services can make life easier for organized criminals,” says Biggar. 

**5- Humans remain the weakest link in the chain**

Cyber-criminals are nothing if not opportunistic. That means they’re always primed to take advantage of any gap in corporate security. Unfortunately, they continue to have a significant and unwitting ally in the form of corporate employees. That makes phishing a key access vector for data compromise, one made more attractive by the ready availability of phishing kits which have lowered the barrier to entry for cyber-criminals, says Europol.  
The NCA’s Biggar also warns of the emerging threat from generative AI in this area, enabling criminals to “write more compelling phishing emails.” If threat actors continue to harvest corporate log-ins via phishing emails, it’s going to be increasingly difficult to stop them from breaching networks. Once again, that puts the focus on protecting the data.

## Taking small steps to a more secure future

That’s the bad news. But there’s also something more positive to takeaway from the reports.

“The impact of such attacks can be significant, but the solution can be simple: basic cyber security will defeat most attacks and it is important all organisations invest in it,” says Biggar.

One of the most important steps to achieving this kind of cyber hygiene should be data-centric security in the form of encryption or tokenization. By protecting what matters most, organizations can significantly mitigate financial, reputational and compliance risk. Even better, they can help to disrupt an entire cybercrime economy enabled by data theft.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/five-things-we-can-learn-from-the-latest-europol/nca-reports&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Learn how to discover, classify, and protect all sensitive data.

Click the button below to download the solution brief for our Data Security Platform:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/65e094b1-44ae-496e-be17-1678a1876675.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/65e094b1-44ae-496e-be17-1678a1876675)

### Related posts

![Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/hubfs/comforte%20AG_%20Reuse%20Reward_%20How%20Banks%20Can%20Safely%20Unlock%20the%20Value%20of%20Their%20Data_03.2025.png)

 Mar 12, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Payments Transformation](https://insights.comforte.com/tag/payments-transformation) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Reuse, Reward: How Banks Can Safely Unlock the Value of Their Data](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

The financial world is awash with data. But too few organizations are able to use it effectively. In [Bank Director’s *2025 Technology Survey*](https://www.bankdirector.com/wp-content/uploads/2025/09/2025TechReport-OpenVersion.pdf), one-third of US banking leaders cite an inability to harness data as a top technology challenge facing their...

[Read more](https://insights.comforte.com/reuse-reward-how-banks-can-safely-unlock-the-value-of-their-data?hsLang=en)

![Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/hubfs/comforte%20AG_Delivering%20a%20Secure%2c%20Trusted%20Foundation%20for%20Cloud%20Growth%20at%20LGT_01.2026.png)

 Jan 15, 2026 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Business Value](https://insights.comforte.com/tag/business-value)

### [Delivering a Secure, Trusted Foundation for Cloud Growth at LGT](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

There’s a world of difference between retail and private banking. While the former is transactional and focused on the mass market, the latter is built on trust and personal relationships. That trust can be hard won, but is easily lost, especially...

[Read more](https://insights.comforte.com/delivering-a-secure-trusted-foundation-for-cloud-growth-at-lgt?hsLang=en)

![Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/hubfs/comforte%20AG_Top%20Indicators%20You%20Have%20a%20Cybersecurity%20Problem_and%20What%20to%20Do%20About%20It.png)

 May 22, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Digital Enablement](https://insights.comforte.com/tag/digital-enablement)

### [Top Indicators You Have a Cybersecurity Problem—and What to Do About It](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

Data is both blessing and curse to the modern enterprise. Yes, when analyzed effectively it can surface intelligence to improve decision making, customer engagement, process efficiency and, ultimately, drive revenue. But it also represents a major...

[Read more](https://insights.comforte.com/top-indicators-you-have-a-cybersecurity-problem-and-what-to-do-about-it?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>