Organized fraud is outgrowing Asia-Pacific’s cyber insurance market

A UN threat assessment reveals a protection gap with direct implications for underwriting, product design, and claims

Organized fraud is outgrowing Asia-Pacific’s cyber insurance market

Cyber

By Roxanne Libatique

Organized crime networks defrauded residents across Asia-Pacific of between US$88.3 billion and US$114.1 billion in 2025 – up from US$18 billion to US$37 billion in 2023 – according to a report published July 21 by the United Nations Office on Drugs and Crime (UNODC). At the low end of both estimates, losses have increased more than fivefold in two years, placing the scale of the problem in direct tension with the region’s insurance capacity.

The report, titled An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for South-East Asia 2026, was developed through consultations with ASEAN member states, national authorities, and international partners, drawing on official data, criminal case records, financial intelligence, and field research.

Franchise model reshapes criminal operations

The report described how crime networks have reorganized from territory-specific operations into multi-market enterprises sharing infrastructure across illicit trades. Delphine Schantz, UNODC regional representative for Southeast Asia and the Pacific, outlined the structure. “Their operating model looks like corporate franchising: imagine specialised departments for laundering money, trafficking people, smuggling migrants, and harvesting data, all plugged into the same, service-based interconnected network,” she said.

Scam centres – concentrated in Southeast Asia and run predominantly by Chinese-origin syndicates – target individuals worldwide, with UNODC identifying people from at least 80 countries and territories inside compounds across the region. Enforcement pressure has displaced rather than dismantled operations, with syndicates relocating from Myanmar and Laos to East Timor, Pacific island states, and parts of Africa – a pattern the report described as “jurisdiction shopping.” Corruption was identified as the “primary enabler” of technology-driven organized crime in the region.

Investment fraud leads on losses; AI accelerates scale

The breakdown of losses matters for line-specific exposure assessment. In Australia – one of the four markets in UNODC’s estimate – investment scams were the single largest loss category in 2025, accounting for AU$837.7 million of AU$2.18 billion in total reported scam losses, according to Australia’s National Anti-Scam Centre (NASC). Payment redirection scams (AU$166.8 million) and romance scams (AU$139.9 million) ranked second and third, with the top five typologies accounting for 60% of total losses. That distribution maps directly onto financial lines, cyber, and crime policy structures.

On the threat side, a separate law enforcement assessment reinforces the UNODC’s trajectory. INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment – produced by INTERPOL’s dedicated cybercrime desk in Singapore and drawing on responses from 18 member countries – recorded over 135,000 ransomware attacks across the region in 2024, a 92% surge in distributed denial-of-service attacks, and a 600% increase in deepfake-related discussions on criminal forums between February and June 2024. More than 6.5 billion cyber threats were detected and mitigated across the region during 2024. More than half of surveyed countries reported cybercrime accounting for over 30% of all nationally recorded crime.

The UNODC report flagged the anticipated shift from generative AI to agentic AI systems capable of autonomously identifying victims, conducting social engineering campaigns, and facilitating cryptocurrency theft and laundering. Two regional incidents illustrate the coverage challenge those developments present: in February 2024, a Hong Kong employee transferred US$25 million after deepfakes impersonated company executives on a video call; in March 2025, a Singapore finance director nearly lost over US$499,000 in a near-identical Zoom-based attack. Both involved AI-generated real-time video impersonation that most existing social engineering sublimits and business email compromise policy language were not written to address.

Conor Keating, head of cyber in Asia at Willis, noted in June 2026 that “AI has not yet emerged as a stand-alone driver of cyber insurance claims; it is already amplifying existing threats – from social engineering and deepfake phishing.” Inshik Sim, lead analyst at UNODC, said existing response structures are not keeping pace. “The scale and complexity of this expanding organised crime economy are outpacing existing responses, which were not structured to address such sophisticated criminal activity,” Sim said.

A protection gap measured in tens of billions

Swiss Re estimated global cyber insurance premiums at US$15.6 billion for 2025, with Asia-Pacific accounting for a 10% share – approximately US$1.56 billion. Against UNODC’s low-end estimate of US$88.3 billion in regional scam losses, that premium base represents coverage capacity equivalent to less than 2 cents on every dollar of documented fraud loss. Swiss Re separately noted that Asia-Pacific’s share of global cyber premium remains disproportionately small relative to the region’s digital exposure, describing the gap as reflecting “untapped cyber market growth potential.”

Regulatory shifts redistribute liability

Two regulatory developments are reshaping loss allocation across the financial services sector. In Australia, the Scams Prevention Framework Act 2025, passed in February 2025, places mandatory anti-scam obligations on banks, telecommunications providers, and digital platforms. Draft rules released by Treasury on May 28, 2026, proposed a reimbursement scheme with a AU$3,000 threshold and an equal liability model, backed by civil penalties of up to AU$50 million per contravention. From July 1, 2026, the Australian Financial Complaints Authority (AFCA) became the authorised external dispute resolution scheme for scam-related complaints under the framework, with insurance listed among sectors potentially brought within its scope.

In Singapore, the Monetary Authority of Singapore (MAS) revised its anti-money laundering and countering the financing of terrorism guidelines for insurers effective July 1, 2025, introducing mandatory proliferation financing assessments and updated suspicious transaction reporting requirements. MAS is also supporting a dedicated Cyber Risk Management Project at Nanyang Technological University’s Insurance Risk and Finance Research Centre, focused on supply and demand constraints in the regional cyber insurance marketplace.

For insurers, the combination of a loss environment growing faster than premium capacity, investment fraud as the dominant typology, AI-enabled social engineering outpacing current policy wording, and a regulatory framework beginning to redistribute liability across financial services creates concurrent pressure across underwriting, product design, and claims. The UNODC’s loss trajectory – more than tripling in two years – suggests the window for incremental adjustment is narrowing.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!