Two days at INTERPOL on youth cybercrime, why offender prevention is real police work and why it has to out-recruit rather than out-threaten.
Sir Robert Peel defined good policing as "the absence of crime and disorder, and not the visible evidence of police action in dealing with them." Gregory Francis of the Netherlands National Police quoted this at the INTERCOP conference held at INTERPOL headquarters, and this principle framed the entire event.
Young people are increasingly drawn into cybercrime through the platforms where they already spend their time — Discord, Telegram and gaming servers. These spaces are rife with disorder that, left unchecked, matures into crime. Because the offending population is overwhelmingly young, effective cyber-policing requires us to look beyond arrests and prioritize offender prevention as real, strategic police work.
From Dutch researchers to Finnish nationwide surveys, data consistently shows that the pathway into cybercrime opens in childhood, with interest often sparked by gaming and tech curiosity before age 14.
As INTERPOL's Mahdi Alaei put it, you cannot arrest your way out of this. The Australian federal police were honest that their first cyber strategy protected victims but forgot offenders, and protecting victims does not slow the supply of young offenders. Reducing that supply is real police work, not a soft add-on.
So across two days full of fantastic information sharing by police, researchers and practitioners, one question kept returning: what draws a young person in, and what could draw them back out? Here are the highlights I came away with.
One Finding From Every Direction
Study after study, from completely different parts of the world, arrived at the same variable. The pathway into cybercrime opens in childhood and results in offending by the mid-teens, which means our window to protect and intervene often closes before most prevention programmes even begin.
Cybercrime committed by young people typically does not start off as a serious crime, but they are often motivated by things such as willingness to experiment, curiosity, mischief or wanting to test their skills.
A French intelligence unit summed up the new profile as socially isolated and craving recognition. Italian investigators profiling a group of minors listed their needs — belonging, a parent's attention, mirroring among peers — and noted there was nothing pathological in that list; it is ordinary adolescence.
On the other side of the world, Dr. Suleman Lazarus' work on West African "Hustle Kingdoms" described how survival needs are driving fraud academies that work like schools, provide much-needed income, status, belonging and a career path the formal economy can't provide.
Belonging and status are built into the infrastructure too.
Two law-enforcement speakers found the same thing built into the market itself. Europol's dark-web team described an underground economy that mirrors legitimate e-commerce — badges, seller tiers, reputation ledgers — and named its most valuable asset in one line: trust and reputation. The market runs on exactly the currency every other session found in the individual.
Finland's national youth survey, found that young people involved skewed younger than expected, and roughly a third were girls, which also breaks a stereotypical profile of the young male offender. That matters, because some crime networks deliberately recruit young women, especially for social-engineering roles, and because a profile drawn only from who gets caught writes much of that risk out of the picture. We should be careful our profile isn't just a profile of the people who get caught or show off.
Would Warning Messages Work?
The clearest confirmation came from someone who had lived it. A former cybercriminal, sharing a stage with a former FBI profiler, was asked what would have kept him out. In his words, a warning would not have moved him. What might have changed his path would have been a trusted adult who took his talent seriously. Coming from a broken home, he described his criminal infrastructure as an extension of himself; the place he got his validation. Strip away the crime and it is an ordinary story: a young person who was good with computers, found somewhere that made him feel like somebody, which he didn’t get in the real world.
Deterrence can also backfire. Dutch researchers sent a warning into an offender group and found the only thing the group took from it was how cool it was to have received one. The warning as well as sensationalized media reporting became a badge, because it registered as attention. You cannot warn a young person out of a recognition deficit.
On the flip side, perceived anonymity is one of the risk factors for many lower-level average users who simply believe they are invisible. When Europol dismantled a major stolen-data forum, it didn't stop at the takedown: it used the seized data to reach the people exposed in it, sending warning and cease-and-desist messages to the email addresses found on the site (a digital version of the FBI's old "knock and talk"). They did this to correct a misplaced belief. Many young people act on a misplaced faith in anonymity, and showing them by name that law enforcement sees more than they think is a direct shot at the perception the whole underground economy runs on and a great example of prevention work.
The Barrier to Entry Has Collapsed
French national intelligence, Europol's dark-web team, and Dr Lazarus' West African fieldwork all described a world where ready-made tools, crime-as-a-service, AI and deepfakes have deleted the skill-development stage. The lack of skill development time is where an intervention window lives.
What This Looks Like in the Global South
One of the strengths of these two days was that the Global South was in the room as a contributor, not just a case study, Lazarus on West Africa, colleagues from Nigeria and the Dominican Republic, and our own data from South Africa and Latin America. Yet most of the models the field relies on are still built on Northern data.
The difference in the South is that unlike in Europe or the U.S.., economic or financial motivation leads; in our own student population survey, South African respondents skewed toward aspiration. Almost none were told "come and commit a crime" they were offered a job, and respondents believe that young cyber offenders often didn't realise it was illegal until it was too late. Crime and career are competing for the same person.
Offenders are seen as skilled in both LATAM and in the South African responses. But in South Africa we saw they were far more likely to be admired where Latin Americans were more likely to simply call them criminals. Where crime is admired, fear doesn't compete. You cannot deter your way past aspiration; the legitimate path has to offer the status instead.
Dr. Lazarus adds to the belonging story with its darker mirror. In the Hustle Kingdoms he studies, recruits are often held in place less by physical force than by what he calls the shackles of the mind: blood rituals, oaths and witch-doctor-style spiritual coercion that bind a young person to the group psychologically. In contrast to the trafficked, physically imprisoned labour of the Southeast Asian scam compounds, a reminder that how people are kept in is as geographically specific as why they join. For prevention that means where the tie that binds is spiritual, an exit ramp has to deal with fear and belief, not just economics.
And there is another edge: where young people doubt the authorities can really act, harmful behavior starts to feel normal, and in countries where enforcement is stretched, that doubt is closer to accurate than cynical.

The Honest Limit
Belonging explains, and can interrupt, the pathway in. It does not reach the deep end of the Com that house groups like Scattered Lapsus ShinyHunters (SLSH) that Unit 221B documented, a genuinely deviant, "not average" population. Amongst those, the Dark Triad, a combination of narcissism, psychopathy and Machiavellianism, together they describe people with high levels of self-promotion, emotional coldness, manipulation and aggression.
It’s a useful lens, and it shows up in studies of offender populations. It lends itself as a description of their behavior, and where the levers for intervention are much narrower: people in that bracket are serial offenders or re-offenders, don’t show any remorse or empathy towards their victims, are proud of their deviance and the only way to intervene with them is through arrest and reputation disruption.

So prevention out-recruits at the top of the funnel while enforcement works at the bottom, and the two are not substitutes. A prevention argument that claims to cover the whole funnel will be wrong. For this group it’s important not to feed their ego. Reputation is their most valuable currency, so every "most dangerous hacker" headline is free advertising that raises their credibility and what victims will pay. It also makes them more mysterious and cool to young people who might admire them. The disruptive move isn't to amplify them as criminal masterminds; it's to deflate them, and cover them as the often unremarkable opportunists they usually are.
Between those two ends sits a large middle: the many lower-level users who simply believe they are invisible. This is the tier that targeted "we see you" messaging reaches — the Europol forum takedown described earlier is the model — because it aims straight at the perceived anonymity the whole underground economy runs on.
So Let's Out-recruit Them
If the criminal pipeline competes on belonging, prevention has to compete on the same terms, not only out-threaten them, but out-recruit. That is already being built in various projects around the world, from Brazil's Hackers do Bem to CYSED in Nigeria and our CyberHelpline pilot MiDO here in South Africa. The last word of my talk belonged to one of our own survey respondents, when asked what would actually help: invest in us as part of the solution, give us the tools, and give us the trust to become the defenders of the future.
Here is where to start.
Practical actions
- Ground it in evidence. Follow the people doing the hard research: Leukfeldt on pathways, Lazarus on Hustle Kingdoms, Unit 221B, the Finnish NBI's youth report, and get involved with INTERCOP's Cyber Offender Debrief project to hear it from offenders directly.
- Start small, and borrow what works. Follow the Australian model, one problem, one partner, one pilot, one measure, and plug into ready-made efforts like INTERCOP's Advanced Ads campaign and other initiatives rather than rebuilding from scratch.
- Out-recruit on belonging. Build the recognition and sense of being seen that the criminal market sells, and back the projects already doing it, The Hacking Games, Brazil's Hackers do Bem, CYSED in Nigeria, the Global South CAN network, and the CyberHelpline partnership with the MiDO Academy here in South Africa.
- Get the attention right. Puncture the anonymity myth, takedown data, warning notes, knock and talks, while speaking to media to deny top-tier actors the oxygen of glorification: embarrass them, don't amplify them. See also Brian Krebs article on this.
- Convene the right stakeholders, strategically. Prevention now runs through the product-governance layer, so bring platforms and AI providers in as partners, Richard Jones's Stakeholder Pathway is a useful playbook and plug into hubs like the World Economic Forum’s Cybercrime Atlas.
Conference sessions are described from my own notes; material presented under confidentiality or law-enforcement handling is deliberately omitted.
References and further reading: the World Cybercrime Index (Bruce, Lusthaus, Kashyap, Phair & Varese, PLOS ONE, 2024) on how offender profiles are geographically specific; KrebsOnSecurity's "Please Don't Feed the Scattered Lapsus ShinyHunters" (2026) on why glorifying threat actors raises their value; Dr Suleman Lazarus's work on West African Hustle Kingdoms (Routledge); Brazil's Hackers do Bem programme (RNP); and The Hacking Games' partnership with the Co-op.
