Cybercrime has become a highly professional and globally interconnected industry, increasingly shaped by artificial intelligence. Criminal groups now operate like businesses, marketing their services and utilising scalable business models, such as ransomware. The economic damage is enormous and affects Switzerland too. Even well-protected organisations can be vulnerable if their supply chains are attacked. Although simple measures such as strong passwords, backups and training can help, many SMEs lack the necessary resources and expertise. Government bodies provide support in the form of reporting requirements and tools, but fear of reputational damage hinders academic exchange. At the same time, AI is accelerating attacks, for example by sending deceptively genuine phishing messages or carrying out automated espionage. Defenders are also using AI, but the competition remains uneven. Successful cybersecurity therefore requires cooperation, transparency, and the targeted use of technology combined with human oversight.

Your browser does not support the audio element or the audio file is not available.

Article

Cybercrime Inc.: How Digital Attacks Became Big Business – and What AI Means for This

Cybercrime is no longer the work of lone hackers in basements. It’s a booming global industry – well organised, profitable, and increasingly powered by artificial intelligence (AI). As attackers get smarter, defenders must learn to think like entrepreneurs too.
Summary Cybercrime has become a highly professional and globally interconnected industry, increasingly shaped by artificial intelligence. Criminal groups now operate like businesses, marketing their services and utilising scalable business models, such as ransomware. The economic damage is enormous and affects Switzerland too. Even well-protected organisations can be vulnerable if their supply chains are attacked. Although simple measures such as strong passwords, backups and training can help, many SMEs lack the necessary resources and expertise. Government bodies provide support in the form of reporting requirements and tools, but fear of reputational damage hinders academic exchange. At the same time, AI is accelerating attacks, for example by sending deceptively genuine phishing messages or carrying out automated espionage. Defenders are also using AI, but the competition remains uneven. Successful cybersecurity therefore requires cooperation, transparency, and the targeted use of technology combined with human oversight.
Published on 02.04.2026
Guido Salvaneschi

“Off the record: we were hit, we paid, but we will never admit it publicly.” This could be the acknowledgment of many CEOs around the world. It’s hard to imagine another industry that has grown as fast and invisibly as cybercrime. What began as a playground for curious teenagers in hoodies has turned into a professional ecosystem with its own business models, talent pipelines and customer relations. Today’s cyber gangs operate almost like regular businesses. They advertise on dark-web forums, rent out hacking tools “as a service”, and even run help desks for victims negotiating a ransom and handling the transaction. The latest ENISA Threat Landscape describes this evolution with chilling precision: cybercrime now mirrors the logic of legitimate business.

“The numbers are staggering. Global damages from cyberattacks are projected to surpass USD 10 trillion a year. Ransomware has become the preferred money-spinner – simple, scalable, and brutally effective.”
Guido Salvaneschi

The numbers are staggering. Global damages from cyberattacks are projected to surpass USD 10 trillion a year. Ransomware has become the preferred money-spinner – simple, scalable, and brutally effective. In Switzerland, a 2024 attack on the Zurich-based procurement firm Chain IQ partially disrupted the financial sector. This has shown how even well-guarded organisations can fall victim when suppliers are breached. Since 1 April 2025, operators of critical infrastructure such as powerplants, hospitals and railways in Switzerland have been legally required to report cyberattacks. Anyone who is attacked must report this to the Federal Office for Cyber Security (BACS) within 24 hours. By the end of that year, 222 mandatory reports had been received. That is almost one per day. The battleground is everywhere: every inbox, every smartphone, every unsecured network is a potential entry point. In contrast, the hotspots of this shadow economy lie mostly in regions where law enforcement can’t or won’t do much.

How to Stay Ahead of Invisible Enemies

For most organisations, good cybersecurity doesn’t begin with expensive technology but with habits. Strong passwords, multifactor authentication, regular backups, and a workforce that spots suspicious messages are still the most effective shields. Yet small and medium-sized enterprises (SME) often lack the resources for dedicated experts. That’s why the Swiss National Cyber Security Centre (NCSC) has become a crucial ally, offering practical checklists and a simple incident-reporting portal. Additionally, various online tools like the “Cybersecurity Check for SME” from the Alliance Digital Security help businesses gauge their resilience without needing an IT department.

“What can really work in combatting cybercrime is collaboration. Sharing information across sectors, learning from incidents, and treating cybersecurity as a shared responsibility to make a difference.”
Guido Salvaneschi

Still, awareness alone is not enough. The latest Swiss Cyber Study found that many companies recognise the risk but fail to budget for it. And while Switzerland’s current National Cyberstrategy strengthens reporting obligations for critical infrastructure, regulations alone cannot keep pace with the ingenuity of attackers. Last October, authorities warned that approximately 200 Swiss companies fell victim to ransomware attacks from one single hacker group alone that had recently intensified its activities in Switzerland. What can really work in combatting cybercrime is collaboration. Sharing information across sectors, learning from incidents, and treating cybersecurity as a shared responsibility to make a difference. However, many victims are reluctant to share their experiences because they fear damage to their reputation. Reporting an attack should no longer feel shameful; it’s an act of solidarity in a connected world.

AI Joins the Game

Artificial Intelligence is the newest player in the cybersecurity arena that is changing the rules for everyone. For attackers, AI is a gift. It writes perfect phishing e-mails, generates convincing fake voices, and can mimic a CEO’s tone in seconds. The result: scams that even seasoned professionals struggle to spot. But the story doesn’t end there. Anthropic’s recent report claims to have observed the first reported AI-orchestrated cyberattack. According to their report, attackers exploited the Claude model to automate a cyber-espionage campaign, allegedly achieving 90 percent automation. How? By bypassing safety restrictions through clever prompt engineering – framing malicious tasks as legitimate penetration tests and breaking them into smaller, seemingly harmless components. Claude then executed network mapping, vulnerability scanning, exploit generation, and credential collection, while humans stepped in only for critical decisions. In reality, this looks less like full autonomy and more like a hybrid model: AI as an orchestration engine under human direction.

“Switzerland, with its culture of trust, collaboration, and precision, is well placed to lead by example. Combining academic research, responsible regulation, and innovative companies can turn cybersecurity from a necessary burden into a national strength.”
Guido Salvaneschi

If Anthropic’s claim holds true, this could mark a turning point – a moment when AI-driven automation reshapes the threat landscape faster than our current defences can adapt. Even if full autonomy isn’t here yet, the trajectory is clear: attacks will scale, and defences must evolve. Defenders aren’t standing still. Security teams now deploy AI to sift through oceans of data, detecting anomalies that would otherwise go unnoticed. Machine-learning models can flag suspicious logins within milliseconds. Yet this remains an uneven race: attackers need one lucky strike; defenders must be right every time. The real advantage will belong to those who use AI wisely – as a transparent tool guided by human judgment, not as a black-box oracle. Switzerland, with its culture of trust, collaboration, and precision, is well placed to lead by example. Combining academic research, responsible regulation, and innovative companies can turn cybersecurity from a necessary burden into a national strength. Cybercrime will continue to evolve. So must we! With smart cooperation, curiosity, and the confidence that even in the digital shadows, resilience can be built.

Media tips

Kris Oosthoek / Jack Cable / Georgios Smaragdakis: A Tale of Two Markets: Investigating the Ransomware Payments Economy (2023)

Article

Kris Oosthoek / Jack Cable / Georgios Smaragdakis: A Tale of Two Markets: Investigating the Ransomware Payments Economy (2023)

The authors of this article follow the money and show how ransomware attacks really pay off. Based on thousands of real transactions, it reveals two distinct approaches: low-end, off-the-shelf attacks and highly professional ransomware-as-a-service operations, who both have their own business logic and incentives. By tracing how crypto payments move through intermediaries, this article gives readers a clear, accessible picture of the ransomware economy.

Jean-Yves Marion: Ransomware: Extortion Is My Business (2025)

Article

Jean-Yves Marion: Ransomware: Extortion Is My Business (2025)

Ransomware attacks are a professional extortion business, not just a technical cyber threat. Drawing on real incidents and current research, this article reveals how attackers organize, negotiate, and pressure victims into paying ransoms. It is an accessible, eye-opening read for anyone who wants to understand what is really driving today’s ransomware wave.