The FBI logged more than one million cybercrime complaints in 2025, with losses reaching $20.87 billion. Yet between 2014 and 2021, only 2,590 individuals were sentenced for hacking, cryptocurrency, or dark-web offenses. This is the prosecution gap. In India, the picture is even more stark.
Introduction
Cybercrime activity is rapidly escalating. Attackers continue to explore both established and novel methods to defraud victims of their assets. The FBI Internet Crime Report 2025 logged more than one million cybercrime complaints for the first time in the agency’s history, with reported losses reaching $20.87 billion, a 26% year-over-year increase.
Yet the enforcement record against those criminals is thin. The U.S. Sentencing Commission’s September 2024 report, “Cyber Technology in Federal Crime,” found that between 2014 and 2021, only 2,590 individuals were federally sentenced for offenses involving hacking, cryptocurrency, or dark-web activity.
In India, the situation is even more alarming. The National Crime Records Bureau reported that cybercrime cases increased three times in five years, rising to 86,420 in 2023 from 27,248 cases in 2018 . The National Cybercrime Reporting Portal received over 22.68 lakh complaints in 2024 alone , with cyber financial fraud losses exceeding ₹22,845 crore in the same year .
For CISOs and security teams, this gap has direct implications for how risk is modeled and where defensive investment should be allocated.
Why Most Attacks Go Unpunished
Attackers are well aware of the scanty rates of prosecution and often use that information to their advantage.
“Much of the decision-making around who they target and how is based on whether prosecution would be difficult. How they set up and manage the attack also goes through that thought process, as it’s possible to host infrastructure across noncolluding jurisdictions and make it harder for everyone trying to take down the malicious infrastructure.”
— Ken Bagnall, CEO, Silent Push
Bagnall, whose firm works alongside the FBI, Treasury Department, and Europol, called the practice “infrastructure laundering.” Russia-aligned groups, he noted, commonly target Western victims to exploit the resulting jurisdictional gap.
Structural Barriers
The structural barriers to prosecution compound the picture:
| Barrier | Description |
|---|---|
| No extradition treaties | The U.S. has no extradition treaty with Russia, China, and many other countries |
| Slow mutual legal assistance | Requests frequently run too slowly to preserve volatile digital evidence |
| Jurisdictional fragmentation | What one nation considers state-sponsored cybercrime, another may view as a legitimate revenue stream |
| Differing enforcement priorities | National agencies vary in their willingness to pursue cross-border cybercrime |
Technical Sophistication
Operational aspects also make it difficult to track down and punish cybercriminals:
- Malware-as-a-service platforms let affiliates with limited technical skills run sophisticated attacks
- Ransomware group proliferation: 138 distinct ransomware groups claimed victims in 2025, up from 98 in 2024
- Encrypted platforms: Criminal markets have migrated from dark web forums to end-to-end encrypted platforms
- Cross-chain laundering: Widespread cross-chain laundering frustrates blockchain analytics
- AI-generated phishing: The vast majority of phishing emails now contain AI-generated elements
The Defender Shortfall
Another reason many attacks go unpunished is due to a cybersecurity skills shortage:
- The majority of organizations experienced at least one significant security consequence from a skills shortage
- The investigator pipeline at law enforcement agencies is under comparable pressure
- Victim organizations often lack the forensic records needed to support a prosecution
“The less-discussed gap is operational readiness on the side of the defender. Many organizations just aren’t prepared to preserve the forensic evidence needed to support attribution or prosecution.”
— Dana Simberkoff, AvePoint
The Indian Enforcement Crisis
The numbers paint a stark picture:
The numbers expose a deep systemic failure. According to official data, cybercrime complaints grew nearly six-fold between 2021 and 2025, clocking a staggering CAGR of around 58% . Yet FIR registration has not kept pace. In 2025, only about 1.4% of complaints (provisional) converted into FIRs . The national average stood at just about 2.22% .
The Conviction Crisis
In Karnataka, over the past five years, there were only 178 convictions compared to 402 acquittals, resulting in a conviction rate of just 0.2% . Financial recovery has also been abysmal—police recovered only ₹626 crore of ₹4,699 crore defrauded over two years, a recovery rate of about 13% .
Why FIR Conversion Is So Low
The 97% gap between complaints and FIRs has several causes :
- Jurisdictional confusion: Cybercrimes often involve multiple states, creating confusion over which police station should register the FIR
- Lack of digital forensic capacity: Many police stations lack the tools and trained personnel to handle complex digital evidence
- Victim hesitation: Many victims, especially in cases of online abuse or sextortion, hesitate to come forward due to shame or fear
- Under-reporting: It is estimated that approximately 68% of cybercrime victims do not report incidents
International Coordination Challenges
India is not a signatory to the Budapest Convention on Cybercrime . Instead, it relies on Mutual Legal Assistance Treaties (MLATs) with 15 countries . However, formalized agreements with countries identified as significant sources of cybercrime activity, such as Nigeria and China, are yet to be concluded . The MLAT process can take one to two years, giving perpetrators ample time to disappear .
How Agencies Are Fighting Back
When prosecution is out of reach, the goal becomes disruption.
Major Disruption Operations
| Operation | Target | Result |
|---|---|---|
| Operation Cronos | LockBit server network (Feb 2024) | Ransom payments fell 79% |
| Operation Endgame | Botnets and infostealer networks | 1,025 servers taken down (Nov 2025) |
| Operation Talent | Cracked and Nulled forums (Jan 2025) | Two largest cybercrime forums shut down; >10 million users combined |
India’s Enforcement Response
Despite the challenges, India has taken several steps:
- National Cybercrime Reporting Portal (NCRP): Received over 22.68 lakh complaints in 2024
- 1930 Helpline: Received 3.24 crore calls in 2025
- Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS): Saved ₹5,489 crore from more than 17.88 lakh complaints
- Indian Cybercrime Coordination Centre (I4C): Coordinates cybercrime response across the country
- Sahyog Portal: Expedites takedown notices to intermediaries
- CyTrain Portal: Capacity building for police officers
The Parliamentary Committee’s Warning:
The Parliamentary Committee on Home Affairs has criticised the government’s failure in tackling cybercrime. It found that “citizens feel that justice in cybercrime cases is slow and uncertain” . The Committee recommended:
- A comprehensive cybercrime legislation with strong penal provisions
- Amendments to the IT Act, 2000, to impose harsher penalties
- Establishing an Integrated Cybercrime Task Force
- Amending the Delhi Special Police Establishment Act to empower CBI to investigate cybercrime cases without state consent
International Frameworks
| Treaty | Status |
|---|---|
| UN Convention against Cybercrime | Adopted Dec 2024; 74 signatories |
| Budapest Convention | >80 ratifying parties; Russia and China do not participate |
“We need mechanisms to ensure faster cross-border cooperation, clearer legal standards and easier sharing of evidence across jurisdictions.”
— Dana Simberkoff, AvePoint
What Organizations Must Do
Forensic Readiness
“It’s important to have data protection frameworks in place before you’re attacked. Even if attackers get access, proactive backup and data protection will give you documentation to make international collaboration less fraught.”
— Dana Simberkoff, AvePoint
Key actions:
- Implement strong logging and retention policies
- Preserve forensic evidence from the moment of detection
- Develop incident response plans that include evidence preservation
- Maintain backups to support recovery and investigation
Collaboration
- Engage with FBI, CISA, and other agencies for intelligence sharing
- Participate in public-private partnerships
- Leverage bug bounty programs to channel offensive security expertise into legitimate investigations
Investment Strategy
- Allocate resources to detection and response, not just prevention
- Invest in forensic capabilities to support attribution and potential prosecution
- Build relationships with law enforcement before incidents occur
Conclusion
The prosecution gap is real. In India, the gap is even more pronounced. The FBI logged more than one million cybercrime complaints in 2025, with losses reaching $20.87 billion. Yet between 2014 and 2021, only 2,590 individuals were sentenced for hacking, cryptocurrency, or dark-web offenses.
In India, cybercrime complaints reached 22.68 lakh in 2024 alone, with losses of ₹22,845 crore. Yet only 1-3% of complaints convert into FIRs. Conviction rates remain in the low single digits.
Attackers know this. They use jurisdictional gaps, infrastructure laundering, encryption, and anonymity to evade prosecution. AI has lowered the skill threshold for launching effective campaigns. The defender shortfall means many victim organizations lack the forensic records needed to support prosecution.
But as long as cybercrime remains profitable and prosecution stays low, attackers will continue. The changes that would shift those odds run deeper than any single operation. Treaty frameworks need to be strengthened. Cross-border cooperation needs to be faster. And organizations need to be forensically ready.
KNOWLEDGE CHECK QUIZ
Q: What is the “Prosecution Gap” as defined in the context of cybercrime? Ans: It is the massive disparity between the volume of cybercrimes committed (e.g., 22.68 lakh complaints in India in 2024) and the extremely low number of actual criminal convictions (e.g., only a 0.2% conviction rate in Karnataka over 5 years).
Q: What is “Infrastructure Laundering” and why do threat actors use it? Ans: Infrastructure laundering is the practice of hosting malicious servers across multiple, non-colluding, or hostile jurisdictions. Threat actors use it specifically to exploit the “Prosecution Gap,” knowing that the legal complexities of securing cross-border cooperation (via MLATs) make it incredibly difficult for law enforcement to take down the network or make an arrest.
Q: What are the primary reasons why the conversion rate of cybercrime complaints to FIRs in India is so low (1-3%)? Ans: The extremely low conversion rate is driven by jurisdictional confusion between police stations, a severe lack of digital forensic capacity and trained personnel at the local precinct level, and victim hesitation to pursue formal legal action.
Q: Because traditional prosecution is largely ineffective against offshore cybercriminals, what alternative strategy have global law enforcement agencies adopted? Ans: Law enforcement has shifted from seeking individual prosecutions to a strategy of “Active Disruption.” This involves massive, coordinated operations (like Operation Cronos or Endgame) to physically seize and destroy the servers, botnets, and financial wallets used by the syndicates, thereby destroying their operational capability.
───
FREQUENTLY ASKED QUESTIONS (FAQ)
Q: If the FBI or I4C knows that a specific group committed a hack, why don’t they just arrest them? Ans: Sovereign nations like the United States and India do not have extradition treaties with countries like Russia, China, or North Korea. Therefore, even if an agency publicly indicts a cybercriminal, they cannot physically arrest them unless the criminal travels to a country that does have an extradition agreement.
Q: What is the “Financial Fraud Kill Chain”? Ans: It is a process utilized by agencies like the FBI’s Recovery Asset Team and India’s CFCFRMS. If a victim reports the illicit wire transfer immediately (within the “Golden Hour”), the agency can use its relationships with global financial institutions to freeze the funds in the destination account before the criminals can withdraw or launder the money.
Q: How is India’s non-participation in the Budapest Convention affecting its ability to prosecute cybercriminals? Ans: Because India is not a signatory to the Budapest Convention on Cybercrime, it relies heavily on Mutual Legal Assistance Treaties (MLATs) to gather cross-border evidence. The MLAT process is notoriously slow, often taking 1-2 years, by which time volatile digital evidence is destroyed and the attackers have moved on.
Adv. Shoeb Hakim
Cybercrime & Digital Forensics Advisor
📌 Follow me on LinkedIn for daily cybercrime and digital forensics insights: https://www.linkedin.com/in/shoebhakim
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
♻️ Share this article with your network.
Disclaimer: This article is for informational purposes only and does not constitute legal advice.
Hashtags: #AdvShoebHakim #Cybercrime #ProsecutionGap #FBI #Ransomware #Cybersecurity #InfoSec #DigitalForensics #Attribution #Malware #Phishing #AI #CryptoCrime #DarkWeb #LawEnforcement #CISO #RiskManagement #NationalSecurity #India #CybercrimeIndia #NCRP #I4C #ITAct #BNS


