INTERPOL's Asia and South Pacific Cyber Threat Assessment Report 2025/2026 pays particular attention to the vulnerability of Pacific Island states painting a sobering picture: countries with the least capacity to respond are increasingly targeted, and often used as unwitting stepping stones for wider criminal networks.
Malware software identified in Pacific countries
INTERPOL's operational data names specific Pacific nations among the countries targeted by major infostealer malware groupings (called ‘families’).
- RedLine Stealer -the most prevalent infostealer in the region - was found targeting Fiji, Kiribati, and Timor-Leste, among others.
- LummaC2, described as the world's largest malware-as-a-service infostealer, was active in Papua New Guinea.
- Lokibot and other credential-harvesting tools were detected more broadly across the region.
These tools quietly extract banking logins, personal data, and cryptocurrency wallet information, which is then sold on dark web marketplaces and used to enable further fraud.
South East Asian scam compounds
The report finds that the "global underground economy" is actively expanding into new regions, recruiting victims through deceptive job advertisements and, in many documented cases, trafficking people into forced labour.
This expansion pattern is a warning sign for the wider Pacific: once criminal infrastructure and networks are established, they tend to spread to jurisdictions with weaker oversight.
INTERPOL's response - ASPJOC
The Asia and South Pacific Joint Operations against Cybercrime (ASPJOC) project, run through INTERPOL's ASP Desk in Singapore and funded by the UK Foreign, Commonwealth & Development Office, explicitly targeted capacity-building in the Pacific during its first phase, which concluded in July 2025.
The 19 focus countries included Fiji, Kiribati, Marshall Islands, Nauru, Papua New Guinea, Samoa, Solomon Islands, Timor-Leste, Tonga, and Vanuatu, alongside several Southeast Asian nations. ASPJOC's work spans four areas: threat intelligence and analytical reports, awareness-raising campaigns, joint operational frameworks for information-sharing, and direct investigative and operational support for cross-border cybercrime cases.
Common challenges include a lack of specialised forensic tools, limited access to targeted cybercrime training, and insufficient technical capacity -obstacles that fall hardest on smaller Pacific administrations with limited law enforcement budgets. Two-thirds of responding agencies across the wider region report having adopted some AI tools for detection and investigation, though adoption is uneven.
Transparency and governance
For Pacific people, the report's findings reinforce a familiar pattern: transnational organised crime exploits weak institutions, thin legislation, and constrained law enforcement capacity -the same conditions that enable corruption more broadly. Strengthening cybercrime legislation, forensic capability, and cross-border cooperation across the Pacific isn't just a technology issue; it's part of the broader institutional resilience that underpins good governance and accountability in the region.
