ArticleCybercrime & Digital Safety

Criminals Are Evolving. Criminologists Must Evolve With Them.

By Criminolohenyo · August 14, 2026

Criminals Are Evolving. Criminologists Must Evolve With Them.

Crime has entered the digital age, but have we adequately prepared the criminologist to enter it as well? The traditional image of criminal investigation often involves fingerprints, physical surveillance, interviews, documents, weapons, and evidence recovered from a crime scene. These remain fundamental investigative competencies, but the environment in which crime occurs has expanded dramatically. Fraud can now begin with a phishing message, extortion can occur through an encrypted communication platform, stolen identities can be traded online, illicit proceeds can move through virtual assets, and evidence may exist inside a smartphone, cloud account, social-media profile, or remote server rather than inside an evidence bag. INTERPOL describes modern cybercrime as an increasingly sophisticated underground economy and notes that even crimes traditionally considered physical increasingly incorporate cyber elements. More recently, its 2025/2026 Asia and South Pacific Cyberthreat Assessment reported that more than half of surveyed countries said cybercrime represented over 30 percent of nationally recorded crime, while phishing was among the most widespread and financially damaging cyber-scam techniques.

This transformation creates an important challenge for criminology education and professional practice. It does not mean that every criminologist must become a programmer, penetration tester, malware analyst, or cybersecurity engineer. Those are distinct technical disciplines requiring their own specialized competencies. What criminologists increasingly need, however, is sufficient digital literacy to understand where evidence exists, how it can be altered or lost, what questions should be asked, and when technical specialists must become involved. Consider an ordinary investigation involving harassment, fraud, sexual exploitation, kidnapping, homicide, or financial crime. Relevant evidence may include metadata, location information, browser activity, cloud records, messaging applications, digital photographs, CCTV files, transaction records, or mobile-device artifacts. NIST defines digital forensics as the retrieval, storage, and analysis of electronic data useful to criminal investigations, while INTERPOL states that electronic evidence is now a component of almost all criminal activities. This means digital evidence is no longer exclusively a concern of a small cybercrime unit. Increasingly, it intersects with ordinary criminal investigation.

This is why the modern criminologist needs a working foundation in Information Technology. Understanding basic networking can help an investigator appreciate IP addresses, network connections, and online infrastructure. Knowledge of operating systems and file structures can help explain where digital artifacts may reside. Understanding metadata can reveal that a digital file contains information beyond what is visually displayed. Knowledge of hashing helps explain how the integrity of acquired evidence can be verified. Familiarity with cloud computing reminds investigators that relevant evidence may not physically reside inside the device they seized. Cryptocurrency and blockchain literacy can help them understand how virtual assets may appear in financial investigations. Most importantly, investigators must understand that digital evidence requires careful preservation. NIST specifically notes that digital evidence presents preservation problems beyond those encountered with traditional evidence, and its scientific review emphasizes that rapidly changing operating systems and applications can alter the meaning and significance of digital artifacts over time. The criminologist does not necessarily have to perform every forensic extraction personally, but should understand the evidence well enough not to destroy, overlook, misinterpret, or improperly handle it before it reaches a qualified examiner.

Another increasingly important competency is Open-Source Intelligence or OSINT, particularly the lawful and ethical exploitation of publicly available information. Much of modern human activity leaves fragments of information online. Usernames, public posts, photographs, websites, business records, online marketplaces, archived pages, publicly visible interactions, geospatial clues, and other open sources can sometimes help investigators develop leads, verify identities, reconstruct timelines, identify associations, or corroborate information obtained through traditional investigative methods. But OSINT should not be reduced to simply "searching Facebook" or typing a person's name into Google. Effective OSINT requires structured collection, source evaluation, corroboration, documentation, legal awareness, and analytical reasoning. The same principle applies to emerging technologies such as artificial intelligence and cryptocurrency. Criminologists do not need to become AI engineers or blockchain developers, but they should understand enough to recognize how these technologies may facilitate offending, generate evidence, create investigative leads, or introduce new possibilities for deception. INTERPOL itself has developed law-enforcement resources concerning virtual assets and blockchain technology, including guidance intended to improve their understanding and use in criminal investigations.

At the same time, technology should complement criminology, not replace it. A technically brilliant examination of a device does not automatically explain criminal motive, victim-offender relationships, deception, opportunity, behavioral patterns, or the legal relevance of the evidence recovered. This is why cybercrime investigation is inherently multidisciplinary. Digital forensic specialists and IT professionals may provide advanced expertise in networks, malware, forensic acquisition, data recovery, and technical interpretation. Criminologists contribute another essential dimension through criminal investigation, criminological theory, intelligence analysis, interviewing, victimology, evidence handling, criminal behavior, crime prevention, and knowledge of investigative and legal processes. INTERPOL's cybercrime strategy similarly emphasizes that successful investigations can depend on the collection, analysis, and attribution of digital evidence, while distinguishing between cyber-dependent crimes and traditional crimes whose scale or reach is enhanced by technology. The strongest investigative team is therefore not one profession attempting to replace another. It is technical specialists and investigators understanding enough of each other's disciplines to communicate, collaborate, and transform technical findings into legally meaningful investigative evidence.

The future criminologist should therefore be viewed as a technology-enabled investigator. Digital forensics, cybercrime investigation, OSINT, digital evidence preservation, basic cybersecurity, artificial intelligence awareness, online investigations, and cryptocurrency fundamentals should increasingly form part of criminological preparedness alongside traditional competencies. This is not simply speculation about where crime might be heading. INTERPOL's current regional assessment reports cybercriminal use of artificial intelligence, ransomware-as-a-service, and sophisticated social engineering at scale, while countries are responding by investing in specialized units, digital-forensics infrastructure, intelligence sharing, and law-enforcement upskilling. The fundamentals of investigation have not disappeared. The crime scene has simply expanded. Sometimes it is still a room, a street, or a physical location. But it may also be a smartphone, cloud account, cryptocurrency transaction, social-media profile, server log, or digital photograph. If criminals continuously adapt to technology while investigators remain confined to yesterday's methods, the investigative capability gap will continue to widen. Criminals are evolving. Criminologists must evolve with them, not by abandoning traditional investigation, but by bringing its principles into the digital world.