That assumption can blunt preparedness. The report shows scam revenue fell sharply, but ransomware rose and impersonation scams remained comparatively resilient. If teams generalise from the average, they may underinvest in incident response, backup resilience, and user awareness for the attack types that are still active. Security planning should follow the specific threat mix, not the headline trend.
Why the headline trend can be misleading
The key failure is treating an aggregate decline as proof that the whole threat environment improved. Crypto crime is not a single risk bucket, so a drop in one category can hide persistence or growth in others, especially where attackers have shifted to different monetisation paths, pressure tactics, or victim profiles.
That matters operationally because trend-based decisions often drive budget and attention. If leaders infer that the environment is broadly safer, they may slow incident response tuning, defer recovery testing, and soften awareness work just when certain attack types are still producing harm.
One useful data point from NHI Mgmt Group’s Ultimate Guide to NHIs is that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, a reminder that apparently separate threat trends can still converge on the same access paths and compromise mechanics.
What breaks in planning and resilience
What usually breaks first is prioritisation. Teams over-correct toward the headline signal and underweight the attack types that remain active, which can leave response playbooks, backups, and user training misaligned with the current mix of abuse. The result is not just weaker defence, but slower detection and slower recovery when a less visible threat lands.
Ransomware is a good example of why the average can mislead. Even if one class of scam revenue falls, extortion-driven operations can remain dangerous because the real operational problem is interruption, data loss, and recovery cost, not just the immediate financial flow that appears in a trend chart.
- Incident response should be tested against the attacks still generating loss, not the ones declining fastest.
- Backup and restore readiness should be validated for extortion scenarios, because recovery time is often the real control failure.
- User awareness should track current lure patterns, not last quarter’s highest-volume scam type.
External guidance that tracks current threat activity, such as CISA cyber threat advisories, is more useful here than relying on a single aggregate crime trend.
Risk and Threat Considerations
The main risk is false reassurance. When organisations infer that falling crypto crime means lower exposure overall, they can miss the fact that threat actors often reallocate effort rather than disappear, leaving the most damaging tactics intact.
Failure mechanism: Security teams anchor on the decline in one metric, then reduce vigilance, funding, or testing for ransomware, impersonation, and other still-active attack paths. That creates a control gap between perceived and actual threat mix.
Impact: The organisation becomes easier to disrupt because response, recovery, and awareness controls are no longer tuned to the threats most likely to affect it. In practice, that can mean slower containment, weaker restoration outcomes, and more successful social engineering or extortion attempts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 17 — Incident Response Management | Ransomware and active scams demand tested response processes. |
| CIS Control 11 — Data Recovery | Recovery readiness matters when ransomware remains a live threat. | |
| Recommendation — Exercise and refine incident response for the attack types still producing loss. Validate backups and restoration paths against extortion scenarios. | ||
| NIST CSF 2.0 | RS.RP — Response Plan Execution | The question is about whether planning stays aligned to current threat conditions. |
| RC.RP — Recovery Planning | Falling overall crime does not reduce the need to restore from extortion events. | |
| Recommendation — Align response execution to the current threat mix, not the average trend. Test recovery plans against ransomware and other still-active disruption scenarios. | ||
| MITRE ATT&CK | T1486 — Data Encrypted for Impact | Ransomware remains the threat type that can still disrupt operations materially. |
| T1566 — Phishing | Impersonation scams remain resilient because social-engineering paths still work. | |
| Recommendation — Map ransomware scenarios to T1486 and prioritize detection plus restore readiness. Hunt for phishing and impersonation patterns that still drive compromise. | ||
Practitioner Guidance
What to prioritise: Rebuild threat planning around attack types and business impact, not around a single market-wide revenue trend. If ransomware or impersonation is still active in your sector, those scenarios deserve the same or greater planning weight than the declining category.
What to verify: Check whether your incident response exercises, restore tests, and awareness content reflect the current threat mix. A mature programme should show clear coverage for the abuse patterns that remain operationally relevant, not just the ones that dominated last year.
Practitioner takeaway: The right question is not whether crypto crime is falling overall, but whether your control stack is still aligned to the threats that can actually hurt you today.
Related resources from NHI Mgmt Group
- What breaks when organisations delay crypto inventory and assume they can migrate quickly later?
- What breaks when organisations assume delayed AI Act enforcement means they can wait to govern model inputs?
- What breaks when organisations still assume network location means trust?
- What breaks if organisations delay crypto-agility until quantum computing is mature?