
Police authorities breached several encrypted chat services in a series of data driven investigations. These services are mostly used by offenders, and the results were thousands of arrests. Limited research has studied the ensuing court cases. In this study, we discuss the strengths and limitations of this data source, and compare the contents of three services: EncroChat, SkyECC, and Anom. We use a sample of 195 court cases from Sweden between 2019 and 2024, where evidence from the encrypted chats was used. The cases involved 667 individuals and 1519 prosecuted offenses, mostly serious drug offences. Network analysis indicates that serious drug offences are strongly connected to violence and weapons in EncroChat, cross-border drug trafficking in SkyECC, and weapons offences in Anom. The average sentence length did not differ between the platforms. Given the sequential breach of the services, this suggests that offenders continued using them for planning serious offending, despite public knowledge of the police interventions. Information from encrypted chat services is an important supplement for research, policy, and practice concerning criminal groups.
Package theft (“porch piracy”) has become one of the most common opportunity-driven crimes, yet almost nothing is known about how offenders perceive the situational cues that shape these opportunities. This study extends the Crime as Opportunity framework by examining how package thieves evaluate guardianship cues, neighborhood cues, and target attractiveness, and whether these perceptions differ by offending frequency. Data were collected via an online survey of 309 self-identified package thieves. Exploratory factor analysis yielded three opportunity-perception scales (guardianship cues, neighborhood cues, target attractiveness). Respondents were grouped by lifetime frequency of theft. Group differences were tested with ANOVA; predictors of higher frequency were examined using ordered logistic regression. Doorbell cameras, human presence, and police visibility were rated the strongest deterrents (M = 4.22, SD = 0.77). Higher-frequency offenders perceived guardianship cues as less deterring than one-time offenders (M = 3.93 vs. M = 4.31; p = .013). Neighborhood cues showed no group differences. Target attractiveness exhibited a non-significant upward trend. In the multivariate model, a one-standard-deviation increase in perceived guardianship cues was associated with an 11
This study provides the first national-level longitudinal analysis directly linking mobility data to police-recorded crime across local authorities in England and Wales, while controlling for stable structural differences between places. Its purpose is to examine how changes in human mobility are associated with changes in crime, taking advantage of the disruption in mobility caused by the COVID-19 pandemic. Negative binomial regression models were applied across 328 local authorities from March 2020 to October 2022, with area fixed effects, to assess how mobility across different activity spaces relates to police-recorded crime while accounting for unobserved, time-invariant local characteristics. The exploratory and modelling analyses showed that the mobility-crime relationship varied considerably by offence type and across local authorities. Increased residential mobility was consistently associated with lower levels of property, violent, and public order crimes, while mobility around retail, grocery, transit, and workplace areas was generally associated with higher crime once stable local differences were controlled. Sensitivity analyses suggested the results are robust to plausible levels of unobserved confounding. The impact of mobility on crime during and after the pandemic in England and Wales was not uniform but was shaped by local conditions and time-invariant characteristics. The findings underline the need for place-specific approaches in crime prevention and suggest that mobility-related interventions should be tailored to the structural and social context of each area.
While it has been widely recognised by researchers that many homicides are reactions to immediate circumstances, there is little research that formally analyses homicide from the situational crime perspective. This study presents the quantitative results from structured interviews with 260 male and female homicide offenders who provided detailed information on the circumstances of their offence. Areas covered included their degree of planning, their emotions immediately prior to the offence, what they were doing with the victim beforehand, the weapon used and how it was obtained, and how they felt immediately after the event. We found that most homicides were unplanned and could be categorised as expressive crimes. The most common weapon was a sharp object, and almost half the weapons used were found at the homicide scene. Intimate partner homicides typically occurred in the home of the victim and were preceded by a verbal argument. Stranger homicides were more likely to be associated with drug and alcohol use, to occur in public and semi-public areas, and to be preceded by a physical fight. We drew on the concept of situational crime precipitators to integrate expressive homicides into the situational crime perspective. Our findings reinforce the preventative value of gun control and suggest the need to extend controls to access of dangerous knives. We suggest situational measures to help prevent intimate partner conflicts (e.g., personal duress buttons) and bar room fights (e.g., server intervention) escalating to homicide.
This study applies crime script analysis (CSA) to a complex economic crime: donation-based tax evasion schemes and evaluates how actors involved in the scheme engage with crime opportunities. To do so, the study introduces a crime opportunity engagement framework drawing on business and white-collar crime scholarship. By combining CSA and the framework, the study identifies how different actors initiate, shape, and exploit crime opportunities across the crime commission process. Drawing on court files from 36 donation-based tax evasion schemes in Canada, a deductive thematic analysis was conducted to reconstruct a crime script and identify key scenes associated with donation-based tax evasion schemes. The analysis was then guided by the novel crime opportunity engagement framework, distinguishing opportunity takers, seekers and creators. Errors, that is, actions that lead to unexpected outcomes, committed by various actors throughout the script were also identified. The analysis revealed a donation-based tax evasion script composed of seven scenes organized into two tracks: a scheme relying on falsified donation receipts and a sophisticated scheme involving the creation of tax shelters and affiliated organizations. When looking at how actors engaged with crime opportunities across the script, most of them (investors, advisors and charitable organizations) acted either as opportunity takers or seekers. Only promoters in the more complex scheme acted as opportunity creators, assembling the organizational, legal, and procedural conditions necessary for the scheme to operate. Also, all promoters acted as opportunity brokers, enabling other actors to access and benefit from the schemes. Various situational prevention measures inspired by the crime script are discussed, many of which are related to errors committed by the involved actors. The findings show that crime opportunities in complex economic crimes are not only discovered or sought for. They can also be actively created and expanded by offenders. By combining CSA with an opportunity engagement framework, this study advances criminological theory by shifting the analytical focus from the mere presence of opportunities to how they are dynamically engaged with across crime scripts.
Abstract This paper aims to improve crime script analysis, with a particular focus on breaking script stages into smaller, more precise steps. After outlining existing scripting methods, we then introduce eight principles designed to guide both the creation of crime scripts and the evaluation of scripts produced by others. Grounded in the concepts of state and activity, these principles address the following themes: Constitution, Chronology, Composition, Cardinality, Categorisation, Completeness, Clarity, and Consistency. Finally, we discuss the limits of template based approaches, including those built around the universal script. We call for the development of a more flexible scripting method, one that retains the chronological and functional cues of the universal script, but can be applied at any level of abstraction and resolution. Within this context, we believe the above principles can play another important role in its development.
Spatial analysis is central to crime science, yet the primary medium used to communicate spatial findings remains the static map. While static cartography effectively illustrates broad spatial patterns, it is often limited in its ability to convey hierarchical, multi-scale, or temporally dynamic crime phenomena. This study evaluates the extent to which contemporary crime-and-place research relies on static visualization and assesses when dynamic mapping would meaningfully enhance interpretability. A scoping review of 930 eligible studies published between 2010 and 2024, with a 10
Mayhew and colleagues (1976) showed that opportunities for crime matter, sparking a revolution in crime theory, research, and prevention. But they could not resolve a conflict between subjective and objective interpretations of opportunity: does a crime opportunity depend on an offender perceiving it, or is it an objective fact of a situation? We reconcile these interpretations. Using a vehicle theft example, we illustrate the conflict and suggest that the subjective interpretation helps describe opportunity exploitation by offenders; only an objective interpretation can account for opportunity creation. We review 62 ideas elaborating crime opportunities. These ideas show that crime scientists embrace both opportunity exploitation and opportunity creation, which we call the Janus-faced opportunity perspective. It requires us to replace the offender view of opportunity with three alternative views: one subjective and two objective. Each has strengths and weaknesses. We conclude that the assumed conflict disappears when we realize that we use subjective explanations and objective explanations for different purposes.
This article discusses the value of integrating spatial crime analysis with local stakeholder engagement to fully leverage opportunity theory in community crime prevention. We begin by describing the literature on opportunity theory applications and the limitations of that research, noting both the value and rarity of employing inclusive research practices. To quantify the frequency, types, and trends in stakeholder engagement employed in opportunity theory-based studies, we conducted a content analysis of Crime Science articles published from 2012 through 2025. Of the 212 eligible studies reviewed, 12.3
The 1976 monograph Crime as Opportunity initiated a paradigm for how crime and criminality should be understood and controlled. Here we define a crime opportunity as any situation in which the benefits of committing crime outweigh the costs, and group crime opportunity-related theories and concepts under the banner of crime opportunity theory. The study details how reducing crime opportunities has proven successful locally for many different crime types, and how reducing crime opportunities has emerged as the leading explanation for the international crime drop. It concludes that crime opportunity theory should be the principal reference point for explaining and preventing crime and criminality.
From its origins in Crime as Opportunity and related papers, through to its current incorporation within crime science, the concept of opportunity has played an important role in research and practice. Yet much of the thinking behind the concept has remained implicit, intuitive and static. A chance to take the concept forward in a practical, yet rigorous way arose when developing a detailed interactive toolkit to guide security managers of large and complex stations to prevent, and prepare responses to, terrorist attacks and other crimes more typical of such places. We describe the requirement for the toolkit; the conceptual architecture we developed, with particular reference to opportunity and how it meshes with other crime science concepts such as crime precipitation, and with broader concepts from traditional security practice such as threat and risk management; and the practical realisation through a process that matches security actions to the threat posed by terrorists/criminals and the risk generated in the particular environment of complex stations. We finish by considering how the development of the toolkit advanced the concept of opportunity.
Abstract Decentralized finance (DeFi) platforms have gained in popularity over the last few years, as they offer a wide range of accessible, innovative, and complex financial services. Because they evolve quickly under limited regulation, it is easy for malicious parties to target them for profit when they notice a vulnerability in these emergent protocols. Existing work has focused on understanding typical attack flows and securing the technology to alleviate crime. However, little is known about what other attributes, beyond technical vulnerabilities, may put DeFi actors at risk. Drawing on Cook’s (Crime Justice 7:1–27, 1986) crime opportunity framework of target attractiveness, this study investigates which attributes are associated with an increase or a decrease in the likelihood of DeFi victimization. We compare actors victimized in 2022 with those that were not across several target dimensions: propinquity, vulnerability, potential payoff, main area of operation, and self-protection activities. Results show that being listed on a popular centralized exchange, operating on a layer-2 blockchain, offering lending services, and having high trading volumes are associated with an increased likelihood of victimization, while operating a dApp and having experienced past victimization are associated with a decrease. By contrast, self-protection measures such as publicly disclosed audits, and bug bounty programs show no measurable effect, likely reflecting variation in their quality and implementation or the fact that undisclosed audits could not be observed. By integrating criminological theory into DeFi security research, this study provides a holistic framework for understanding crime opportunities in this novel ecosystem, while informing potential prevention strategies to reduce associated harms.
Government responses to violence associated with organized criminal groups have traditionally emphasized offender-based strategies aimed at incapacitating individuals and disrupting criminal organizations. Despite their long-standing use, these approaches show limited evidence of producing durable reductions in violence. Echoing the foundational insights of Mayhew et al. (1976) in Crime as Opportunity, researchers have increasingly recognized that organized crime activity is shaped by environmental conditions, opportunity structures, and the geographic distribution of resources. Yet empirical examinations of how these features contribute to the spatial concentration of violent crime linked to organized groups remain limited. This study applies GIS-based spatial analysis and multivariate regression modeling to investigate homicide concentrations in Colombia from 2010 to 2020, assessing the relative influence of organized offending groups alongside a range of situational and geographic characteristics. Results indicate that environmental features were significant predictors of homicide clustering, independent of the presence of organized crime groups. These findings further demonstrate the explanatory value of opportunity and environmental frameworks for understanding organized crime violence. They also highlight the importance of situational prevention strategies that seek to modify local opportunity structures rather than relying exclusively on offender-focused interventions.
Crime prevention strategies often rely on the small set of micro-places where crime is most concentrated, the so-called hotspots, yet it has remained unclear how close existing hotspot detection methods come to the maximum coverage theoretically possible. This study introduces GraphVenn, the first algorithm that identifies the globally optimal placement of N fixed-radius hotspots directly from the empirical crime distribution, without relying on heuristic or approximate approaches. GraphVenn was evaluated on three years of crime data from Malmö, Boston, and New York City (in total 1.75 million crimes) and compared against kernel density estimation (KDE), greedy PAI maximization (PAI-Max), and GraphTrace. Both the globally optimal and the greedy (fast approximation) modes of GraphVenn were evaluated across different spatial resolutions, demonstrating scalability to large urban datasets. In optimal mode, GraphVenn identified the absolute maximum coverage of incidents achievable under fixed-radius constraints. The greedy variant reached within 0.1–−1.9
Purpose: Social robots are set to permeate every area of our lives from childhood, well into our old age—from education, policing, and entertainment, to healthcare. Ensuring that their deployment happens in a safe and secure way requires a firm understanding of the broad scope of crime and security threats that social robots may facilitate. Methods: We conducted a scoping literature review to provide an overview of the crime and security threats related to social robots, and potential countermeasures. Results: We identified 18 distinct crime threats and 17 possible countermeasures described across 388 academic and non-academic articles from any discipline. The crime threats ranged from fraud and trespassing, to espionage and abuse towards robots. Countermeasure themes included establishing social robot rights and many technological adaptations. Conclusions: Stakeholders in the social robotics domain are encouraged to use these findings to pre-empt future crime risks related to social robots.
Police reports made following attendance at various events (e.g., crashes, domestic violence, theft) often contain rich contextual details including indicators of mental health issues or abuse types, and persons/entities involved and their relationships, which are not typically captured in structured administrative data, interviews or official statistics. However, the sheer volume of information along with strict data access protocols render manual analysis impractical. Computational text analysis methods offer a feasible and effective approach to automatically process this underutilized data source. This article is an overview of studies using computational text analysis (e.g., text mining, natural language processing (NLP)), on unstructured police data, serving as a guide for researchers interested in employing similar methodologies. This scoping review was conducted in accordance with the PRISMA-SCR guidelines, following the two screening processes (title/abstract and full text screening) and the development of a pre-defined protocol. A search was conducted across seven electronic databases (ProQuest, IEEE Xplore, Scopus, PubMed, Web of Science, Criminal Justice Abstracts, Google Scholar) covering the past 20 years. A total of 5426 records were identified. After removing duplicate entries and screening titles/abstracts and full-text publications, 61 studies met the inclusion criteria. Included studies were published between 2004 and 2024, with most from the United States, Australia and the Netherlands. Most studies used opensource tools: Bidirectional Encoder Representations from Transformers (BERT), natural language tool kit (NLTK), scikit-learn, or General Architecture for Text Engineering (GATE) to analyze unstructured police data. Our review indicates applications of computational text analysis on unstructured police data have moderate to high performance. Common limitations included variable data quality, with reliability depending on the level of detail provided by the police report’s author, and failure to report ethical implications or methodological limitations. Computational text analysis can extract key information from unstructured police data. However, future research should clearly report ethics approvals and implications, and methodological limitations. Establishing a structured data-sharing framework between law enforcement and researchers is also crucial to facilitate access and support high quality, impactful research in this field.
The proliferation of large language models (LLMs) and generative artificial intelligence (GenAI) applications has provided ample opportunities for crime, including technology-facilitated financial crimes. The present study conducted a quantitative systematic literature review to examine the evolving intersection of GenAI and financial crime. Specifically, the study identified keyword concentrations, latent research topics, and thematic relationships within this emerging domain to explore how current scholarship understands the role of GenAI in financial crimes. Guided by the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) 2020, this systematic literature review employed three quantitative analytical methods—bibliometric analysis, topic modelling, and knowledge graph analysis—to reveal trends, concentrations, and connections of prominent keywords and topics that emerged from the extant literature. With the assistance of the PRISMA 2020 framework, a total of 94 studies were incorporated for the quantitative systematic review. The bibliometric analysis identified five keyword clusters, while the topic modelling and knowledge graph revealed six latent research topics with nuanced patterns, highlighting a growing concentration on automated financial crimes that are distinctive from human-centric social engineering. The results also revealed the dual-use nature of GenAI in both facilitating and preventing financial crimes. On one hand, GenAI has been widely misused in financial cybercrimes such as algorithmic fraud, deepfake attacks, and smart contract exploitation. On the other hand, GenAI has enhanced crime prevention capacities, such as detection capabilities and vulnerability screening. While GenAI facilitates various criminal opportunities for financial crime, it also provides insight into effective crime prevention strategies. This study demonstrated that research is increasingly focused on the technical and adversarial dimensions of the dual-use nature of GenAI, outlining a structural distinction between human-centric social engineering and automated financial crimes. The findings shed light on the importance of recognising the evolutionary landscape of financial crimes enabled by GenAI and the significance of embracing forward-looking governance frameworks for regulatory compliance in decentralised financial (DeFi) systems.
This study evaluates the impact of the COVID-19 pandemic and the associated “epidemiological traffic-light” system on homicide rates in Ecuador. We exploit monthly panel data at the canton level for 2020–2021 and estimate an event-study difference-in-differences design using Poisson pseudo-maximum likelihood with two-way fixed effects. The treatment is defined as the first transition from the red (strict) alert level to more flexible yellow or green stages, and we control for COVID-19 incidence and mortality, local economic activity, mobility indices and demographic characteristics. Our preferred event-study specification suggests a temporary increase in homicides in the month of the first relaxation of restrictions, but the estimated effects in subsequent months are imprecise and statistically indistinguishable from zero. The average post-treatment effect across the first five months after the transition is small and not statistically significant. Linear specifications in levels and in log(1 + homicides), as well as wild-cluster bootstrap inference, corroborate the absence of robust effects of the traffic-light policy on homicide rates. These findings indicate that, conditional on epidemiological and economic conditions, the traffic-light mobility regime did not generate systematic or sustained changes in lethal violence at the canton level. We discuss possible mechanisms and implications for the joint design of public-health and public-safety interventions.
Vehicle-as-a-Weapon (VAAW) attacks, distinct from explosive-based vehicle attacks (VBIEDs), pose an evolving threat to public, urban spaces. Existing security guidance overlooks spatial, behavioural, and operational nuances, limiting effective design and response. This paper proposes a multidimensional taxonomy of VAAW attacks, developed using Factor Analysis for Mixed Data and k-means clustering of 135 global cases. Six distinct clusters are identified across three axes: Temporal Attack Complexity, Tactical Sophistication, and Operational Lethality. These clusters are mapped to situational crime-prevention, offering actionable insights for security planners, urban designers, and policymakers. The taxonomy reframes vehicle-based threats not as attacks to be managed through rigid perimeters of protection, but as situated, probabilistic scenarios that require differentiated mitigation; advancing the integration of protective security within broader urban resilience strategies.
The rise of ‘cryptojacking’ – the covert use of victim resources for unauthorised cryptocurrency mining – has become a significant cyber threat since the introduction of Bitcoin. Such cryptomining malware secretly hijacks a user’s computational power to generate cryptocurrency without their knowledge or consent, leading to reduced and/or degraded performance at the victim’s expense. This paper presents a systematic literature review of 119 articles tracing the evolution of cryptomining malware, past trends in their dissemination and detection, security recommendations, and anticipated future developments. We specifically highlight the dual impact of this threat, which targets not only individual users on devices like IoT, mobile phones, and cloud infrastructures, but also critical national infrastructure, large corporate networks, and high-traffic websites. Our analysis reveals that the threat landscape, which significantly expanded around 2017, continues to grow steadily. Additionally, we systematically identify and discuss detection methods – such as network traffic analysis, CPU utilization monitoring, and machine learning classifiers – as well as security recommendations like browser extensions, patch management, and network-level blocking. Our findings highlight the urgent need for a unified, multi-stakeholder security strategy to mitigate this pervasive and adaptable threat.