by
Saron Obia & Nicasio Viana
CyJurII Theorists
on 18 August 2026
The increasing weaponization of digital technologies has transformed the organisation, execution and investigation of cyber-enabled crime. This article critically examines the Triangular Theory of Crimes, developed by Saron Obia as a framework for understanding the relationship between offenders, intermediaries and victims in technology-enabled criminal activity. The theory proposes that cyber-enabled fraud frequently depends not upon a single offender but upon a network of compartmentalized actors who perform different functions within the criminal enterprise. Social engineering, compromised identities, fraudulent documentation, mobile-payment systems and insider assistance may operate together to conceal the principal offender and facilitate the movement of criminal proceeds.
The article argues that the theory provides a useful operational perspective on cyber-enabled fraud, particularly in environments where weaknesses in identification systems, telecommunications regulation and financial controls create opportunities for criminal exploitation. Nevertheless, the theory should not be treated as a universally established criminological theory without further empirical validation. Its principal contribution lies in identifying the relational and layered nature of cyber-enabled offending and in demonstrating why attribution of an individual device, account or transaction may not establish the structure of the wider criminal network. The article therefore proposes an integrated investigative approach combining criminological analysis, digital forensics, cybersecurity governance, financial intelligence and international cooperation.
Keywords: cybercrime; criminology; Triangular Theory of Crimes; social engineering; digital forensics; identity fraud; Cameroon; cybersecurity; attribution; cyber-enabled fraud.
Cybercrime has become increasingly organized, transnational and technologically mediated. Digital technologies do not merely provide new instruments for committing conventional offences; they can also restructure the relationships between offenders, victims, intermediaries and service providers. Contemporary cybercriminal operations may involve actors located in different jurisdictions, compromised accounts, fraudulent identities, payment intermediaries and commercially available technological tools. INTERPOL has similarly observed that a single cyberattack may involve offenders operating across several countries, infrastructure located in multiple jurisdictions and victims situated elsewhere, creating significant challenges for law-enforcement agencies.³
Against this background, the Triangular Theory of Crimes seeks to explain a particular operational structure in which three principal components interact: the criminal, the intermediary or ‘pick-up’, and the victim. The theory was initially formulated by Saron Obia in the context of research undertaken in Cameroon and subsequently conceptualized as the Triangular Theory of Crimes in 2015.⁴
The theory’s significance lies less in presenting a general theory of all cybercrime than in identifying a recurring mechanism through which cyber-enabled fraud may be operationalized. In particular, it draws attention to the separation between the person who deceives the victim and the person who receives or withdraws the proceeds. This separation can create an attributional gap: the evidence may identify the recipient of funds without identifying the person who planned or executed the deception.
The central argument of this article is therefore that the Triangular Theory is potentially useful as an investigative and criminological framework, but its explanatory claims require further empirical testing. Its greatest contribution is its emphasis on the layered structure of cyber-enabled criminality and the corresponding limitations of investigations that focus exclusively on the immediate device, account or suspect.
The Triangular Theory of Crimes was developed from Obia’s postgraduate research concerning cybercriminality as an emerging security challenge in Cameroon.⁵ The authors describe the theory as having been conceptualized in 2015 following a postgraduate diploma defence at the Pan African Institute for Development West Africa.⁶
The theory should, however, be distinguished from established criminological theories containing similar terminology. The expression ‘crime triangle’ is already associated with situational crime-prevention scholarship, particularly the work of Ronald Clarke and Marcus Felson, which conceptualizes crime as requiring convergence between an offender, a suitable target and the abnce of capable guardianship.⁷ The Triangular Theory of Crimes examined here has a materially different emphasis. Rather than primarily examining the situational conditions necessary for an offence, it focuses on the internal operational relationship among participants in cyber-enabled criminal activity.
This distinction is important. Describing the Triangular Theory as ‘one of the leading criminological theories’ would be difficult to sustain without a broader body of peer-reviewed empirical literature demonstrating its acceptance within criminology. The more defensible claim is that the theory constitutes a proposed criminological and investigative framework developed to explain particular patterns of cyber-enabled offending.
The theory can be represented schematically as follows:
Criminal → Victim → Intermediary/Pick-up → Criminal
The criminal establishes contact with or deceives the victim. The victim is instructed to transfer money or provide information. The intermediary receives, withdraws or transfers the proceeds, frequently retaining an agreed commission. The principal criminal is thereby physically and digitally separated from the victim and, potentially, from the financial transaction itself.
This structure is consistent with the broader observation that contemporary cybercrime can involve multiple specialized participants rather than a single technically sophisticated offender. INTERPOL has documented organized cybercrime operations involving fraudsters, money launderers, technical specialists and other participants performing different functions.⁸
The contemporary digital environment facilitates the fragmentation of criminal activity. Internet-connected devices, electronic communications, mobile-money platforms, online banking and digital identification systems provide legitimate economic and social functions but may simultaneously create opportunities for exploitation.
The technology does not necessarily create the criminal motivation. Rather, it can reduce the costs of communication, concealment and coordination while increasing the geographical distance between offenders and victims. The availability of relatively inexpensive cybercrime tools may also lower the technical threshold for participation in cyber-enabled offences.⁹
This is particularly significant in relation to social engineering. INTERPOL defines social-engineering fraud broadly as criminal conduct that exploits a person’s trust to obtain money or confidential information.¹⁰ Phishing, vishing, smishing, telecommunications fraud and business-email-compromise schemes all demonstrate how psychological manipulation can be combined with technological infrastructure.
The importance of social engineering to the Triangular Theory is therefore considerable. An offender does not necessarily need sophisticated technical capabilities if another person can be manipulated into providing credentials, opening a malicious link, transferring money or facilitating access. The human element becomes the point through which technological security controls can be circumvented.
UNODC similarly identifies social engineering fraud as involving the manipulation of victims into providing personal information or funds, while phishing may involve impersonating legitimate organisations to induce victims to disclose information or access malicious links.¹¹
Social engineering can consequently function as the gateway mechanism through which the criminal triangle is established.
The insider represents an important but underdeveloped dimension of the theory. In some cases, an employee may deliberately participate in a criminal scheme. In others, the employee may unintentionally facilitate the offence after being deceived through social engineering.
This distinction is critical.
An insider who knowingly assists an offender is conceptually different from an employee whose credentials are compromised or who unknowingly performs an action requested by a criminal. Treating both situations simply as ‘insider cooperation’ risks obscuring the different criminological and legal mechanisms involved.
For example, an employee might:
1. deliberately provide confidential information;
2. knowingly process a fraudulent transaction;
3. provide credentials in exchange for payment;
4. unknowingly disclose credentials after responding to a phishing message; or
5. unknowingly execute instructions contained in a malicious communication.
Each scenario produces different evidentiary questions concerning intention, knowledge, causation and culpability.
The theory is therefore strongest when it treats the intermediary not as a single fixed category but as a functional position within a criminal process. The intermediary may be a willing participant, a recruited money mule, a compromised employee or an unwitting facilitator.
The theory proposes that the criminal relationship may become visible through a sequence of communications and financial transactions. A typical fraud may involve repeated requests for payment, with each request ostensibly justified by a new expense or administrative obstacle.
The manuscript describes a three-stage payment pattern involving transportation or vaccination costs, alleged delays during transit and subsequent document-clearance or related expenses.¹² Such a sequence should not, however, be presented as a universal or standardized pattern of cybercrime. Rather, it is better understood as an illustrative fraud scenario demonstrating how repeated requests can progressively extract funds from a victim.
Once the victim transfers funds, the intermediary may receive the money, retain a commission and transfer the remaining proceeds to another participant. The criminal may therefore avoid direct contact with the victim and may never appear as the holder of the receiving account.
This arrangement resembles the broader use of money mules and financial intermediaries in cyber-enabled fraud. International law-enforcement operations have demonstrated the extent to which social engineering, telecommunications fraud and money laundering can operate together within organized criminal networks.¹³
The evidentiary consequence is significant. A bank account, mobile-money account or telephone number may identify an intermediate participant, rather than the principal offender. An investigation that terminates at that point risks confusing the recipient of the proceeds with the person responsible for initiating the fraudulent scheme.
The theory’s most significant analytical contribution concerns the limitations of digital attribution.
Digital evidence can be highly valuable in identifying devices, accounts, communications and transactions. Digital forensics involves the identification, acquisition, processing, analysis and reporting of electronically stored data, and electronic evidence is now relevant to a substantial proportion of criminal investigations.¹⁴
However, the existence of a digital trace does not necessarily establish who was responsible for creating or controlling that trace. An IP address may identify a connection rather than a person. A telephone number may identify a subscriber without establishing who physically used the device. A bank account may identify the account holder without demonstrating who instructed the transaction. A mobile-money account may similarly represent only one layer in a wider criminal operation.
INTERPOL recognizes that digital evidence may be volatile and that offenders may operate behind multiple layers of anonymity-enhancing technology.¹⁵ The increasing availability of commercially accessible cybercrime tools further complicates attribution.¹⁶
The Triangular Theory consequently encourages investigators to ask a broader question:
Who is behind the identified participant, account, device or transaction?
This question shifts the investigation from individual attribution towards network attribution.
The theory further proposes that cybercriminal organisations may be compartmentalized. Individuals involved in one stage may know little or nothing about participants operating at other stages.
Such compartmentalisation is consistent with broader understandings of organized cybercrime. The UNODC has noted that cybercrime investigations can involve multiple levels of command, technical infrastructure and participants, creating difficulties in attributing criminal conduct to specific individuals or groups.¹⁷
The implication is that discovering the immediate suspect may constitute only the beginning of an investigation.
For example, investigators may identify:
Level 1: the victim;
Level 2: the person communicating with the victim;
Level 3: the intermediary receiving the funds;
Level 4: the person controlling the intermediary’s account;
Level 5: the organizer or coordinator;
Level 6: the technical infrastructure supporting the operation.
The levels should not be regarded as an empirical universal model. Rather, they provide an investigative hypothesis capable of being tested against evidence.
The central weakness of conventional attribution is that it may stop at the first identifiable participant. The central proposition of the Triangular Theory is that the investigator should continue tracing the relationships between participants until the wider criminal structure is understood.
Weaknesses in identity-management systems can create additional opportunities for criminal exploitation. Cameroon provides a useful case study.
Cameroon enacted Law No 2010/012 of 21 December 2010 relating to cybersecurity and cybercriminality. The legislation establishes a legal framework governing the security of electronic communication networks and information systems and addresses offences involving information and communication technologies.¹⁸ Cameroon also has legislation governing electronic communications, including Law No 2010/013 of 21 December 2010.¹⁹
The problem, therefore, is not necessarily the absence of legislation. A more difficult question is whether identification requirements are effectively implemented and supervised.
In April 2024, the Cameroonian government ordered major telecommunications operators to update subscriber information and intensified scrutiny of unidentified SIM cards. Reports indicated that regulatory authorities had previously identified problems involving pre-activated SIM cards and subscriber-identification failures.²⁰
These developments illustrate an important proposition within the Triangular Theory: formal identification requirements do not necessarily produce reliable attribution unless the underlying registration and verification mechanisms are effectively enforced.
A telephone number registered in a person’s name does not automatically establish that the registered person committed an offence. Conversely, an improperly registered or fraudulently obtained SIM card may make attribution considerably more difficult.
The investigative significance therefore lies not merely in identifying the subscriber but in establishing the chain connecting:
identity document → SIM registration → device → user → communication → transaction → intermediary → ultimate beneficiary.
This chain should be treated as an evidentiary network rather than as a single point of attribution.
Financial institutions and mobile-money operators occupy a particularly important position within the criminal triangle because they may represent the point at which digital deception is converted into physical or transferable value.
The theory suggests that dishonest employees may assist criminals by altering, deleting or fabricating information or by facilitating the withdrawal of criminal proceeds. These are serious allegations and should not be generalized to financial-sector employees as a class. The stronger analytical point is that internal access can become a vulnerability when legitimate institutional privileges are exploited for criminal purposes.
UNODC has identified the relationship between cybercrime and corruption as an emerging area of concern, including the manipulation, alteration or deletion of electronic information and fraudulent transactions designed to redirect funds.²¹
Accordingly, financial investigations should not terminate merely because the receiving account has been identified. Investigators should examine the origin of the instruction, authentication records, account-opening documentation, device information, communications, withdrawal patterns and relationships between the account holder and other participants.
Cybercrime is frequently characterized by its transnational nature. Yar and Steinmetz emphasise the challenges created by the geographical displacement of cybercrime and the difficulties that this creates for traditional mechanisms of criminal justice.²²
The term ‘de-territorialized’ is useful, but it should not be interpreted as meaning that cybercrime exists outside territorial law. Cybercrime remains subject to national jurisdiction, but its constituent acts may occur across multiple jurisdictions.
For example:
● the victim may be located in Cameroon;
● the offender may operate from another country;
● the intermediary may be located in a third jurisdiction;
● the bank account may be maintained elsewhere;
● the server may be hosted in another country; and
● relevant communications data may be held by an international service provider.
This fragmentation creates a jurisdictional and evidentiary problem.
The Budapest Convention on Cybercrime provides an important international framework for harmonising cybercrime legislation, investigative powers and international cooperation concerning electronic evidence.²³ Its Second Additional Protocol further seeks to strengthen international cooperation and disclosure of electronic evidence, including cooperation with service providers and mechanisms for more efficient cross-border investigations.²⁴
The Triangular Theory is therefore most useful when combined with international cooperation mechanisms rather than treated as a self-contained solution to attribution.
The expansion of cyber-enabled crime requires law-enforcement agencies to develop investigative capabilities beyond traditional computer and smartphone examinations.
Digital evidence can originate from numerous sources, including computers, smartphones, remote storage and other connected systems.²⁵ Investigators should therefore consider the entire digital environment surrounding an offence.
The authors identify devices and technologies such as SIM cards, USB drives, internet modems and other equipment as potentially relevant sources of evidence. The important principle is not the particular device but the relationship between multiple sources of evidence.
A successful investigation may require correlation between:
● telecommunications records;
● financial transactions;
● device metadata;
● email accounts;
● social-media accounts;
● IP addresses;
● subscriber information;
● geolocation data, where lawfully available;
● CCTV;
● identity documents;
● cloud-service records; and
● communications between suspected participants.
Digital forensics should consequently be understood as a process of evidentiary correlation, rather than merely the extraction of information from a confiscated computer.
The proposition that offenders may deliberately create misleading evidence is also important. Criminal actors can attempt to conceal their identity, use compromised accounts or devices, exploit stolen credentials and route activity through intermediaries.
Nevertheless, investigators should distinguish between deliberate false attribution and ordinary evidentiary ambiguity. Not every inconsistent digital trace is evidence of an intentional attempt to mislead investigators.
A robust forensic methodology should therefore seek independent corroboration. An IP address, for example, should not ordinarily be treated as conclusive proof of authorship. Its evidentiary significance becomes stronger when correlated with other evidence such as device data, subscriber records, authentication logs, financial records and communications.
This approach is consistent with modern digital-forensic practice, which seeks to transform electronic data into actionable intelligence while preserving its evidentiary value.²⁶
The Triangular Theory also highlights the relationship between cybersecurity and identity governance.
Weak identity-management systems may allow criminals to obtain or exploit:
● improperly registered SIM cards;
● stolen identity documents;
● compromised financial accounts;
● fraudulent mobile-money accounts;
● synthetic identities; and
● accounts controlled by intermediaries.
Cameroon’s experience demonstrates that statutory regulation must be accompanied by effective enforcement. In April 2024, government authorities required telecommunications operators to strengthen subscriber identification and update customer information, citing concerns regarding unidentified SIM cards and their use in criminal and security-related activities.²⁷
The problem is therefore not simply technological. It is institutional.
Effective attribution requires cooperation between telecommunications companies, financial institutions, law-enforcement agencies, regulators and other relevant stakeholders. Without effective information-sharing mechanisms, evidence may remain fragmented across separate institutional databases.
One of the strongest implications of the Triangular Theory is that cybercrime prevention should not begin after the victim has suffered financial loss.
The theory suggests a shift from a predominantly reactive model towards a preventive and intelligence-led model.
Financial institutions and telecommunications providers should be encouraged to identify anomalous patterns before criminal proceeds can be withdrawn or transferred. Relevant indicators may include unusual account activity, rapid movement of funds between newly established accounts, repeated use of accounts associated with multiple unrelated transactions, suspicious SIM-registration patterns and other indicators of organized fraud.
Such measures must, however, be balanced against privacy, due-process and data-protection obligations. Cybersecurity cannot justify unrestricted surveillance or indiscriminate collection of personal information.
The appropriate objective is therefore proportionate risk-based monitoring combined with lawful access, procedural safeguards and accountable information sharing.
The effectiveness of the Triangular Theory ultimately depends upon the capacity of investigators to operationalize it.
Law-enforcement officers require continuing education in:
● digital forensics;
● financial investigations;
● telecommunications evidence;
● social engineering;
● cryptocurrency and digital payments;
● open-source intelligence;
● cloud evidence;
● identity fraud;
● network analysis; and
● cross-border evidence gathering.
INTERPOL provides dedicated training concerning the identification and seizure of digital evidence and the acquisition of electronic evidence from service providers located in other jurisdictions.²⁸
This demonstrates that modern cybercrime investigation is increasingly interdisciplinary. The investigator must understand not only computers but also telecommunications, finance, human behaviour, law and international cooperation.
The Triangular Theory makes a useful conceptual contribution by emphasizing that cyber-enabled crime may involve multiple actors performing different functions. It draws attention to an important investigative error: assuming that the person or account closest to the transaction is necessarily the principal offender.
Its principal strengths are therefore threefold.
First, it emphasizes relational criminality rather than isolated offenders.
Secondly, it recognizes intermediaries as an important investigative target.
Thirdly, it highlights the distinction between digital identification and substantive attribution.
Nevertheless, the theory has limitations.
Most importantly, its empirical foundation requires further development. A theory intended for broader criminological acceptance should be tested across different countries, offence types and criminal networks. Evidence should establish how frequently the proposed three-part relationship occurs and under what circumstances.
Secondly, the concept of the ‘triangle’ may oversimplify contemporary cybercriminal organisations. Some operations involve dozens of participants performing specialized functions. The structure may therefore be better understood as a network than as a triangle.
Thirdly, the theory risks conflating different types of intermediaries. A willing money mule, a corrupt employee and an unwitting victim whose account has been compromised have materially different roles.
Fourthly, the theory should more explicitly incorporate emerging technologies. Artificial intelligence, cryptocurrency, deepfakes, automated phishing and crime-as-a-service models are increasingly capable of altering the organisation of cybercrime. INTERPOL’s recent assessments indicate that cybercriminals are increasingly combining social engineering with AI-generated content and other accessible technological tools.²⁹
The theory should therefore be regarded as dynamic rather than static.
The most productive development of the theory may be to reconceptualize the triangle as the nucleus of a larger criminal network.
The original relationship can be expressed as:
Criminal — Victim — Intermediary
A more comprehensive model would add:
Criminal → Technical Infrastructure → Social Engineer → Victim → Financial Intermediary → Money Mule → Financial Institution → Ultimate Beneficiary
Not every offence will contain every component. The purpose of the expanded model is therefore not to create another rigid typology but to encourage investigators to identify functional relationships.
The principal investigative question becomes:
What role does each participant perform, and what evidence connects that participant to the other components of the criminal network?
This network-based approach also makes the theory compatible with contemporary digital-forensic methods, financial intelligence and international cooperation.
The weaponisation of technology has transformed the organisational structure of cyber-enabled crime. Criminals can exploit social engineering, telecommunications systems, online payment platforms, stolen identities and compromised accounts to separate themselves from victims and criminal proceeds.
The Triangular Theory of Crimes provides a useful framework for understanding this phenomenon by emphasising the interaction between criminals, victims and intermediaries. Its principal contribution is its recognition that the person immediately visible within a digital or financial transaction may represent only one component of a much larger criminal network.
The theory should nevertheless be presented cautiously. It is more accurately described as a developing criminological and investigative framework than as an established universal theory of cybercrime. Its propositions require systematic empirical testing and comparative research.
Its greatest potential lies in combining criminological theory with digital forensics, financial intelligence, cybersecurity governance, telecommunications regulation and international cooperation. The investigation of cybercrime must move beyond the question of ‘who used this device or account?’ towards the broader question of ‘what network of relationships made this offence possible?’
Such an approach is particularly important in jurisdictions where weaknesses in identity-management systems, telecommunications regulation and institutional oversight may create opportunities for cyber-enabled criminal networks. Ultimately, breaking the criminal triangle requires more than identifying an individual offender. It requires investigators to reconstruct the relationships, technologies, financial pathways and institutional vulnerabilities that connect the participants.
1. Saron Obia is an author and international-security practitioner and serves as Executive Director of Intelligence Security Solutions. He holds an MSc in Security Studies and a PGD in Criminology and Security Management from the Pan African Institute for Development West Africa. He is also identified by the authors as a certified cyber criminologist and public-policy analyst.
2. Nicasio Viana is Professor of Law at Candido Mendes University and a Federal Highway Police Agent in Brazil. He holds an LLM from the University of Michigan Law School and degrees in law and computer science.
3. INTERPOL, ‘Cybercrime’ (2026) (describing the transnational structure of contemporary cybercrime and the resulting challenges for law enforcement).
4. Saron Messembe Obia, Cyber Criminality as an Emergent Security Challenge in Cameroon (PGD thesis, Pan African Institute for Development West Africa 2015).
5. ibid.
6. ibid.
7. Ronald V Clarke and Marcus Felson (eds), Routine Activity and Rational Choice (Transaction Publishers 1993).
8. INTERPOL, ‘Hundreds arrested and millions seized in global INTERPOL operation against social engineering scams’ (15 June 2022).
9. INTERPOL, ‘Cybercrime’ (n 3).
10. INTERPOL, ‘Social engineering scams’ (2026).
11. United Nations Office on Drugs and Crime (UNODC), Digest of Cyber Organized Crime (2nd edn 2025).
12. Obia (n 4).
13. INTERPOL (n 8).
14. INTERPOL, ‘Digital forensics’ (2026).
15. INTERPOL, ‘Cybercrime’ (n 3).
16. ibid.
17. UNODC, Digest of Cyber Organized Crime (n 11).
18. Republic of Cameroon, Law No 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality in Cameroon, s 1. The law establishes the security framework for electronic communication networks and information systems and defines and punishes offences relating to ICT.
19. Republic of Cameroon, Law No 2010/013 of 21 December 2010 governing Electronic Communications in Cameroon. The legislation is listed by the Cameroonian telecommunications authorities as part of the country’s telecommunications and ICT legal framework.
20. ‘Cameroon cracks down on SIM misuse, orders subscriber data update’, Business in Cameroon (11 April 2024).
21. UNODC, The Nexus Between Cybercrime and Corruption (2025), discussing ICT-related forgery, alteration or deletion of electronic data and ICT-related fraud.
22. Majid Yar and Kevin F Steinmetz, Cybercrime and Society (3rd edn, SAGE 2019). The third edition expressly addresses cybercrime, computer hacking, cyberterrorism, policing the internet and criminological theorising of cybercrime.
23. Council of Europe, Convention on Cybercrime (Budapest Convention). The Convention is regarded as a comprehensive international framework for cybercrime and electronic evidence and provides a basis for international cooperation.
24. Council of Europe, Second Additional Protocol to the Convention on Cybercrime on Enhanced Co-operation and Disclosure of Electronic Evidence; see also Eurojust, ‘Second Additional Protocol to the Budapest Convention on Cybercrime and Cross-Border Access to Electronic Evidence’ (2024).
25. INTERPOL, ‘Digital forensics’ (n 14).
26. ibid.
27. ‘Cameroon cracks down on SIM misuse, orders subscriber data update’ (n 20). The report notes a 60-day requirement for subscriber-data updating and describes earlier regulatory problems involving pre-activated and inadequately identified SIM cards.
28. INTERPOL, ‘Cyber Capabilities & Capacity Development Project’ (2026).
29. INTERPOL, Africa Cyberthreat Assessment Report 2025. The report identifies increasingly targeted social-engineering attacks in Africa and notes the use of AI-generated text, audio and video to enhance fraudulent communications.
Republic of Cameroon, Law No 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality in Cameroon.
Republic of Cameroon, Law No 2010/013 of 21 December 2010 governing Electronic Communications in Cameroon.
Republic of Cameroon, Law No 2010/021 of 21 December 2010 governing Electronic Commerce in Cameroon.
Council of Europe, Convention on Cybercrime (Budapest Convention).
Council of Europe, Second Additional Protocol to the Convention on Cybercrime on Enhanced Co-operation and Disclosure of Electronic Evidence.
Clarke RV and Felson M (eds), Routine Activity and Rational Choice (Transaction Publishers 1993).
Obia SM, Cyber Criminality as an Emergent Security Challenge in Cameroon (PGD thesis, Pan African Institute for Development West Africa 2015).
Yar M and Steinmetz KF, Cybercrime and Society (3rd edn, SAGE 2019).
INTERPOL, ‘Cybercrime’ (2026).
INTERPOL, ‘Digital forensics’ (2026).
INTERPOL, ‘Social engineering scams’ (2026).
INTERPOL, ‘Cyber Capabilities & Capacity Development Project’ (2026).
INTERPOL, Africa Cyberthreat Assessment Report 2025.
INTERPOL, ‘Hundreds arrested and millions seized in global INTERPOL operation against social engineering scams’ (15 June 2022).
Ndofor, ‘MINAT boss goes tough on terrorism financing’, The Guardian Post (10 April 2024).
‘Cameroon cracks down on SIM misuse, orders subscriber data update’, Business in Cameroon (11 April 2024).
United Nations Office on Drugs and Crime, Digest of Cyber Organized Crime (2nd edn 2025).
United Nations Office on Drugs and Crime, The Nexus Between Cybercrime and Corruption (2025).