Cognyte TechHorizon 2024

by Cognyte

Cognyte TechHorizon

Top Tech Trends Impacting Law Enforcement Investigations in 2024

Technology Domains Covered:

  • Group Messaging Platforms
  • Cryptocurrency
  • IoT Devices
  • Satellite Comms
  • Drones
  • Responsible AI
  • Social Media Incitement
  • Quantum Computing
  • Video Analytics
  • Metaverse
  • Generative AI & LLMs
  • Human-Machine Collaboration
  • 5G Networks
  • 6G Networks

Page 1

What You Need to Know

The rapid pace of technology advancement is shaping the future of crime. Criminals are quick to adopt the latest technologies for their illicit aims, while law enforcement authorities often find themselves playing catchup. The aim of this report is to examine developing technologies and to analyze their impact on criminal activities as well as the implications for law enforcement practices.

Technology is often a double-edged sword, with technological advancements posing threats, as well as opportunities. It is essential for members of the law enforcement community, including those operating in investigations, intelligence analysis and information technology roles, to consider not only the challenges created by developing technologies but also the opportunities to use them to fight crime.

Cognyte's TechHorizon report serves as a starting point to:

  • Analyze technology trends impacting the criminal landscape.
  • Explore the impact on law enforcement investigations, intelligence analysis and tactical operations.
  • Consider when these technologies will reach mainstream adoption and consequently when your organization must be ready for the implications.
  • Assess which technological capabilities your organization requires today, and in the coming years.
  • Consider key questions to help assess your organization's readiness level.

Page 2

Technology Domains Overview

The report explores the following technology domains:

The analysis in this report is based on Cognyte's technological expertise in domains including big data, machine learning and AI, decades of experience in investigation and intelligence best practices, and ongoing engagement with hundreds of our customers worldwide.

Domain Categories:

DIGITAL AGE

Tracking bad actors' digital footprints is crucial for combating crime

CONNECTED WORLD

Criminals are more connected than ever, and find it easier to evade detection

NEXT-GEN CAPABILITIES

Powerful technology is becoming more accessible to criminals

AI-POWERED INFRASTRUCTURE

AI capabilities are critical for Law Enforcement to keep up

Time to Mainstream Adoption (TODAY to LONG-TERM):

  • TODAY: Group Messaging Platforms, Cryptocurrency
  • Near-term: IoT Devices, Online Incitement, 5G Networks, Drones, Generative AI & LLMs, Video Analytics
  • Near-term to Long-term: Satellite Communications, Human-machine Collaboration, Responsible AI
  • Long-term: Metaverse, Quantum Computing, 6G Networks

Page 3

DIGITAL AGE

Group Messaging Platforms

Group messaging platforms, originally conceived to enable one-to-one interactions and group chats, today have in many cases evolved into full-fledged communities and are competing with traditional social media platforms as the primary space where users socialize, communicate and consume news.

Telegram and Discord have soared in popularity, while other popular messaging apps have followed suit by launching community features, such as WhatsApp communities and Viber groups.

Criminals and extremists are moving away from traditional social media platforms, such as Facebook and X, and they are also shifting away from Dark Web marketplaces and forums. Bad actors are migrating to group messaging apps, especially Telegram, Discord and Signal, which are attractive to criminals for their focus on privacy and security, as well as perceived anonymity.

Impact:

After the outbreak of war in Ukraine, several significant Dark Web marketplaces and forums were shut down through intensive law enforcement operations by Western European and US agencies. As a result, cyber-criminals, threat actors and ransomware groups were looking for a new online arena to exchange information, trade stolen data, share attack tools, exchange target lists, and discuss vulnerabilities. Many messaging apps have seen a huge influx of criminals, with rapidly multiplying numbers of channels and accounts dedicated to cyber-crime, financial fraud, hacktivism, migrant smuggling, drug trafficking and terrorism.

It is easier for bad actors to hide their identity on Telegram and Discord, because fewer identifying details are required to use the service. Another advantage for bad actors is that less technical proficiency is needed to make purchases and open new channels related to illicit activities, compared to Tor sites on the Dark Web.

  • 800M Telegram monthly users worldwide
  • 150M Discord monthly active users worldwide

Page 4

Time till mainstream adoption: TODAY

Findings from Cognyte's cyber research team illustrate the migration of criminals to messaging platforms. The number of cyber-crime related messages in Telegram exploded from 27 million in 2019 to almost 2 billion in 2022, while the volume of such messages in Dark Web forums declined 54% to roughly 101 million during the same period.

Number of Messages & Posts Related to Cyber-Crime

Year Telegram Dark Web
2019 27M 219M
2020 342M 202M
2021 1,569M 160M
2022 1,915M 101M

Source: Cognyte Cyber Research Team

Technology capabilities needed:

The migration of bad actors to group messaging apps has created challenges for authorities attempting to keep up with the scope and scale of criminal and extremist activity on these platforms. Criminals frequently close groups and servers and open new ones, requiring investigators to keep up. It's harder to search and find Telegram groups and channels and Discord servers associated with illicit activity, compared to platforms like Facebook and X. For example, the search capability on Discord is limited, a user needs to obtain the direct link to a server in order to join it. In addition, Telegram and Discord gather less user data compared to traditional social media platforms. For example, Discord does not require a user's phone number to open an account. These conditions make it harder for law enforcement to track and monitor illegal activity and discover the real identities of criminals.

Page 5

Technology Capabilities Needed for Group Messaging Platforms

Threat intelligence- Monitoring illicit content in Telegram and Discord is technologically more complex than monitoring Dark Web forums and sites. In addition, Telegram and Discord have a more lenient approach to content moderation, and as a result, illicit content is proliferating rapidly on these platforms. To keep up with the massive data volumes and technological constraints, authorities require threat intelligence solutions that incorporate advanced AI capabilities, including generative AI, to monitor, collect, process, analyze, classify and prioritize threat data at scale.

Web intelligence- Authorities require the ability to track suspects' digital footsteps across all layers of the web in order to connect the virtual identities of messaging app users to their accounts on other social media and web platforms.

Investigators require AI-powered media analytics to analyze all types of content, including text, images, video and even audio. For example, many Discord servers are audio-only - they only allow voice notes. Therefore, audio analytics, speech-to-text transcription and text analytics are crucial.

Key questions:

  • What are the top messaging apps being used by criminal and extremist elements in your jurisdiction?
  • What are the most prominent threat vectors your organization is seeing in those messaging apps?
  • Is your organization able to effectively monitor and analyze criminal activity on group messaging apps?

Page 6

DIGITAL AGE

Cryptocurrency

While the crypto market has experienced severe volatility in the past few years, with many crypto coins and exchanges collapsing, criminals remain keenly interested in using cryptocurrencies.

Crypto is particularly appealing to criminals due to:

  • Anonymity: While transactions are recorded on the blockchain, the identities of transaction makers are unknown.
  • Easy storage & transfer: Unlike cash, requires no physical space to store and can be swiftly moved.
  • Access & speed: Transactions are not processed through traditional financial institutions, and trading can be done easily and cheaply through a wallet app or crypto ATM.
  • Borderless: Crypto can be transferred across borders without currency controls, regulations or other barriers.

Impact:

Criminals are using crypto to facilitate fraud, money laundering, drug trafficking, terror funding, ransomware attacks and other cybercrimes. The types of crimes and sophistication of techniques are constantly evolving, forcing law enforcement to keep up.

Sanction evaders are increasingly using crypto to bypass economic regulations. In fact, 43% of illicit crypto transaction volume in 2022 came from activity associated with sanctioned entities.

Criminals are increasingly using stablecoins, such as USDT and USDC, due to volatility in the crypto market. Stablecoins are cryptocurrencies that attempt to maintain price stability by keeping reserves of fiat currencies, or through other methods. While Bitcoin was the currency used in 97% of illicit trade volume in 2016, in 2022 it accounted for only 19%, in part due to the move to stablecoins.

Page 7

Time till mainstream adoption: TODAY

Illicit cryptocurrency transactions reached an all-time high of $20.6 billion worldwide in 2022. While this represents less than 1% of the total worldwide value of cryptocurrency transactions, these illicit transactions have an outsize impact by fueling many types of serious crime.

Total Cryptocurrency Value Received by Illicit Addresses

Year Total Value
2020 $8.4B
2021 $18.1B
2022 $20.6B

Categories: Sanctions, Ransomware, Fraud shop, Scams, Cybercriminal administrator, Darknet market, Stolen funds

Source: Chainalysis 2023

Technology capabilities needed:

Blockchain analysis- Investigators can use blockchain analysis solutions to analyze, identify and cluster data from blockchain public ledgers. These tools model and visually represent data to help investigators identify key information about suspicious users and transactions. In certain cases, investigators can successfully breach the anonymity of crypto if they follow the money trail of transactions to mainstream exchanges which enforce Know Your Customer (KYC) regulations and then obtain the account holder's identity.

Blockchain analytics for de-anonymization- Criminals often employ the use of mixers and shapeshifters, stealth addresses, chain and asset swapping, privacy-enhanced communication, and privacy wallets to hide their identities. Instead of using mainstream exchanges, they often "cash out" through illicit exchanges or decentralized, peer-to-peer exchanges, and use non-custodial wallets. In the case of non-custodial wallets, also known as unhosted wallets, no entity enforces KYC regulations and only the wallet owner has the private keys which enable accessing and transferring funds.

Authorities may detect that a non-custodial wallet is associated with illicit activity, but without the right blockchain analytics solutions they cannot determine who is the owner of the wallet and have no way to seize the funds.

Page 8

Advanced Cryptocurrency Investigation Capabilities

Even when criminals do use mainstream exchanges, law enforcement must obtain cooperation from the exchanges, which can be difficult due to legal jurisdiction, compliance constraints, and other factors.

In these more complex scenarios, authorities require blockchain analytics solutions which:

  • De-anonymize wallet owners and transaction makers suspected of illicit activity, despite obstacles which impede traditional blockchain analysis tools, such as illicit exchanges, mixers, shapeshifters and privacy coins.
  • Remove the need for cooperation from third parties such as exchanges, CSPs and wallet application vendors, who may not cooperate or may complicate confidential or time-sensitive investigations.
  • Provide a holistic profile of suspects by tracking suspects' crypto activity and behavior over time, allowing investigators to understand their methods of operation, including which devices and wallets they use.
  • Tap into intelligence data sources beyond open-source data and publicly available information.

Decision intelligence- With crypto being used by criminals to facilitate diverse types of crime and to launder the illicit profits, crypto investigations are no longer siloed but are now part of complex, cross-domain investigations.

Decision intelligence platforms enable authorities to fuse data from multiple systems and sources including blockchain analytics, open-source intelligence, financial transactions and more. This enables investigators to construct a full picture of all suspects, organizations, companies and financial accounts involved and to map out the money trail and uncover hidden connections and insights.

Page 9

Key questions:

  • What is the volume of cryptocurrency transactions in your country, and how much is connected to illicit activities?
  • Does your organization have the ability to de-anonymize crypto wallets and transaction makers involved in criminal activities?

Top Countries by Cryptocurrency Value Received (Billions USD)

Jul 2022-Jun 2023 (excluding United States)

Country Value (Billions USD)
India ~270B
UK ~250B
Turkey ~150B
Russia ~130B
Canada ~110B
Vietnam ~105B
Thailand ~100B
Germany ~100B

Source: Chainalysis 2023

Page 10

DIGITAL AGE

IoT & connected devices

From wearables to smart houses and connected cars, the Internet of Things (IoT) has penetrated our lives across a broad range of uses, including:

Residential:

Consumers are using an ever-expanding array of IoT devices including wearables, electronics, smart home devices, as well as smart TVs and speakers. Households in developed markets typically have dozens of devices, with an average of 21 connected devices in the US and 20.5 in Australia.

Transportation:

There are an estimated 192 million connected vehicles worldwide, many of them electric vehicles. These vehicles leverage IoT for many purposes including the monitoring of telemetry and maintenance data, fleet management, logistics, infotainment and more.

Enterprise:

IoT has many applications in the enterprise domain including retail, manufacturing, supply chain management, shipping and much more.

Critical infrastructure:

IoT devices, sensors and cameras are widely used in critical infrastructure, including energy, water, transportation and public safety. Use cases range from monitoring and controlling electricity, gas and oil utilities, to enabling smart grid and smart meter technologies, orchestrating smart traffic management and monitoring surveillance cameras to combat crime.

Common Types of IoT & Connected Devices

Fitness Trackers, Cameras, Smart TVs, Smartwatches, Health Monitors, Thermostats, Door Locks, Pet Cameras, Doorbell Cameras, Home Assistants, Earbuds, Speakers, Connected cars

Page 11

Impact:

IoT and connected devices present law enforcement with valuable new sources of data for investigations, beyond the traditional focus on mobile phones.

Today, gathering and analyzing information from IoT and connected devices is crucial and can help to deepen and enrich intelligence on suspects, especially when suspects use burner phones or employ other tactics to evade detection.

The right tools can help investigators and analysts to understand with whom suspects are communicating, with which gangs or organizations they are affiliated, and which locations they frequent. Authorities can be alerted when suspects enter an area of interest or deviate from their typical routes.

However, the growing number of IoT devices also presents a challenge given that they create more attack vectors for criminals to engage in cybercrime.

"There is a growing number of cases involving malware-infected IoT devices, which exploit software vulnerabilities or weak authentication settings. These vulnerabilities can be exploited by criminals seeking to collect personal data, compromise user credentials or even spy on people or organizations" — Europol

As IoT technology is increasingly used in industrial settings, public utilities and smart city infrastructure, cyber-attacks are becoming a physical threat.

Time till mainstream adoption: TODAY

IoT and connected devices have reached mainstream adoption in many countries, with an estimated 16.7 billion devices worldwide in 2023, a number expected to pass 29 billion by 2030.

IoT devices rely on cellular, Wi-Fi or Bluetooth connectivity, and it is expected that the rollout of 5G networks will speed adoption even further by providing faster and more reliable connectivity.

Number of IoT Devices Worldwide

  • 2023: 16.7B
  • 2030: 29B

Page 12

Technology capabilities needed:

Network intelligence - To tap into valuable information generated by IoT devices and obtain critical clues and evidence, investigators and analysts require network intelligence solutions that are capable of accessing and analyzing the huge amounts of data and extracting actionable intelligence.

Operational intelligence - Tactical teams in the field require advanced operational intelligence solutions in order to effectively identify, locate and gather valuable information from IoT devices while remaining covert. Staying up to date with the ever-expanding types of devices as well as new Wi-Fi, Bluetooth and cellular protocols, all while overcoming the related technological barriers, is crucial.

Decision intelligence – A wealth of valuable data can be obtained from IoT devices, however decision intelligence platforms are needed for fusing together and analyzing those disconnected and diverse sources into a holistic picture of a suspect, an incident or a geographic location in order to enable investigators and decision-makers to make critical decisions.

In many cases the fusion and analysis is done in hindsight, for example after a crime has been committed or when a suspect is being investigated. However, data feeds from IoT devices, such as security cameras from retail stores, are increasingly being provided to law enforcement in real time so that suspicious indicators or activities can be analyzed proactively.

Key questions:

  • How much of a suspect's digital footprint are your investigative and tactical teams able to cover today?

LEARN MORE ABOUT DECISION INTELLIGENCE

Page 13

DIGITAL AGE

Social media incitement

Social media and web apps are integral to people's lives today, serving as indispensable tools for communications, commerce, and the consumption of entertainment and news. The dark side of social media is the growing threat posed to public safety and social cohesion by influence campaigns, fake news and disinformation.

Impact:

Social media incitement can amplify and escalate conflicts, violence and crime, endanger public health and undermine public trust in government authorities.

This phenomenon is a challenge for law enforcement because what begins online, quickly reaches the physical world.

Social media incitement has frequently fueled the targeting of migrants and minorities, soccer hooliganism, harassment of women, organized mass looting and public disorder. Many instances have been documented of violent attacks against migrants or minority groups that were directly fueled by xenophobic and anti-immigrant online campaigns.

For example, "Operation Dudula" in South Africa started in 2019 by spreading false and misleading information about Zimbabweans, Namibians, and other migrants, accusing them of stealing jobs, committing crimes, or spreading diseases. Since then, Operation Dudula has grown into an organized movement that organizes raids and protests against foreign-owned businesses and undocumented immigrants. In May 2023, the movement declared itself a political party intending to contest the 2024 elections.

"Disinformation poses increasing challenges to police forces and society, especially when it is spread in a coordinated campaign. In times of political, economic and social instability, disinformation is able to discredit state institutions, spread hatred and trigger subgroups of the population to pursue their own political, social or economic objectives in an inadmissible or unlawful way." Joachim Fassbender, German Police University

Page 14

The spread of false narratives can encourage further acts of violence (retaliatory attacks), deepen ethnic hatred and strife, and destabilize entire communities.

TikTok video associated with Operation Dudula

Time till mainstream adoption: TODAY

An estimated 4.9 billion people worldwide use social media in 2023, a number which is expected to reach 5.85 billion by 2027. This presents bad actors with a large and easily accessible audience to target with influence campaigns, fake news and disinformation. One measure of the threat can be seen in a University of Oxford report, which found evidence of organized social media influence campaigns in each of the 81 surveyed countries in 2020, up from 70 countries in 2019.

Of 81 countries surveyed around the world:

  • 86% were attacked by organized social media influence campaigns in 2019
  • 100% were attacked by organized social media influence campaigns in 2020

Page 15

Technology capabilities needed:

Web intelligence- Authorities require web intelligence solutions with advanced analytics to detect influence campaigns, fake news and disinformation across all layers of the web, across all media formats (text, image, video and audio) and in multiple languages, and to de-anonymize the bad actors behind them. Authorities require the ability to quickly pinpoint trending hashtags and online discourse promoting violence and illicit activities. AI-powered enrichment, including image and video analytics, is crucial for detecting harmful content, such as graphic violence and weapons.

Decision intelligence- These solutions enable authorities to uncover the real-world identities of anonymous online users who are inciting violence, and to map whether they are part of extremist networks or criminal organizations. Decision intelligence platforms use data fusion and machine learning to fuse data from virtually any source to provide a cohesive investigative picture, uncover hidden relations and accelerate investigations.

Key questions:

  • Is your organization able to effectively monitor trending online topics and discourse which are fostering violence and public disorder?
  • Is your organization able to effectively analyze whether opinions and content being shared online are genuine, or part of an organized campaign orchestrated by bad actors?

LEARN MORE ABOUT DECISION INTELLIGENCE

Page 16

DIGITAL AGE

Metaverse

The metaverse is broadly defined as a single, interconnected virtual world offering users persistent and immersive spaces to work, learn and play. The very concept of what the metaverse will be is still evolving, however many technologies and platforms already in use today represent the beginnings of the metaverse. Virtual reality headsets, spatial computing, sensors and haptics can create immersive, virtual realities. Over half a billion users today are already active on gaming platforms (such as Roblox and Fortnite) and blockchain-based virtual worlds (such as Decentraland and Sandbox) where players interact in the form of avatars and can take part in a larger virtual world.

Impact:

Although the metaverse is in early stages, cybercriminals are already finding various methods to defraud victims, including phishing, social engineering, fake NFTs, and more. There have been numerous cases documented of social engineering scams which impersonated legitimate metaverse platforms, creators, or influencers, and tricked users into clicking on malicious links, downloading malware, purchasing fake assets or revealing sensitive information such as passwords, private keys, or wallet addresses. Other scams include selling counterfeit or stolen NFTs, or schemes where the developers or promoters of a metaverse project suddenly disappear with the funds raised from investors or users, leaving them with worthless tokens or assets.

Page 17

In the future, a fully realized metaverse, as it is currently envisioned, will provide greater potential for anonymity. The use of avatars and cryptocurrencies will create challenges for law enforcement in tracking crime carried out in the virtual world. The use of virtual assets, goods and money will likely create new opportunities for theft and money laundering. The importance of digital identities in the metaverse and the potential for manipulation will likely lead to an increase in ransomware attacks. As physical location becomes almost devoid of significance, the ability to conduct crimes across borders - whether financial scams, bullying, harassment or others - will increase. It will be difficult, at least under today's judicial systems, to determine which country has jurisdiction and which legal framework applies to crimes carried out in virtual reality.

Time till mainstream adoption: LONG TERM

After the massive hype around the metaverse peaked in 2022, expectations have become more tempered. Sales of VR and AR headsets have fallen short of overly optimistic estimates, and metaverse platforms are seeing very modest growth in the number of users. Research firms Gartner and Forrester expect it will be at least 2030 before a full-blown version of the metaverse reaches mainstream adoption. However, criminals are already finding ways to exploit the beginnings of the metaverse for their illicit aims.

Technology capabilities needed:

Web intelligence- To map suspects' digital footprint across all layers of the web and connect them to virtual identities in the metaverse, authorities will require robust web intelligence solutions.

Blockchain analytics- As it is expected that cryptocurrencies will underpin financial activity in the metaverse, authorities will require blockchain analytics solutions to de-anonymize the identities of suspects behind illicit transactions.

LEARN MORE ABOUT BLOCKCHAIN ANALYTICS

Page 18

CONNECTED WORLD

5G Networks

Communications Service Providers (CSPs) worldwide are rolling out fifth generation wireless networks. 5G represents a significant leap forward from 4G networks and enables substantially faster data connections, low latency and more reliable and secure connections. Most 5G networks that have been rolled out to date use a 5G NSA (Non-Standalone) architecture, which relies on existing 4G LTE network infrastructure as the backbone. However, an increasing number of networks are using 5G SA (Standalone) architecture, meaning they are built on a completely new core network and offer the full potential of 5G.

Impact:

5G SA is a new cellular technology which uses high speed bands, and introduces new protocols and encrypted subscriber identifiers. This creates new challenges for the network intelligence solutions which law enforcement organizations rely on to enable the lawful interception of suspects, in accordance with warrants or court orders. It also creates challenges for operational intelligence solutions used by tactical teams in field missions. Europol has stated that 5G SA technology will "complicate the use of the unique mobile phone card identifiers that allow law enforcement to identify and locate devices," thus making it more difficult to carry out legally permissible investigations of suspected criminals.

Europol states that without 5G-ready solutions "one of the most important tactical operational and investigation tools would therefore become obsolete," providing a potential boon for criminals who want to evade detection and hide their illicit activities.

Page 19

Time till mainstream adoption: TODAY

Despite economic slowdowns in some markets, 5G network rollouts are continuing and subscriptions are increasing in every region worldwide and expected to reach 1.5 billion by the end of 2023. 273 CSPs worldwide have already launched commercial 5G services, of which 47 are 5G SA.

  • 1.5Bn 5G subscriptions by the end of 2023
  • 240 CSPs have launched 5G services
  • 47 of these network rollouts are 5G SA

Technology capabilities needed:

Law enforcement organizations require network intelligence and operational intelligence solutions that can operate successfully in 5G SA environments, including support for:

New interfaces & standards- 5G SA introduces a brand-new network architecture centered around IP connectivity. The 5G infrastructure has new network elements and functions, new interfaces, protocols and control flows, as well as new encrypted subscriber identifiers.

Growing data throughput- Mobile traffic will grow dramatically as 5G networks spread. Ericsson reports that worldwide mobile traffic reached 93EB per month in 2022 and is expected to grow to a staggering 472EB per month by the end of 2028, with 5G accounting for the majority of traffic. In addition, the average consumption per device per month is expected to grow from 20GB/month in 2023 to more than 47GB/month in 2028. System processing power and sizing will need to adapt accordingly.

Handover between legacy and new technologies- A commercial 5G launch does not mean the full country is covered by 5G service, typically the coverage is centered around major cities. Therefore, 2G, 3G and 4G technologies will remain for at least several years. To provide continuous support, solutions must be able to properly operate during handover between different network access technologies.

Worldwide Mobile Data Traffic

  • 2022: 93EB
  • 2028: 472EB

Data Consumption Per Mobile Device

  • 2023: 20GB/month
  • 2028: 47GB/month

Page 20

5G Networks

With increased adoption of 5G, the amount of mobile data generated by suspects will grow significantly, especially as more usage may shift away from Wi-Fi. Law enforcement teams will need solutions powered by advanced analytics to help them parse through massive volumes of data in order to generate actionable insights to investigate and combat crime.

5G SA Deployments by Region

as of July 2023

Region Deployments
Asia-Pacific 21
Europe 11
North America 7
Middle East & Africa 5
Caribbean & Latin America 3

Western Europe Countries with Largest Number of 5G Subscribers

as of July 2022

Country Subscribers
Germany 100.7M
UK 67.7M
Italy 57.9M
France 55.2M
Spain 40.3M

Key questions:

  • What is the current 5G adoption level in your country or jurisdiction?
  • Are the lawful interception systems used by your organization's investigators and analysts 5G-ready?
  • Are your organization's field teams equipped with 5G-ready operational intelligence solutions that can adequately support their tactical missions?

Page 21

CONNECTED WORLD

Satellite communications

Traditional satellite communications providers, such as Iridium, Thuraya and Inmarsat, have been providing satellite phone services for many years, and today support a subscriber base of a few million users worldwide. This legacy domain is undergoing disruption as new and more advanced satellite constellations are being launched, fast and affordable satellite broadband service has emerged, and the first stages of convergence between traditional mobile phones and satellite telephony have begun.

Especially in remote, rural and hard to reach areas, which typically suffer from limited mobile and fixed telephony coverage, satellite is becoming the new internet backbone.

Starlink, a satellite constellation of over 5,000 thousand low-Earth orbit (LEO) satellites, was launched by SpaceX in 2019. Competing satellite broadband players, such as OneWeb and O3B, are emerging, and additional players such as the Amazon-backed Project Kuiper have announced plans to invest and launch their own new satellite constellations.

Impact:

With satellite communications maturing and becoming commoditized, this technology is becoming more widely accessible to a broader population, both for legitimate as well as illicit purposes.

Satellite internet

Criminals, including drug traffickers, smugglers and illegal miners, have long used satellite communications in remote regions with poor mobile coverage, but until now, that entailed installing a heavy, fixed antenna in challenging terrain and conditions. And those connections were slow and unstable, especially in bad weather. Starlink's service offers affordable pricing, fast speeds, easy do-it-yourself installation, and the routers are small and portable.

As a result, criminals have begun to adopt the service. For example, police in Brazil have reported seizing Starlink terminals in raids at numerous illegal mining camps. Even governments which have not yet licensed Starlink for use are seeing the service being operated illegally in their countries. Regulators in Ghana, South Africa, Zimbabwe and Senegal have recently issued warnings to the public and Starlink resellers against operating without permission.

Page 22

Satellite and mobile device convergence

Enabling satellite calls, messaging and data is becoming a focus for chipmakers, smartphone manufacturers and CSPs, with recent developments including:

Huawei: Mate 60 Pro device reportedly supports satellite connectivity for voice calls and SMS, using China's Tiantong-1 satellite system.

Apple: Limited satellite connectivity for the iPhone 14 and 15 enables sending one-way emergency SOS messages.

Qualcomm: 6 smartphone manufacturers, including Motorola and Xiaomi, will launch devices using Qualcomm's Snapdragon Satellite feature, which enables two-way SMS messaging through the Iridium satellite network.

Starlink: Direct to Cell service to roll out in 2024, first with text messaging, and expanding to voice and data in 2025. The service reportedly will work with standard LTE devices for subscribers of T-Mobile (US), Rogers (Canada), Optus (Australia), One NZ (New Zealand), Salt (Switzerland) and KDDI (Japan).

Today, authorities rely on their ability to monitor and investigate suspects' communications on traditional communications networks. If criminals circumvent these channels, it creates new challenges for law enforcement.

With more accessible satellite communications, criminals and other bad actors will find it easier to communicate independently of cellular networks, and thus more easily evade detection by authorities.

Time till mainstream adoption: NEAR TERM

Starlink's satellite internet service is currently available in over 60 countries and has reached 2 million customers worldwide as of Sept. 2023, with analysts projecting over 30 million customers by 2027.

Convergence of satellite and mobile devices is in initial stages, but is expected to grow over the coming years.

Page 23

Technology capabilities needed:

Network intelligence- Authorities rely on lawful interception capabilities to conduct legally permissible investigations of suspects, in accordance with warrants or court orders. As satellite communications becomes more prevalent, it will be critical for law enforcement to leverage advanced and comprehensive network intelligence solutions that can connect not only to standard gateways but also support new communications technologies, such as satellite. Solutions that can enable investigators and analysts to rapidly transform vast amounts of data into meaningful intelligence, and generate court-compliant evidence, will be ever more crucial.

Operational intelligence- Tactical teams can gather valuable intelligence in the field on criminals who are using traditional satellite communications services, such as Iridium, Thuraya and Inmarsat, by using operational intelligence solutions. As satellite internet and satellite-cellular convergence become mainstream, operational intelligence solutions that can support these new communications technologies will be essential.

Satellite communications- Satellite technology can also be a valuable tool for law enforcement's own use. The EU has launched an initiative to build the IRIS2 Satellite Constellation as a sovereign alternative. IRIS2, which is planned to be fully operational by 2027, is meant to fill gaps in internet blackspots and allow European governments, intelligence agencies and militaries to communicate securely. It will also support border surveillance, crisis management and secure communications for EU embassies.

Key questions:

  • To what extent is satellite communications being used in your jurisdiction by criminals, and through which providers?
  • Do your organization's analysts and field teams have the necessary tools to investigate suspects that use satellite communications?

Page 24

CONNECTED WORLD

6G Networks

6G wireless networks will be the successor to 5G, however the technology is still in early stages of research and development, and industry or government standards have not been defined yet. While it is still too early to determine which use cases 6G will support and what capabilities it will provide in terms of bandwidth, latency and speed, experts believe 6G will enable more advanced applications and services such as immersive experiences and life-like, hologram video calls, as well as cyber-physical fusion through wearable devices and micro-devices mounted on the human body.

Impact:

When 6G networks are rolled out in the future, criminals using those services will have an easier time evading detection and hiding their illicit activities, until authorities upgrade their systems.

Time till mainstream adoption: LONG TERM

Experts anticipate 6G networks will become available in the early 2030s.

Technology capabilities needed:

It will take time until 6G standards are defined, however it is likely that the new network protocols and technologies will impact law enforcement authorities' ability to carry out legally permissible investigations of suspects and tactical operations. As a result, authorities will need to upgrade the network intelligence solutions used by investigators and the operational intelligence solutions used by tactical teams in the field.

Page 25

NEXT-GEN CAPABILITIES

Drones

As drone technology has evolved quickly in recent years, drones have become smaller, more affordable and easier to operate while offering increased range and flight time. In many countries, the use of drones for non-commercial purposes is unregulated, making it easy for individuals to use drones without needing special permissions or licenses.

Impact:

Drones are creating new challenges for law enforcement as criminals use them in diverse ways, including:

  • Surveilling borders to enable cartels and traffickers to find gaps in barriers and detect pauses in patrols by border agents
  • Physically smuggling illicit drugs across borders, and dropping contraband into prisons
  • Scoping out potential targets for thefts, such as construction sites and agricultural areas

In addition, incidents of drones disrupting airport operations have been rising in frequency and pose a significant flight safety risk.

However, drones also present an opportunity for law enforcement, as they can be used to conduct surveillance, search for missing persons, conduct border patrols, and provide operational support for tactical missions.

75% of contraband seizures in Canadian prisons are attributed to drone drops

Page 26

Time till mainstream adoption: TODAY

Drones have reached mainstream adoption, with an estimated 7.56 million consumer drones sold worldwide annually.

Technology capabilities needed:

Network intelligence- By using sophisticated models and algorithms, cutting-edge network intelligence solutions can analyze massive quantities of network data rapidly and effectively and thus enable authorities to detect mobile devices being used to operate drones for illicit purposes, and ultimately track down the operators.

Counter-drone- Authorities require solutions which enable them to detect and classify unauthorized or rogue drones, with the ability to locate, track, and ultimately neutralize them.

Decision intelligence- Decision intelligence solutions can enable authorities to analyze video received by drones operated by law enforcement in order to extract insights, provide alerts and trigger actions. For example, video received from surveillance drones can be analyzed to detect individuals moving through defined areas, determine how many individuals are in the group, how fast they are moving and in which direction, and if needed trigger alerts to send tactical teams to intercept.

Key questions:

  • Does your organization have the ability to detect and uncover the operators of rogue drones?

LEARN MORE ABOUT DECISION INTELLIGENCE

Page 27

NEXT-GEN CAPABILITIES

Generative AI & Large Language Models

Generative AI capabilities allow AI systems to create original content, such as text, images, audio, video or programming code, based on learned patterns and knowledge. Generative AI systems do this using various methods and models, such as generative adversarial networks (GANs) and large language models (LLMs).

Thanks to tools such as Midjourney, GANs can be easily leveraged to create new images for legitimate purposes. However, criminals are using GANs to create deepfakes (fake audio or video) for malicious purposes.

LLMs are designed and trained to understand language and generate human-like text. LLMs excel at a variety of natural language processing (NLP) tasks, including text completion, sentiment analysis, translation and answering questions. AI bots, such as ChatGPT, Bard and Bing, which are powered by LLMs have become immensely popular. AI bots developed by legitimate companies include safety features designed to prevent malicious usage. Many of these safeguards, however, can be easily circumvented through prompt engineering.

Impact:

Generative AI capabilities can be harnessed to accelerate the speed and scope of cyber-crime and other criminal activities:

Committing fraud and scams- Different types of generative AI can be employed alone or in combination:

  • Text-based: Creating more believable phishing emails personalized to recipients, on a mass scale. LLMs can utilize original documentation, such as emails from a legitimate payment provider, to compose content that mimics the author's writing style, tone, and commonly used words. Criminals can also leverage LLMs to run automated bots, which can convincingly mimic the communication style of real individuals or customer service representatives, to aid scams relating to phishing emails or malicious websites.
  • Video-based: Creating deepfake videos for the purposes of extortion, to help establish false identities for scams and frauds, etc.

Page 28

Generative AI & Large Language Models (continued)

  • Audio-based: Using AI-generated voice synthesis for voice phishing (vishing) to impersonate individuals and trick victims into revealing personal details, transfer funds to an external account, etc.
  • Image-based: Creating fake identities for social engineering, to scam victims or manipulate them into revealing sensitive information.

Creating and spreading malware- LLMs lower the bar for would-be hackers to build effective malware and makes it easier for those with basic skills to develop much more advanced programs. Bad actors will no longer need extensive development expertise or coding skills, which could lead to an increase in the number of attacks. ChatGPT makes writing code in less common languages simpler for novices and experts alike. Anti-malware software tools have a harder time detecting malware in these languages, making it more likely to slip through the cracks of that security layer.

Financial crime and others- LLMs accelerate the scope and scale of financial crime by facilitating document fraud, falsification of online identities and enabling criminals to circumvent Know Your Customer (KYC) mechanisms. LLMs are also enabling increased online harassment and bullying, and the spread of disinformation.

Page 29

Time till mainstream adoption: TODAY

The first cases of criminals using LLMs for cyber-crime have been documented, and experts believe this is only the beginning. Not only are criminals using LLM-powered AI bots developed by legitimate tech companies such as Google, Microsoft, and OpenAI, but there is also a new trend of 'dark' AI bots emerging, such as WormGPT and FraudGPT, which have been developed expressly without ethical guardrails in place, in order to facilitate malicious uses.

Technology capabilities needed:

Threat intelligence- As Generative AI technology becomes more accessible and sophisticated, cyber-attacks are expected to grow in scale and sophistication. Threat intelligence solutions with generative AI capabilities can enable law enforcement authorities to tackle two main challenges - data overload and alert fatigue. By employing such technologies, massive amounts of data can be analyzed, filtered, classified and scored in a matter of minutes. Moreover, it will reduce overall risk by strengthening the ability of SOC analysts and threat intelligence teams to mitigate threats more quickly and effectively and to analyze more relevant risk indicators.

Cyber-security- In addition to threat intelligence, additional cybersecurity solutions are needed for use cases including vulnerability detection, false-positive reduction, remediation assistant, code generation and code documentation.

Key questions:

  • Has your organization mapped where generative AI can improve cyber security processes, such as operating threat intelligence at scale, accelerating response time and improving detection accuracy?

LEARN MORE ABOUT THREAT INTELLIGENCE

Page 30