A Dutch government-commissioned study found that most young cybercriminals reach the height of their illicit activity around age 20, with the vast majority ceasing such behavior soon after. Data from over 500,000 Dutch students showed that 76% of cybercrime actors peaked at this age, and only 4% continued to show increased odds of criminal activity later in life. The research highlights that hacking skills and technological curiosity are key factors for those who remain involved in cybercrime beyond their early twenties.
The study also revealed that cybercrime among adolescents is relatively rare compared to other offenses, such as property crimes, and that the risk of being caught is low. Most young offenders never enter the justice system, and a small percentage are only suspected once. The findings suggest that, similar to other forms of youth crime, cybercriminal activity is typically a transient phase, with only a small minority persisting due to ongoing interest and skill development in technology.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A Dutch government report found that most young cybercriminals reach peak offending around age 20 and then desist soon after, with only a small minority continuing into adulthood. The study linked longer-term offending to greater technical skill and sustained technological curiosity, and noted that perceived risk of being caught is low.
Atlas Research conducted a study for the Dutch Research and Data Centre using a cohort of roughly 500,000 students who finished primary school between 2008 and 2011 to analyze how cybercrime offending develops over time among young people in the Netherlands.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.