Cybercrime DB

Joint Cybercrime Investigation Teams in the EU

Europe creates permanent cross-border teams to chase cybercriminals.

Features Editor · · 10 min read
Cover illustration for “Joint Cybercrime Investigation Teams in the EU”
cybercrime investigations · October 1, 2026 · 10 min read · 2,342 words

Cybercrime doesn't respect borders, so the EU stopped pretending its enforcement could either. Ransomware crews, malware operators, social engineers, and the people running denial-of-service attacks and supply chain compromises all build operations that span multiple countries at once, using infrastructure, victims, and personnel scattered across jurisdictions the moment an attack launches. That's the whole design problem in one sentence.

It's not just the cybercrime units feeling this. Nearly every serious organized crime case now drags a digital trail behind it, from drug trafficking ledgers kept on encrypted phones to money laundering routed through crypto exchanges. So the jurisdictional headache that used to be a cybercrime specialty has become a standard condition of policing, full stop.

A national police force that investigates up to its own border hasn't failed, exactly. It's just built half a case. The network it's chasing keeps operating outside that force's legal reach.

Defining and forming a Joint Investigation Team

A JIT is an agreement between the competent judicial and law enforcement authorities of two or more states, established for a limited duration and for a specific purpose, to carry out criminal investigations in one or more of the participating states. That "judicial and law enforcement" phrasing signals who sits at the table. Prosecutors and investigative judges sit at the table alongside police, because the goal is building a case that will hold up in a courtroom later, not just kicking down doors in different countries. It's building a case that will actually hold up in a courtroom later.

The time limit and narrow purpose are deliberate features, not a shortcoming. A JIT lets national authorities assemble a working partnership fast, around one target, without signing up for some permanent cross-border bureaucracy that outlives the investigation. Given how fast cybercriminal infrastructure moves, or disappears, that speed matters more than institutional tidiness.

JITs aren't new. What's changed is the toolkit. Cybercrime cases exposed needs the original model didn't anticipate, so Eurojust and the JITs Network built a cybercrime-specific JIT template that adapts the standard agreement. That template adapts the standard model agreement to the specifics of cybercrime cases: the speed at which digital evidence degrades, the multinational distribution of criminal infrastructure, and the need for rapid parallel action across jurisdictions.

Eurojust and the JITs Network's role in forming and running JITs

JITs don't spring into existence on their own. Somebody has to introduce the right prosecutors to each other, sort out the paperwork, and keep everyone rowing in the same direction, and that job belongs to Eurojust. Supporting JITs operationally, legally, and financially sits at the center of Eurojust's mandate, not on the sidelines of it.

The JITs Network adds a second layer to that support. Eurojust hosts its Secretariat, and the network itself is made up of national experts whose job is encouraging countries to actually form JITs and sharing what's worked elsewhere. For a national authority that has never run a cross-border case, that kind of guidance cuts the setup time dramatically.

Coordination meetings do the heavy lifting day to day. These are the sessions where prosecutors and investigators from different countries compare notes, figure out who's chasing the same suspect from a different angle, and agree on when to move so nobody tips off the target early. It's the diplomatic equivalent of making sure four people don't all try to merge into the same highway lane simultaneously.

The volume of this work jumped considerably. Eurojust supported substantially more JITs in 2024 than the year before, including a doubling in newly formed JITs compared to 2023, plus a sharp rise in coordination meetings tied to cybercrime cases. Spain led EU member state involvement in cross-border cybercrime cases at Eurojust that year, followed by the Netherlands, Germany, and France, while the United Kingdom, the United States, and Switzerland were the third countries showing up most often. That last detail matters. Third-country partners are regulars at this table. They're regulars.

What J-CAT adds to the operational picture at Europol

Eurojust handles the judicial coordination. Europol's Joint Cybercrime Action Taskforce, known as J-CAT, handles the operational muscle, and it's built to run continuously rather than assemble fresh for each case. Established in September 2014, J-CAT operates as a permanent taskforce at Europol's headquarters, working alongside the European Cybercrime Centre. Being permanent rather than case-by-case is what lets it track targets and threats on an ongoing basis instead of starting from zero every time a new investigation opens.

J-CAT's stated job covers three things: helping identify and launch cross-border investigations jointly, prioritizing the highest-value cases among member agencies, and coordinating action against the cybercrime threats and targets that matter most. Its focus areas line up neatly with the threat categories driving the whole cross-border problem in the first place, covering cyber-dependent crime like ransomware and botnets, cross-border payment fraud, dark web marketplaces, and the enablers, like bulletproof hosting providers and the financial facilitators who move the money.

Its membership tells the real story of how far this reach extends. As of 2025, J-CAT draws cyber liaison officers from 13 EU member states and seven non-EU partners, including Australia, Canada, Colombia, Norway, Switzerland, and the United Kingdom, plus four US agencies (the FBI, the Secret Service, the IRS, and Homeland Security Investigations). A Eurojust liaison officer sits inside J-CAT too, making sure judicial coordination happens alongside the operational work rather than getting bolted on afterward. That single seat is the hinge connecting the two halves of this whole system: Europol chasing servers and suspects, Eurojust making sure the case built along the way survives contact with a courtroom.

The operational rhythm runs in four stages: identifying cyber cases, preparing and de-conflicting the priority ones, running the operational and investigative work itself, and finally the judicial measures and follow-up. Laid end to end, those four stages trace the full arc of a transnational investigation, from the first tip that something's wrong to a conviction landing years later.

What the SIRIUS project does for cross-border electronic evidence

Coordination between agencies solves one problem. Getting the evidence itself is a different fight entirely, and that fight usually plays out over emails, subpoenas, and legal requests sent to tech companies headquartered somewhere else. The SIRIUS project, built jointly by Europol and Eurojust, exists to close that specific gap: the evidence sits on a server in one country, while the investigator with legal standing to request it sits in another.

SIRIUS is a working resource, handing out practical tools, training, and reference material to a community of more than 9,000 practitioners. That's a genuinely large working group of people trying to solve the same recurring headache: how to get a service provider to hand over the right data before that data disappears.

And the data does disappear, often fast. Nearly all criminal investigations today lean on electronic evidence in some form, the number of requests investigators send to service providers has climbed sharply in recent years, and providers routinely delete records under their own retention rules. Speed decides whether that evidence survives long enough to matter. A ransomware log sitting on a cloud server before automatic deletion still matters. It's a countdown clock running against every investigator trying to build a case.

Even SIRIUS has a ceiling, and the European Commission's Roadmap on lawful and effective access to data spells out where it sits. The roadmap identifies five categories of evidence still structurally out of reach for investigators: data already deleted by providers, data blocked by conflicting jurisdictional rules, data that can't be pulled off seized devices due to forensic limits, encrypted data, and data too large in volume for current analysis tools to handle. That framing treats SIRIUS and the broader e-evidence toolkit as a partial answer. Which sets up the next question fairly directly: what else is straining under the weight of this system?

Three operational frictions that limit what JITs can achieve

JITs work, but they work inside three structural constraints that don't go away just because the institutional machinery is running smoothly.

The evidence problem isn't about investigators being short-staffed or underfunded. The 2024 joint Eurojust and Europol assessment names the sheer volume of digital data generated by cybercrime cases, combined with the risk that it vanishes before a JIT can even form, as a genuinely pressing operational challenge. Digital evidence gets created, moves, and gets deleted faster than legal paperwork can keep pace with, so this is a structural mismatch between how fast bits travel and how fast treaties get invoked.

Anonymization tools compound the attribution headache. Investigators can trace a ransomware payment or a piece of malware right up to a specific node in the network, only to lose the thread entirely once the trail hits a mixer or an anonymizing relay. Attribution fails hardest in ransomware cases and dark web platform investigations, where the whole business model depends on nobody being traceable.

The legal-basis problem is the least glamorous friction and arguably the most stubborn. Which legal instrument applies to a JIT involving a non-EU country depends entirely on which country it is, drawing on the Second Additional Protocol to the European Convention on Mutual Assistance in Criminal Matters, the Second Additional Protocol to the Budapest Convention on Cybercrime, or the UN Convention against Transnational Organised Crime, depending on the case. Three different treaties, three different sets of procedural rules, and no single playbook. That inconsistency can slow down exactly the moment when speed matters most.

None of this is a new discovery. These frictions have included the secure exchange of electronic information as a technical headache since the mechanism was introduced in 2002, and the persistence of these problems across two decades explains why a dedicated infrastructure response, the collaboration platform, became a legislative priority.

What recent operations show about JIT effectiveness in practice

None of this stays theoretical for long. Operation Cronos, run in February 2024, showed the mechanism working at full stretch. A coordinated action backed by Eurojust and Europol, with judicial and law enforcement authorities from 10 countries involved, led to two arrests in Poland and Ukraine, the takedown of 34 LockBit servers spread across the Netherlands, Germany, Finland, France, Switzerland, Australia, the United States, and the United Kingdom, and the freezing of more than 200 cryptocurrency accounts tied to the operation.

LockBit wasn't one gang running one scheme. It was a service, a core team building ransomware and renting it out to affiliates who did the actual attacking. Taking that down meant hitting infrastructure in several countries at the exact same moment, rather than picking off individuals one extradition request at a time. Arrest the boss and the franchise keeps running under new management. Killing the servers everywhere at once leaves nothing left to franchise.

A 2023 operation dismantled a ransomware network based in Ukraine, one whose attacks had hit victims across a large number of countries and caused losses running into the hundreds of millions of euros, with Eurojust's role centered on getting judicial cooperation moving fast between everyone involved. A separate 2023 operation went after the Ragnar Locker group, which had been attacking companies across multiple countries since 2020.

Operation Endgame, in May 2024, pointed the model at infrastructure rather than actors. Authorities across the EU and beyond moved simultaneously against the dropper ecosystem behind a long list of malware families, including IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and Trickbot, the tools that quietly open the door for bigger attacks downstream. Rather than chasing the burglars, this operation went after everyone selling lockpicks.

The MATRIX takedown, also in 2024, added yet another wrinkle. The target this time was an encrypted communications platform built by criminals, for criminals, and decrypting it produced evidence spanning drug trafficking, arms trafficking, and money laundering. That result says something important: the JIT infrastructure built for cybercrime is increasingly doing double duty for organized crime cases that aren't cyber at all.

The JITs Collaboration Platform's infrastructure for future operations

The friction around secure evidence exchange finally got a legislative answer. A dedicated EU regulation, adopted in 2023, sets up a collaboration platform built specifically to support how JITs function, aimed directly at the problem of secure electronic exchange of information that has constrained the mechanism since its introduction.

The platform does three things. It allows secure electronic exchange and temporary storage of operational data, including large files. It supports secure communication with JIT members and participants, including Eurojust, Europol, and OLAF. And it builds in traceability, logging and tracking how evidence moves through the system. eu-LISA is developing the platform, with operations required to start no later than December 7, 2025, which puts it somewhere between early deployment and recently live, depending on when this gets read.

Two of the three frictions named earlier get addressed here directly. Secure exchange changes from a workaround cobbled together case by case to a system with a logging function that builds a proper chain of custody, strengthening how prosecutors can use JIT-gathered evidence in court.

Using the platform is voluntary. That's not a minor footnote. The authorities buried under the most casework, the ones who'd benefit most from a shared, secure system, may well be the last ones to actually adopt it, simply because switching systems takes time nobody overloaded has to spare. It's an open tension the EU hasn't resolved.

And the third friction doesn't move at all. Inconsistent legal bases for JITs involving non-EU countries sit entirely outside what this platform was built to fix, so the treaty patchwork problem remains exactly as unresolved as before.

What the JIT model means for security vendors

It's the byproduct of real investigations, backed by arrests, seized servers, and frozen accounts.

Understanding how Eurojust, J-CAT, and SIRIUS fit together explains why some threats get dismantled at the infrastructure level while others limp along for years. A vendor who grasps that difference writes sharper analysis than one treating every takedown as an identical news bullet. Cyberou, a content studio that works exclusively with cybersecurity companies, is built on exactly that kind of practitioner-first thinking. The mechanism behind the headline often explains more than the headline itself.

Sources

  1. Europol Public Information Europol Programming Document 2025 – 2027
  2. EUROPEAN COMMISSION Brussels, 24.6.2025 ... - IPEX.eu
  3. Joint Cybercrime Action Taskforce (J-CAT) – Fighting cybercrime worldwide | Europol
  4. Joint Investigation Teams - JITs – Numerous successes across the board | Europol
  5. Joint investigation teams | Eurojust - Europa.eu
  6. Joint Investigation Teams collaboration platform
  7. JITs Network | Eurojust | European Union Agency for Criminal Justice Cooperation
  8. Tackling cybercrime through joint investigation teams | Eurojust | European Union Agency for Criminal Justice Cooperation

More in cybercrime investigations