Principles of Cybercrime - Chapter 1
Cybercrime
1. The Evolution of Cybercrime
Quote on Technology: Technology is described as providing great gifts and simultaneously causing harm. (C. P. Snow, quoted by A. Lewis, New York Times, March 15, 1971)
Case Study: Sergei Tšurikov
Background: In October 2014, Sergei Tšurikov, an Estonian national, was sentenced to 11 years in prison in the U.S. for a conspiracy that led to a loss of over US$9.4 million during 2008 at RBS WorldPay.
Methodology: Tšurikov and accomplices hacked into the computer network and compromised data encryption to raise limits on payroll debit cards. They issued 44 counterfeit cards exploited in 2,100 ATMs across at least 280 cities globally within 12 hours.
Impact: The attack demonstrated highly organized, technologically sophisticated, and transnational crime. Tšurikov was able to monitor the withdrawals in real time, showcasing a blend of technology and criminality.
Characteristics of Modern Cybercrimes:
Organized and financially motivated.
Highly sophisticated in technology.
Transnational due to the global nature of the internet.
Historical Context of Computer Crime:
The notion of ‘computer crime’ surfaced in the 1960s with instances of computer manipulation, sabotage, and espionage.
Three Generations of Cybercrime (Wall):
Cybercrimes facilitating traditional crimes (e.g., fraud).
Crimes across networks (e.g., hacking).
Crimes wholly mediated by technology (e.g., botnets).
Evolution of Motivations:
Transitioned from curiosity and status to organized, financially driven criminal behavior.
Development of Laws:
Early computer crime primarily involved telecommunication service theft and fraudulent electronic fund transfers.
Specific laws emerged as computer networking and personal computer use became widespread.
2. The Challenges of Cybercrime
Societal Dependence on Technology:
Dr. Carl Sagan's observation on society's reliance on technology contrasted with its general lack of understanding of it.
Routine Activity Theory:
Identifies three necessary components for predatory crime: motivated offenders, suitable opportunities, absence of capable guardians.
Cybercrime Factors:
Technology features that increase crime opportunities:
A. Scale: Over 3 billion internet users provide an extensive pool for potential offenders and victims.
Example: The Bredolab botnet infected approximately 30 million computers generating 3 billion emails/day.
B. Accessibility: Historically limited to experts, technology has become widespread and user-friendly.
Statistics: 80% of adults in Australia, Canada, and the UK accessed the internet; U.S. figure rose from 18% (1997) to 74.4% (2013).
C. Anonymity: Facilitates crime through tools that hide identity (proxy servers, spoofing).
D. Portability: Capability to store vast data and replicate easily; costless sharing of digital media.
E. Global Reach: Challenges traditional territorial law enforcement paradigms as cybercriminals can operate globally.
UN report indicated over 50% of countries identified cybercrime with a transnational element.
F. Absence of Capable Guardians:
Difficulty in detection and prosecution.
Need for collaborative roles within communities for crime prevention.
3. Defining Cybercrime
Terminology:
Varied terms for cybercrime indicate complexity (computer-related crime, computer crime, cybercrime, e-crime).
Terms suffer from limitations in definition focus (e.g., ‘computer crime’ may exclude networks).
Categories of Cybercrime:
Cyber-dependent Crimes: Only possible through computer/computer networks (e.g., hacking).
Cyber-enabled Crimes: Traditional crimes intensified in scale by technology (e.g., fraud, child pornography).
Computer-supported Crimes: Traditional crimes with incidental technological evidence (e.g., records in murder suspect’s computer).
Consensus on Cybercrime:
The two main categories recognized: cyber-dependent and cyber-enabled crimes.
Dominance of existing traditional crimes modified by technology.
4. Cyberterrorism
Definition and Impact:
Growing dependency on networked digital services renders critical infrastructure vulnerable to cyberattacks.
Motivations for Cyberterrorism: Political, religious, or ideological intentions.
Potential Effects: Disruption of essential services (water, power, hospitals).
Examples of Cyberattacks:
Stuxnet worm: Targeted equipment at Iran’s uranium-enrichment facility.
Use of ICTs: Facilitated real-time coordination of attacks (e.g., Mumbai 2008 attacks through Twitter).
Challenges in Definition:
Varying interpretations of terrorism limits consensus on cyberterrorism.
Examples like ‘hacktivism’ blur the line between cyberterrorism and politically motivated cyberattacks.
5. The Scale of the Problem
Challenges in Data Collection:
Lack of reliable statistics hampers understanding the cybercrime landscape.
Reasons for Underreporting:
Lack of consensus on ‘cybercrime’ meaning in statistics.
Existing offences may not categorize technology use distinctly.
Challenges related to law enforcement capabilities and resources.
Statistical Insights:
E.g., 27.5% of incidents were reported to law enforcement (CSI 2010–11).
6. Online/Offline Consistency
Principle: Online conduct should be regulated similarly to offline conduct.
Approach to Reform:
New offences introduced only when necessary while amending existing laws to address online issues.
7. Virtual Crimes
Debate on ‘Virtual Crimes’:
Examples include antisocial behaviour in games/virtual communities (LambdaMOO case).
Physical Reality of Online Offenses: Criminal law fundamentally revolves around physical conduct leading to harm.
8. A Global Problem: The Convention on Cybercrime
Need for International Cooperation:
Cybercrime harmonization crucial for effective law enforcement and prosecution.
Council of Europe Convention on Cybercrime:
Opened for signature in 2001, aimed at addressing cybercrime globally, includes both substantive and procedural law considerations.
Provisions:
Chapter II tackles substantive criminal laws, key offences such as:
Title 1: Offences against computer data integrity.
Title 2: Computer-related offences (forgery, fraud).
Title 3: Content-related offences (e.g., child pornography).
Title 4: Copyright infringements.
Summary: The conventions and proposed frameworks for addressing cybercrime are set against a backdrop of evolving threats shaped by advancements in technology, necessitating continuous adaptation in regulatory approaches and international cooperation to combat cybercrime effectively.