Introduction to Cybercrime and Environment Laws

INTRODUCTION TO CYBERCRIME AND ENVIRONMENT LAWS

Prepared By

  • Maria Lourdes Camigla-Alviento, RCrim, MSCJ
  • Princess Beronica Esteban, RCrim, MSCJ

CYBERCRIME DEFINITION

  • Cyber Crime: Refers to the convergence of computer- and internet-based offenses, encompassing unlawful acts committed against individuals or groups. It aims to damage the victim's reputation or inflict physical or psychological harm through telecommunication channels, such as the Internet and mobile devices.
  • Cyber Crime has two central aspects:
    • Targeting computer systems directly.
    • Using a computer/network to facilitate other crimes.

CYBERCRIMINOLOGY

  • Cyber Criminology: The study of the causation of crimes occurring in cyberspace and their impact on physical space.

GENERAL CATEGORIES OF CYBER CRIME

A. Computer as a Target
  • Definition: Offenses where the primary goal is to compromise the computer system itself, rather than using it merely as a tool for other crimes.
  • Identification of Target:
    1. Confidentiality: Aim to steal or expose protected data.
    2. Integrity: Involves altering or corrupting data/programs.
    3. Availability: Disrupting or denying access to systems/services.
B. Computer as Weapon
  • Definition: Computers used deliberately to execute malicious actions against another system or network.
  • Characteristics:
    1. Offensive Use: Computers are launchpads for crime.
    2. Remote Reach: Attacks across borders without physical presence.
    3. Automation: Malicious software operates without human input.
    4. Scalability: Ability to target multiple victims at once.
  • Examples of Cyber Weapons:
    • Distributed Denial of Service (DDoS) attacks.
    • Malware, Worms, Trojans.
    • Phishing Campaigns.
    • Botnet Operations.
    • Cyber Espionage.

COMPONENTS OF COMPUTER

1. Hardware
  • Definition: Physical components of a computer.
  • Examples:
    • Input Devices (Keyboard, Mouse, Scanner, etc.)
    • Output Devices (Monitor, Printer, Speaker).
2. Software
  • Definition: Instructions that tell the computer what and how to do things.
  • Categories:
    1. System Software: Operating Systems (e.g., IOS, Windows, Linux).
    2. Application Software: Programs that allow the user to perform specific tasks (e.g., Word Processing).

CLASSIFICATION OF CYBERCRIME

A. Computer Fraud and Financial Crimes
  • Definition: Using computers/network/digital systems to unlawfully obtain financial advantages or property.
  • Types and Examples:
    • Computer-Related Fraud: Unauthorized input or alteration of data.
    • Phishing/Social Engineering: Deceiving victims to reveal credentials.
    • Credit/Debit Card Fraud: Unauthorized purchases using stolen data.
    • Identity Theft: Using stolen personal data for financial gain.
    • Online Investment/Ponzi Schemes: Fraudulent offers.
  • Legal Framework:
    • RA 10175 (Cybercrime Prevention Act of 2012): Penalizes various cyber offenses.
    • RA 8795 (Electronic Commerce Act of 2020): Deals with hacking.
    • Revised Penal Code: Applies to digital estafa and swindling.
B. Cyberterrorism
  • Definition: Pre-mediated use of cyberspace to conduct acts that harm life, property, or infrastructures for political or ideological benefit.
  • Core Elements: Coercion, Intimidation, Fear, alongside digital methods.
  • Examples:
    • DDoS attacks on critical infrastructure (Estonia 2007, Ukraine Power Grid).
    • Malware attacks (Stuxnet targeting Iranian nuclear facilities).
  • Legal Context: Acts may be prosecuted under acts relating to terrorism if they meet certain criteria.
C. Cyber Extortion
  • Also Known As: Digital Blackmail or Ransomware.
  • Definition: Criminals demand payment under threat of harm to the data/system.
  • Characteristics:
    1. Criminal Leverage: Holding data hostage.
    2. Threat of Harm: Could be reputational or financial harm.
    3. Digital Delivery: All conducted via online platforms.
  • Types of Cyber Extortion:
    • Ransomware: Malware encrypts data; ransom is demanded.
    • Ransom DDoS: Attacking a site demands payment.
D. Cyber Warfare
  • Definition: The use of cyberattacks by state-sponsored actors against another state's digital infrastructure.
  • Characteristics:
    1. State-Linked Actors: Often military or intelligence services.
    2. Critical Infrastructure Focus: Attacks geared towards power grids, communication systems.
  • Examples: SolarWinds breach, Ukraine Power Grid attacks.
E. Cyber Fraud
  • Definition: Commit fraud via ICT for financial gain or data theft.
  • Modus Operandi:
    1. Phishing/Spoofing.
    2. Business E-mail Compromise.
    3. Online scams involving loans or investments.
F. Obscene or Offensive Content
  • Definition: Content deemed distasteful, obscene, or offensive.
  • Legal Basis: Art. 201 of RPC criminalizing publication of obscene materials; Cybercrime Prevention Act
    offenses through ICT.
G. Harassment
  • Definition: Utilizing ICT to intimidate or cause distress to individuals.
  • Common Forms: Cyberstalking, Cyberbullying, Doxxing, Impersonation.
H. Drug Trafficking
  • Definition: Using digital technologies to facilitate drug-related activities.

TYPES OF CYBER CRIMINALS

1. Script Kiddies
  • Individuals lacking technical expertise but using prewritten tools for attacks.
2. Scammers
  • Exploit human psychology for fraud and identity theft.
3. Hacker Groups
  • Operate anonymously, creating tools for ethical hacking or malicious attacks.
4. White Hat Hackers
  • Ethical hackers who help organizations test security.
5. Black Hat Hackers
  • Malicious hackers aiming for financial gain or espionage.
6. Insiders
  • High-risk attackers within organizations.
7. Advanced Persistent Threat (APT) Agents
  • Highly organized state-sponsored groups conducting targeted attacks.

CYBER CRIME PREVENTION ACT OF 2012 (RA 10175)

  • Comprehensive legislation addressing cybercrimes.
  • Empower various agencies for enforcement and mitigation.

CYBER INVESTIGATION FRAMEWORK

  • Detailed process of investigating cybercrime, including tracking, analyzing, and presenting digital evidence.
  • Key Agencies Involved:
    • DOJ-Office of Cybercrime (Policy, Prosecution).
    • PNP-Anti-Cybercrime Group (Investigations).
    • NBI-Cybercrime Division (Forensics).

PRESERVATION ORDERS AND WARRANTS

  • Framework established for obtaining necessary orders for preservation and legal access to electronic evidence.
  • Types of Warrants:
    • Reveal subscriber info, intercept computer data, and search, seize or examine digital devices/data.

ELECTRONIC EVIDENCE RULES

  • Establish the guidelines for admissibility and handling of electronic documents in legal proceedings.
  • Key Highlights:
    • Expanded evidentiary tools.
    • Importance of authentication in legal contexts.
    • Shift in litigation strategies due to electronic evidence availability.
    • Increased efficiency in legal processes through technology.

CONCLUSIONS

  • Cybercrimes necessitate a comprehensive legal framework due to their digital nature and the complexities involved in prosecution.
  • Ongoing challenges remain in ensuring compliance and adapting to evolving threats in the digital landscape.