Cyber Crime Overview and Categories
Cyber Crime Overview and Categories
VIJAYANAGAR,BANGALORE-40
SUBJECT: CYBER SECURITY
[Link]/B.A
MODULE 2: CYBER CRIME
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 1
Trademarks violations: Using trademarks and associated rights without
permission of the actual holder. Theft of computer source code: Stealing,
destroying or misusing the source code of a computer.
Internet time theft: This happens by the usage of the Internet hours by an
unauthorized person which is actually paid by another person.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 2
3)Explain Cyber crime targeting computers and mobiles?
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 3
8. Mobile Device Theft and Hacking: Criminals can steal mobile devices
for resale or hack into them to access personal data, financial information, or
install malware.
9. Cyber Extortion:
Criminals may threaten to release sensitive or embarrassing
information unless a victim pays a ransom.
This can involve sextortion (threatening to expose explicit content) or
other forms of extortion.
10. Insider Threats:
Employees or individuals with insider access to computer systems and data
may misuse their privileges to steal or manipulate information.
11. Cryptojacking: Cybercriminals use a victim's computer or mobile device
to mine cryptocurrency without their consent, which can slow down the
device and increase energy consumption.
1. Cyberbullying:
Both women and children can be victims of cyberbullying, which
includes online harassment, threats, and intimidation.
Perpetrators may use social media, messaging apps, or other
digital platforms to target their victims.
2. Online Harassment:
This includes sending unsolicited, offensive, or threatening messages,
images, or videos to women or children.
It can be a form of cyberbullying and may have severe emotional and
psychological effects.
3. Revenge Porn:
Perpetrators may share explicit or intimate images or videos of women
without their consent, often as an act of revenge.
This is a violation of privacy and can cause significant harm to
victims.
4. Sexting Exploitation: In cases involving children, sexting can lead to
exploitation when someone coerces or blackmails minors into sharing
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 4
explicit images or videos. This can have legal and psychological
consequences for the child involved.
5. Online Grooming:
Predators may use online platforms to groom children for sexual
exploitation.
They build trust with the child and gradually manipulate them into
sharing personal information or engaging in inappropriate activities.
6. Child Pornography: The distribution, possession, or creation of child
pornography is illegal and exploits children. Criminals often use the internet
to share such material.
7. Online Trafficking:
Human traffickers may use the internet to lure and exploit women and
children, including for purposes of forced labor or sexual exploitation.
Online platforms can be used to recruit victims.
8. Cyberstalking:
This involves persistent and unwanted online attention, often leading
to fear or emotional distress.
Women and children can be targeted by cyberstalkers who may
threaten or harass them through digital means.
9. Financial Fraud: Women can also be victims of financial fraud,
including online scams targeting personal finances or online dating scams
where perpetrators exploit emotional connections for financial gain.
[Link] Violations: Privacy breaches can occur when personal
information or photographs are shared without consent, affecting both
women and children. This can lead to identity theft or other forms of
cybercrime.
Identity fraud:
• Identity fraud is common on Internet. Criminals have a few options when
it comes to stealing your sensitive information.
• They might target you with a phishing attack where they email, call, or
text pretending to be from your bank. Or, they could target you with a cyber
attack to get you to install malware on your devices that steals your logins
and passwords.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 5
• How do you know you're being targeted?
− Unfamiliar transactions on your credit card.
− Strange charges on your bank statements.
− New credit cards or loans in your name.
− Missing or error-filled tax returns.
− Calls from debt collectors about purchases you didn‟t make.
− A drop in credit score.
− Bounced checks.
Fraudulent charities:
Scammers use philanthropy as fraud, too. Charity fraud entails
creating a fake charity and collecting “donations” that disappear along
with the thief
Scammers create fake charities like military veteran charities that
sound like ones you know and trust.
These scams are especially common during natural disasters or
international news events.
Credit card fraud:
There are several ways that criminals can steal your credit card information.
They could steal your physical card, trick you into entering information on a
phishing website or email, buy your details on the Dark Web, or use any
number of other credit card scams.
Stock Market Manipulation:
Stock market manipulation includes activities like price rigging,
spreading false information, insider trading, and pump-and-dump
schemes.
Fraudsters manipulate stock prices, deceiving investors and causing
significant financial losses.
Bank Frauds:
• Bank frauds encompass various fraudulent activities, including loan
frauds, cheque frauds, forged documents, and unauthorized transactions.
These frauds result in substantial financial losses for banks and individuals.
• One notable case is the Nirav Modi-PNB scam, where fraudulent Letters
of Undertaking were issued, causing a massive loss to Punjab National Bank.
Types of Malware
1. Adware: Display ads (sometimes malicious ads) to users as they work on
their computers or browse the web.
2. Viruses: A virus infects a computer and performs a variety of payloads.
It may corrupt files, destroy operating systems, delete or move files, or
deliver a payload at a specific date.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 8
3. Worms: A worm is a self-replicating virus, but instead of affecting local
files, a worm spreads to other systems and exhausts resources.
4. Trojans: A Trojan is named after the Greek war strategy of using a
Trojan horse to enter the city of Troy.
5. Bots: Infected computers can become a part of a botnet used to launch a
distributed denial- of-service by sending extensive traffic to a specific host.
6. Keyloggers: Capture keystrokes as users type in URLs, credentials, and
personal information and send it to an attacker.
7. RAT: “Remote access tools” enable attackers to access and control the
targeted device remotely.
8. Downloaders: Download other malware to install locally. The type of
malware depends on the attacker‟s motives.
9. POS: Compromise a point-of-sale (PoS) device to steal credit card
numbers, debit card and PINs, transaction history, and contact information.
How do I know I’ve been infected with malware?
The most common signs that your computer has been compromised by
malware are:
Slow computer performance
Browser redirects, or when your web browser takes you to sites you
did not intend to visit
Infection warnings, frequently accompanied by solicitations to buy
something to fix them
Problems shutting down or starting up your computer
Frequent pop-up ads
Types of Ransomware
1. Locker ransomware
It is a type of malware that blocks standard computer functions from
being accessed until the payment to the hackers is not complete.
It shows a lock screen that doesn't allow the victim to use the
computer for primary purposes.
2. Crypto ransomware
This ransomware encrypts the local files and documents on the
computers.
Once the files are encrypted, finding the decryption key is impossible
unless the ransomware variant is old and the keys are already available
on the internet.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 10
3. Scareware
It is a fake software that claims to have detected a virus or other issue
on your computer and directs you to pay to resolve the problem.
Some scareware locks the computer, while others flood the screen
with pop-up alerts without damaging files.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 11
How to protect yourself against zero-day attacks
Keep all software and operating systems up to date.
Use only essential applications. The more software you have, the more
potential vulnerabilities you have.
Use a firewall. A firewall plays an essential role in protecting your
system against zero-day threats.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 13
13)Explain Reporting of cyber crimes?
Reporting cybercrimes is essential online threats and hold perpetrators
accountable. Here are the steps you can take to report cybercrimes:
1. Contact Your Local Law Enforcement:
If you believe you are a victim of a cybercrime, you should report it to
your local police department or law enforcement agency.
They can investigate the incident and take appropriate action.
2. Report to a National Cybersecurity Agency:
In many countries, there are dedicated agencies responsible for handling
cybercrimes.
Ex: Federal Bureau of Investigation (FBI)
3. Report to the Appropriate Online Platforms:
If the cybercrime occurred on a specific online platform, such as a social
media site, email service, or e-commerce website, report the incident to
that platform.
4. Report to Anti-Fraud Organizations:
There are organizations like the Anti-Phishing Working Group (APWG)
and the Anti-Malware Testing Standards Organization (AMTSO) that
collect information about cyber threats and work with law enforcement.
5. Report to Financial Institutions:
If the cybercrime involves financial fraud, contact your bank or financial
institution immediately.
6. Report to Internet Service Providers (ISPs):
If you have evidence of cybercrimes, such as hacking or distribution of
illegal content, involving an IP address, contact the relevant Internet
Service Provider (ISP).
7. Document the Incident:
Make sure to document all evidence related to the cybercrime, including
emails, messages, screenshots, IP addresses, and any other relevant
information. This documentation can be crucial for investigations.
8. Use Online Reporting Portals:
Many countries and regions have online reporting portals where you can
report cybercrimes.
9. Consider Legal Advice:
In some cases, it may be necessary to seek legal advice or consult with a
cybersecurity expert to understand the best course of action and to help
with the investigation.
[Link] Yourself:
While reporting the cybercrime, take steps to secure your online presence,
change passwords, update security settings, and install or update security
software to prevent further incidents.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 14
14)Explain Remedial and mitigation measures?
Remedial Measures:
1. Incident Response:
In the event of a cyber crime, organizations should have an
incident response plan in place to quickly identify, contain, and
mitigate the impact of the attack.
This includes isolating affected systems, restoring backups, and
applying patches or security updates.
2. Forensic Investigation:
Engaging professional forensic investigators can help identify the source
and extent of the cyber crime, gather evidence, and aid in legal
proceedings.
3. Data Recovery:
If data is compromised or encrypted due to a cyber attack, organizations
should have backups in place to restore affected systems and minimize
data loss.
Mitigation Measures:
1. Strong Security Practices:
Implement robust security measures, such as firewalls, antivirus
software, and intrusion detection and prevention systems, to protect
against cyber threats.
2. Regular Updates and Patching:
Keep software, operating systems, and firmware up to date with the latest
security patches to mitigate vulnerabilities that cyber criminals may
exploit.
3. Employee Education:
Provide cybersecurity awareness and training programs to employees to
educate them about common cyber threats, phishing techniques, and safe
online practices.
4. Multi-factor Authentication (MFA):
Implement MFA wherever possible to add an extra layer of security,
making it harder for cyber criminals to gain unauthorized access to
accounts or systems.
5. Data Encryption:
Encrypt sensitive data, both in transit and at rest, to ensure that even if it
is intercepted or stolen, it remains unreadable and unusable for
unauthorized individuals.
6. Regular Security Audits:
Conduct regular security audits and vulnerability assessments to identify
and address any weaknesses or potential entry points for cyber criminals.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 15
15)Explain Legal perspective of cyber crime?
In today‟s techno-savvy environment, the world is becoming more and
more digitally sophisticated and so are the crimes.
All legal issues related to internet crime are dealt with through cyber
laws.
As the number of internet users is on the rise, the need for cyber laws
and their application has also gathered great momentum.
Cyber law is a framework created to give legal recognition to all risks
arising out of the usage of computers and computer networks.
Cyber law encompasses laws relating to:
1. Cyber crimes
2. Electronic and digital signatures
3. Intellectual property
4. Data protection and privacy
Legal perspective of cybercrime in India
In India, cybercrime is primarily governed by the Information
Technology Act, 2000 (IT Act). This law was established to address
various cyber offenses and provide a legal framework for electronic
transactions, digital signatures, and data protection.
The purpose of the Indian IT Act(ITA) was to amend the Indian Penal
Code(IPC).
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 16
Amendments and Updates
The IT Act has undergone amendments over the years to address
emerging cyber threats and strengthen cybercrime provisions.
For example, the Information Technology (Amendment) Act, 2008
introduced additional provisions to tackle cyber terrorism, data privacy,
and intermediary liability.
It is important to consult with legal professionals or refer to official
sources for comprehensive and up-to-date information on the legal
aspects of cybercrime in India.
17)Explain Cyber crime and offences?
Cybercrime encompasses various illegal activities conducted through digital
means, often targeting individuals, organizations, or systems. Here are some
common cybercrimes and offenses:
[Link]: Unauthorized access to computer systems, networks, or devices to
manipulate, steal data, or disrupt operations.
[Link] Theft: Stealing personal information (such as Social Security
numbers, credit card details) to impersonate someone else, commit fraud, or
gain access to financial resources.
[Link] and Spoofing: Sending deceptive emails or creating fake websites
to trick individuals into revealing sensitive information (passwords, financial
data) or downloading malware.
[Link]: Harassment, threats, or intimidation using digital platforms,
often directed at individuals, which can have serious emotional and
psychological effects.
[Link] Fraud: Illegitimate schemes to deceive individuals or entities for
financial gain, including investment scams, online shopping fraud, and auction
fraud.
[Link] Denial of Service (DDoS) Attacks: Overloading servers or
networks with excessive traffic to disrupt access, making websites or services
unavailable to users.
[Link] Espionage: Unauthorized access to confidential information or
intellectual property of governments, organizations, or individuals, often carried
out by other governments or corporate entities.
[Link] Exploitation and Pornography: Using digital means to produce,
distribute, or possess child pornography or engage in illegal activities involving
minors.
[Link] Attacks: Malicious software that encrypts files or systems,
demanding payment (usually in cryptocurrency) for decryption or to avoid data
exposure.
[Link]: Persistent harassment or monitoring of an individual online,
causing fear or emotional distress.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 17
17)Explain Organizations dealing with Cybercrime and Cyber security in
India?
In India, several organizations are involved in dealing with cybercrime and
cybersecurity at various levels, including law enforcement, regulatory bodies,
and agencies focused on awareness and prevention.
Some prominent ones include:
[Link] Cyber Security Coordinator (NCSC): The NCSC operates under
the Prime Minister's Office and is responsible for coordinating all cybersecurity
initiatives in the country.
[Link] Emergency Response Team-India (CERT-In): CERT-In is the
national nodal agency under the Ministry of Electronics and Information
Technology that deals with cybersecurity incidents, response, and related issues.
[Link] Critical Information Infrastructure Protection Centre
(NCIIPC):
NCIIPC is responsible for protecting critical information infrastructure in the
country and formulating policies and guidelines for securing these assets.
[Link] Police Cyber Cells: Many states have established specialized cyber
cells within their police departments to investigate and handle cybercrimes at
the state level.
[Link] Investigation Agency (NIA): NIA deals with investigating and
prosecuting offenses affecting the sovereignty, security, and integrity of India,
including cybercrimes with national implications.
[Link] Appellate Tribunal (CAT): It hears appeals against any order passed
by CERT- In or the Adjudicating Officer under the Information Technology
Act, 2000.
[Link] and Financial Institutions: Regulatory bodies like the Reserve Bank
of India (RBI) and Securities and Exchange Board of India (SEBI) have
guidelines and teams dedicated to cybersecurity in the financial sector.
[Link] Cybersecurity Firms: Several private cybersecurity companies
operate in India, offering services ranging from consulting and risk assessment
to incident response and security solutions.
Yogesha S N
Asst Prof in Computer Science
Vasavi Jnana Peetha Evening College Page 18