Understanding Cyber Crime and Laws
Understanding Cyber Crime and Laws
MODULE 2
Cyber – crime and Cyber law:
In Simple way we can say that cyber crime is unlawful acts wherein the computer is
either a tool or a target or both.
Cyber crimes can involve criminal activities that are traditional in nature, such as theft,
fraud, forgery, defamation and mischief, all of which are subject to the Indian Penal
Code.
Cybercrime can be defined as any criminal conduct involving a computer, networked
device, or any other similar equipment.
It can be classified in to 4 major categories as
1. Against Individuals
1. Email spoofing:
A spoofed email is one in which e-mail header is forged so that mail appears to originate
from one source but actually has been sent from another source
2. Spamming:
Spamming means sending multiple copies of unsolicited mails or mass e-mails such as
chain letters.
3. Cyber Defamation:
This occurs when defamation takes place with the help of computers and / or the
Internet. E.g. someone publishes defamatory matter about someone on a website or sends
e-mails containing defamatory information.
2. Against Property:
1. Credit Card Fraud :
2. Intellectual Property crimes : These include Software piracy: illegal copying of
programs, distribution of copies of software.
1. Copyright infringement:
2. Trademarks violations:
Theft of computer source code:
4. Against Organisation:
3. Unauthorized Accessing of Computer:
Accessing the computer/network without permission from the owner.
it can be of 2 forms:
1. Changing/deleting data:
Unauthorized changing of data.
2. Computer voyeur:
The criminal reads or copies confidential or proprietary information, but the data is
neither deleted nor changed.
2. DenialOf Service:
When Internet server is flooded with continuous bogus requests so as to denying
legitimate users to use the server or to crash the server.
4. Email Bombing:
Sending large numbers of mails to the individual or company or mail servers thereby
ultimately resulting into crashing.
5. Salami Attack:
When negligible amounts are removed & accumulated in to something larger. These
attacks are used for the commission of financial crimes.
6. Logic Bomb:
Its an event dependent programme , as soon as the designated event occurs, it crashes the
computer, release a virus or any other harmful possibilities.
7. Trojan Horse:
an unauthorized program which functions from inside what seems to be an authorized
program, thereby concealing what it is actually doing.
8. Data diddling:
This kind of an attack involves altering raw data just before it is processed by a computer
and then changing it back after the processing is completed.
4. Against Society:
1. Forgery: currency notes, revenue stamps, mark sheets etc can be forged using computers
and high quality scanners and printers.
3. Web Jacking: Hackers gain access and control over the website of another, even they
change the content of website for fulfilling political objective or for money.
2. Identity Theft
Identity theft occurs when a cybercriminal uses another person‘s personal data like credit
card numbers or personal pictures without their permission to commit a fraud or a crime.
3. Ransomware Attack
Ransomware attacks are a very common type of cybercrime.
It is a type of malware that has the capability to prevent users from accessing all of their
personal data on the system by encrypting them and then asking for a ransom in order to
give access to the encrypted data.
5. Internet Fraud
Internet fraud is a type of cybercrimes that makes use of the internet and it can be
considered a general term that groups all of the crimes that happen over the internet like
spam, banking frauds, theft of service, etc.
Unsecured Wi-Fi
Free wi-fi is easily attractive to people, if anyone connects to the free wifi, then the
hackers might steal your data.
Never use the free wifi when accessing confidential services like banking and
transactions, there might be a chance of stealing your money.
Phishing Attacks
Phishing attacks are mostly seen in emails and messages.
When the user clicks on a suspicious link, there might be a chance of virus files
download which can corrupt and hack your devices which results in data loss.
In some cases, they will send a form to fill in the confidential information.
Weak Passwords
If the passwords of the mobile devices are weak there might be a change of others
accessing the data.
This might result in data leakage and privacy issues. So make sure that the passwords for
mobile devices or apps must be strong.
As we all know most of the things are correcting to the internet and works easily, fast
with the internet from wearable tech like smartphones, watches, etc.
If these devices are hacked then misuse of these devices might result in huge costs.
Cyber violence uses Computer Technology to access women‘s personal information and use
the internet for harassment and exploitation.
CYBERCRIME IN FINANCE:
Cybercrime in finance is the act of obtaining financial gain through profit-driven criminal
activity, including identity fraud, ransomware attacks, email and internet fraud, and
attempts to steal financial accounts, credit cards, or other payment card information.
In other words: Financial cybercrime includes activities such as stealing payment card
information, gaining access to financial accounts in order to initiate unauthorized
transactions, extortion, identity fraud in order to apply for financial products, and so on.
Financial crime is a crime against property involving the unlawful conversion of
ownership of property belonging to one person to one‘s personal use and benefit.
Cybercrime in finance includes acts such as stealing payment card information, gaining
access to financial accounts in order to initiate unauthorised transactions, extort and
impersonate.
Social engineering attacks come in many different forms and can be performed anywhere where
human interaction is involved. The following are the five most common forms of digital social
engineering assaults.
Baiting
As its name implies, baiting attacks use a false promise to pique a victim‘s greed or
curiosity.
They lure users into a trap that steals their personal information or inflicts their systems
with malware.
The most reviled form of baiting uses physical media to disperse malware.
For example, attackers leave the bait—typically malware-infected flash drives—in
conspicuous areas where potential victims are certain to see them (e.g., bathrooms,
elevators, the parking lot of a targeted company). The bait has an authentic look to it,
such as a label presenting it as the company‘s payroll list.
Scareware
Scareware involves victims being bombarded with false alarms and fictitious threats.
Users are deceived to think their system is infected with malware, prompting them to
install software that has no real benefit (other than for the perpetrator) or is malware
itself.
Scareware is also referred to as deception software, rogue scanner software and
fraudware.
A common scareware example is the legitimate-looking popup banners appearing in your
browser while surfing the web, displaying such text such as, ―Your computer may be
infected with harmful spyware programs.‖ It either offers to install the tool (often
malware-infected) for you, or will direct you to a malicious site where your computer
becomes infected.
Pretexting
Here an attacker obtains information through a series of cleverly crafted lies.
The scam is often initiated by a perpetrator pretending to need sensitive information
from a victim so as to perform a critical task.
The attacker usually starts by establishing trust with their victim by impersonating co-
workers, police, bank and tax officials, or other persons who have right-to-know
authority.
The pretexter asks questions that are ostensibly required to confirm the victim‘s
identity, through which they gather important personal data.
Phishing
As one of the most popular social engineering attack types, phishing scams are email and
text message campaigns aimed at creating a sense of urgency, curiosity or fear in victims.
It then prods them into revealing sensitive information, clicking on links to malicious
websites, or opening attachments that contain malware.
An example is an email sent to users of an online service that alerts them of a policy
violation requiring immediate action on their part, such as a required password change..
Ransomware is a type of malware and cybercrime that holds data for ransom.
Access to data on computer networks, mobile devices, and servers is locked until the victim pays
a ransom.
Common ransomware targets include individuals, companies, organizations such as h Locker
ransomware.
This type of malware blocks basic computer functions. For example, you may be denied access
to the desktop, while the mouse and keyboard are partially disabled.
Crypto ransomware. The aim of crypto ransomware is to encrypt your important data, such
as documents, pictures and videos, but not to interfere with basic computer functions.
This spreads panic because users can see their files but cannot access them.
Crypto developers often add a countdown to their ransom demand: "If you don't pay the ransom
by the deadline, all your files will be deleted."
Victims are lured through part-time job offers and other advertisements on Internet and /
or messaging platforms, etc. and are promised high commissions / returns.
The advertisements / SMS messages usually contain a link, prompting for chat. Mobile
applications, bulk SMS messages, SIM-box-based Virtual Private Network (VPNs),
phishing websites, cloud services, virtual accounts in banks, Application Programming
Interfaces (APIs), etc. are used to carry out financial frauds.
Earn Online‘, ‗Part Time Job‘, etc. are the key words used by fraudsters and criminals to
match their advertisements.
Such advertisements are generally displayed from 10 am to 7 pm, i.e. the peak time for
internet use by Indian public.
These websites used by fraudsters generally have domains – ‗xyz‘ and ‗wixsite‘.
Multiple Indian numbers were used for communications with victims.
In some cases, the mobile number holder knowingly shares OTP in return for some
money from the fraudsters.
A screen-shot needs to be sent to the person over the messaging platform to activate the
account. Once the account is activated, a task is given to the user to gain confidence of
the person.
Once the task is completed, the victim is asked to withdraw the money. Money is
withdrawn through various Payment Aggregators.
On getting the first refund, the victim is now lured to do more tasks which involve
loading of more money.
The process continues and once a big amount is loaded by the victim, the person
(fraudster) stops responding over chat.
Reporting cybercrime:
While filing a complaint, ensure that you have necessary documents, like your bank
account number, account to which you transferred the amount and your contact number
which is linked to the bank. You can also track the status of your complaint once you file
it.
In case of anonymous complaints, you do not need to provide any personal information.
However, information related to the incident / complaint should be complete for the
police authorities to take necessary action.
You will need to register yourself using your mobile number. You will receive a One
Time Password (OTP) on your mobile number.
The OTP remains valid for 30 minutes only. Once you successfully register your mobile
number on the portal, you will be able to report the complaint.
Mitigation and remediation are a result of risk assessment, following either a new or
advanced persistent threat (APT).
Mitigation includes reducing the impact of a threat when it cannot be eliminated.
Remediation completely removes the threat when it‘s possible.
Vulnerability remediation refers to the process of identifying the gaps in a potential
vendor‘s security controls and prioritizing the vulnerabilities that your organization
would like to fix.
For example, an organization decides to employ a vendor to deliver office supplies to the
workplace. Since the organization wants to reduce security risks posed by the vendor, it
requires the vendor‘s employees to sign in at the front desk and wear a visitor‘s badge
upon arrival.
4 Steps to Remediation
What is Mitigation?
Mitigation is the process of dealing with risk or vulnerabilities after the fact and setting
controls around a supplier so that your organization can defend against those
vulnerabilities internally.
Let‘s take a company that has calculated that the inherent risk minus control effectiveness
for a supplier equals a residual risk of 3 out of 5, which is not satisfactory.
Mitigation offers a method for reducing that risk through an internal process of setting
controls around a supplier to internally defend against any risk presented.
Indian Cybercrime Coordination Centre (I4C) was established by MHA, in New Delhi to
provide a framework and eco-system for Law Enforcement Agencies (LEAs) for dealing
with Cybercrime in a coordinated and comprehensive manner.
I4C is envisaged to act as the nodal point to curb Cybercrime in the country.
The organization was founded in 2004. The main thrust is Development of Technology
and Technological Development.
This covers areas like aviation, remote sencing, cryptography and cyber security.
The NTRO acts as the primary advisor on security issues to the Prime Minister and the
Union Council of Ministers of India.
It also provides technical intelligence to other Indian agencies. NTRO‘s activities include
satellite and terrestrial monitoring.
It is an organisation of the Government of India created under the Section 70A of the
Information Technology Act, 2000 (amended 2008), through a gazette notification on 16
January 2014.
Based in New Delhi, India, it is designated as the National Nodal Agency in terms of
Critical Information Infrastructure Protection.
It is a unit of the National Technical Research Organisation (NTRO) and therefore comes
under the Prime Minister‘s Office (PMO). NCIIP has identified