a server, therein giving the appearance that the traffic is coming out of that source rather than from the user, might be used to improve privacy. By failing to take simple security actions, the user not only becomes a vulnerable target but also allows criminals to coopt electronic devices to conduct other malicious and criminal behavior, costs which are potentially both considerable and which are passed on to society.32 However, while many countries encourage the use of appropriate protection, only a few go so far as to sanction failure to use protection.33 Of greater concern than the role of the individual is the role of the private sector companies involved or operating critical infrastructure. Companies—frequently driven almost-exclusively by profit in the age of privatization—have proven themselves slow to invest the necessary resources in many aspects but quite notably in the area of industrial controls and security.34 Indeed, Kaspersky Labs found critical infrastructure companies still running 30-year-oId operating systems.35 In the United States, attempts to legislate requiring companies to maintain better security practices were stymied on the grounds that it would be too costly for businesses.36 Such infrastructural lacks have been aggravated by user apathy, with many companies operating industrial control systems not even changing the default passwords.37 C. Private Sector Cooperation The ease and speed of information-sharing between cybercriminals, and the disparateness of criminal activity, makes it difficult for either law enforcement or targets to keep up. As discussed in the previous section in greater depth (see section 1 B, above), cybercrime cannot be effectively combatted without cooperation between the public and private sectors.38 As cyberspace continues to develop, different investigative tools will be required of law enforcement, as dramatically shown in the FBI’s inability to independently unlock iPhone.39 Only partnerships with the private sector will make such possible. Box 1.2: WannaCry Ransomware Attack In May 2017, a huge cyberattack—described by Europol chief as “unprecedented in its scale”—affected more than 200,000 victims in over 150 countries.40 While the United Kingdom and Russia were the worst affected, the attack was global in nature, with large affected institutions including the UK’s National Health Service, Russia’s Interior Ministry, Germany’s rail network Deutsche Bahn, France’s car manufacturer Renault, Spain’s telecommunications operator Telefonica and US logistics giant FedEx. The virus, a worm-application, was paired with ransomware that takes control of users’ files and demands payments of US$300 in Bitcoin in order to unlock files and return control to users. What made this malware—having permutations on the name WannaCry and WannaCrypt—particularly virulent was its ability to move around a network by itself, Page 33 | Chapter 1 | § C. Challenges to Fighting Cybercrime Table of Contents

Select target paragraph3