What is cybercrime?
Cybercrime is part of a continuum of activity that ranges from cyber safety challenges to threats to
national security. Cybercrime can encompass criminal activity from cyberbullying to state-sponsored
theft of intellectual property. Cybercrime can be devastating to individuals, communities and
business at both ends of the scale.
For the purposes of this Plan, the definition of cybercrime has two elements.1
• A criminal act that can only be committed through the use of ICT or the Internet and where the
computer or network is the target of the offence. This is regardless of what the criminal goal
is – whether political or financial gain, espionage or any other reason. Examples of cybercrime
include producing malicious software, network intrusions, denial of service attacks and phishing.
• Cyber-enabled crime is any criminal act that could be committed without ICT or the Internet,
but is assisted, facilitated or escalated in scale by the use of technology. This includes a vast
amount of serious and organised crime, such as cyber-enabled fraud or the distribution of
child exploitation material.
However, cybercrime is a subset of general crime, and the boundaries will not always be
hard and fast.
The nature of the cybercrime problem and the
challenges for New Zealand
THE COSTS OF CYBERCRIME ARE DIFFICULT TO CALCULATE RELIABLY
The extent of the cybercrime problem is not well understood. Worldwide, many instances of
cybercrime go unreported. In some instances, victims will be unaware they have been affected.
Other victims are too embarrassed to report the crime, do not know to whom to report, whether
a crime has been committed, or do not believe law enforcement can provide a remedy. If victims
receive a remedy from a supplier or financial institution, they may not also report a crime. Finally,
businesses can be reluctant to disclose losses or breaches for fear of reputational damage.
According to the UK Home Office, survey data suggests that in 2012, businesses reported only 2%
of online crime incidents.2 As a result, the economic cost of cybercrime is notoriously difficult to
calculate reliably.3 What we do know is that survey and anecdotal evidence indicates a high level
of experience with cybercrime. One recent report estimated the annual cost to the global economy
at more than US$400 billion.4
The indirect costs from cybercrime are equally difficult to quantify, including the opportunity costs.
For many small-to-medium enterprises, cybercrime may result in ‘denial of business’ – nothing may
be stolen, but an attack can reduce their ability to trade. Businesses and individuals also face costs
to protect against cybercrime and for remediation (if required). Overseas, well-known losses include
the theft of personal and financial information for 70 million customers of US retailer Target in 2013
and the theft of data related to 56 million credit cards from Home Depot in 2014. Cybercrime
can also enable the organisation and perpetration of physical crime, for example fraud, extortion,
disorder, sexual and other violent assaults.
New Zealand Police “Prevention First: National Cybercrime Operating Strategy 2014-2017” (Wellington, 2014).
1
M McGuire and S Dowling “Cyber crime: A review of the evidence” (Home Office Research Report 75, October 2013).
2
Police National Intelligence Centre (NIC) “Summary from ‘Cyber crime: The need to improve public confidence’ (May 2014)”
(New Zealand Police, Wellington, 2014).
3
Police, 2014.
4
4
National Plan to Address Cybercrime 2015