CYBERCRIME: THE NEW CRIMINAL FRONTIER The growth of the Internet has created numerous business and social opportunities. However, where there are opportunities, there are also risks. Locally and internationally, the Internet has been exploited for cybercrimes like scams, hacks and thefts. For businesses, malicious cyber activities may cause service disruptions and loss of data pertaining to customers, employees, and commercial entities. These can result in substantial revenue losses, erosion of customer goodwill, and loss of reputation. Inextricably, personal lives may also be affected. For individuals, poor personal cybersecurity habits can open doors to cybercrime and malicious activities. Extortion, fraud, and adverse credit ratings are some of the detrimental consequences that individuals and their families may face, when their computers and mobile devices are compromised and personal data stolen. Ransomware In May 2016, ransomware encrypted University of Calgary’s computer systems on the eve of a conference. The conference organisers had to re-create processes and conference data by hand for the event to continue. To prevent the malware from spreading to the rest of the systems, the University had to shut down other IT services, causing a week-long, campuswide disruption that was more far-reaching than the impact of the malware. The malicious actors behind this incident demanded the equivalent of Canadian $20,000 in Bitcoins to decrypt the data. The University eventually gave in and paid the ransom to retrieve the research data. Supply chain malware attack In 2013, more than 40 million credit card numbers were stolen through malware that was injected into the US retailer Target’s Point-of-Sales system. Although Target had multiple cybersecurity solutions in place, the malware slipped in through one of Target’s vendors. Further investigations were hindered as the stolen data was sent offshore. Target incurred US$252 million of breach-related expenses and faced several lawsuits. Target’s CEO held himself personally accountable and resigned. 24 CHAPTER 2 Distributed Denial of Service (DDoS) Smartphone hack In January 2016, online banking services for millions of HSBC UK customers were taken offline by a DDoS attack. The disruption happened on an important day for personal finances; it was the first pay-day of the year, and two days before the deadline for personal tax returns. Many HSBC customers took to social media to vent their anger. In 2015, 50 Singapore users had their smartphones infected by a malware that disguised itself as a banking application to steal credit card details and other user credentials. Today’s smartphones are essentially computers that execute highly personal tasks while being always connected to the Internet, making them attractive targets for cybercrime. DDoS attacks work by overwhelming websites with Internet traffic. Globally, such attacks have become more frequent against even small businesses. The motives are varied. Attacks can be used to protest against a company, take down a competitor temporarily, or be part of extortion threats. Online scams Malware enabled heist In February 2016, US$81 million was stolen from Bangladeshi Bank in a carefully coordinated hack. After using stolen credentials to initiate fraudulent bank transfers, the hackers used malware to hide the traces of the transactions, hindering remediation actions. Traditional crime is increasingly migrating to where Singaporeans spend a good part of their time – online. The number of e-commerce and online scam cases in Singapore doubled from 1,929 in 2014 to 3,759 in 2015, resulting in a loss of S$16.7 million. CHAPTER 2 25

Select target paragraph3