CYBERCRIME:
THE NEW CRIMINAL FRONTIER
The growth of the Internet has created numerous business and social opportunities. However,
where there are opportunities, there are also risks. Locally and internationally, the Internet has been
exploited for cybercrimes like scams, hacks and thefts.
For businesses, malicious cyber activities may cause service disruptions and loss of data pertaining
to customers, employees, and commercial entities. These can result in substantial revenue losses,
erosion of customer goodwill, and loss of reputation. Inextricably, personal lives may also be affected.
For individuals, poor personal cybersecurity habits can open doors to cybercrime and malicious
activities. Extortion, fraud, and adverse credit ratings are some of the detrimental consequences that
individuals and their families may face, when their computers and mobile devices are compromised
and personal data stolen.
Ransomware
In May 2016, ransomware
encrypted University of
Calgary’s computer systems
on the eve of a conference.
The conference organisers
had to re-create processes
and conference data by hand
for the event to continue.
To prevent the malware from
spreading to the rest of the
systems, the University had
to shut down other IT services,
causing a week-long, campuswide disruption that was more
far-reaching than the impact
of the malware.
The malicious actors behind
this incident demanded the
equivalent of Canadian $20,000
in Bitcoins to decrypt the data.
The University eventually
gave in and paid the ransom
to retrieve the research data.
Supply chain malware attack
In 2013, more than 40 million credit
card numbers were stolen through
malware that was injected into the
US retailer Target’s Point-of-Sales
system. Although Target had
multiple cybersecurity solutions in
place, the malware slipped in through
one of Target’s vendors. Further
investigations were hindered as
the stolen data was sent offshore.
Target incurred US$252 million
of breach-related expenses and
faced several lawsuits. Target’s CEO
held himself personally accountable
and resigned.
24
CHAPTER 2
Distributed Denial of Service (DDoS)
Smartphone hack
In January 2016, online banking
services for millions of HSBC UK
customers were taken offline by a
DDoS attack. The disruption happened
on an important day for personal
finances; it was the first pay-day of the
year, and two days before the deadline
for personal tax returns. Many HSBC
customers took to social media to vent
their anger.
In 2015, 50 Singapore users
had their smartphones infected
by a malware that disguised
itself as a banking application
to steal credit card details and
other user credentials.
Today’s smartphones are
essentially computers that
execute highly personal tasks
while being always connected
to the Internet, making them
attractive targets for cybercrime.
DDoS attacks work by overwhelming
websites with Internet traffic. Globally,
such attacks have become more
frequent against even small businesses.
The motives are varied. Attacks can be
used to protest against a company, take
down a competitor temporarily, or be
part of extortion threats.
Online scams
Malware enabled heist
In February 2016, US$81 million was
stolen from Bangladeshi Bank in a carefully
coordinated hack. After using stolen credentials
to initiate fraudulent bank transfers, the
hackers used malware to hide the traces of
the transactions, hindering remediation actions.
Traditional crime is increasingly
migrating to where Singaporeans
spend a good part of their
time – online. The number of
e-commerce and online scam
cases in Singapore doubled from
1,929 in 2014 to 3,759 in 2015,
resulting in a loss of S$16.7
million.
CHAPTER 2
25