‘intrusion to our web banking service’; ‘attempts to hack customer data systems’; ‘intrusion attacks’; ‘information leakage by employees’; and ‘denial of service attacks.’11 As discussed below, all private sector organizations are vulnerable to cyber-victimization and costs can be significant. Prevalence and impact of cybercrime acts Measurements of cybercrime act prevalence can be divided into general population (or consumer) victimization, and victimization of organizations – such as businesses, academic institutions, and others.12 Consumer victimization – For the general population, levels of cybercrime victimization are significantly higher than for ‘conventional’ offline forms of crime – with respect to the relevant populations at risk.13 Cybercrime victimization rates for 21 countries across all regions of the world, for example, vary between one and 17 per cent of the online population for four specific acts: online credit card fraud; identity theft; responding to a phishing attempt; and experiencing unauthorized access to an email account.14 In contrast, victimization surveys show that – for these same 21 countries – ‘conventional’ crime victimization rates, for burglary, robbery and car theft, vary between 0.1 and 13 per cent, with the vast majority of rates for these crimes under four per cent.15 One factor responsible for this difference is likely the ‘bulk’ nature of many cybercrime acts. For acts such as phishing, or ‘brute-forcing’ email passwords to gain unauthorized access, a single individual can simultaneously target many victims in a way not possible in forms of conventional crime. 11 12 13 14 15 Figure 2.4: Cybercrime and conventional crime victimization % respondents reporting victimization in last year, 2011 or latest available year A second pattern is that cybercrime victimization rates (at least for the sample of 21 countries) are generally higher in those countries with lower levels of development. Dividing the countries into two groups – those with a human development index measurement lower than 0.8 (Group 1), 16% HDI < 0.8 (8 countries) 14% HDI > 0.8 (13 countries) 12% 10% 8% 6% 4% 2% 0% Email account Responded to Identity theft Online credit card fraud hacked phishing attempt Burglary Robbery Car theft Source: UNODC elaboration of Norton Cybercrime Report and crime victimization surveys. Study cybercrime questionnaire (private sector). Q50-52 and Q56. Victimization of government institutions is excluded from the scope of this Study. All individuals for ‘conventional’ crime, and internet users for cybercrime. Symantec, 2012. Norton Cybercrime Report 2012. Research for the Norton Cybercrime Report was conducted independently by StrategyOne (now EdelmanBerland) through an online survey in 24 countries using identical questions translated into the primary language of each country. Interviews were conducted between 16 July 2012 and 30 July 2012. The margin of error for the total sample of adults (n=13,018) is +0.9 per cent at the 95 per cent level of confidence. Data from 3 countries in the Norton Cybercrime Report are excluded as national victimization data for conventional crime were not available. Victimization rates refer to 12 month prevalence of victimization. UNODC analysis of results from International Crime Victimization Survey (ICVS) and national crime victimization surveys. Victimization rates refer to 12 month prevalence of victimization. 28

Select target paragraph3