CHAPTER TWO: THE GLOBAL PICTURE
and those greater than 0.8 (Group 2)16 – shows higher victimization rates in the less developed
countries (Group 1) for unauthorized access to an email account, identity theft, and responding to a
phishing attempt. Online credit card victimization is slightly higher in the group of more developed
countries. The figure shows the average victimization rate for these four cybercrime types, alongside
average rates for burglary, robbery and car theft, for the two groups of countries.17
The pattern of higher cyber-victimization in less developed countries is consistent with
generally higher conventional crime rates in less developed countries. For conventional crime, this
difference is attributable to a number of factors, including income inequality, economic challenges,
youthful populations, urbanization, a history of conflict, a proliferation of firearms, and poorlyresourced criminal justice systems.18 Some of these factors have less relevance to cybercrime.
Others, however, such as economic and demographic pressures, likely do form part of the
cybercrime equation. Cyber-victims in lesser developed countries could, in principle, be targeted by
perpetrators from anywhere in the world. Local cultural and language factors, however, can mean
that potential victims are also targeted by perpetrators from their own country – making national
perpetrator risk factors relevant. In addition, internet users in developing countries often face
challenges of low cybersecurity awareness – making them especially vulnerable to crimes such as
unauthorized access, phishing and identity theft.19 This pattern also fits with the fact that – despite
the pattern suggested by victimization surveys – law enforcement authorities in less developed
countries do not identify illegal access-type cybercrime acts as particularly common.20
In contrast, online credit card fraud shows the opposite pattern. Victimization rates for this
crime are broadly equivalent and possibly slightly higher in more developed countries. It is likely that
this pattern is related in part to differences in credit card ownership and use online, as well as to
differences in victim targeting due to perceptions of target worth. EUROPOL, for example, notes
that high levels of ‘card-not-present’ credit card fraud affect EU credit cards, as a result of data
breaches and illegal transactions.21
Widespread cybercrime consumer victimization carries with it significant financial costs –
both direct and indirect. Direct and indirect costs include money withdrawn from victim accounts,
time and effort to reset account credentials or repair computer systems, and secondary costs such as
for overdrawn accounts. Indirect costs are the monetary equivalent of losses imposed on society by
the existence (in general) of a particular cybercrime phenomenon. Indirect costs include loss of trust
in online banking and reduced uptake by individuals of electronic services. The overall cost to
society of cybercrime might also include ‘defence costs’ of cybersecurity products and services, as
well as fraud detection and law enforcement efforts.22
Consumer victims of cybercrime in 24 countries across the world report that they suffered
average direct losses of between 50 and 850 US dollars as a result of a cybercrime incident(s)
experienced in one year.23 Around 40 per cent of these costs were reported to consist of financial
16
17
18
19
20
21
22
23
Group 1: HDI mean=0.69, median=0.7; Group 2: HDI mean=0.89, median=0.90, The Human Development Index represents a
combined measurement of social and economic development. See http://hdr.undp.org/en/statistics/hdi/
Averages are calculated as medians of victimization rates for each country group. Bars represent upper and lower quartiles.
See, for example, UNODC, 2005. Crime and Development in Africa; and UNODC, 2007. Crime and Development in Central America.
See, for example, Tagert, A.C., 2010. Cybersecurity Challenges in Developing Nations. Dissertation. Paper 22; and Grobler, M., et al.,
2010. Evaluating Cyber Security Awareness in South Africa. In: Ottis, R. (ed.) 2011. The Proceedings of the 10th European Conference on
Information Warfare and Security. Talinn: Cooperative Cyber Defence Centre of Excellence.
See above, for instance regarding information shown in Figure 2.4.
Europol, 2012. Situation Report. Payment Card Fraud in the European Union. Perspective of Law Enforcement Agencies.
See, for example, Anderson, R., et al., 2012. Measuring the Cost of Cybercrime. 11th Annual Workshop on the Economics of Information
Security, WEIS 2012, Berlin, 25-26 June 2012.
Symantec, 2012. Norton Cybercrime Report 2012. The survey question used asked all persons reporting any cybercrime victimization in
the past 12 months how much they had lost financially over the past 12 months due to cybercrime. Respondents were asked to
29