CHAPTER ONE: CONNECTIVITY AND CYBERCRIME motive, crime scene presence, or criminal involvement of a suspect in almost any form of crime. Acts against the confidentiality, integrity and availability of computer data or systems The core list of cybercrime acts have as their object a computer system or computer data. ‘Operation Aurora’ Basic actions include unauthorized access, In 2010, a series of online attacks were reported by interception, acquisition, or interference with a several high-profile software companies, and, computer system or data. Chapter Four ultimately, breaches were recorded at a large search engine firm. Using a zero-day vulnerability in a web (Criminalization) examines these further, both browser, the attackers created a tunnel into an internal from a sample of national laws, and from network via employees’ compromised workstations, and gained access to e-mail accounts and inadequately international and regional instruments. These acts secured source code repositories. may be committed using many different modus operandi. Illegal access to a computer system, for The same year, users of a social networking site received e-mails from a fake account with links to a example, may consist of the unauthorized use of a fictitious new login system appearing to be from the discovered password, or remote access using company, with the victim’s username already entered in the login system. Users’ credentials would then be exploit software.95 The latter may also constitute compromised, and the infected host could potentially interference with computer data and/or a become a member of the ZeuS botnet. computer system. Individual acts can thus show a Source: Trustwave. 2011. SpiderLabs Global Security Report. degree of overlap across offence ‘baskets.’ The first category also includes acts related to tools that can be used to carry out acts against computer systems or data.96 Finally, the category includes criminal acts related to the (mis)handling of computer data in accordance with specified requirements. Computer-related acts for personal or financial gain or harm The ‘Gozi’ virus In early 2013, three European men were charged by North American prosecutors with the creation and distribution of a computer virus that infected more than a million computers worldwide, enabling them to access personal bank information and steal at least 50 million dollars in the period between 2005 and 2011. The virus was introduced in Europe and spread to North America, where it also infected computers belonging to national agencies. Extradition proceedings against two of the accused are under way. The case is said to be ‘one of the most financially destructive yet seen.’ Soure: http://www.fbi.gov/ The second category focuses on acts for which the use of a computer system is inherent to the modus operandi. The object of such acts differs. In the case of computer-related fraud, the object may be considered as the economic property targeted. In the case of computerrelated copyright or trademark offences, the offence object may be considered as the protected intellectual property right. In the case of computer-related acts causing personal harm, such as the use of a computer system to harass, bully, threaten, stalk or to cause fear or intimidation of an individual, or ‘grooming’ of a child, the offence object may be regarded as the individual targeted. The view that a diverse range of acts with different material offence objects can nonetheless 95 96 United Nations, 1994. UN Manual on the Prevention and Control of Computer Related Crime. Examples include Low orbit ion cannon (LOIC), sKyWIper and the ZeuS banking malware. 17

Select target paragraph3