CHAPTER ONE: CONNECTIVITY AND CYBERCRIME
motive, crime scene presence, or criminal involvement of a suspect in almost any form of crime.
Acts against the confidentiality, integrity and availability of computer data or
systems
The core list of cybercrime acts have as
their object a computer system or computer data.
‘Operation Aurora’
Basic actions include unauthorized access,
In 2010, a series of online attacks were reported by
interception, acquisition, or interference with a
several high-profile software companies, and,
computer system or data. Chapter Four
ultimately, breaches were recorded at a large search
engine firm. Using a zero-day vulnerability in a web
(Criminalization) examines these further, both
browser, the attackers created a tunnel into an internal
from a sample of national laws, and from
network via employees’ compromised workstations,
and gained access to e-mail accounts and inadequately
international and regional instruments. These acts
secured source code repositories.
may be committed using many different modus
operandi. Illegal access to a computer system, for
The same year, users of a social networking site
received e-mails from a fake account with links to a
example, may consist of the unauthorized use of a
fictitious new login system appearing to be from the
discovered password, or remote access using
company, with the victim’s username already entered
in the login system. Users’ credentials would then be
exploit software.95 The latter may also constitute
compromised, and the infected host could potentially
interference with computer data and/or a
become a member of the ZeuS botnet.
computer system. Individual acts can thus show a
Source: Trustwave. 2011. SpiderLabs Global Security Report.
degree of overlap across offence ‘baskets.’ The
first category also includes acts related to tools that
can be used to carry out acts against computer
systems or data.96 Finally, the category includes criminal acts related to the (mis)handling of
computer data in accordance with specified requirements.
Computer-related acts for personal or financial gain or harm
The ‘Gozi’ virus
In early 2013, three European men were charged
by North American prosecutors with the creation
and distribution of a computer virus that infected
more than a million computers worldwide,
enabling them to access personal bank
information and steal at least 50 million dollars in
the period between 2005 and 2011. The virus was
introduced in Europe and spread to North
America, where it also infected computers
belonging to national agencies. Extradition
proceedings against two of the accused are under
way. The case is said to be ‘one of the most financially
destructive yet seen.’
Soure: http://www.fbi.gov/
The second category focuses on acts for
which the use of a computer system is inherent
to the modus operandi. The object of such acts
differs. In the case of computer-related fraud, the
object may be considered as the economic
property targeted. In the case of computerrelated copyright or trademark offences, the
offence object may be considered as the
protected intellectual property right. In the case
of computer-related acts causing personal harm,
such as the use of a computer system to harass,
bully, threaten, stalk or to cause fear or
intimidation of an individual, or ‘grooming’ of a
child, the offence object may be regarded as the
individual targeted.
The view that a diverse range of acts with different material offence objects can nonetheless
95
96
United Nations, 1994. UN Manual on the Prevention and Control of Computer Related Crime.
Examples include Low orbit ion cannon (LOIC), sKyWIper and the ZeuS banking malware.
17