Cybersecurity guide for developing countries II.1.8.3 Trends Today, viruses no longer have as their principal objective gratuitous large-scale data destruction. They tend to be designed for a much more intelligent purpose: making money. Thanks to this new pragmatic focus and their inherent characteristics, they can be used for fraud. Thus, viruses have become highly lucrative tools for organized criminals engaged in financial crime. For spam and related nuisances, the French Club de la sécurité des systèmes d’information français (Clusif)16 reported that AOL filtered 500 billion spam messages in 2003, and the most prolific spammer in the world, as revealed in December 2003 by the anti-spam organization Spamhaus17, is thought to have despatched 70 million e-mail messages in a single day! Clusif also reported how, in May 2003, the so-called Buffalo spammer was sentenced in the United States to pay USD 16.4 million to the internet service provider Earthlink, for sending 820 million unsolicited messages. According to Ferris Research, in 2003 spam cost the business world USD 2.5 billion in Europe and USD 8.9 billion in the USA. When added to the USD 500 million that service providers have invested to block spam, the full magnitude of this problem of e-mail abuse becomes clear. It is obviously an issue that can no longer be ignored. In addition to the direct costs resulting from fraud, one has to consider the costs related to service interruption, leading to disruption of operations, loss of sales, collateral damage, loss of image and reputation, and the cost of restoring the systems to an operational state. These represent a considerable cost for the organizations that are the targets of computer crime. Observations show that the number of attacks is growing all the time and computer viruses have become veritable pandemics. Identity-theft operations are growing and have taken on an impressive level of sophistication, as have fraud and the various forms of swindles and blackmail that are the daily reality of cyberspace. They have become ubiquitous, affecting everyone and all sectors of activity, across barriers of geography and time. There is not a system, hardware or software platform, or operating system that is immune, including mobile systems (laptops and mobile telephones). II.1.9 Principal forms of internet crime II.1.9.1 Swindles, espionage and intelligence activities, rackets and blackmail The various common forms of organized crime (protection rackets, human trafficking, confidence schemes, theft, etc.) can benefit from using new information technologies, in particular the internet. By making it easy to communicate, the internet assists those engaged in any form of smuggling (whether it be of arms or human beings), and swindles (attacks against property, computer systems and infrastructure, data theft, copyright infringements, etc.). Criminals use the internet in various ways. Some use another person’s identity in order to make purchases on the victim’s account. This is frequently done by means of credit-card fraud, for example by creating valid card numbers that do not correspond to any real account. The information is used to purchase something online, using a “disposable” address for one-time delivery. The cost will be borne by the bank system or the merchant. Card users may also be victimized, for example when their creditcard numbers have been divulged, by a pickpocket or a dishonest merchant, to a specialized gang. 16 www.clusif.asso.fr 17 www.spamhaus.org Cybercrime 39

Select target paragraph3