Part 1: What is digital crime? basic concepts
What is “crime”?
- act, activity, behaviour prohibited by law
- punished with penalties and sanctions
- defined mainly in the national law of sovereign states
→ nullum crimen sine lege: no crime without law
→ Substantive law: what crime is (here, the law defines that f.e. murder is a crime)
→ Procedural law: how to investigate crime ((f.e. here, the law defines when and how
authorities can access certain premises; establishes requirements for conducting house
searches; regulates retrieval of data from electronic devices)
Defining cybercrime, or do we even need a definition?
“Cyber” and crime: what is new?
→ Peter Grabovsky: ”Old wine, new bottles”: “To be sure, some of the manifestations are
new. But a great deal of crime committed with or against computers differs only in terms of
the medium. It is less a question of something completely different than a recognizable crime
committed in a completely different way
→ David Wall (1999): “New wine, no bottles”: “What is significantly different this time is that
the communications are two-way and can reach a potentially infinite number of people
across a wide range of jurisdictions almost without restriction
Cyberspace and crime: new medium? new form?
→ New types of cybercrime → crimes that did not exist before computers and networks
→ migration of traditional crime online → computers and networks used to facilitate
commission of traditional crimes
Early classifications: computer as a tool and target
The most common classification: is this classification helpful?
→ cyber-dependent: “true”, “pure” cybercrimes, cannot exist without technology (CIA crimes)
→ cyber-enabled crimes: technology facilitates traditional crime
EU → both
Cybercrime in context of investigations → cyber-enabled & dependent crime +
procedural frameworks to investigate not only cybercrime but any crime
a broader policy context →
Do we need to define cybercrime?
→ Substantive criminal law (nullum crimen sine lege): definition of specific
“cyber” crimes should be very precise
→ Cybercrime investigations: definition of cybercrime should be sufficiently broad:
● to apply procedural frameworks developed to fight cybercrime to any criminal
investigations in cyberspace
● to guarantee the protection of human rights in any digital investigations
,No definition? Not an issue (e.g. United Nations Convention against Corruption)
Part 2: cybercrime in a historical perspective
→ Early years and development of internet → more user-friendly internet and development
of cybercrime → worldwide adoption of the internet and increase of cybercrime → explosive
increase of cybercrime and true cyber attacks (stuxnet, saudi aramco, notpetya) → serious
consequences of cybercrime, AI adoption and state actor involvement
Part 3: types of cybercrime
→ Cyber-dependent: criminal behaviour whereby computers are the target and the means of
crime (CIA triad)
→ Computer hacking: four common ways:
1. gaining access through a cunning trick
2. exploitation of (known) vulnerabilities
3. use of previously stolen login credential offered on the internet
4. use of ‘brute force attacks’
Ethical hacking
→ Individuals who hack with permission usually hired by companies to ‘hack into’ computers
and provide security advice
→ ‘Penetration testers”: hacking takes place with consent of the client and is therefore not
punishable
→ Hack may also be conducted without consent, but not with the aim of committing criminal
offences – this conduct may be punishable
(Dutch) coordinated vulnerability disclosure guideline
→ created by a small number of countries, goal:
- decriminalise the disclosure of vulnerabilities
- provide guidelines for companies and governments on how to deal with ethical
hackers
NSCS has drawn up a guideline since 2013
The reporting party:
- is responsible for its own actions and must observe principles of proportionality when
investigating and reporting vulnerabilities
- must report the problem as soon as possible
- must make the report to the organisation in a confidential manner to prevent others
from gaining access
- may not make the filing of a report or the provision of information dependent on the
reward
- and the organisation make clear agreements on the disclosure of the vulnerability to
the public
Malware (malicious
software)
→ virus = malicious
software that infects a
computer system
,→ worm = malicious software that spreads itself within a network
→ trojan horse = innocent-looking program or file containing malware
The psychology of ransomware: coercion and compliance
→ Botnet: a network of computers infected by malware that are under the control of a single
attacking party, known as the “bot-herder.”
→ Dismantling botnets: botmaster arrest, infrastructure shutdown, removal of individual
infections
→ DDoS attack: malicious attempt to disrupt normal traffic of a targeted server, service, or
network by overwhelming it with a flood of internet traffic from multiple compromised
sources. (use of botnet)
→ Cybercrime-as-a-service: perpetrators can rent out a botnet to carry out DDoS attack for
as little as 10,-
Cyber-enabled crime
Online criminal marketplaces: digital environment or platforms that trade illicit goods,
services, or data. three functions:
1. market function: trading of illegal goods and/or data
2. social function: connection and interaction with other potential offenders
3. learning function: exchange of information and knowledge
Online fraud → one of the most common types of cyber enabled crime worldwide, phishing =
most common type
→ Online scams are criminalised using the general offence for fraud, However: fraud
charges are difficult to prove, perpetrators are often convicted for other offences
Online sexual offences
→ Images of sexual abuse of minors: Creation or distribution of a photograph or video of a
child under the age of eighteen performing sexual acts, posing sexually or being present in a
sexually oriented environment
CSAM: criminalisation. Art. 9 Convention on Cybercrime (2001):
a. a minor engaged in sexually explicit conduct;
b. a person appearing to be a minor engaged in sexually explicit conduct;
c. realistic images representing a minor engaged in sexually explicit conduct.
→ Abuse of sexual imagery: The creation, distribution, or threat of distribution of sexual or
intimate images without the consent or the person depicted.
→ Online expression offences: Internet facilitates expression offences because content can
be shared quickly with little to no monitoring on social media platforms
→ Freedom of expression vs. criminalisation: Any encroachment upon an individual’s
freedom of expression entails an interference with the freedom of expression
Defamation and slander:
- Defamation: Expression offence where an individual’s reputation is tarnished, casting
them in an unfavourable light
, - Slander distinguishes itself from defamation by the deliberate
dissemination of false claims by the offender (while knowing it
to be untrue)
Lecture 2 - Emerging technologies and cybercrime policies &
digital evidence and cross-border investigations
Part 1: emerging technologies and cybercrime policies
→ Characteristics: radical novelty, relatively fast
growth, coherence, prominent impact, uncertainty
and ambiguity
Criminal law and technological developments →
Emerging technologies and crime
Technology:
- becomes a target: hacking a self-driving car,
targeting AI assistants
- facilitates existing crimes: AI facilitating spear
phishing campaigns; use of deepfakes for fraud
- creates new harms (new crimes): the criminalisation of creation of sexually explicit
deepfakes
- commits crimes autonomously: More of a scenario for future crimes
→ these categories are not mutually exclusive
AI technologies and crime
- deceptive uses of generative AI for committing crimes, e.g. deepfakes
- better automation, e.g. password-guassing tools
- malware written/modified by large language models (LLMs)
- AI models for crime: fraudgpt, wormgpt
- LLMs facilitating spear phishing campaigns
Example: deepfake nudes → Grok
AI and crime: what are the possible policy options?
→ Criminal law and related aspects:
- identifying the gaps in criminal law based on harms, establishing the need for new
offences
- challenge of technology-neutral legislation
- consideration on banning certain technologies
→ Technology aspects:
- reducing risks when designing technologies (might need subject matter expertise)
- responsibilities of technology developers and provides, e.g. mandatory obligations or
voluntary efforts → class on the role of the private sector in tackling cybercrime
- tools for detection, e.g. upload filters, labelling, and tools for establishing authenticity
→ Education, awareness, and support for victims:
- raising awareness among possible targets (users and businesses)
- Creation of mechanisms to help victims
→ Strengthening collaboration