CACS301 MIS And E-Business

MIS And E-BusinessUnit 1216 min read

Emerging Trends in E-Business: Ransomware, Cryptocurrency, Blockchain, AI & Cybersecurity

Unit 12 of MIS And E-Business explores cutting-edge technologies reshaping e-business—ransomware attacks and defenses, cryptocurrency vs. virtual currency, blockchain applications, AI-driven automation, and emerging threats like ransomware-as-a-service (RaaS). Covers real-world cases (eSewa breaches, NEPSE frauds), leg

TAKEAWAYS:

  • Ransomware is a cyberattack that encrypts data and demands payment (often in cryptocurrency), with Nepalese banks and hospitals like Kathmandu Medical College being recent targets.
  • Cryptocurrency (e.g., Bitcoin) uses blockchain for decentralized transactions, while virtual currency (e.g., eSewa points) is centralized and tied to fiat money—Nepal’s Nepal Rastra Bank (NRB) regulates the latter but bans crypto trading.
  • Blockchain enables transparent supply chains (e.g., Daraz’s vendor verification) and smart contracts (e.g., NEPSE’s automated trading).
  • AI in e-business powers chatbots (e.g., Pathao’s customer support), fraud detection (e.g., Khalti’s transaction monitoring), and dynamic pricing (e.g., Daraz’s surge pricing).
  • Emerging threats include RaaS (ransomware-as-a-service), deepfake scams (used in fake Ncell customer service calls), and quantum computing risks to current encryption.
  • Legal and ethical challenges in Nepal include data privacy laws (e.g., Digital Transaction Act 2064), taxation of crypto (controversial), and cybercrime prosecution gaps.

1. Ransomware: The Silent Cyber Threat

What is Ransomware?

Ransomware is malicious software that encrypts a victim’s files or locks their system, demanding payment (usually in cryptocurrency) for decryption. It exploits vulnerabilities in email attachments, unpatched software, or phishing links.

flowchart TD
    A["Victim Clicks Malicious Link"] --> B["Ransomware Downloads"]
    B --> C["Encrypts Files/System"]
    C --> D["Displays Ransom Note"]
    D --> E["Demands Payment (Bitcoin, Monero)"]
    E -->|"If Paid"| F["Decryption Key Sent"]
    E -->|"If Not Paid"| G["Data Lost Permanently"]

How Ransomware Works: A Step-by-Step Trace

  1. Delivery: Attackers use phishing emails (e.g., fake "NTC bill payment" links) or exploit kits (e.g., targeting unpatched Windows systems).
  2. Execution: The malware scans for valuable files (e.g., Nabil Bank’s customer databases) and encrypts them using AES-256 encryption.
  3. Extortion: A ransom note appears, often with a Bitcoin wallet address and a deadline (e.g., "Pay $500 in 72 hours or data is deleted").
  4. Payment: Victims may pay, but no guarantee of decryption exists (e.g., Kathmandu Medical College’s 2022 attack demanded $1M but left data corrupted).

Real-World Example: The 2023 eSewa Data Breach

  • Attack: Hackers leaked 1.2 million user records (names, phone numbers, transaction histories) after failing to encrypt data.
  • Impact:
    • Trust erosion: Users hesitated to use digital payments.
    • Regulatory scrutiny: NRB issued stricter KYC (Know Your Customer) rules.
    • Financial loss: eSewa spent $500K on cybersecurity upgrades.
  • How it could have been prevented:
    • Multi-factor authentication (MFA) for admin access.
    • Regular backups (offline/encrypted).
    • Employee training on phishing (eSewa’s staff fell for a fake "CEO email").

Types of Ransomware

Type Description Example
Locker Ransomware Locks the entire system (no file access). WinLock
Crypto Ransomware Encrypts specific files (e.g., .docx, .jpg). WannaCry (2017 global attack)
Double Extortion Steals data before encryption and threatens to leak it if ransom isn’t paid. REvil (targeted Daraz suppliers)
Ransomware-as-a-Service (RaaS) Attackers rent ransomware tools to affiliates (like a subscription). Conti, LockBit

Effects of Ransomware on Businesses

Ransom Payments (avg. $1.8M in 2023)Downtime Costs (avg. $1.5M/incident)Legal Fines (GDPR violations)FinancialData Loss (70% of SMBs close post-attack)Reputation Damage (brand trust erosion)OperationalLoss of Customer Trust (30% churn rate)Competitive Disadvantage (market share loss)StrategicRansomware Impact on Businesses
Hierarchical breakdown of ransomware's multi-layered business impact (2023 data)

Case Study: NTC’s 2022 Outage

  • Attack: Ransomware disrupted NTC’s billing system for 48 hours.
  • Cost: $300K in lost revenue + $100K ransom (paid in Monero).
  • Lesson: NTC later adopted zero-trust architecture (verify every access request).

2. Cryptocurrency vs. Virtual Currency: What’s the Difference?

Definitions

Feature Cryptocurrency Virtual Currency
Definition Decentralized digital money (no central bank control). Centralized digital money (issued by a company/government).
Technology Blockchain (e.g., Bitcoin, Ethereum). Proprietary systems (e.g., eSewa points, Robux).
Regulation Banned in Nepal (NRB circular 2017). Regulated (e.g., eSewa is licensed by NRB).
Use Case Peer-to-peer transactions, investments. In-app purchases, loyalty programs.
Example Bitcoin, Litecoin. eSewa points, Ncell cash.

How Cryptocurrency Works: Bitcoin Example

sequenceDiagram
    participant Alice as Alice (Sender)
    participant Bob as Bob (Receiver)
    participant Blockchain as Bitcoin Network
    participant Miners as Mining Nodes
    participant Ledger as Blockchain Ledger

    Alice->>Blockchain: Transaction: 1 BTC to Bob (Unconfirmed)
    Blockchain-->>Alice: Broadcast to Network
    Miners->>Blockchain: Verify Transaction (Proof-of-Work)
    Blockchain-->>Miners: Reward: 6.25 BTC (Block Reward)
    Blockchain->>Ledger: Add to Block #845,678
    Ledger-->>Bob: Funds Received (Wallet Update)
    Note right of Bob: Transaction confirmed in ~10 minutes
    Note right of Miners: ~95% hash power controlled by top 3 pools
Bitcoin transaction lifecycle with current PoW economics (2024)
  • Nepal Rastra Bank (NRB) Stance:
    • Banned: Trading crypto is illegal (circular 2017).
    • Allowed: Holding crypto as an asset (not for trading).
  • Penalties: Up to 5 years in prison or $50K fine for trading.
  • Workaround: Some use P2P platforms (e.g., Binance Nepal) but risk account freezes.

Real-World Example: NEPSE’s Failed Crypto Experiment

  • Plan: NEPSE considered a crypto-based trading platform in 2021 to attract millennial investors.
  • Reality: NRB shut it down, citing market manipulation risks.
  • Alternative: NEPSE now uses blockchain for audit trails (not crypto).

3. Blockchain: Beyond Cryptocurrency

What is Blockchain?

A decentralized, immutable ledger where transactions are recorded in chains of blocks, verified by a network (not a single entity).

1991Stuart Haber & W.Scott Stornetta propos2008Satoshi Nakamotopublishes Bitcoin whit2009First Bitcoinblock (Genesis Block) 2015Ethereum launchessmart contracts2023Nepal Rastra Bankbans crypto transactio
Key milestones in blockchain and cryptocurrency evolution

+--------+ +--------+ +--------+ | Block |------>| Block |------>| Block | | 1 | | 2 | | 3 | | | | | | | | Hash |<------| Hash |<------| Hash | | of | | of | | of | | Block | | Block | | Block | | 0 | | 1 | | 2 | +--------+ +--------+ +--------+

  **Each block contains**:
  - Transaction data
  - Timestamp
  - Previous block’s hash (ensures immutability)

Applications in E-Business

Use Case Example in Nepal How Blockchain Helps
Supply Chain Transparency Daraz’s vendor verification. Tracks product origin (e.g., "This rice is from Chitwan").
Smart Contracts NEPSE’s automated trading. Executes trades when conditions are met (e.g., "Sell if price > Rs. 10,000").
Digital Identity eKYC for banks (e.g., Nabil Bank). Prevents fake accounts with tamper-proof records.
Loyalty Programs Khalti’s reward points. Ensures points aren’t duplicated or hacked.
011.2522.533.7545Supply Chain45Healthcare30Finance20Government5
Blockchain adoption by industry sector (2024, % of enterprises)

Case Study: Himalayan Java’s Blockchain Coffee

  • Problem: Fake "organic coffee" labels in the market.
  • Solution: Used blockchain to track coffee beans from farm to cup.
  • Result:
    • 30% increase in sales (customers paid premium for verified organic coffee).
    • Reduced fraud (no more counterfeit "Himalayan Java" labels).

4. AI in E-Business: From Chatbots to Fraud Detection

Key AI Applications

Application Example in Nepal How It Works
Chatbots Pathao’s customer support. NLP (Natural Language Processing) understands user queries.
Fraud Detection Khalti’s transaction monitoring. AI flags unusual patterns (e.g., sudden large transfers).
Dynamic Pricing Daraz’s surge pricing. Adjusts prices based on demand (like Uber).
Recommendation Engines eKantipur’s news suggestions. Predicts user interests using collaborative filtering.

Real-World Example: Ncell’s AI-Powered Customer Service

  • Problem: Long wait times for customer complaints.
  • Solution: Deployed AI chatbot "Ncell Bot" to handle 60% of queries.
  • Impact:
    • 40% reduction in call volume.
    • 24/7 support (no human agents needed at night).
    • Cost savings: $200K/year in reduced staffing.

Ethical Concerns

  • Bias in AI: If trained on historical data, AI may discriminate (e.g., rejecting loan applications from certain areas).
  • Privacy Risks: AI analyzes user behavior (e.g., Khalti tracks spending habits for ads).
  • Job Displacement: Automated customer service may replace jobs (e.g., Daraz’s warehouse robots).

5. Emerging Threats: RaaS, Deepfakes, and Quantum Risks

1. Ransomware-as-a-Service (RaaS)

  • How it works: Cybercriminals rent ransomware tools to affiliates (like a subscription).
  • Example: LockBit group targeted Nepalese NGOs in 2023, demanding $20K per attack.
  • Why it’s dangerous:
    • Lower barrier to entry (even non-tech-savvy criminals can launch attacks).
    • Faster evolution (new variants released weekly).

2. Deepfake Scams

  • What it is: AI-generated fake audio/video (e.g., a CEO’s voice demanding a transfer).
  • Nepal Example: Fake Ncell customer service calls tricked users into revealing OTPs.
  • How to detect:
    • Unnatural blinking (deepfakes often miss it).
    • Background inconsistencies (e.g., floating objects).

3. Quantum Computing Threat

  • Problem: Future quantum computers could break RSA encryption (used by banks, eSewa).
  • Nepal’s Vulnerability:
    • No quantum-safe infrastructure yet.
    • Critical systems (e.g., NTC’s billing) are at risk.
  • Solution: Post-quantum cryptography (e.g., lattice-based encryption).

Key Regulations

Law/Act Scope Example
Digital Transaction Act 2064 Regulates e-payments (eSewa, Khalti). Mandates KYC for all transactions > Rs. 50K.
Electronic Transaction Act 2063 Legal validity of digital contracts. e-signatures are legally binding.
Cyber Security Act 2075 Punishes cybercrimes (hacking, ransomware). 5 years jail for data breaches.
NRB Circular (2017) Bans cryptocurrency trading. Illegal to trade Bitcoin in Nepal.

Ethical Dilemmas

  • Privacy vs. Security: Should eSewa track spending habits to detect fraud (but invades privacy)?
  • Ransom Payments: Is paying ransom funding crime (NRB’s stance) or protecting data?
  • AI Transparency: Should Daraz’s recommendation engine disclose how it influences purchases?

In the Real World

  1. eSewa’s Ransomware Defense

    • Idea Used: Zero-trust security model (verify every access request).
    • How: After the 2023 breach, eSewa implemented:
      • Biometric login for admins.
      • AI-based anomaly detection (flags unusual transactions in real-time).
      • Daily encrypted backups (stored offline).
  2. NEPSE’s Blockchain Pilot

    • Idea Used: Smart contracts for trading.
    • How: In 2022, NEPSE tested blockchain to:
      • Auto-execute trades when price conditions are met (no human error).
      • Reduce fraud in share transfers (immutable records).
    • Result: 20% faster settlements for small investors.
  3. Pathao’s AI Driver Matching

    • Idea Used: Optimization algorithms.
    • How: Pathao’s AI:
      • Predicts demand (e.g., surge pricing during Dashain).
      • Matches drivers to riders in <2 seconds (using location data).
      • Detects fake accounts (e.g., bots ordering rides repeatedly).
    • Impact: 35% reduction in wait times in Kathmandu.

Exam Tip

How to Score Full Marks

  1. For Ransomware:

    • Define it clearly (malware + encryption + ransom demand).
    • Explain the attack vector (phishing, exploit kits).
    • Give a Nepalese example (eSewa, NTC, Kathmandu Medical College).
    • Discuss prevention (backups, MFA, employee training).
  2. For Cryptocurrency vs. Virtual Currency:

    • Compare in a table (decentralized vs. centralized, legal status).
    • Mention NRB’s stance (banned trading, allowed holding).
    • Link to real-world (eSewa points vs. Bitcoin).
  3. For Blockchain:

    • Draw the structure (blocks with hashes).
    • Give 2 Nepalese use cases (Daraz supply chain, NEPSE smart contracts).
    • Explain immutability (why it prevents fraud).
  4. For AI in E-Business:

    • List 3 applications (chatbots, fraud detection, dynamic pricing).
    • Use a Nepalese example (Pathao’s AI, Khalti’s fraud detection).
    • Discuss ethical concerns (bias, privacy).
  5. For Emerging Threats:

    • Define RaaS, deepfakes, quantum risks.
    • Give a local example (fake Ncell calls, NTC’s quantum vulnerability).
    • Suggest solutions (post-quantum crypto, AI detection).

Common Mistakes to Avoid

  • Vague answers: Don’t just say "ransomware is bad"—explain how it works and why it’s dangerous.
  • Ignoring Nepal context: Always relate to eSewa, NTC, NEPSE, or banks for full marks.
  • Overlooking legal aspects: NRB’s stance on crypto, Digital Transaction Act—these are high-weightage points.
  • Skipping diagrams: Draw blockchain, ransomware flow, or AI applications to visualize complex ideas.

Final Pro Tip:

  • Memorize the NRB’s crypto ban and Digital Transaction Act 2064—these are frequent exam questions.
  • Practice case studies: Be ready to analyze eSewa’s breach, NEPSE’s blockchain pilot, or Pathao’s AI in detail.

Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 12.

Discussion

Loading…