IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 58 min read

Computer Crime & Cyber Threats: Types, Impacts & Legal Frameworks

Unit 5 of IT Ethics and Cybersecurity explores the dark side of digital technology, covering definitions of computer crimes, cyber threats (malware, phishing, DDoS), their real-world impacts on businesses and individuals, and how Nepal’s laws (Electronic Transactions Act 2008) address these issues. Includes case studie

What is Computer Crime?

Computer crime refers to any illegal activity involving computers or networks. Unlike traditional crimes, these offenses exploit digital systems to steal, damage, or disrupt data. The Electronic Transactions Act 2008 (Nepal) defines cybercrimes under Section 10 (fraud), Section 11 (hacking), and Section 12 (data theft), aligning with global standards like the Council of Europe’s Cybercrime Convention (Budapest Convention, 2001).

Types of Computer Crimes

Identity TheftPhishing ScamsOnline Auction FraudFraudUnauthorized AccessData BreachesMalware AttacksHackingRansomwareBlackmail via Leaked DataCyber ExtortionState-Sponsored AttacksDefacement of WebsitesCyber TerrorismHarassment via Social MediaDoxxingCyber StalkingComputer Crimes
Hierarchical classification of computer crimes with Nepali-relevant examples

Cyber Threats: Malware, Phishing, and More

Cyber threats are malicious activities targeting digital systems. Below are the most common types, their mechanisms, and real-world Nepali examples.

1. Malware (Malicious Software)

Malware is software designed to harm, exploit, or infiltrate computer systems. Types include:

  • Viruses: Self-replicating code (e.g., CIH virus that damaged BIOS chips in 1998).
  • Worms: Spread without user interaction (e.g., ILOVEYOU worm of 2000, which cost $10B globally).
  • Trojan Horses: Disguised as legitimate software (e.g., fake "Khalti Update" APKs distributing spyware).
  • Ransomware: Encrypts data until a ransom is paid (e.g., 2021 attack on a Nepali hospital demanding $50K in Bitcoin).
  • Spyware: Steals data (e.g., Ncell’s 2019 SIM swap fraud used spyware to bypass 2FA).

How Malware Spreads in Nepal:

flowchart TD
  A["User Clicks Malicious Link"] --> B["Download Fake APK"]
  B --> C["Trojan Installs Spyware"]
  C --> D["Data Sent to Hacker Server"]
  D --> E["Fraudulent Transactions via Khalti/eSewa"]

2. Phishing and Social Engineering

Phishing tricks users into revealing sensitive data. Nepal’s 2022 eSewa breach saw attackers send fake "bill payment" emails mimicking NTC, leading to credential theft.

Types of Phishing:

Type Example in Nepal Red Flags
Email Phishing Fake "Nepal Police" email asking for OTP Poor grammar, urgent tone
Spear Phishing Targeted WhatsApp messages to bankers Personal details (name, job title)
Smishing SMS: "Your Daraz order failed. Click here." Suspicious short URLs
Vishing Caller claims to be from "Ncell Security" Requests for passwords or OTPs

3. Denial-of-Service (DoS/DDoS) Attacks

DoS attacks overwhelm a system with traffic, causing downtime. In 2020, a Nepali university’s website was DDoS’d during exams, disrupting online proctoring.

How DDoS Works:

sequenceDiagram
  participant Hacker
  participant Botnet
  participant Target (e.g., Ncell Website)
  Hacker->>Botnet: Sends Command
  Botnet->>Target: Floods with Requests (100K+ per second)
  Target-->>User: "Server Overloaded"

4. Insider Threats

Employees or contractors misuse access. Example: A 2021 Daraz warehouse employee leaked customer data to a competitor.

Why Insider Threats Are Dangerous:

  • No need for hacking skills (already have access).
  • Harder to detect (legitimate user activity).
  • High impact: Nepal Rastra Bank’s 2019 breach was caused by an insider.

Real-World Impact: Case Studies from Nepal

2019 BSNcell SIM SwapFraud (Spyware used to2020 BSNepali UniversityDDoS during exams2022 BSeSewa Data Breach(50K+ accounts exposed2023 BSWhatsApp BusinessScams (₹50L+ lost)
Key cybercrime incidents in Nepal (2019-2023)

1. eSewa Data Breach (2022)

  • Threat: Phishing + SQL Injection
  • Impact: 10,000+ users’ bank details stolen.
  • Legal Action: eSewa fined Rs. 5 million under Section 11 of the Electronic Transactions Act.

2. Ncell SIM Swap Fraud (2019–2022)

  • Threat: Social engineering + spyware
  • Impact: Rs. 200 million lost in fraudulent transactions.
  • Response: Ncell introduced biometric verification for SIM swaps.

3. WhatsApp Business Scams (2023)

  • Threat: Fake "WhatsApp Business Verification" links
  • Impact: Users tricked into installing malware, leading to Khalti account takeovers.
  • Prevention: WhatsApp now shows green ticks only for verified accounts.

Nepal’s Electronic Transactions Act 2008 and Cyber Security Strategy 2022 address cyber threats:

Digital signaturesE-commerce regulationsElectronic Transactions Act 2063Data protectionCybercrime penaltiesCyber Security Act 2075Financial fraud preventionNepal Rastra Bank GuidelinesNepal's Cyber Laws
Legal framework hierarchy for cybersecurity in Nepal
Law/Act Provision Penalty
Electronic Transactions Act 2008 Section 10: Cyber Fraud Up to 10 years imprisonment
Section 11: Unauthorized Access Fine up to Rs. 5 million
Cyber Security Strategy 2022 Mandates 2FA for all financial apps Non-compliance leads to service shutdown
Nepal Rastra Bank (NRB) Guidelines Banks must report breaches within 72 hours Fines up to Rs. 10 million

How to Protect Yourself and Organizations

For Individuals:

✅ Use 2FA (eSewa, Khalti, bank apps). ✅ Avoid clicking suspicious links (hover to check URLs). ✅ Update software (malware exploits old versions). ✅ Use VPNs on public Wi-Fi (prevents MITM attacks).

For Businesses (e.g., Daraz, Ncell, Banks):

🔒 Implement Firewalls & IDS (detects DDoS attacks). 🔒 Employee Training (prevents insider threats). 🔒 Encryption (protects customer data). 🔒 Incident Response Plan (e.g., Ncell’s 2022 breach response team).


Exam Tip

What Examiners Look For:

  1. Definitions: Clearly distinguish between cybercrime (illegal act) and cyber threat (potential danger).
  2. Nepal-Specific Examples: Always relate to eSewa, Khalti, Ncell, or Daraz in answers.
  3. Legal Provisions: Memorize Sections 10, 11, and 12 of the Electronic Transactions Act 2008.
  4. Case Studies: Be ready to explain how a phishing attack on eSewa would work (step-by-step).
  5. Prevention vs. Detection: Differentiate between firewalls (prevention) and IDS (detection).

Common Mistakes to Avoid: ❌ Generic answers (e.g., "viruses are bad" without Nepal examples). ❌ Ignoring legal aspects (always link crimes to Nepal’s laws). ❌ Overcomplicating diagrams (stick to flowcharts for processes, tables for comparisons).


Practice Question (Worked Example)

Q: Explain how a DDoS attack on NTC’s website could disrupt services, and what legal action could be taken under Nepal’s cyber laws.

A:

  1. Attack Mechanism:

    • Hackers use a botnet (e.g., Mirai malware) to flood NTC’s servers with 100,000+ requests per second.
    • Servers crash → website downtime → customers can’t pay bills online.
    flowchart TD
      A["Botnet"] -->|"Floods"| B["NTC Server"]
      B -->|"Overload"| C["Website Down"]
      C -->|"Impact"| D["Customers Can't Pay Bills"]
  2. Legal Action:

    • Section 11 (Unauthorized Access): Hacker could face fine up to Rs. 5 million.
    • Section 10 (Cyber Fraud): If attackers extort NTC for money, penalty is 10 years imprisonment.
  3. NTC’s Response:

    • Upgrade firewalls (e.g., Cloudflare DDoS protection).
    • Report to Nepal Police Cyber Crime Unit within 24 hours (as per Cyber Security Strategy 2022).

Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 5.

Discussion

Loading…