IT Ethics and CybersecurityUnit 58 min read
Computer Crime & Cyber Threats: Types, Impacts & Legal Frameworks
Unit 5 of IT Ethics and Cybersecurity explores the dark side of digital technology, covering definitions of computer crimes, cyber threats (malware, phishing, DDoS), their real-world impacts on businesses and individuals, and how Nepal’s laws (Electronic Transactions Act 2008) address these issues. Includes case studie
What is Computer Crime?
Computer crime refers to any illegal activity involving computers or networks. Unlike traditional crimes, these offenses exploit digital systems to steal, damage, or disrupt data. The Electronic Transactions Act 2008 (Nepal) defines cybercrimes under Section 10 (fraud), Section 11 (hacking), and Section 12 (data theft), aligning with global standards like the Council of Europe’s Cybercrime Convention (Budapest Convention, 2001).
Types of Computer Crimes
Cyber Threats: Malware, Phishing, and More
Cyber threats are malicious activities targeting digital systems. Below are the most common types, their mechanisms, and real-world Nepali examples.
1. Malware (Malicious Software)
Malware is software designed to harm, exploit, or infiltrate computer systems. Types include:
- Viruses: Self-replicating code (e.g., CIH virus that damaged BIOS chips in 1998).
- Worms: Spread without user interaction (e.g., ILOVEYOU worm of 2000, which cost $10B globally).
- Trojan Horses: Disguised as legitimate software (e.g., fake "Khalti Update" APKs distributing spyware).
- Ransomware: Encrypts data until a ransom is paid (e.g., 2021 attack on a Nepali hospital demanding $50K in Bitcoin).
- Spyware: Steals data (e.g., Ncell’s 2019 SIM swap fraud used spyware to bypass 2FA).
How Malware Spreads in Nepal:
flowchart TD A["User Clicks Malicious Link"] --> B["Download Fake APK"] B --> C["Trojan Installs Spyware"] C --> D["Data Sent to Hacker Server"] D --> E["Fraudulent Transactions via Khalti/eSewa"]
2. Phishing and Social Engineering
Phishing tricks users into revealing sensitive data. Nepal’s 2022 eSewa breach saw attackers send fake "bill payment" emails mimicking NTC, leading to credential theft.
Types of Phishing:
| Type | Example in Nepal | Red Flags |
|---|---|---|
| Email Phishing | Fake "Nepal Police" email asking for OTP | Poor grammar, urgent tone |
| Spear Phishing | Targeted WhatsApp messages to bankers | Personal details (name, job title) |
| Smishing | SMS: "Your Daraz order failed. Click here." | Suspicious short URLs |
| Vishing | Caller claims to be from "Ncell Security" | Requests for passwords or OTPs |
3. Denial-of-Service (DoS/DDoS) Attacks
DoS attacks overwhelm a system with traffic, causing downtime. In 2020, a Nepali university’s website was DDoS’d during exams, disrupting online proctoring.
How DDoS Works:
sequenceDiagram participant Hacker participant Botnet participant Target (e.g., Ncell Website) Hacker->>Botnet: Sends Command Botnet->>Target: Floods with Requests (100K+ per second) Target-->>User: "Server Overloaded"
4. Insider Threats
Employees or contractors misuse access. Example: A 2021 Daraz warehouse employee leaked customer data to a competitor.
Why Insider Threats Are Dangerous:
- No need for hacking skills (already have access).
- Harder to detect (legitimate user activity).
- High impact: Nepal Rastra Bank’s 2019 breach was caused by an insider.
Real-World Impact: Case Studies from Nepal
1. eSewa Data Breach (2022)
- Threat: Phishing + SQL Injection
- Impact: 10,000+ users’ bank details stolen.
- Legal Action: eSewa fined Rs. 5 million under Section 11 of the Electronic Transactions Act.
2. Ncell SIM Swap Fraud (2019–2022)
- Threat: Social engineering + spyware
- Impact: Rs. 200 million lost in fraudulent transactions.
- Response: Ncell introduced biometric verification for SIM swaps.
3. WhatsApp Business Scams (2023)
- Threat: Fake "WhatsApp Business Verification" links
- Impact: Users tricked into installing malware, leading to Khalti account takeovers.
- Prevention: WhatsApp now shows green ticks only for verified accounts.
Legal Frameworks in Nepal
Nepal’s Electronic Transactions Act 2008 and Cyber Security Strategy 2022 address cyber threats:
| Law/Act | Provision | Penalty |
|---|---|---|
| Electronic Transactions Act 2008 | Section 10: Cyber Fraud | Up to 10 years imprisonment |
| Section 11: Unauthorized Access | Fine up to Rs. 5 million | |
| Cyber Security Strategy 2022 | Mandates 2FA for all financial apps | Non-compliance leads to service shutdown |
| Nepal Rastra Bank (NRB) Guidelines | Banks must report breaches within 72 hours | Fines up to Rs. 10 million |
How to Protect Yourself and Organizations
For Individuals:
✅ Use 2FA (eSewa, Khalti, bank apps). ✅ Avoid clicking suspicious links (hover to check URLs). ✅ Update software (malware exploits old versions). ✅ Use VPNs on public Wi-Fi (prevents MITM attacks).
For Businesses (e.g., Daraz, Ncell, Banks):
🔒 Implement Firewalls & IDS (detects DDoS attacks). 🔒 Employee Training (prevents insider threats). 🔒 Encryption (protects customer data). 🔒 Incident Response Plan (e.g., Ncell’s 2022 breach response team).
Exam Tip
What Examiners Look For:
- Definitions: Clearly distinguish between cybercrime (illegal act) and cyber threat (potential danger).
- Nepal-Specific Examples: Always relate to eSewa, Khalti, Ncell, or Daraz in answers.
- Legal Provisions: Memorize Sections 10, 11, and 12 of the Electronic Transactions Act 2008.
- Case Studies: Be ready to explain how a phishing attack on eSewa would work (step-by-step).
- Prevention vs. Detection: Differentiate between firewalls (prevention) and IDS (detection).
Common Mistakes to Avoid: ❌ Generic answers (e.g., "viruses are bad" without Nepal examples). ❌ Ignoring legal aspects (always link crimes to Nepal’s laws). ❌ Overcomplicating diagrams (stick to flowcharts for processes, tables for comparisons).
Practice Question (Worked Example)
Q: Explain how a DDoS attack on NTC’s website could disrupt services, and what legal action could be taken under Nepal’s cyber laws.
A:
Attack Mechanism:
- Hackers use a botnet (e.g., Mirai malware) to flood NTC’s servers with 100,000+ requests per second.
- Servers crash → website downtime → customers can’t pay bills online.
flowchart TD A["Botnet"] -->|"Floods"| B["NTC Server"] B -->|"Overload"| C["Website Down"] C -->|"Impact"| D["Customers Can't Pay Bills"]
Legal Action:
- Section 11 (Unauthorized Access): Hacker could face fine up to Rs. 5 million.
- Section 10 (Cyber Fraud): If attackers extort NTC for money, penalty is 10 years imprisonment.
NTC’s Response:
- Upgrade firewalls (e.g., Cloudflare DDoS protection).
- Report to Nepal Police Cyber Crime Unit within 24 hours (as per Cyber Security Strategy 2022).
Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 5.
Discussion
Loading…