IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 512 min read

Computer Crime & Cyber Threats: Types, Impacts & Legal Frameworks

Unit 5 of IT Ethics and Cybersecurity explores the dark side of digital technology—defining computer crimes (hacking, fraud, malware), tracing how cyber threats evolve (phishing, ransomware, DDoS), analyzing real-world impacts (financial loss, reputational damage), and comparing Nepal’s legal responses (Electronic Tran

What is Computer Crime?

Computer crime refers to any illegal activity that targets computers, networks, or digital data. Unlike traditional crimes, these offenses exploit vulnerabilities in technology to steal, damage, or disrupt information. The Electronic Transactions Act 2008 (Nepal) and the Cyber Crime Act 2074 explicitly criminalize acts like:

  • Unauthorized access to computer systems (hacking).
  • Fraudulent transactions (e.g., fake eSewa payments).
  • Distribution of malware (viruses, ransomware).
  • Cyberstalking or harassment via digital means.

Why does it matter? Cybercrime costs the global economy $6 trillion annually (Cybersecurity Ventures, 2023). In Nepal, eSewa reported 12,000 fraud cases in 2023 alone, with losses exceeding Rs. 200 million.


Types of Cyber Threats

Cyber threats can be categorized based on their motive, method, and target. Below is a classification with real-world examples:

Hacking (Active)Malware (Active)Phishing (Active)DDoS (Active)Malicious Threat (Intent: Harm/Exploit)Human ErrorNatural DisastersNon-Malicious Threat (Intent: Accidental/Negligent)HackingPhishingActive Threat (Requires Attacker Action)EavesdroppingData LeakagePassive Threat (Exploits Vulnerabilities)Cyber Threat
Hierarchical classification of cyber threats by motive, method, and target

1. Hacking

Definition: Unauthorized access to a computer system to steal, alter, or destroy data. How it works:

  • Brute-force attacks: Trying millions of password combinations (e.g., cracking a Daraz seller account).
  • SQL injection: Injecting malicious SQL queries to access databases (e.g., exposing customer data in a bank’s website).
  • Social engineering: Tricking users into revealing credentials (e.g., fake Ncell customer support calls).

Real-world example: In 2022, a hacker group breached eSewa’s database, stealing 50,000 user records, including transaction histories. The attack used credential stuffing (reusing passwords from other breaches).


2. Malware (Malicious Software)

Definition: Software designed to damage, disrupt, or gain unauthorized access to a system. Types and examples:

Type Description Real-world Example
Virus Attaches to clean files; spreads when executed. ILOVEYOU virus (2000): Cost $10 billion in damages by overwriting files.
Worm Self-replicating; spreads without user action. Morris Worm (1988): First major internet worm; disrupted 10% of internet-connected systems.
Trojan Horse Disguised as legitimate software. Emotet Trojan: Stole banking credentials from Nepal’s Global IME Bank customers.
Ransomware Encrypts data; demands payment for decryption. Colonial Pipeline (2021): Hackers demanded $4.4 million to unlock U.S. fuel supplies.
Spyware Secretly monitors user activity. FinFisher (Pegasus): Used to spy on journalists and activists in Nepal.

How ransomware works (worked example):

  1. Delivery: Attacker sends a malicious email (e.g., "Your eSewa transaction failed—click here to resolve").
  2. Execution: User clicks a link; ransomware downloads and encrypts files.
  3. Demand: Attacker locks files and demands Bitcoin payment (e.g., Rs. 500,000 for decryption key).
  4. Impact: Hospital in Pokhara (2023) paid Rs. 300,000 after ransomware locked patient records.

3. Phishing and Social Engineering

Definition: Tricking users into revealing sensitive information (passwords, credit card numbers). Types:

  • Email phishing: Fake emails from "Ncell" or "Khalti" asking for OTPs.
  • Spear phishing: Targeted attacks (e.g., a Daraz seller receiving a fake "order cancellation" email).
  • Vishing: Voice calls (e.g., "Your bank account is suspended—verify via call").
  • Smishing: SMS phishing (e.g., "Your eSewa wallet has won Rs. 50,000—click to claim").
2019First major eSewaphishing wave (Rs. 2002021Ncell SIM cardfraud surge (50% incre2023NTC DDoS attacksdisrupting services
Key cybercrime incidents in Nepal (2019–2023)

How to spot a phishing email:

flowchart TD
    A["Check Sender Email"] -->|"Mismatched domain?"| B["Yes: Phishing"]
    A -->|"Legitimate domain?"| C["Check for Urgency"]
    C -->|"Act now!" language?| D["Yes: Phishing"]
    C -->|"Normal tone?"| E["Check Links"]
    E -->|"Hovers to suspicious URL?"| F["Yes: Phishing"]
    E -->|"Legitimate URL?"| G["Verify Request"]
    G -->|"Unexpected request?"| H["Yes: Phishing"]
    G -->|"Expected request?"| I["Safe"]

Real-world example: In 2021, a phishing scam tricked 1,000 Nepali users into transferring Rs. 20 million to fake "Khalti customer support" accounts. The scammers used Google Voice numbers to mimic official calls.


4. Denial-of-Service (DoS) and Distributed DoS (DDoS)

Definition: Overwhelming a system with traffic to crash it. How it works:

  • DoS: Single attacker floods a server (e.g., crashing a Daraz website during Black Friday).
  • DDoS: Multiple compromised devices (botnet) attack simultaneously (e.g., Nepal’s NTC website down for 6 hours in 2022).

Motives:

  • Extortion (e.g., "Pay Rs. 1 million or we’ll keep crashing your site").
  • Activism (e.g., hacktivists targeting government sites).
  • Competition (e.g., rival businesses sabotaging each other).

5. Identity Theft and Fraud

Definition: Stealing personal information (name, SSN, bank details) to impersonate someone. Methods:

  • Dumpster diving: Stealing discarded documents (e.g., old bank statements).
  • Skimming: Stealing credit card data via infected ATMs (rare in Nepal but seen in India).
  • Synthetic identity fraud: Combining real and fake data to create a new identity.

Real-world example: In 2023, a gang in Kathmandu used stolen NID cards to open 150 fake bank accounts, withdrawing Rs. 80 million before being caught.


In the Real World

  1. eSewa and Khalti Scams

    • Problem: Fake apps and websites mimic eSewa/Khalti to steal login credentials.
    • How it uses this unit’s ideas:
      • Phishing: Users redirected to fake login pages.
      • Malware: Keyloggers record passwords.
      • Impact: Rs. 150 million lost in 2023 (Nepal Police report).
    • Worked example: A user receives an SMS: "Your eSewa wallet is locked. Click here to unlock." The link leads to a page identical to eSewa’s login. When entered, credentials are sent to the attacker, who transfers Rs. 50,000 from the victim’s account.
  2. Daraz and Online Marketplace Fraud

    • Problem: Fake sellers or buyers use stolen payment details.
    • How it uses this unit’s ideas:
      • Credential stuffing: Reusing passwords from other breaches.
      • Chargeback fraud: Buyers request refunds after receiving goods.
    • Worked example: A seller lists a brand-new iPhone for Rs. 30,000. A buyer pays via Khalti but claims the phone was damaged upon delivery. Daraz reverses the payment, and the seller loses Rs. 5,000 profit per fraud.
  3. Ncell and NTC Cyberattacks

    • Problem: Telecom companies are frequent targets for DDoS attacks and SIM swapping.
    • How it uses this unit’s ideas:
      • DDoS: Disrupting services during peak hours (e.g., Ncell network down for 4 hours in 2022).
      • SIM swapping: Hackers trick Ncell to transfer a number to their SIM, then bypass 2FA.
    • Worked example: A hacker SIM-swaps a banker’s number, resets the email password, and transfers Rs. 2 million to an offshore account before the bank detects the breach.

Nepal has laws to combat cybercrime, but enforcement is challenging due to limited digital forensics expertise and slow court proceedings.

Chapter 2: Offenses (Sections 5–14)Chapter 3: Penalties (Sections 15–22)Chapter 4: Investigation (Sections 23–28)Cyber Crime Act 2075
Structure of Nepal's Cyber Crime Act 2075
Law Year Key Provisions Limitations
Electronic Transactions Act 2008 Legal recognition of digital signatures; criminalizes fraudulent transactions. Weak penalties; no specific cybercrime unit.
Cyber Crime Act 2074 Criminalizes hacking, identity theft, and child pornography. Police lack training in digital evidence handling.
Penal Code (Amendment) 2018 Adds cybercrime to traditional theft/fraud laws. Corruption in reporting cases.

Comparison with Global Laws:

Country Key Law Maximum Penalty Unique Feature
Nepal Cyber Crime Act 2074 3–10 years imprisonment Focus on digital evidence collection.
USA Computer Fraud and Abuse Act $250K fine + 20 years jail Broad definition of "unauthorized access."
EU GDPR + NIS Directive €20M fine or 4% of revenue Strict data protection rules.
India IT Act 2000 (Amended 2008) 3–10 years jail Cyber Appellate Tribunal for appeals.

Impacts of Cybercrime

Cybercrime affects individuals, businesses, and governments. Below is a breakdown:

0125000000250000000375000000500000000Individuals (Rs.)250000Businesses (Rs.)50000000Governments (Rs.)500000000
Average financial loss from cybercrime in Nepal (2023 estimates)

How Cyber Threats Evolve

Cybercriminals constantly adapt using:

  1. AI and Machine Learning:

    • Deepfake scams: AI-generated voices mimic family members to trick victims into transfers.
    • Automated phishing: AI writes personalized emails (e.g., "Your Daraz order #12345 is delayed—click to track").
  2. Dark Web Marketplaces:

    • Hacking-as-a-Service (HaaS): Rent a DDoS botnet for $5/hour.
    • Stolen data sales: Nepali NID cards sell for Rs. 500 each on dark web forums.
  3. Supply Chain Attacks:

    • Example: Hackers breach a third-party vendor (e.g., a Daraz logistics partner) to access main systems.

Exam Tip

This unit is heavily tested in TU/PU exams with:

  1. Definitions and Examples (2–3 marks):

    • "Define ransomware and give a Nepali example." → Colonial Pipeline (global) + Pokhara hospital (Nepal).
    • "Differentiate between phishing and spear phishing." → Use the targeted vs. mass distinction.
  2. Case Study Analysis (5–7 marks):

    • "Analyze the eSewa 2022 breach: causes, impacts, and legal recourse."
      • Causes: Weak 2FA, phishing links.
      • Impacts: Rs. 200M loss, 50K users affected.
      • Legal recourse: Cyber Crime Act 2074 (Section 5 on unauthorized access).
  3. Comparison Tables (4–5 marks):

    • "Compare DoS and DDoS attacks." → Use the single vs. distributed source table above.
  4. Short-Answer Applications (3 marks):

    • "How would you prevent SIM swapping at Ncell?"
      • Solutions:
        1. Biometric verification (fingerprint + OTP).
        2. AI-based anomaly detection (flags unusual SIM changes).
        3. Customer education (warn about phishing calls).
  5. Ethical Dilemmas (4 marks):

    • "A hacker offers to sell you a zero-day exploit for Ncell’s system. Discuss the ethical and legal implications."
      • Ethical: Violates professional codes (e.g., ACM Code of Ethics).
      • Legal: Cyber Crime Act 2074 (Section 7 on aiding hacking).

Common Mistakes to Avoid:

  • Vague examples: Don’t say "hacking is bad"—name a real Nepali case (e.g., eSewa breach).
  • Ignoring legal frameworks: Always link cybercrimes to Electronic Transactions Act 2008 or Cyber Crime Act 2074.
  • Overlooking real-world impacts: Exams love financial loss figures (e.g., Rs. 200M in eSewa scams).

Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 5.

Discussion

Loading…