Cybercrime
Definition
Offences where a computer network is the tool or the target. Tool-based cybercrime includes fraud, harassment, and intellectual property theft conducted online. Target-based cybercrime includes hacking, ransomware attacks, and denial-of-service attacks directed at computer systems. The Budapest Convention (2001) defines the main categories in international law.
- Categories
- Tool-based (crime committed via computer) and target-based (crime against a computer)
- Tool-based examples
- Online fraud, harassment, IP theft
- Target-based examples
- Hacking, ransomware, denial-of-service
- International instrument
- Budapest Convention, 2001
Common questions
Why does the tool-based versus target-based distinction matter for classifying an offence?+
The distinction shapes which laws apply and how evidence is gathered, since a tool-based crime like online fraud is fundamentally the traditional offence of fraud carried out through a digital medium, while a target-based crime like hacking specifically criminalises unauthorised interference with a computer system regardless of what the attacker did once inside.
What is the significance of the Budapest Convention for cross-border cybercrime cases?+
It is the first international treaty to harmonise cybercrime definitions and set standards for cross-border cooperation and evidence sharing among signatory states, which matters because cybercrime investigations routinely need evidence held in a different country from where the offence was reported.
Can a single incident count as both tool-based and target-based cybercrime?+
Yes, a ransomware attack is target-based because it involves unauthorised access to and interference with a computer system, but the subsequent extortion demand is tool-based, using the compromised computer as the instrument of a traditional extortion offence, so the same incident can be charged under both categories.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Corporate Crime
- Illegal acts committed by or on behalf of a corporate organisation for the organisation's benefit. Distinct from occupational crime because the wrongdoing...
- Cyber Forensics
- The branch of forensic science concerned with collecting, preserving, and analysing digital evidence from networked environments for use in legal proceedings. Covers...
- Digital Forensics
- The discipline concerned with the recovery, preservation, and analysis of evidence stored on physical digital devices. Primary evidence sources are disk images,...
- Enterprise Theory
- A theoretical framework that analyses organised crime as a rational business enterprise responding to market conditions. Associated with criminologist Dwight Smith, who...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Network Flow Record (NetFlow)
- A summarised record of a network conversation: source IP, destination IP, ports, protocol, byte count, and duration. Flow records do not contain...
- Neutralisation Techniques
- The vocabulary of justifications identified by Sykes and Matza (1957) by which offenders deny the wrongfulness of their acts: denial of injury,...
- Organised Crime
- A structured group of three or more persons that operates continuously, with the aim of committing serious offences for material benefit, and...
- White-Collar Crime
- Crime committed by a person of respectability and high social status in the course of their occupation (Sutherland, 1939). The category covers...
Explained in these topics
- Cyber Forensics vs Digital Forensics: Scope and BoundariesCriminal offences in which a computer or network is either the instrument (used to commit the offence) or the target (attacked by the offence). Examples includ...
- Organised, White-Collar, Corporate, and Cybercrime