Skip to content

Mass Victimisation and Cyber Victimology

Mass victimisation studies harm produced by a single cause, disaster, atrocity or breach, at large scale, while cyber victimology examines online harassment, fraud and image-based abuse as a distinct field.

By Reviewed by Sourabh

Last updated:

Mass victimisation is the production of large numbers of victims by a single cause, whether a disaster, a war crime or a coordinated online attack, and it forces victimology to study harm at a scale that ordinary interpersonal crime theory was never built for.

Cyber victimology is the study of the same discipline's core questions, who is harmed, how, and with what consequences, applied to victimisation that happens through networked computers rather than in a physical location. Both extensions share a common thread: classical victimology, built around a lone victim and a known offender, struggles to explain harm that is dispersed, anonymous or produced by a system failure.

Victimology as a field grew out of the work of Hans von Hentig and Benjamin Mendelsohn in the late 1940s, who first asked whether victims contribute to the dynamics of the crimes committed against them. That early focus on the victim-offender dyad assumed one victim and one perpetrator. Mass casualty events and networked digital harm both break that assumption, and each has produced its own specialist literature, institutions and response systems that this topic surveys in turn.

The two extensions are not identical. Mass victimisation research grew out of disaster studies and international criminal law. Cyber victimology grew out of the internet era. What unites them for the study of victimology is that both force the field to rethink the ideal-victim model that Norwegian criminologist Nils Christie described in 1986, a weak, blameless victim harmed by a clearly identifiable stranger, because mass and cyber victims often fit neither the stereotype nor the support systems built around it.

By the end of this topic you should be able to do the following.

  • Distinguish mass victimisation from ordinary interpersonal crime victimisation by scale, cause and the type of institutional response it triggers.
  • Identify the main sources of mass victimisation and the specialised response mechanisms built around each.
  • Explain why cyber victimology treats online harm as analytically distinct from its physical-world equivalent.
  • Classify the main categories of cyber victimisation and describe the harm each produces.
  • Account for why cyber victims face distinct patterns of secondary victimisation and underreporting.
Key terms
Mass victimisation
Harm produced simultaneously in a large number of people by a single cause, such as a disaster, an act of war or a coordinated attack, rather than by discrete one-on-one criminal acts.
Disaster victimology
The branch of victimology concerned with identifying, supporting and compensating people harmed by natural, industrial or transport disasters.
Cyber victimology
The study of victimisation that occurs through networked computers and digital platforms, including its distinct causes and consequences.
Cyberstalking
A persistent pattern of unwanted online contact, monitoring or threats directed at a specific person, carried out through email, social media, messaging apps or tracking technology.
Image-based sexual abuse
The non-consensual creation, taking or distribution of intimate images, a term proposed in the 2010s to replace the misleading label revenge pornography.
Secondary victimisation
Additional harm caused not by the original offender but by the response of institutions, such as a platform, a police force or the media, to a victim's report of the original harm.

Defining mass victimisation

Ordinary interpersonal victimisation, the kind that dominates classical victimology, assumes a single victim, a single offender, and harm that arises from a discrete act with a beginning and an end. Mass victimisation breaks each part of that assumption. It refers to harm produced simultaneously in large numbers of people by one cause: an earthquake, a factory explosion, an act of terrorism, a genocide, or, as later sections will show, a data breach affecting millions of accounts at once.

The scale is the first distinguishing feature, but scale alone does not define the category. A pattern of similar but independent burglaries across a city produces many victims without being mass victimisation, because each act is separate and typically has its own offender and its own causal chain.

The second distinguishing feature is cause. Mass victimisation research groups its subject matter by the type of event that generates the harm rather than by the type of harm itself, because the type of event determines what kind of response is needed. A natural disaster calls for search, identification and shelter.

A genocide calls for criminal prosecution, truth-telling and reparation. This event-first framing is why disaster victimology, war crimes victimology and terrorism victimology, though they study very different events, share methods and often the same specialist agencies, since identifying the dead and administering compensation are common tasks across all three.

A third feature is that mass victimisation typically overwhelms ordinary criminal justice and welfare institutions, which are built to process cases one at a time. A single mass-casualty event can generate more claims, more bodies to identify and more media attention in a week than an ordinary police force handles in a year.

This is why mass victimisation almost always produces a bespoke, temporary institution rather than being absorbed into existing case processing: a compensation fund, a commission of inquiry, or an international tribunal, each purpose-built for the scale of the event rather than borrowed from routine practice.

Finally, mass victimisation raises distinct questions about attribution of responsibility that ordinary crime victimology rarely has to confront. Where a natural disaster has no human offender at all, liability questions shift to negligence, building codes or emergency planning.

Where the cause is a deliberate atrocity, responsibility can be distributed across a state, an organisation and named individuals, which is why international criminal law, rather than domestic criminal procedure, has become the primary legal vocabulary for the most severe cases. Insurance law and administrative law therefore do much of the analytical work that ordinary criminal procedure does in ordinary cases, since most survivors need a fund or agency to process their claim, not a prosecution.

Sources of mass victimisation

Natural disasters, earthquakes, floods, cyclones and pandemics, are the most common source of mass victimisation and the one furthest removed from criminal intent. Even here victimology has a role, because the scale and distribution of harm from a nominally natural event is shaped by human decisions: where housing was permitted, how early a warning was issued, and how relief was distributed. Industrial and transport disasters sit closer to the criminal justice system, since they frequently involve negligence or regulatory failure.

The 1984 gas leak at a pesticide plant in Bhopal, India, remains one of the most studied industrial mass-victimisation events worldwide precisely because it combined mass death and injury with a protracted and heavily contested compensation and liability process. Transport disasters, a capsized ferry or a derailed train, sit in the same category, since investigators examine maintenance and regulatory compliance alongside the immediate cause.

Terrorism produces mass victimisation through deliberate, ideologically motivated attacks designed to maximise casualties and public fear in a single incident or coordinated series of incidents. Its victims are usually unconnected to the perpetrator's stated grievance, chosen for location rather than any individual trait, which is why terrorism victims are often treated as a distinct category with dedicated compensation schemes, such as the fund created in the United States after the attacks of 11 September 2001.

War crimes and genocide represent the most severe end of the spectrum, and international law has developed a specific vocabulary for them. Genocide, defined in the 1948 Convention on the Prevention and Punishment of the Crime of Genocide as acts committed with intent to destroy a national, ethnical, racial or religious group in whole or in part, is distinguished from other mass atrocities by that specific intent requirement.

Crimes against humanity and war crimes, codified more fully in the 1998 Rome Statute that established the International Criminal Court, cover widespread or systematic attacks on civilian populations that may not meet genocide's intent threshold but still produce mass victimisation on a comparable scale.

These categories are not always cleanly separable in practice. A single conflict can generate victims of direct violence, of forced displacement, of destroyed livelihoods and of long-term psychological harm, all at once, and the same population can be victimised by more than one source simultaneously, for instance where an earthquake strikes an area already displaced by conflict.

Victimology's contribution is to insist that response planning treat the resulting needs as an overlapping set of problems rather than a single uniform harm. Sources of mass victimisation are therefore studied together with their slower-moving downstream harms, not just the initial death toll.

Responding to mass-victim events

Mass-victim events require response mechanisms that ordinary criminal justice and welfare systems do not routinely maintain. The first is forensic and logistical: identifying the dead. Disaster Victim Identification, the structured process coordinated internationally through bodies such as Interpol, matches recovered remains against dental records, DNA and personal effects, and its procedures are largely the same whether the deaths result from a natural disaster, a transport accident or a mass atrocity.

Reliable identification is a precondition for almost everything that follows, since death certificates, inheritance, compensation claims and closure for families all depend on it. Where the dead cannot be identified at all, families are left in a prolonged and psychologically difficult state that researchers term ambiguous loss, unable to complete mourning or to access the legal and financial entitlements that normally follow a confirmed death.

The second mechanism is compensation. Because mass-victim events generate claims far beyond what tort litigation against an individual offender can realistically resolve, many jurisdictions create dedicated compensation funds rather than relying on courts case by case.

These funds trade some of the adversarial rigour of a lawsuit for speed and consistency, distributing payments according to a schedule rather than requiring each claimant to prove causation and quantum individually. The tradeoff is deliberate: mass victimisation would otherwise leave most victims waiting years for a resolution that ordinary civil procedure was never designed to deliver at that volume.

The third mechanism, used mainly for atrocity and conflict victimisation, is the truth commission. Bodies such as South Africa's Truth and Reconciliation Commission, established in 1995 under the Promotion of National Unity and Reconciliation Act, aimed to document what happened, name responsibility and, in some cases, offer conditional amnesty in exchange for full disclosure.

Truth commissions differ from criminal trials in that their central output is an authoritative public record rather than a set of convictions, a design suited to situations where the scale of implication across a society makes individual prosecution of every perpetrator impractical.

Finally, mass victimisation typically generates collective memorialisation: memorials, annual commemorations and museums that convert individual loss into shared public memory. Victimologists study memorialisation because it performs a recognised function of victim support, acknowledgement, even where it offers no direct compensation, and because contested memorials can themselves become a site of ongoing conflict over whose victimhood is recognised and whose is not.

Decisions about which events receive a permanent memorial and which are allowed to fade from public memory are rarely neutral, and they often track the same inequalities of power and voice that shaped who was harmed by the original event in the first place.

Cyber victimology as a distinct sub-field

Cyber victimology asks the same questions classical victimology asks, who is harmed, by whom, how often and with what consequences, but applies them to harm that occurs through networked computers and digital platforms. The sub-field grew alongside criminology's broader turn toward cybercrime from the 1990s onward, and scholars such as K. Jaishankar, who proposed the term cyber criminology in 2007, argued that online offending needed its own theoretical vocabulary rather than a straightforward transplant of physical-world crime theory.

The core reason online harm resists a direct mapping onto physical-world concepts is that several of victimology's foundational assumptions do not hold online. Physical proximity between victim and offender, central to routine activity theory's motivated offender, suitable target and absence of a capable guardian, is not required for most cyber offences, since an offender on another continent can victimise a target with no shared physical space at all.

The crime scene, a fixed location that anchors physical evidence collection, has no clean equivalent when the relevant conduct occurred across servers in several jurisdictions. And the boundary between a single offence and a continuing one blurs online, since a harassing message or a leaked image does not end when it is first sent, it persists and can be re-shared indefinitely.

Even the ordinary language of victimology strains under this shift, since asking who was present at the scene of the crime presumes a scene in the first place.

A further complication is that cyber victimisation frequently has no single identifiable offender at all, as in a mass data breach caused by a security failure, or has an offender population so large and anonymous that individual attribution is effectively impossible, as in a pile-on harassment campaign involving thousands of separate accounts.

Classical victimology's offender-focused questions, about victim precipitation or victim-offender relationship, have limited purchase in these scenarios, which is part of why cyber victimology has developed its own typologies rather than simply extending existing ones.

Jurisdiction compounds the problem. A victim, an offender and the platform hosting the harmful content can each sit in a different country, each with different criminal law, different evidentiary rules and different willingness to cooperate with a foreign investigation.

This is one reason international instruments such as the Council of Europe's 2001 Budapest Convention on Cybercrime, which sets common standards for defining offences and for cross-border evidence requests, matter more in cyber victimology than in most areas of domestic criminal victimisation. Domestic law still matters, but works best paired with treaty-based cooperation, since a conviction under one country's statute means little if the offender and the server both sit beyond its reach.

Categories of cyber victimisation

Cyber victimisation is not one phenomenon but a cluster of distinct harms with different offender profiles and different victim experiences. Financial cyber fraud, phishing, business email compromise, romance scams and identity theft, is the most reported category and the one most often perpetrated by strangers operating at scale, frequently through organised networks rather than lone offenders.

Its harm is primarily material, though victims commonly also report shame and self-blame that discourage reporting, an emotional pattern more often associated with interpersonal crime than with theft. Because the offender is rarely known to the victim, financial cyber fraud is analytically closer to conventional property crime than to the interpersonal categories discussed next, even though it happens entirely online.

Harassment and cyberstalking form a second category, and unlike financial fraud they are frequently perpetrated by someone known to the victim, an ex-partner, a former colleague or an acquaintance, which mirrors the offender profile of physical-world stalking and domestic abuse more than it resembles anonymous cybercrime.

Cyberstalking uses persistent unwanted contact, monitoring software, location tracking or coordinated harassment by multiple accounts to instil fear, and its cross-platform nature makes it harder for a victim to escape than physical stalking confined to a single location.

Image-based sexual abuse is a third category: the non-consensual creation, taking or distribution of intimate images. Legal scholars Clare McGlynn and Erika Rackley proposed this label in 2017 to replace the earlier term revenge pornography, arguing that revenge implies a wronged party retaliating and pornography implies deliberate self-exposure, when in fact many cases involve images obtained by hacking, coercion or covert filming with no revenge motive and no consent to distribution at all.

The category also includes threats to distribute such images, sometimes called sextortion, which can cause serious harm even where no image is ever actually released, since the threat alone can be enough to coerce a victim.

Reputational harm, defamatory posts, doxxing and coordinated harassment campaigns, forms a fourth category whose defining feature is that the damage compounds through repetition and search-engine visibility rather than through a single act. A defamatory post shared once has limited reach; the same content indexed and repeatedly resurfaced can damage a victim's employment prospects and social standing for years, which is why remedies in this category increasingly focus on removal and de-indexing rather than compensation alone.

Because search engines index content indefinitely, a single false or humiliating post can outlast the platform it was originally posted on, resurfacing in searches long after the account that posted it has been deleted or suspended.

Offender: usually a strangerOffender: usually known to victimFinancial cyber fraudReputational harmImage-based sexualabuseHarassment andcyberstalkingStrangers, organisednetworks, at scaleAnonymous accounts,compounds via searchindexingHacking, coercion, or aknown ex-partnerUsually someone thevictim already knows
Four categories of cyber victimisation positioned along a spectrum from anonymous stranger offenders to offenders already known to the victim, showing why financial fraud and cyberstalking sit at opposite ends despite both occurring online.

Secondary victimisation, underreporting and mass cyber events

Cyber victims face a distinctive pattern of secondary victimisation, harm added by an institution's response rather than by the original offender. Platform inaction is the most commonly cited form: a victim reports harassing content or an intimate image and the platform is slow to remove it, applies an inconsistent standard, or requires the victim to relive the harm by describing it in detail to a support form with no clear escalation path.

Police response adds a second layer where officers are unfamiliar with digital evidence and misclassify a cyberstalking pattern as a series of unrelated minor incidents.

Jurisdictional confusion compounds this: a victim, an offender and a platform in three different countries create genuine uncertainty over which police force, court or law applies, and victims are often redirected between agencies before any accepts responsibility.

Persistence is the final distinctive feature of cyber secondary victimisation: unlike a physical crime scene that can be cleaned and a stolen item that can be replaced, harmful content that has been copied or archived elsewhere can resurface years later, meaning the harm has no reliable endpoint even after an initial report is resolved.

These features feed directly into underreporting, which has its own shape online. Some victims do not report because they blame themselves, a pattern well documented in financial fraud. Others do not report because they doubt that anything will be done, a rational response given documented platform and police inconsistency.

Others do not recognise a pattern of online conduct as reportable at all, since a single instance can seem trivial even where the cumulative pattern is serious. Official statistics in this area, discussed further in official crime statistics, capture only reported cases, so the dark figure in cyber victimisation is widely judged to be larger than in most conventional offence categories.

Mass victimisation and cyber victimology finally intersect directly in the large-scale data breach, an event in which a single security failure exposes personal data belonging to a very large number of people at once.

A breach shares mass victimisation's core structural feature, one cause producing simultaneous harm to a large population, but its response mechanisms echo the disaster model discussed earlier rather than an ordinary cybercrime case: mandatory notification requirements, such as the 72-hour reporting duty to a supervisory authority under Article 33 of the European Union's General Data Protection Regulation and credit monitoring, with class remedies where litigation follows.

The 2017 breach at the American credit reporting company Equifax, which exposed the personal data of a very large share of the adult population of the United States and led to a coordinated regulatory settlement, is frequently used to illustrate how a single cybersecurity failure can produce victimisation at a scale that only mass-event response frameworks, not routine cybercrime casework, can realistically manage.

Check your understanding
Question 1 of 4ยท 0 answered

What primarily distinguishes mass victimisation from a series of similar but unrelated interpersonal crimes?

Key Takeaways

  • Mass victimisation is defined by a single cause producing simultaneous harm to a large population, which requires purpose-built response mechanisms.
  • Sources of mass victimisation include natural disasters, industrial and transport accidents, terrorism, and war crimes and genocide, each triggering related but distinct response systems.
  • Mass-victim response includes forensic identification of the dead, compensation funds, truth commissions and memorialisation.
  • Cyber victimology treats online harm as analytically distinct because physical proximity, a fixed crime scene and a single identifiable offender are frequently absent online.
  • Cyber victimisation spans financial fraud, harassment and cyberstalking, image-based sexual abuse and reputational harm, each with a different typical offender profile.
  • Cyber victims face distinct secondary victimisation from platform inaction, jurisdictional confusion and the persistence of harmful content, which also drives a wide dark figure through underreporting.
  • A large-scale data breach sits at the intersection of both fields, a single cause producing mass harm whose response borrows disaster-style mechanisms such as mandatory notification and scheduled compensation.
Is mass victimisation the same thing as a high crime rate in an area?
No. A high crime rate reflects many separate offences over time. Mass victimisation refers to one cause producing harm to a large number of people simultaneously, such as a single disaster, atrocity or security failure, which is why it needs a different kind of institutional response.
Does cyber victimology replace routine victimology concepts entirely?
No. It adapts and extends them. Concepts such as the ideal victim and secondary victimisation still apply online, but assumptions built around physical proximity, a fixed crime scene and a single offender often do not transfer cleanly, which is why cyber victimology developed its own typologies.
Why are cyberstalking and financial cyber fraud grouped separately even though both happen online?
They differ in offender profile and victim experience. Cyberstalking is frequently perpetrated by someone the victim already knows, resembling physical-world stalking, while financial cyber fraud is typically perpetrated by anonymous strangers operating at scale, resembling organised theft.
What makes a data breach a mass-victimisation event rather than an ordinary cybercrime?
Scale and cause. A breach exposes many people's data through one security failure at once, so its response mirrors disaster-style mass-event handling rather than case-by-case cybercrime investigation.
Why do cyber victims underreport more than victims of many conventional offences?
Several factors compound: self-blame, especially in fraud cases, low confidence that platforms or police will act, jurisdictional confusion when offenders and platforms sit in different countries, and difficulty recognising a cumulative pattern of low-level conduct as a reportable offence.

Test yourself on Criminology with free, timed mocks.

Practice Criminology questions

Found this useful? Pass it along.

Share

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.