📚 What Is Cybercrime, Really?
I remember the first time someone tried to scam my gran. She got a phone call from “Microsoft” saying her computer was infected. She didn’t even own a computer. That, right there, is a tiny sliver of cybercrime — and it’s far more ordinary and crafty than most people think. Forget the hooded hacker in a dark room; cybercrime is often a phone call, a dodgy email, or a fake website that looks more legitimate than the real one. It’s crime, just moved online.

Cybercrime covers any illegal activity that involves a computer, a network, or a digital device. Sometimes the computer is the target (like hacking a server), and sometimes it’s the tool (like sending phishing emails to steal money). What makes it uniquely tricky is scale and anonymity — a single person in one country can rob thousands of victims worldwide before breakfast.
Let’s unpack this properly, not as a dusty textbook definition, but as something that affects how we live, work, and trust technology.
💻 The Two Big Buckets of Cybercrime
I find it helpful to split cybercrime into two categories. It stops the subject from feeling like an overwhelming soup of scary terms.
1. Cyber-Dependent Crime
These are offences that can only exist using computers and networks. Turn off the internet, and the crime disappears.
- 🔹 Hacking into systems without permission
- 🔹 Writing and distributing malware (viruses, ransomware, worms)
- 🔹 Denial-of-service attacks that flood a website until it crashes
- 🔹 Taking control of a device remotely (botnets)
2. Cyber-Enabled Crime
Traditional crimes, but scaled up or modified using digital tools. The internet acts as a force multiplier.
- 🔹 Fraud — fake online shops, investment scams, romance scams
- 🔹 Theft — stealing banking credentials, identity theft
- 🔹 Harassment and stalking online
- 🔹 Selling illegal goods on the dark web (drugs, weapons, stolen data)
This split isn’t just academic. It shapes how laws are written and how police forces train their officers. A fraud investigator might handle a phishing scam, while a digital forensics expert tackles ransomware.
🕵️ Who’s Doing It, and Why?
Criminals aren’t all the same, and motivations are rarely just “being evil.” I’ve seen three broad flavours in real-world cases:
- Financially motivated — The overwhelming majority. They want money, pure and simple. Ransomware gangs, BEC (business email compromise) scammers, carders who sell stolen credit card details.
- Ideological or political — Hacktivists deface websites to spread a message, or nation-state groups steal intellectual property and interfere with elections.
- Personal or emotional — A disgruntled ex-employee sabotages systems. A stalker uses spyware to track a partner. The damage can be devastating and intimate.
Understanding the why helps you spot patterns. It also reminds you that most cybercriminals are opportunistic businesspeople, not supervillains.
📬 Common Types You’ll Actually Encounter
You’ve probably brushed up against a few of these already. Recognising them cuts your risk dramatically.
- Phishing — Emails, texts, or DMs that impersonate trusted sources to trick you into handing over passwords or card numbers. Modern versions are frighteningly personalised (spear-phishing).
- Ransomware — Malicious software that encrypts your files and demands payment. Hospitals, schools, and businesses are favourite targets because they’re more likely to pay to restore critical data.
- Business Email Compromise (BEC) — Someone pretends to be the CEO and asks finance to wire money urgently. No malware required, just social engineering and a convincing email.
- Identity Theft — Using stolen personal data to open bank accounts, apply for credit, or claim benefits in your name. It can take years to sort out the mess.
- Cyber-Enabled Sexual Offences — Sharing intimate images without consent, online grooming, sextortion. Hugely underreported and deeply harmful.
🌍 Real-World Example — The Scattered Canary Group
Let me share a case that shows how ordinary this can feel. A West African crime group (often called Scattered Canary) ran BEC scams for years. They’d research a company’s structure on LinkedIn, then send an email from a spoofed domain that looked like the real boss. A typical email: “Hi Sarah, I need a wire transfer processed today — client emergency, I’m in meetings, can’t call. Confirm amount and I’ll send details.”
No flashy tech. Just patience, confidence, and a free email account. One small business lost over £200,000. The money moved through multiple countries within hours. This shows how social engineering often beats even the best firewall.
⚖️ Why It’s So Hard to Stop
A few honest reasons that keep cybersecurity professionals up at night:
- Jurisdictional nightmares — Victim in Manchester, server in the Netherlands, attacker in Lagos, money laundered through cryptocurrency wallets in three other countries. Which police force takes the lead?
- Underreporting — Companies fear reputational damage. Individuals feel ashamed. The true numbers are far higher than any official statistics.
- Anonymity tools — VPNs, Tor, and cryptocurrencies make attribution a slow, painstaking puzzle.
- Human factor — We’re the weakest link. You can patch a server, but you can’t patch a tired employee who clicks a link without thinking.
🎯 Key Points
- Cybercrime is any criminal activity involving a computer or network — either as the target or the tool.
- It splits into cyber-dependent (impossible offline) and cyber-enabled (traditional crime amplified online).
- Financially motivated attacks like phishing and ransomware are the most common.
- Social engineering exploits human trust more often than technical weakness.
- Jurisdiction and anonymity make law enforcement exceptionally complex.
- Recognising common tactics is your first and best defence.
❓ Knowledge Check
Test yourself on the core ideas — not the real-world example, just the definition and types.
