Cybercrimes and Data Breaches

Data breaches happen all the time. Some breaches are caused by the negligence of internal users, while other breaches are realized due to malicious activities and cybercrime. Some data breaches have dire repercussions. And unfortunately, jurisdiction by jurisdiction, the laws that determine which of these actions are criminal offenses and which are not can be confusing and contradictory. Q 0.

5 slides · 2 min read · Domain 1

Slide 1

For example, many sources define cybercrime as

an act that involves the use of information, information systems, or information technologies in ways that violate the laws that pertain to the system and the information in question.

A data breach that involves a server located in Russia, for example, which results in data that originated in the United States being exfiltrated to New Zealand might be a violation of laws in one, two, or three countries.

If the information pertains to people from other countries, the jurisdictional and definitional situation becomes even cloudier. We also must consider that many jurisdictions define data protection requirements in law and regulation in ways that may not explicitly label breaches of those protections as criminal acts. Nonetheless, real people and real businesses get hurt.

CASE STUDY

An example is the Ashley Madison website data breach in 2015. More than 30 million records were compromised, and data was exposed concerning married men and women who wanted to have extramarital affairs.

Users of the site relied on its promise of privacy and confidentiality, but the breach exposed their identities to the world. Unsurprisingly, this upset users and even resulted in suicides.

Every organization has a responsibility to its customers, employees, and other stakeholders to protect personal data. A data breach that includes employees' financial details, for example, can have a significant influence on the organization. It can lead to the headhunting of leaders, as well as personal distress for employees.

Crime organizations all over the world adapted to the internet era by hiring malicious actors and scammers to achieve their goals. In the past, to acquire financial gain, crime organizations kidnapped loved ones and held them for ransom.

Today they use ransomware, encrypting the organizations' data and demanding money to provide the decryption key. Running ransomware operations is considered by cybercrime organizations as their business, and they take it seriously. They target both individuals and organizations, and they know they must maintain a reputation as "trustworthy" criminals by returning the decryption key to those who pay and operate a legitimate support call center.

In the past few years, crime organizations have started taking extortion to the next level. Not only do they encrypt all the data, but they also first leak a copy and threaten to publish it if the organization does not pay. That way, even an organization that has full backup of its data is still prone to the attack since the organization will suffer if the data is disclosed.

Test this domain