1 / 26100%
ACCT 660 – INFORMATION TECHNOLOGY AND FRAUD
Introduction
IT can be define as the ability to manage the computer system, installation and
equipment, data storage structures and facilities, and any type of business process, activity or
method linked with the input, manipulation, storage, security and transit of all types of electronic
data. From the micro managing the major points of various fields of industry to macro level
where it involves the connection between two or more countries/regions and from the
transformation to the agent of change IT has come a long way. But this has been made possible
through Information Technology new types of frauds notes and techniques that have developed
have become very hard shocking to handle since they are practiced on individuals organizations
and even the government.
Fraud can be, in its basic sense, a plan that one wants to provide a fake image to gain
some sort of gain, monetary or otherwise. That way, when connected to IT, fraud is in an
altogether different, more complicated manner relying on the digital environment and
technology. The problem of fraud in the sphere of IT cannot be actually dismissed as this is a
potentially dangerous phenomenon, which may led to significant companies’ overdraws, trust
losses, and even socio-political conflicts.
Historical Context of IT and Fraud
Early Instances of IT-Related Fraud
With the advancement of Information Technology, that too is related with fraud ever since the
advent of computing. This paper presents that there is ample documentation of the computer
related fraud since the early 1960s. For instance, the well-known “penny shaving” practice was
used by malefactors infecting computers to steal minute quantities of money - a mere penny or a
less amount. These amounts were usually insignificant to be distinguished but, when the yearend
was approaching, the consideration value of all the petty change would add up the staggering
figures.
Another important and also rather typical early scandal was the so-called ‘salami slicing’
fraud, which also occurred in the period of the 1960s and 1970s. This method entailed shaving
small portions of money in many transactions a bit like shaving of thin slices of a salami. Such
methods are examples of how early criminals in cyberspace were innovative with computing
deficiencies for the purpose of committing a crime.
Evolution of Technology and Corresponding Evolution of Fraud Techniques
The advancement in technology and the subsequent advancement of fraud methodologies
Increase in Advanced IT Solutions and the corresponding sophistication of Fraud Schemes
Predominant IT frauds on rise as technology enhanced and new inventions were made in the way
of conduction of IT related frauds. The relative arrival of the internet within the last quarter of
the 20th Century offered a new method of communication and moneymaking; however it also
introduced new ways of embezzlement. The revelations of e-commerce during the early 1990s
also came with its darker elements including credit card fraud and identity theft. These acted as a
basis for encouraging criminals to work across the globe, which was likely to make it even hard
to capture them and prosecute them.
Phishing became a common attack in the 2000s, the process where the perpetrators
deceived users into giving out data under the disguise of e-mail and fake websites. Phishing also
has subcategories that are far more personal than the general ones; these are the spear phishing
and whaling, which are personalized to very senior people in organizations.
In the modern world with sophisticated technological applications of artificial
intelligence and, in particular, machine learning, both fraud prevention and fraudsters use them
simultaneously. Today, malware authors employ a great number of scripts and algorithms to
automate the process of penetration, while on the other hand security professionals apply the
same techniques to estimate such risks and neutralize them.
Types of IT-Related Fraud
Phishing and Spear Phishing
Phishing and spear phishing are different types of cyber fraud that target human beings by mail
or messages of some kind
Phishing is a method which uses the mass mailing of emails or messages that upon
opening, the contents of which appear to be from genuine sources like a bank, social network
account or even institutions. These can be better understood as phony e-mails or web pages
whose main purpose is to make the recipient disclose secret data such as passwords or credit card
and social security numbers. As a rule, the phishing messages are designed to create an
impression of urgency or even threat, stating that the account has been breached or stating that
the recipient has to act and react immediately, otherwise certain consequences will occur. These
messages usually lead to other websites that are imitation sites, hard for the user to determine
genuine site and fake sites.
Phishing often requires users to reveal certain information in order to use a particular site
They bear slight resemblance to each other, and the second type of fraud is somewhat more
complex that the first one, yet it’s called spear phishing. While regular phishing attacks use a
very broad approach to try spear phishing attacks are more explicit and only target chosen
individuals or organizations by using information about these targets. A much elaborate process
of data collection is employed by the attackers where they get as much data as they can from
social accounts, organization website and other available resources. This information is then used
to write genuine look alike emails that are composed on behalf of fromfriendly co workers,
businessassociates, or even executives. Often it will be personalized to the recipient, even use his
or her name and certain details unique to the person that would make it appear like a genuine
message.
Some of the techniques used in phishing and spear phishing include the following; Email
spoofing this involves altering the sender’s address to look like that of a genuine sender, link
manipulation this involves using incorrect links in emails that will redirect the user to a
counterfeit site. However, there is website spoofing that involves the development of other looks
that are copies of the original ones; attackers and such malware that is delivered through emails
containing fake i’s that make install the software on the victim’s computer an example of
malware distribution.
Phishing is dangerous in the way it leads to substantial financial losses and identity thefts,
and leakage of business information in spear-phishing attacks. This is a more complex kind of
Phishing because the consequences are usually the production of a lot of damage in terms of
company information loss, cash losses and damaging the image of the organization . Exploiting
these threats is possible to develop an ideal and generalized training and awareness programs
where by people will be in able to distinguish an attacking phishing attempt. On the same note,
simply developed email filtering tools can also attain intelligence and expunge all forms of
phishing emails before reaching the intended users. Visits to the site also become protected
through such issues like strong passwords, pin codes, or web keys, and it seems that most bad
actors cannot penetrate the accounts, despite possessing the username/passwords. Further,
development of the incident response plans and amendments on the periodic basis is also a good
technique, which will prepared the organization to give a quick response when it undergoes the
phishing attack.
Identity Theft
Identity theft is a situation where a person’s identity including social, security numbers,
bank accounts, identity cards or any other numbers and documents belonging to the person is
used in other illicit activities by the third party without the willing consent of the owner. the use
of personal information without the owner’s consent can lead to severe financial damages and
emotional suffering of the people concerned. Financial identity theft involves the use of an
individual’s personal information for economic gain while medical identity theft and criminal
identity, the former involves the use of an individual’s personal information in a medical context
and the latter involves the use of an individual’s credit details in criminal activities respectively.
Financial theft is the most frequent type of identity theft. It entails the usage of your
details to get into your money accounts and or open more accounts with your information. This
may include cases of credit card fraud, misuse of credit, and unauthorized access to personal
loans and bank accounts. Sometimes, a victim does not know the extent to which the identity
thief used their information until the notices of unpaid bills arrive or see that their credit scores
have lowered substantially.
Medical identity theft is a situation where a person uses another individual’s identity to
get medical treatment, prescription medication, and even health captivating benefits. Such acts of
deception can result in wrong information being recorded in the patient’s record, which in turn,
will impact on the further treatment of the affected individual. Also, health care consumers may
find themselves paying hefty amounts of money to doctors for services that never had any
delivery and complex health insurance issues.
Criminal identity theft is distinguished such as when a person is arrested and the
perpetrator uses that person’s identification information. The imposter hands the law
enforcement with wrong details about the victim including but not limited to the criminal
records. This may lead to a mistrial or the courts being brought against the victim or people
being taken as attempts to clear an ascribed stain.
The above explained effects of identity theft does not only demand for other extreme
financial losses, but entails virtually all other areas that are in the life of the survivors. For the
following days or perhaps hours after becoming a part of an occurrence, a person undergoes
tremendous and at times psychological torture. Preventing identity theft, therefore, may be a
slow and complicated undertaking of contacting the institutions which one had held transactions
with, the credit referencing companies and police to make amends on the fabricated identity and
fake credit reports. Although one can decide to take a much more cautious approach and try to
observe some measures which could help one avoid getting his/her identity stolen. Fraud is
suspected if one start to realize that something is wrong with statement, credit report, or even
with the health policy gotten from insurers. Some of the ways in which individuals can
minimize the likelihood of becoming victims of identity theft include: entering many accounts,
choosing secure and distinctive passwords, using the multiple factor authentication features, and
also using privacy features to prevent revealing of personal information in public domains.
Finally, any documents containing one’s juicy information that should not be seen by any other
person other than the owner/of that identity, if not wanted by other people, then it should be
shredded into pieces then chucked out, and whenever on email/receiving messages/receiving
calls, make sure ‘the phishers’ do not phish the identity.
Credit Card Fraud
Credit card fraud entails making unauthorized charges on a credit card or any other form
of utilisation of the card details to perform any commercial activity that includes making
purchases as well as withdrawing cash, among others. Fraudsters who seek to access credit card
information and utilize them engage in several procedures, including electromechanical that
involves skimming of the cards, and others that utilize the world wide web.
Thieves attach devices called skimmers to an ATM, a gas station pump, or POS
terminals. It reads the magnetic stripe data from a credit card each time it is passed over the
device, as well as the PIN if a pad overlay has been installed. Since skimmers are very stealthy,
this can be quite useful, Their ambusher strategy makes it even more so. Some of the things that
can be done with the data stolen includes making of fake credit cards or using the credit card data
to make further purchases online without the actual physical card.
Another common type of remote payment fraud is the CNP fraud, which is especially
popular since people are increasingly ordering goods online. Another high risk involves
penetration performed by fraudsters who engage in the following activities to obtain the credit
card details from the internet commerce. Another technique used is the Phishing attacks which is
a creation of Web sites that resemble the actual Web site of genuine e-commerce site where
while carrying out a transaction with the authentic e- commerce site the customer is diverted to
the fake Web site and thus enters his credit card details into the fake Web site. The second type
of attack is through technical weakness, whereby the attacker seeks to penetrate into the e
commerce sites, then get to the databases holding credit card details. For some time now identity
theft is no longer a small matter or a joke as hackers recently stole millions of credit card data of
several famous online shopping websites by getting into the corporate headquarters data base.
Also, the cybercriminals use ‘carding’ which I describe as they transact with a small amount to
test whether the accomplishing stolen credit card details are active and charge big amounts with
large consequences. Them it is also possible that the highly skilled hackers may use virus to
acquire the credit card numbers that one enters in a malicious website or even using other
gadgets such as manipulating people to reveal their credibility details such as the credit card
details.
Being aware to avoid credit card fraud is extremely important along with making an
effort to make it hard or almost impossible to occur. Based on the aspects discussed above,
cardholders are advised to check their statements frequently for any transactions that they did not
authorize and take the necessary action as explained below. It is believed that credit cards with
EMV chip technology are safer than those possessing a standard stripe, it means, for instance,
that the rate of skimming of credit cards is lower when using chip cards. Further, this implies that
the setting of transaction alerts enables real-time notifications of such transactions which are
believe to be fraudulent.
In online purchases, some ways that can be adopted to avoid such incidence include,
using secure forms of payment as well as transacting with authorised and genuine online outlets.
Specifically, always using sound familiar passwords on various accounts, refraining from the
usage of public Wi-Fi networks when undertaking some financial transactions, and especially
using the virtual credit cards or the popular PayPal can also increase security. The use of
elaborate anti-fraud measures in banking and other financial organizations have yielded
numerous tools for detecting fraudulent transactions by assessing the patterns of usual
transactions.
Cyber Attacks
Many organizations today face cyber threats such as ransomware, and malware among
others. The first type is ransomware it encodes a victim’s files and requests payment for a
decryption tool, while the second one – malware – can obtain information, hinder the activity, or
open a portal for other malicious activities. it is necessary to give attention to the fact that cyber
attacks are exist in the currently developing digital world like no other kind of attack which is
aimed at people or companies, as well as governments. There are two major types of cyber
threats, ransomware, and malware, which differ in a type of threat and the scale of the possible
negative outcomes and consequences.
Ransomeware is a form of malware that seizes the victim’s files under a threat to delete,
hide or encode them for a certain fee. In its message, the ransom is usually stated along with how
one is supposed to make the payment which, depending on the variant the attacker is using, could
be in the form of cryptocurrency in exchange for the decryption key. Ransomware attacks can
lead to devastating effects to individuals and organizations resulting to data loss, loss of funds
and multiple organizational downtimes. Sometimes it happens that after the payment of the
ransom the cybercriminals do not deliver the decryption key at all or, perhaps, ask for more
money.
Malware is a shortened form of malicious software Technically, malware can be defined
as aggressive software products that are designed with the intent to infiltrate computer systems.
Malicious software exists in her five types: A brief discussion with the help of figures is as
follows – A virus may be of three types depending on the nature of its operation; a worm may be
defined based on its functionality and it is different from a Virus; A Trojan may be defined based
on its capability; A Spyware may be defined by mode of operation. Some of its purposes
include: To spy itself on the user then capture login details, banking details, passwords or any
data that the owner of the system considers as sensitive or restricted; Some malware abnormally
changes system functionality or the user is granted access to their system by the hackers. It is
achieved by attaching malware to emails, while the links containing possible download of files
are also malware; and finally, the networks of computers have some vulnerability that may me
outdated. While ransomware and malware at first glance can be regarded as actions where the
motivation of the villains is not completely clear, and the outcome is often far from dangerous
and even a little silly, in fact, they can have serious consequences and can harm the company’s
financial situation, reputation, and legal compliance. Some of the effects that cyber attack can
cause are as follows; It interrupts the normal flow of broke within the firm, it may lead to loss of
confidence from clients and lastly it may be charged withcompound fines for violating data
protection laws. The telecom sector is equally vulnerable and such issues threaten government
bodies, personalities, and organizations that protect the country from different security threats.
To this effect, cyber security that seeks to halt cyber attack entails covering all forms of
security technical mechanisms, Educating employees in organizations, and mitigating and
eliminating threats that exist within organizations. The following are recommended security
measures that organizations should prioritize in a bid to reduce cyber terrorism L, password
protection, regular update of all software, segmentation of networks. Having many security
updates in combination with vulnerability sweeps and other penetration tests will also help
reduce such susceptibility to malicious parties.
Another facet of the fundamental concept of a robust cybersecurity framework relates to
the organization’s personnel by advocating for enhanced awareness and training of its workforce.
There are many threats existing in cyberspace; however, in place of reliably rejecting all the
threats defined, adding a potential policy reinforcing employee awareness regarding typical
cyber threats such as phishing scams and types of social engineering might assist in making sure
that the employees of the particular firm are not likely to commit mistakes that endanger the
security of the firm. Some of the much effective strategies that could help to enhance the
protection from the prospective cyber attacks include advocating for high level of authentication
processes like the multi-factor type together with; embracing of the recommended policies like
the safe internet browsing; and; lastly, exercising careful selection of the methods of email
communication.
Social Engineering
Cyber social engineering can be described as a relatively modern type of cyber threats
that exploits human factors rather than the weaknesses of information technology, in order to
achieve the attacker’s goals and penetrate computer networks or obtain information and data.
This tactic targets people’s psychology and tours to manipulate their trust, authority
figures/figures of fear or curiosity to make them reveal information or perform actions that are
violating security protocols. Pretexting is the act of fusing a given scenario or coming up with an
alibi in an effort to get the targeted people, or the subjects, to reveal important information about
themselves to the actor; this is normally done under fake pretenses of authority or business.
Baiting is a type of attack that makes use of an offer that seems interesting such as free
downloads or free gifts and this will require the user to provide some of their account credentials
or other details. Physically, tailgating takes advantage of people’s inclination toward holding the
door open for others, or the disinclination toward confrontation by permitting strangers to closely
follow them into protected zones or to provide them with access codes and combinations. The
goal of social engineering is to trick people into divulging personal information, or letting them
into a facility or building, and the result is typically catastrophic for the targets of the attacks.
Consequently, to mitigate the effects of social engineering attacks, organizations ought to ensure
that their employees receive periodic awareness training about the techniques frequently used by
social engineers, as well as identifying warning signs which would make the staff wary and
critically analytical. Proper security measures like the use of authentication, authorization, and
other measures like social engineering prevention, and the current incident response should be in
place to avoid any social engineering attacks that may result in a leakage of the firm’s data.
Insider Threats
Another and probably the most dangerous type is inbound threats that come from insiders
who have full rights access and who misuse this privilege for their own personal benefits or just
for pure evil. These insiders are in fact employees, contractors, or other third-party affiliated
persons who are permitted to access pertinent information or applications. Insider threats could
take various roles; they are one where the individuals involved engage in unauthorized acts of
copying and transferring of corporate secrets with the intention of gaining financial benefits or
outcompeting their former employers. Intellectual property leakage involves the act of divulging
sensitive information or any authorized person/testimony or the propagation of proprietary
information or trade secrets or research and development contents to unauthorised personnel or
otherwise causing the organisation to become vulnerable to competitors through exposure or loss
of Organizational reputation. In a similar manner, insiders may cause harm by their actions
through sabotage where they intentionally interfere with systems, networks, or operations with
the aim of incurring losses, damaging the reputation of the organization, or reduced ability to
produce goods or provide services. The more inaccessible insider threats are difficult to contain,
since these persons enjoy the confidence of the organization and are privy to certain privileges. It
is essential to recognize that insider threats remain a severe problem and require a full-scale
security solution, access controls, monitoring, and user behavior analytics tools to mitigate
threats quickly. Furthermore, the training and awareness sessions for the employees are
necessary to ensure that all the employees are clear about the insider threats and other security
implications among their counterparts. Thus, it is possible to conclude that by focusing on an
effective protection against these risks and creating a positive environment that would encourage
people to act responsibly, it is possible to minimize the threat of an insider attack and prevent
potentially dire consequences.
E-commerce Fraud
Most electronic fraud is a type of cybercrime that is executed through the use of the
internet to transact illegitimate business. Due to emerging technologies in e-business
organization, different methods are applied by criminals to have a loophole in online payment
system and suitably capture those consumers & business organizations who fall in this trap. Its
most common source is through the stolen credit card details of the victims, which could be
acquired through an online break-in into their accounts or through stealing of their account login
details through a phishing email. Such information is then used by the fraudsters in having the
Cards used to make purchases in the social sites dealing in merchandise with the aim of making
purchases of expensive merchandise which can be sold at a higher price in the market. Another
technique is what the scammers will pretend to be a copy of the real store and selling fake and
non existent products to the buyers. The intended websites are usually quite sophisticated; as a
result they convincingly mimic such things as proper layout of professional web sites and/or fake
references sections complete with fake testimonials. Consequently, there are e-commerce
fraudsters who engage in the faking and manipulating appearance of reviews and ratings that
would allow swindling possible consumers or improving the facade of scams. Scammers can
achieve this by either painting a positive outlook to other potential customers who may help in
providing favorable ratings or they can bury other negative feedbacks in a bid to deceive other
customers to visit their fake websites. Aile client fraud is one of the biggest threats to consumers
and corporate entities as it see their hard earned money go down the drain besides being dragged
through the court system for Business Defamation.Regrettably however, e-commerce fraud is a
continually increasing problem, which every company in the field of e-commerce has to combat
by incorporating measures such as the recovery system for detecting fraudulent traffic in credit
card operations and the user authentication system. Additionally, the public requires to open its
eyes when purchasing the products online; it should only spend its cash to well established
sellers and if at times it chances on a unfamiliar website it should try hard and establish if it is
authentic or a counterfeit website. As considering the possible threats on the part of e-commerce
and using the advice to implementing security measures in an online context, not only businesses
but also consumers will be shielded from being confronted by e-commerce frauds.
4.Techniques Used in IT-Related Fraud
Hacking Techniques
Hacking techniques help us with a broad picture of what a perpetrator does in an attempt
to breach computer, network or data holding considered to be targeted. This is one of them as it
refers to the scanning for built in flaws which are openings or vulnerabilities in a particular
portion of the software over which the hacker can gain control of the system or launch fixed
programs. The following may be expected due to a mistake in the programming of BWH, using
a wrong version of the software, or Circuitry not shielding the system hence a hacker attacks.
Indeed, there is quite a vast list with varieties of attacks: Another powerful kind of an attack
typically employed by hackers is known as direct attack, this is an assault aimed at gaining
passwords or keys for encryption. It is then applied to break into passwords that need accounts
and secure documents and data by encrypting them; it is rather efficient, especially if the
passwords created are plain and not so intelligent. there is still another way of manipulating
someone’s computer and other hand-held devices such as using the key logging software or a
key logging hardware that is a script or a program that enables the hacker or the attacker to
monitor all the activities of a user of the particular device, including all the passwords, credit
card numbers, or any other sensitive information that resides in the computer and is entered by
the user of the particular device.
These approaches, somehow, can be utilized by hackers with the purpose of unauthorized
access to definite system/control network, information or other immoral operations that can lead
to substantial losses. The hacking technique risks could only be managed well with the
contemporary tools available and hence organizations should embrace use of software’s,
authentications, intrusion detections and many others…The possibility of hack technique as a
threat was clearly understood by the organizations and hence efforts to make the employees
know how to control the threat should be made. Social Engineering Tactics
It is a long-planned and well-executed method that is implemented with the aim to
deceive people into doing specific things or to give out certain information. For instance, the use
of emails for the purpose of exploiting the target, an organization or an individual, making calls
in order to con people as well as imitating another person in an organization may be in the
capacity of a supervisor or director.
Sentry, in essence, is a new class of SE malware that uses human targets’ trusting nature
to extend the degree of trust that standard SE tools cannot. Phishing emails are by far one of the
most common and most effective social engineering tactics that exist globally and it involves the
act of designing fakes mails that originate from trustworthy sources such as institutions or
organizations that the recipients are likely to frequent, with the chief aim of forcing the recipients
to click on links or provide other personal details such as login information or financial
information. These e-mails put pressure on the addressee: it is important since people get
infected with a fear or a specific kind of concern, they will not waste time to verify the identity
of the sender of the e-mail or even the letter and really if this message is from a different one.
Phone scams can also be categorized under social engineering since the attacker disguises the
call or arranges it to have a high chance of getting the victim to provide information or pay.
These may exploit people’s belief in certain legitimate career fields or organizations, as
well as their obedience to perceived authoritative and effective guidelines and direction.. In
addition, social engineers may pretentiously be in the organisational structure of an organisation
with an intention of making it difficult for the actual personnel of the organisation irrespective of
their consent to grant them access to sensitive information or systems like IT administrators or
company managers. This is the act of deceiving people, companies, or computer systems, and get
them yield sensitive data or resources that are ignored by the attackers. Hence, it becomes
warranted for the management to make its employees wise on potential social-engineering scams
and, at the same time, have adequate measures in the counterase of the scams.
Malware and Ransomware Deployment
Malware and ransomware are other significant and common cybersecurity threats that are
constantly developing and are spreading through different internet connection. Malware is an
undefined term that embraces viruses, worms, and trojans it is created to harm computers and
networks deliberately. It is a program or code that becomes a part of other legitimate programs
and replicates itself when the host program is run, and modifies them or renders them useless or
non-functional. Worms are self-perpetuating and automatically propagate on the networks, and
once they get a grip, they spread to other devices within a short time. Specifically, the Trojans
appear to be normal applications that can be installed and run on the victim’s computer without
their knowledge and authorisation, thus allowing the attackers access and control over the
systems.
Ransomware is a specific type of malware, which does not simply delete the data of the
infected devices: it encrypts the data and requires the user to pay the encryption key in exchange.
This type of attack goes to specific people, companies, and organizations, and the effects usually
include financial damage, downtime, and compromise of confidential information. Malware and
ransomware are usually delivered through one or more techniques, for example, phishing emails
with links leading to downloads, links to other downloads found in an email attachment, links
from compromised websites, and others obtained from an exploit kits with software bugs.
Malware and ransomware loose in a network demand rapid action because they can infect other
connected system rapidly, eradicating whichever stability and security existing in the realities of
a network.
Measures in minimizing the risks that come with malware and ransomware deployment
include having decent cybersecurityprotocols, educating workers on dangers of viruses and
taking preventive measures such as ensuring workers don’t open suspicious links or emails,
frequent updates that apply security patches whenever necessary, and having efficient backup
and recovery solutions in place. By being on the lookout for fresh threats while going the extra
mile in preventing such attacks, businesses and other entities can guard their personnel,
infrastructure, assets, and clients against complete devastation caused by malware and
ransomware.
Data Breaches and Exploitation
A data breach therefore can be defined as a scenario whereby information belonging to a
certain individual is vulnerable for it to be accessed by another and gained by this other party.
The skills to harness data can then be sold in the black market or immediately used for phishing.
There are two calamities that entail violation of privacy and the subsequent utilization of the
suppressed information to cause havoc on people, corporations, and institutions. Information
leakage therefore refers to a scenario where some people penetrate an enclosed establishment or
gain access to some information that is exclusive to a specific outfit. These could be in form of
hacking attack, internal threats, loss or theft of physical medium containing sensitive data and the
rest.
According to Messmer, the assaulted data can be used in so many ways, and once inside ,
it is so difficult to regulate its usage again and again.in many ways as well, they also encompass
so many risks that it can also perceive as being a threat to the groups of people and organisations
in particular. This raw data may be bought by individuals in the black market or in other black
markets that contain hackers and fraudsters in order to gain from the stolen credentials which
could be used for their own personal or business gain. Some of the information that can be
mined from such sites are as follows; Even within half an hour of browsing the identity
information may be used directly in cases of frauds like frauds identity thefts, credit card felonies
or phishing for scams risking an individual’s money as well as reputation. In addition, and long
range and many folds, attack of tens of million records and the sorts should affect many, and are
closely watch, but one must state that this cost is not the only direct price associated with a data
breach since it has legal implications as well as fines from the supervisory bodies to which one
must add the damages resulting from lost reputation that should is a concern for all sectors. To
tackle or at best mitigate such risks organizations must consider measures that include; security
policies and practices that provided proactively for standards and protocols plus encryption
techniques that can assured safety of the data in addition to safe controls where organizations
have secure and detect mechanisms for data security. However, maybe there is still the need to
assess how far the organization has gone in the implementation of training and awareness
activities, which should assist in reducing awareness of the Human Resource staff in the
organization about risks facing the company’s data. Of course before becoming threatened by a
data breach is almost as plausible but having some preventive measures which decreases the
threatening ability, as well as the actions to be taken each sign of the event occurrence can also
assist to lessen the impacts of the loss to the organizations and their shareholders.
Use of the Dark Web
It mostly consists of criminal goods including hypothesis, fake documentations, unlawful
copies and some other similar merchandise. All people try to do business in a discreet manner;
this is why the inhabitants of the world engage in business utilizing virtual currency. The
darknet commonly referred to as the black web is the region of WWW that is out of range of
physical reach or of such technologies and applications and users browse the darknet with the
help of TOR. It helps serve a number of criminal purposes such as sales of banned products and
services.
Another most important application of the dark web is also for the sale of information in
general that has been created and stated often to have them stolen like credit card information,
identification numbers, passwords and the like. This lost data is usually obtained through other
means such as data thefts, cyber criminal activities and other cyber related malpractices and is
then sold in the market by the culprits. Additionally, it also serves as a marketplace for buying
and selling of hacking services and tools including but not limited to exploit kit, malware, and
DDoS of different types that assist the cyber criminals in the subsequent Cybercriminal activities
Other counterfeit products such as passports, ids, driver licenses, credit cards, and access
to these services are sold in black market on the side of the digital platform.
Asorganaisedearlierinthispiece,ittakestheuseofBitcointoensurethatthepurchaser/
sellercannotbeidentifiedbythePoliceandotherauthoritieswhilerobbingcybercriminalswhopracticec
onomyandotherIllegalactivitiesinblackmarkets. The following are the challenges that still
persist this time around regarding the use of the dark web; These danger points therefore are
about the whole list of cybersecurity and police work as more is required, more is feasible, and
more need to be spent to combat cybercriminals and ensure that clients, companies, and countries
do not fall prey to what is now termed deep web.
5.Impact of IT-Related Fraud
Economic Impact
The losses generated by IT frauds and cyber criminals are not only in monetary terms but
also for the individuals, the businesses and the government agencies that have been swindled and
hacked including by scammers and hackers. This can be stealization of stock, tampering with
the financial records or the actual resources and others related to the prevention and prevention
of fraud. In regards to the actual and non-actual losses, it is stated that global approximations of
such losses have forecasted that in the distant unknown future, such loses could likely rise to as
much as $10 trillion, barring any unprecedented and catastrophic epidemiological disasters such
as another deadly flu pandemic among others. It means that it is investing approximately five
trillions of dollars every year by the year 2025.
Impact on Businesses and Consumers
Consequently, IT-related fraud can lead to financial losses, legal consequences, revenue
losses, and damaged reputation for the establishments. The consequent risks customers are
exposed to include risks towards identity theft, monetary theft, and emotional distress. Fraud in
business affects the trust aspect as consumers may tend to lose confidence in firms they deal
with.
Psychological Impact on Victims
Testifying to this are the studies on the impact which IT-related fraud has on victims: The
victims experience high levels of psychological modulations. Among the many traumatizing
effects that may emerge in people who have witnessed violence are violation stress, anxiety, as
well as helplessness. Necessary financial fraud and identity thefts cases are extremely heinous,
and it is very long to restore the situation.
Societal and Cultural Implications
Both broadly at digital platforms’ levels and at the level of respective institutions, IT-
related fraud risks’ identification along with outline of an efficient response presupposes
consideration. It will slow down the process of how people start to use new technologies in their
different activities; it will slow down digital transformation. It is still also viable to indicate that
modern IT-related frauds alter the standards of privacy, security, and trust often.
Case Studies
Target Data Breach (2013)
The largest data breach that is often considered took place in 2013 with the retail chain,
Target, being a victim of the large-scale attack within a few bureaus; 40 million credit and debit
card accounts were affected. The criminalsassaultedTarget’s pervious security failure in a retail
chain, and the use of the_strerror error in the HVAC contractor’s segment that was associated
with Target’s processing payment stations. The breach resulted into tremendous amount of
money and couples with legal consequences and reputational volatility for the corresponding
company. As a result, Target spent a significant amount of money, financial capital that is,
towards strengthening their protective measures of their computer networks as well as modifying
their security policies and procedures.
Equifax Data Breach (2017)
The data breach was expressed in the year 2017 where Equifax exposed personal information of
up to 147 million people and this comprised of social Security numbers, date of birth and
address. Its blame was associated with the firm’s poor software update measures in which a
vulnerability in the web application framework with which the company operates was not
address earlier. It also came with the challenges of not being able to build consumers trust as
well as facing regulatory actions and Lawsuits all across the country. This clearly indicates,
why, apart from the regular updates, the software should be updated as frequent as possible,
besides maintaining an ironclad security.
Combating IT-Related Fraud
Technological Measures
Encryption is the earliest form of security, the act of encoding information to ensure that
it cannot be easily comprehended by anyone We can encrypt the data in a way that it cannot be
comprehended by anyone without the key. In this manner, organizations ensure that even if the
transmission data is intercepted, it cannot be disclosed in an intelligible form and is only
available to a particular subject.
Firewalls, which are essential components of network security, are security systems that
inspect and manage traffic on logic interfaces between trusted internal networks and suspect,
external networks. They examine incoming and outgoing pack Compiled by INB425: B
networking basics: Ethernet packets and filter out or deny any traffic than can be regulated
through specific access control policies aimed at combating controversionary entry into and out
of the network.
It is also known that anti-virus software helps to combat the viruses, worms and trojans as
its primary function is in recognizing and eliminating them. Anti-virus programs work on a
constant check on system activities and files, delete or quarantine infections in an attempt to
restrict further impacts on the same system and avoid passe of infections to other parts of the
system.
Commonly referred to as two-factor authentication, MFA amplifies security measures by
requesting that users confirm multiple aspects in order to be granted access to the company’s
systems or data. MFA entails using multiple factors like passwords, a security token, or
biometric features to bolster security, and it effectively minimizes the danger of an unauthorized
penetration, even if one of the factors is hacked. Combined with the additional measures
explained above, such a security level increases access controls and guards against try and buy or
identity theft.
IRegulatory Frameworks and Compliance
Governments and regulatory bodies have implemented various frameworks to combat IT-
related fraud:For the purpose of minimizing the cases of IT related fraud, different governments
and other necessary regulatory institutions came up with the following measures:
Global research is underway in similar fields and significant structures implemented by
governments and regulative authorities to respond to IT related frauds and increase the strength
to data security. The GDPR is a regulation of international applicability which is strict to
anyone processing the EU citizens’ data; its objective is the protection of data and privacy which
is extremely rigorous. On the positive aspect, it averted the situation where people donated so
much power to organizations such that they got to decide what one would like to be shared with
organizations concerning personal details, he gave out permission and documented measures to
be taken in case of violation of certain personal details asked for consent while outlining steps
that would be implemented so as to be taken to protect the data that had been collected and
explained the reason as to why personal details would be required The penalties for the breach
of the right of data subjects under the GDPR are quite steep; thus, it can be argued that GDPR
has a huge role in the protection of the EU residents.
The purpose of the CCPA is to raise the level of consumer and their personal information
protection in California state. It will be necessary to ensure that according to the CCPA,
consumers should be informed about the data collected about the consumers, rights of consumers
to delete the data, and even the rights of consumers that stops the selling of the data. It is an
endeavor that seeks to address the growing crisis where businesses are under pressure to
acknowledge the consumer data right hence the name; the act means the rights of consumer in
regard to data.
A number of very stringent rules that have to do with financial reporting and internal
controls of US public firms and which was set by the Sarbanes Oxley Act. That was initiated as
the policy in response to ostentatious corporate frauds which tightened the aspect of corporate
governance to produce SOX. The internal controls in the context of accounting give assurance in
the financial reporting processes and it can be interpreted to mean that the company should have
controls that will help mitigate fraud. The appearance of which, further proves the need for the
adoption of the SOX and the need to gain compliance to it, in an effort to retain public
confidence to the economy and to prevent the sanctity of share trading to be compromised.
Role of Cybersecurity Professionals
IT related fraud is on the rise and cybersecurity professionals are among the many
working on preventing and responding to the trends. Information technology security specialists
are responsible for guarding organizations against information technology crime, and assume
important roles in managing IT security solutions. One of the main responsibilities of most of
them is to evaluate and analyze the organization of risks and threats that may exist within the
network of the business. Thus, security professionals when conducting their analysis will be able
to identify potential fates and then come up with valid long-term countermeasures to prevent
malicious actors from taking advantage of the detected vulnerabilities.
In a state of attack or compromise, IT security professionals are expected to transition
toward the right course. This consists of speed of response, ‘While the violation needs to be
understood in terms of how it was made, and kept local so that the loss does not spread to other
parts of the organization, extent of occurrence impact needs to be evaluated, and a range of
subsequent actions such as release of patching software needs to be made. As such the
cybersecurity professionals can mitigate the impacts on the organization, and assist in regaining
normalcy quickly, due to timely mitigation of security breaches.
Public Awareness and Education
To curb such scams and other sorts of IT frauds, it is important to rely on education.
Such awareness programmes can be seen to help create awareness to people and the general
public regarding the various fraud related previous cases. Another way of risking the lives of the
employees is through offering training sessions time and again with regard to threats and the
means of safeguarding oneself.
It is important to address the issue at the international level due to the growing trends of
IT-related fraud. Responsible authorities in governments, private corporations and facets of
global organizations require cooperation to foster sharing of intelligence in capacities,
establishment of norms and policies as well as enhanced enforcement of rules laid down. Bearing
the same vision of promoting the increase of the global cybersecurity capacity and international
cooperation, today many organizations and institutions, including the Global Forum on Cyber
Expertise (GFCE), operate.
Regulations and Legal Frameworks
Overview of Major Regulations
The GDPR is another new legal instrument for information protection that sets quite strict
requirements for the implementation and functioning of data protection and data belonging to EU
citizens. It strives to extend and formalize people’s rights to privacy so that they can have much
more control over who and how they control their information and what is done with it,
including access to, rights to make edits on, and even outright erasure of personal data.
The California Consumer Privacy Act often abbreviated as CCPA is a comprehensive
privacy law in the state of California that brings about reforms to give the consumers
http://(2001’s George W Bush stem project. org/index. # Improving_the_CCPA additional rights
over the personal information of the consumers. About this, the Companies used in businesses
need to explain their data collection process; they should say whether consumers can choose not
to have their data collected or sold; and the sale of consumer’s identity information is forbidden.
PCI DSS refers to Payment Card Industry Data Security Standard and can be well
described as a framework formed by around fifteen requirements to ensure consumers card
information will not be exposed in the process of effecting transactions or during storage. The
full acronym stands for Payment Card Industry Data Security Standard and this is a set of
measures that had been created to prevent card holder data from being compromised by frauds.
HIPAA is a legislation policy in United States that governs health care industry and set
guidelines for maintaining privacy of patients’ health information known as protected health
information or PHI. HIPAA maintain that PHI can be used, disclosed or stored at patient’s
convenience in a way that remain secure as part of patients’ rights to privacy. It relates to those
who manage the PHI such as the healthcare institutions, the healthcare plans, the healthcare
clearing houses and any other business associates.
Effectiveness of These Regulations
These regulations apply to various degrees in keeping its promise of reducing emissions.
Such regulations like GDPR are very welcome to draw strict line on the data protection rules and
severe consequences for the organizations that fail to adhere to them so that organizations could
implement higher degrees of data protection. Nonetheless, the sources have also identified
challenges such as the problems of compliance and legal enforcement of the policies particularly
when the level of the two differs across countries.
It is on record that regulations are often rigorous activities which can be further
operational challenges when there is likelihood of engaging in legal proceedings across
countries. In a similar way to many arrangements existing in Internet society, the legal disputes,
the difference of technologies as well as the issues of regions are considered as possible
obstacles towards the international collaboration. Unfortunately, such inconsistencies and yes,
these two, undermine specific areas where cybercriminals may be located due to the inept
enforcement mechanism.
Future Legislative Trends
Based on the analyzed legislation trends in cybersecurity and data protection, we can
predict the following areas for the further legislation development: First of all, it is possible to
pointed a quite controversial tendency toward increasing consumers’ protection measures with a
special emphasis on the EU activities in changing the consumers’ role in governing their data.
The strength of the law is to give special regulations to individuals more ownership, rights, and
options with regard to data in relation to entities.
This essay also anticipates that there will be stiff penalties that organizations will be
subject to when they are found not to be compliant with those requirements alongside instances
of data breach. This is likely to add pressure to the governmental as well as the regulatory
authorities increase regulatory fines on the companies engaged in one way or the other in
infringing data protection laws or facing cyber-security threats. They can also involve hefty
fines by which some amount of money is recovered from the firms and the fact that the firms
have to go for trial and their firms reputation to ensure they adopt improved cybersecurity
measures.
More trends in work from home vulnerability are likely to be observed moving forward
as more and more individuals engage in this model since the attackers are afforded the
opportunity to corner individuals who are using their personal equipment and are not subjected to
the same level of protection that corporate entities have implemented for their employees.
Criminals can therefore come up with different methods like emails and phone calls,
impersonation, or exploiting any weaknesses in remote access programs and gain access to the
organizations networks with the intent of stealing information or installing viruses.
This can also be quite real in the domain of the frauds grounded on deep fake that gives
the attackers the suitable AI generated audio and video messages as the tools to impersonate and
perform the social engineering scams. It is, therefore, can be used in any operation that true
media can be used in to induce people into divulging some information or money or make
decisions that will be unfavorable for them to make. Kits suggests that, with deepfakes on the
increase and get easier and better to perpetrate, organizations and individual targets of
impersonation must learn to lookout for this emerging adversary and/or ensure deployment of
sound data identification and accreditation solutions to contain the spread of mimic.
The Evolving Role of Cybersecurity
Cybersecurity is also expected to function in a new way, particularly where there is
greater focus on predictive threat detection, which is, in fact, threat hunting. Threat hunting
means using various techniques to search for specific threats that may potentially harm an
organization’s systems or networks before those threats acquire the ability to cause damage.
Through use of analytical processing tools, threat intelligence, and forensic analysis,
cybersecurity specialists have the greatest ability to identify and counter new threats while
increasing defenses in the organization and minimizing the time and space for the cyber attacker.
Another important element of the shift in the development of cybersecurity is the
transition to using the ‘‘zero trust’’ security models. The model of zero trust can be summarized
in the logic that threats can come from outside and inside the network. Therefore, access requests
need to be checked as if the access was made via the open network even if the request is internal
in nature within the organization’s perimeters. In this model, every user, device, and application
has to be identified and accredited to enter this network in order to reduce on chances of getting
compromised within the network.
To avoid such mishaps, information security awareness should be embraced across the
entire organization so that people can be well informed of the threats that they face alongside the
measures that can be taken to safeguard individuals and their information. This is because
threats are still present and the users need to be aware of what kind of threats are out there if it is
in any Phishing scams or even social engineering; more over they need to know safe methods of
handling digital tools and how to process data securely. This, therefore means that the ongoing
training and awareness programs help the human aspect to have enhanced understanding of the
potential threats but acquire skills in how to handle these threats effectively hence eradicating
the gaps occasioned by human blunders and by doing this, reinforcing other aspects of security.
The utilization of security solutions, which is related to intelligent security and artificial
intelligence as well as machine learning, is being adopted in recent times. This can help in the
designing and implementation of security solutions that may range from being adaptive to the
most important risks, to the extent that they can modify their action in relation to the change in
the characteristics of the threats in real time. The feature of producing constant conclusions on
the basis of its observations of the procured average large volumes of data also makes the
artificial intelligence and machine learning capable of identifying the suspicious risky activities
that can lead to illegitimate actions and also capable of preventing such illegitimate actions at the
same instant. This is because there is more readiness toward the threats, which are often
encountered mainly in the cyber space domain, resulting in the improvement of the defense.
Conclusion
This has been made because every now and then, there is a close relationship between
information technology and frauds, as it is dynamic, meaning that it changes due to factors such
as advances in technology or even invention of new ways that fraudsters use. This phase is a
rich depository of a number of techniques and proaches of frauds and this is all set to escalate
with the increase in the technological advancement. Taking into consideration the historical
background, types of IT fraud, and the possibility of using the techniques of such fraudsters, it
becomes easier possible to comprehend the steps which are used in the identification of
countermeasure. Others in line with previous research findings on IT- related fraud have
elaborated the loss repercussions of the vice in economic business organizational and individual
levels.
Calls for the criminology of IT fraud continue to highlight the need for the concept of an
integrated strategy for combating fraud in informatics, based on the technologies, legislation, and
people. It is therefore important that different global entities and government and/or private
organizations should endeavor for the accomplishment of this mission. As the next section
describes new technologies and facts several of them tend to suggest that, new technology
equally assists in the perpetration of frauds while it also equally assists in preventing frauds. In
all these, we as cybersecurity experts are going to be faced with new challenges that are in the
near future that will therefore compel us to look for new unique ideas on how we are going to
defend securities of computer resources.
References
1. Symantec. (2019). Internet Security Threat Report. Retrieved from Symantec website
2. Europol. (2020). Internet Organized Crime Threat Assessment (IOCTA). Retrieved from
Europol website
3. Verizon. (2021). Data Breach Investigations Report. Retrieved from Verizon website
4. Ponemon Institute. (2020). Cost of a Data Breach Report. Retrieved from IBM Security
website
5. U.S. Federal Trade Commission. (2021). Consumer Sentinel Network Data Book 2020.
Retrieved from FTC website
Students also viewed