News: 1636356670

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Computer misuse crimes in UK surge to high not seen since 2017 even as prosecutions slump 20%

(2021/11/08)


Public reports of computer-linked crimes are soaring thanks to a huge rise in data breaches, even as prosecutions against Computer Misuse Act offenders slump.

The Crime Survey for England and Wales said it recorded 1.8 million computer misuse offences in the 12 months ending June 2021, [1]matching the number it recorded in 2017 .

"This was an 85 per cent increase compared with the year ending June 2019, largely driven by a 161 per cent increase in 'Unauthorised access to personal information (including hacking)' offences," said the Office for National Statistics, which owns the survey.

[2]

Jed Kafetz, head of pentesting at UK-based infosec firm Redscan, described the latest stats as "a useful barometer for understanding how cybercrime impacts UK citizens in their day-to-day lives."

[3]UK households hit by 1.8m computer misuse offences in a year

[4]If there were almost a million computer misuse crimes last year, Action Fraud is only passing 2% of cases to cops

[5]Reports of cyber attacks fall, says UK.gov survey: GDPR? Fewer nasties? More targeted attacks? We just don't know

[6]Shocking crime surge – THE TRUTH: England, Wales stats now include hacking and fraud

"The 1.8 million estimated computer misuse offences are likely to be a fraction of the real number, when you consider how many details are lost, stolen and sold during big data breaches in a typical year," said a rather gloomy Kafetz. "I'm sure hacking incidents are grossly underreported, because people increasingly expect them in day-to-day life."

The ONS added that according to a 2019 survey it carried out, 68 per cent of those who reported being included in a data breach said they were "not affected at all" by it.

[7]

[8]

In the 11 months between July 2017 and June 2018, the Crime Survey recorded 1.1 million "computer misuse" crimes in its telephone survey of a nationally representative sample of Britons – though the ONS claimed these figures are not comparable to this week's telephone survey because the older data includes teens aged 16-18 and is not restricted to adults only.

The survey's data is different from data collected by police forces because, so the ONS says, it captures information about crimes that are not reported to police.

[9]

Despite the large jump in computer misuse crimes experienced by the population, prosecutions brought under the Computer Misuse Act over a similar time period [10]dropped by 20 per cent .

Reporting computer misuse crimes to the police can have varying outcomes. In 2019 we reported how crime reports to Action Fraud rarely do more than [11]get added to a row in a spreadsheet . While police and related agencies are notably good, in the UK, at diverting wayward youth away from hacking and towards legitimate infosec life choices, there is a balance to be struck between shying away from investigations and prosecutions and ensuring the law is actually enforced. ®

Bootnote

A little-known fact is that the Computer Misuse Act [12]can be applied to crimes committed overseas , similar to how the US Department of Justice regularly announces charges against overseas criminals. Strangely, this provision is rarely used – possibly because, in the absence of a firm sentencing guideline for the CMA, prosecutors fear foreign criminals getting a slap on the wrist instead of a strong prison sentence.

Get our [13]Tech Resources



[1] https://www.theregister.com/2017/07/20/uk_computer_misuse_statistics/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YYlXwro0-NBTGX6sTi1AJwAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2017/07/20/uk_computer_misuse_statistics/

[4] https://www.theregister.com/2019/10/21/action_fraud_computer_misuse_crimes_decrease/

[5] https://www.theregister.com/2019/07/04/reports_of_cyber_breaches_fall_due_to_less_virus_nasties/

[6] https://www.theregister.com/2017/01/20/cybercrime_stats_uk/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXwro0-NBTGX6sTi1AJwAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYlXwro0-NBTGX6sTi1AJwAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYlXwro0-NBTGX6sTi1AJwAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/05/21/computer_misuse_act_2020_prosecutions/

[11] https://www.theregister.com/2019/10/21/action_fraud_computer_misuse_crimes_decrease/

[12] https://www.legislation.gov.uk/ukpga/1990/18/crossheading/jurisdiction

[13] https://whitepapers.theregister.com/



Chris G

Using a telephone survey to assess the level of criminal actions that may be used as a basis for legislation is iffy at best.

How was the survey phrased and the participants validated and what other parameters were applied?

For an organisation like the ONS a telephone survey is lazy research.

Depends on selection criteria

Richard 12

How would you do it?

Stopping people in the street is inherently biased as it only surveys people who will stop, and who the researchers feel able to ask.

Self-selected (online) surveys like El Reg, newspapers and the like runs are statistically useless for population, as you only survey people who feel strongly about the issue and know about the survey, so you can easily get the result you want by how you advertise it.

Which leaves phone surveys. These have other problems of course, as not everyone has a phone or would answer it.

The ONS are reasonably good at both selection and understanding - and publishing - the errors it creates.

There's also other places to cross-check whether the numbers are plausible, like phishing reporting systems and the like.

Eg they say it's probably an underestimate, presumably because someone who's suffered from a data breach is unlikely to talk to a survey.

It's easy to monitor this

Version 1.0

We just monitor the daily attempts to log into the mail server administer account ... they have dropped recently to only one attempt every 30 seconds, 24 hours a day. But this is just a "feature" of the modern internet - it allows criminals free access to everything and there is virtually nothing being done to stop them - when they access your systems then you are blamed.

Re: It's easy to monitor this

dave 81

Just look at your fail2ban logs. Its kind of scary how many attempts there are on SSH and SMTP.

KarMann

In 2019 we reported how crime reports to Action Fraud rarely do more than [1]get added to a row in a spreadsheet .

Well, I suppose at least that's better than if [2]they added a row to the spreadsheet instead.

[1] https://www.theregister.com/2019/10/21/action_fraud_computer_misuse_crimes_decrease/

[2] https://www.theregister.com/2020/10/05/excel_england_coronavirus_contact_error/

Legitimate Pentest Professionals

Clausewitz 4.0

QUOTE: "prosecutors fear foreign criminals getting a slap on the wrist"

In the other hand, legitimate and intelligent penetration test professionals need always to make their clients to sign a contract, where the client assumes any kind of liability - civil, administrative, criminal and others.

I like, in particular, a clause that says software cannot be used in any circustance against or in partnership with foreign entities - thus, limiting the jurisdiction only to your own country.

I have a few of those contracts signed myself, for some clients.

jollyboyspecial

Prosecutions down? Under the party of law and order? Shurley shome mishtake?

Home on the Range was originally written in beef-flat.