All articles

What Is Cyber Crime

Learn what cyber crime is, how it works, major types of attacks, federal laws like CFAA, and practical steps to report and protect yourself from digital threats.

Sep 2, 2026 · Universal Investigations Agency

This article provides general information about cyber crime and is not legal advice. If you are involved in a criminal matter or believe you are a victim of cyber crime, consult with a licensed attorney or law enforcement agency about your specific situation.

Cyber crime is criminal activity carried out through computers, networks, or digital devices, and it affects millions of individuals and businesses every year. The threat grows more sophisticated daily, targeting everything from personal bank accounts to critical infrastructure. Understanding what cyber crime is, how it works, and what steps you can take when targeted forms the foundation of any meaningful defense. At Universal Investigations Agency, we've worked with clients who discovered breaches weeks or months after the initial intrusion—often because they didn't recognize the warning signs. This guide covers the core definitions, major types, real-world examples, legal frameworks, and practical steps for reporting and protecting yourself. If you're dealing with a suspected breach, fraud, or digital threat, professional cyber crime Investigation services can help secure evidence and identify the scope of the intrusion before further damage occurs. Knowing what cyber crime looks like is half the battle; knowing how to respond is the other half.

What Exactly Is Cyber Crime?

Cyber crime is any criminal activity that involves a computer, network, or digital device as either the target or the tool. The legal definition under federal law encompasses a broad range of offenses, from hacking into secure systems to stealing someone's identity through phishing emails. Two main categories organize most cyber crimes: those where technology is the target and those where technology is the tool. When a hacker breaks into a corporate server to steal customer data, technology is the target. When a fraudster uses a fake email to trick someone into wiring money, technology is the tool. Both fall under the cyber crime umbrella.

Federal statutes, particularly the Computer Fraud and Abuse Act (CFAA), define unauthorized access, computer fraud, and related offenses with significant penalties. The CFAA, enacted in 1986 and amended multiple times, criminalizes accessing a computer without authorization or exceeding authorized access to obtain information, commit fraud, or cause damage. States also maintain their own cyber crime laws, which vary in scope and enforcement. What remains consistent is this: if a crime involves digital systems or exploits digital communication, it's likely prosecutable as cyber crime.

The distinction between property crimes and crimes against individuals matters. A data breach that exposes millions of credit card numbers is primarily a property crime with widespread financial impact. Cyberstalking or online harassment, by contrast, targets an individual's safety and well-being. Both require investigation, but the methods and legal remedies differ. Understanding the category helps clarify the appropriate response and the agencies that will handle the case.

What Are the Main Types of Cyber Crime?

Cyber crime divides into several well-recognized categories, each with distinct methods, targets, and consequences. Recognizing these types helps you identify threats and respond appropriately when something looks wrong.

Phishing and Social Engineering Attacks

Phishing is the practice of sending fraudulent emails, text messages, or creating fake websites designed to steal login credentials, payment information, or other personal data. The attacker impersonates a trusted entity—a bank, a government agency, a popular online retailer, or even a coworker. The message typically creates urgency: your account will be locked, you owe taxes, a package can't be delivered unless you verify your information immediately. You click a link, enter your credentials on a convincing but fake login page, and the attacker captures everything you type.

Phishing is the entry point for the majority of successful cyber attacks. Once an attacker has valid credentials, they can access email accounts, financial systems, or corporate networks without triggering alarms. Social engineering extends beyond email to phone calls (vishing), text messages (smishing), and even in-person pretexting. The goal is always the same: manipulate a person into divulging information or performing an action that compromises security. Common tactics include spoofed sender addresses, logos copied from legitimate companies, and language designed to bypass critical thinking—fear, greed, curiosity, or helpfulness.

Ransomware and Malware Infections

Ransomware is malicious software that encrypts files on a victim's computer or network, rendering them inaccessible until a ransom is paid—usually in cryptocurrency. The attacker promises a decryption key in exchange for payment, though there's no guarantee they'll deliver. Ransomware spreads through phishing emails with infected attachments, malicious downloads disguised as legitimate software, or by exploiting unpatched software vulnerabilities. Once executed, it can propagate across a network, encrypting servers, backups, and connected devices within minutes.

The impact on businesses, healthcare facilities, and municipalities has escalated dramatically. Hospitals have been forced to divert patients during ransomware outages. City governments have lost access to records and services for weeks. Even if the ransom is paid, recovery is slow and expensive, and the risk of repeat attacks remains. Beyond ransomware, other malware types include spyware (which monitors activity and steals data), trojans (which masquerade as legitimate software to gain access), and keyloggers (which record every keystroke to capture passwords and messages). Each variant serves a different criminal objective, but all rely on unauthorized installation and execution.

Identity Theft and Financial Fraud

Identity theft occurs when someone uses another person's personal information—Social Security number, credit card details, bank account credentials—without permission to commit fraud. Criminals open credit accounts, make purchases, file fraudulent tax returns, or even obtain medical services in the victim's name. The data used for identity theft often comes from data breaches, phishing attacks, or purchases on dark web marketplaces where stolen credentials are sold in bulk.

The damage extends beyond immediate financial loss. Victims spend months or years disputing fraudulent charges, correcting credit reports, and dealing with collection agencies. Credit scores plummet. Loan applications are denied. Tax refunds are delayed. The emotional toll is significant, and the process of restoring one's identity is exhausting. Financial fraud schemes also include business email compromise (BEC), where attackers impersonate executives to authorize wire transfers, and account takeover, where criminals gain access to online banking or payment platforms and drain accounts before the victim notices.

Hacking and Unauthorized Access

Hacking is the act of gaining unauthorized access to computer systems, networks, or accounts. Motivations vary: stealing data for sale or espionage, sabotaging operations, proving technical skill, or gaining leverage for extortion. Common methods include exploiting weak or reused passwords, taking advantage of unpatched software vulnerabilities, and brute-force attacks that systematically try thousands of password combinations until one works. Hackers also use credential-stuffing attacks, where stolen username-password pairs from one breach are tested across other platforms, exploiting the fact that people reuse passwords.

Not all hacking is criminal. Ethical hacking, also called penetration testing, involves authorized security professionals attempting to breach systems to identify weaknesses before malicious actors find them. The distinction is consent and intent. Criminal hacking operates without authorization and often with the goal of theft, destruction, or disruption. Unauthorized access is a violation of the Computer Fraud and Abuse Act, and penalties increase with the severity of the intrusion and the damage caused.

Distributed Denial-of-Service (DDoS) Attacks

A distributed denial-of-service attack floods a server, website, or network with so much traffic that it becomes unavailable to legitimate users. The attacker commands a botnet—a network of infected devices, often compromised through malware—to send requests simultaneously, overwhelming the target's capacity. Websites crash. Online services go offline. Business operations halt.

Criminals use DDoS for several reasons: extortion, demanding payment to stop the attack; competitive sabotage, taking down a rival's website during a critical sales period; or distraction, drawing attention away while conducting a quieter, more damaging intrusion elsewhere. DDoS attacks are relatively easy to execute using readily available tools and rented botnets, making them a common tactic even for less sophisticated threat actors. The financial impact includes lost revenue, mitigation costs, and reputational damage when customers lose trust in a service's reliability.

Online Harassment and Cyberstalking

Cyber crimes aren't limited to financial or data theft. Online harassment, cyberstalking, threats, doxing (publishing private information to incite harassment), and sextortion (threatening to release intimate images unless demands are met) are serious crimes that target individuals. Perpetrators use social media platforms, email, messaging apps, and public forums to intimidate, control, or harm victims. The anonymity and reach of the internet amplify the impact, allowing harassment to follow victims across platforms and into their daily lives.

These crimes often escalate. What begins as unwanted messages can evolve into credible threats, identity theft, or real-world stalking. The psychological toll is severe: anxiety, depression, fear for physical safety, and loss of trust in online spaces. Federal law and many state statutes criminalize cyberstalking and online harassment. People can get arrested for online harassment, and prosecutions do occur, though enforcement depends on evidence quality, jurisdiction, and the ability to identify the perpetrator. Courts increasingly recognize the harm caused by digital harassment and impose meaningful penalties.

How Does Cyber Crime Work?

Most successful cyber crimes follow a predictable lifecycle. Understanding these stages clarifies why attacks succeed and where defenses can interrupt the process. The first stage is reconnaissance: attackers gather information about their targets. For individuals, this might mean scraping social media profiles for personal details or identifying which bank a person uses. For businesses, it involves mapping network infrastructure, identifying employees with access to sensitive systems, and discovering outdated software versions.

Next comes initial compromise. The attacker delivers malicious software or tricks someone into providing credentials. A phishing email with an infected attachment is common. So is a malicious download disguised as a software update or a link that exploits a browser vulnerability. Once the payload executes or credentials are entered, the attacker gains a foothold.

The third stage is establishing access. The attacker installs malware that persists after a reboot, creates backdoor accounts, or elevates privileges to move laterally across a network. This phase can last days or months as the attacker maps systems, identifies valuable data, and prepares for extraction or encryption. During this time, digital evidence accumulates—logs, file access records, network traffic anomalies—but many victims don't notice until the damage is done.

The fourth stage is executing the crime itself: exfiltrating customer data, encrypting files for ransom, transferring funds, or using stolen credentials to commit fraud elsewhere. Finally, attackers cover their tracks, deleting logs, using anonymization tools like VPNs or Tor, and laundering proceeds through cryptocurrency mixers. The effectiveness of cyber crime lies in exploiting human behavior—trust, urgency, routine—more than purely technical vulnerabilities. People click links, reuse passwords, and delay updates, creating opportunities attackers systematically exploit.

What Are Real-World Examples of Cyber Crime?

Concrete examples illustrate the scale and variety of cyber crime. The Target data breach in 2013 exposed payment card information for approximately 40 million customers and personal data for 70 million more. Attackers gained access through credentials stolen from a third-party HVAC vendor, then moved laterally through Target's network to reach point-of-sale systems. The breach cost the company hundreds of millions in settlements, system upgrades, and reputational damage.

The Colonial Pipeline ransomware attack in May 2021 forced the shutdown of a major fuel pipeline supplying the U.S. East Coast. The attackers, using ransomware known as DarkSide, encrypted systems and demanded payment in cryptocurrency. Colonial paid approximately $4.4 million to regain access, though law enforcement later recovered a portion of the ransom. The incident caused fuel shortages, panic buying, and highlighted the vulnerability of critical infrastructure to cyber attacks.

IRS tax refund fraud schemes represent a different type of cyber crime. Criminals use stolen Social Security numbers and personal information—often obtained from prior breaches—to file fraudulent tax returns and claim refunds before the legitimate taxpayer files. The IRS has implemented stronger verification measures, but the scheme persists, costing taxpayers and the government billions annually. Victims discover the fraud when they attempt to file their own return and are told one has already been submitted.

These examples share common elements: unauthorized access, exploitation of weak security practices, significant financial and operational impact, and the difficulty of swift recovery. Each case also involved complex investigations spanning multiple jurisdictions and required coordination between private sector entities and law enforcement.

What Are the Effects and Costs of Cyber Crime?

The financial impact of cyber crime is staggering. The FBI's Internet Crime Complaint Center (IC3) reported losses exceeding $10 billion from cyber crime complaints in recent years, and that figure represents only reported incidents. Many breaches and fraud cases go unreported due to embarrassment, uncertainty about how to report, or fear of reputational harm.

For individuals, the average identity theft victim spends hundreds of dollars and dozens of hours resolving fraudulent accounts, correcting credit reports, and disputing charges. Emotional distress, anxiety, and a lasting sense of violation are harder to quantify but no less real. Credit damage can linger for years, affecting loan applications, employment background checks, and housing opportunities.

Businesses face even steeper costs. The average data breach costs companies millions when factoring in forensic investigation, notification requirements, legal fees, regulatory fines, system remediation, and lost business. Operational downtime during a ransomware attack can halt revenue entirely. Healthcare organizations face additional consequences when patient care is disrupted. Reputational damage erodes customer trust, and competitors capitalize on the instability.

Society bears hidden costs as well. Cyber attacks on healthcare systems delay treatments and compromise patient safety. Attacks on infrastructure disrupt essential services. The cumulative effect is a loss of trust in digital systems and institutions, which undermines economic activity and innovation. Law enforcement and regulatory agencies expend significant resources investigating and prosecuting cyber crime, often with limited success due to jurisdictional challenges and the use of anonymization technologies.

How Is Cyber Crime Investigated?

Investigating cyber crime begins with preserving digital evidence. Compromised systems must be isolated to prevent further damage and to maintain the integrity of logs, file metadata, and network traffic records. Digital forensics specialists create forensic images of hard drives and memory, capturing a snapshot of the system state at the time of discovery. This evidence is fragile—rebooting a machine, continuing to use it, or deleting files can destroy critical clues.

Investigators trace IP addresses, domain registrations, and email headers to identify the origin of attacks, though sophisticated criminals use VPNs, proxy servers, and compromised devices to obscure their location. Malware analysis involves reverse-engineering malicious code to understand its behavior, identify command-and-control servers, and discover indicators of compromise that can be used to detect similar infections elsewhere. Following financial transactions, especially cryptocurrency flows, helps investigators track ransom payments or proceeds from fraud, though mixers and privacy coins complicate this process.

Coordination with law enforcement agencies is essential for cases involving criminal prosecution. The FBI, Secret Service, and state-level cyber crime units have specialized resources and legal authority to compel evidence from internet service providers and financial institutions. International cases require cooperation with agencies like Interpol and Europol, adding layers of complexity and delay.

At Universal Investigations Agency, digital forensics and cyber crime investigation often start with securing compromised systems and identifying the scope of intrusion. Private investigators play a critical role in corporate incidents, employee misconduct cases, or situations requiring discretion before law enforcement involvement. Businesses may need to understand what data was accessed, whether intellectual property was stolen, or if an insider facilitated the breach—questions that require thorough investigation before deciding whether to report to authorities. The challenge is significant: jurisdictional issues, encryption, and the use of anonymization tools mean not every case results in identifying the perpetrator, but thorough investigation maximizes the chance of recovery and accountability.

What Laws Address Cyber Crime?

The primary federal statute governing cyber crime is the Computer Fraud and Abuse Act (CFAA), originally enacted in 1986 and amended several times to address evolving threats. The CFAA criminalizes unauthorized access to computers, exceeding authorized access, computer fraud, and damage to computer systems. Penalties range from fines to imprisonment, with severity depending on the nature of the access, the damage caused, and whether the defendant has prior convictions. The law also provides a civil cause of action, allowing victims to sue for damages.

The Electronic Communications Privacy Act (ECPA) protects the privacy of electronic communications, criminalizing unauthorized interception of emails, phone calls, and other digital messages. The Identity Theft and Assumption Deterrence Act makes it a federal crime to knowingly transfer or use another person's identification with the intent to commit unlawful activity. The USA PATRIOT Act expanded law enforcement's investigative powers in cyber crime cases, particularly those involving terrorism or national security.

States also maintain their own cyber crime statutes, which vary in scope and enforcement. Some states have robust laws addressing hacking, identity theft, and online harassment, while others rely more heavily on federal prosecution. Penalties at the state level can include fines, restitution, probation, and imprisonment. Sentencing depends on the value of stolen property, the extent of damage, and whether the crime involved vulnerable victims like minors or the elderly.

International cooperation is critical for cross-border cases. The Budapest Convention on Cybercrime facilitates coordination among signatory nations, enabling mutual legal assistance and extradition in cyber crime investigations. Despite these frameworks, prosecution remains challenging. Attribution is difficult, evidence is often located across multiple jurisdictions, and many attackers operate from countries with limited law enforcement cooperation or where cyber crime is tolerated as long as it targets foreign victims.

How Can You Report Cyber Crime to Police or Authorities?

Reporting cyber crime promptly increases the chance of investigation and recovery. If you face an immediate threat—such as ongoing harassment, extortion, or a live intrusion—contact local law enforcement. Many police departments now have cyber crime units or can escalate cases to state or federal agencies. Provide as much detail as possible: what happened, when you first noticed it, what information or money was taken, and any communication from the attacker.

For federal-level reporting, file a complaint with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. The IC3 accepts reports on a wide range of cyber crimes, including phishing, ransomware, business email compromise, and online fraud. While not every complaint results in an individual investigation, the data helps law enforcement identify trends, track criminal networks, and prioritize resources.

If you are a victim of identity theft, report it to the Federal Trade Commission (FTC) at IdentityTheft.gov. The FTC provides a recovery plan tailored to your situation and generates an Identity Theft Report that can help you dispute fraudulent accounts and charges. This report is also useful when working with credit bureaus and financial institutions.

Report email scams and phishing attempts to the Anti-Phishing Working Group at reportphishing@apwg.org. Forward the suspicious message as an attachment so investigators can analyze headers and trace the source. If financial fraud occurred, notify your bank or credit card company immediately. Many institutions have fraud departments that can freeze accounts, reverse unauthorized transactions, and issue new credentials.

Document everything: take screenshots of emails, messages, and websites before they disappear; save transaction records, account statements, and any correspondence with the attacker; note timestamps and the sequence of events. This documentation is critical both for law enforcement and for any civil or insurance claims. Private investigators can assist with evidence gathering before or alongside law enforcement reporting, especially in corporate cases or situations where discretion is required. At Universal Investigations Agency, we've helped clients compile comprehensive evidence packages that streamline coordination with authorities and improve the chances of successful prosecution or recovery.

How Can You Protect Yourself from Cyber Crime?

No security measure is foolproof, but layered defenses dramatically reduce your risk. Start with strong, unique passwords for every account. Use a password manager to generate and store complex passwords—reusing passwords across sites is one of the most exploited vulnerabilities. Enable multi-factor authentication (MFA) wherever possible. MFA requires a second verification step—typically a code sent to your phone or generated by an app—making it far harder for attackers to access your accounts even if they have your password.

Keep software and operating systems updated. Patches close known vulnerabilities that attackers exploit to install malware or gain unauthorized access. Enable automatic updates when available, and don't delay installing security patches. Recognize phishing red flags: urgent language pressuring immediate action, sender addresses that don't quite match the legitimate domain, generic greetings instead of your name, requests for sensitive information via email, and links or attachments you weren't expecting. When in doubt, navigate directly to the website or call the organization using a number you find independently—never use contact information provided in a suspicious message.

Avoid conducting sensitive transactions over public Wi-Fi unless you use a virtual private network (VPN), which encrypts your internet traffic and shields it from eavesdropping. Regularly monitor your financial statements and credit reports for unauthorized activity. Early detection limits damage. Back up important data to an external drive or secure cloud service that isn't continuously connected to your computer—offline backups can't be encrypted by ransomware.

Perfect security is impossible. Motivated attackers with enough resources can breach even well-defended systems. The goal is to raise the cost and difficulty of attack so that criminals move on to easier targets. For businesses, this means employee training, network segmentation, incident response planning, and regular security assessments. For individuals, it means vigilance, skepticism, and basic hygiene—strong passwords, updates, backups, and awareness.

Understanding cyber crime is the foundation for protecting yourself and responding effectively when something goes wrong. The threats are real, diverse, and constantly evolving, but knowing how attackers operate, what laws govern prosecution, and where to turn for help puts you in a stronger position. If you're dealing with a suspected breach, fraud, or ongoing digital threat, professional cyber crime investigation can help secure evidence, identify the scope of intrusion, and coordinate with law enforcement or legal counsel. At Universal Investigations Agency, we approach these cases with the urgency they demand, recognizing that every hour matters when data, money, or safety is at risk. Learn more about how we support clients facing cyber threats, or reach out if you need guidance on the next steps in your situation.

Quick Answers To Common Questions

Common questions related to What Is Cyber Crime.

What is the legal definition of cyber crime?

Cyber crime is any illegal activity that involves computers, networks, or digital devices as either the target or the tool. Under federal law, particularly the Computer Fraud and Abuse Act, it encompasses unauthorized access to protected systems, data theft, distribution of malicious software, and using digital means to commit fraud or harassment.

What are the main types of cyber crime?

The main types include phishing and social engineering attacks that trick victims into revealing sensitive information, ransomware that holds data hostage, identity theft, hacking and unauthorized access to systems, and fraud committed through digital channels. Some crimes target technology itself, while others use technology as a tool to commit traditional offenses like theft and extortion.

What is the Computer Fraud and Abuse Act?

The Computer Fraud and Abuse Act is a federal law that defines and prosecutes computer-related crimes in the United States. It covers unauthorized access to protected computer systems, theft of data, distribution of malicious software, and other cyber offenses, establishing the legal framework for how these crimes are investigated and prosecuted at the federal level.

How do you report cyber crime?

You can report cyber crime to the FBI's Internet Crime Complaint Center (IC3), your local law enforcement, or the Federal Trade Commission depending on the type of offense. Many cases also benefit from working with a professional cyber crime investigator who can help preserve digital evidence and coordinate with authorities to document the full scope of the incident.

What is the difference between hacking and phishing?

Hacking involves directly breaking into computer systems or networks through technical means like exploiting software vulnerabilities or bypassing security controls. Phishing relies on tricking people into voluntarily giving up their credentials or sensitive information through fraudulent emails, messages, or fake websites that impersonate trusted entities.

What is cyber crime in simple words?

Cyber crime is criminal activity that targets computer systems and networks or uses digital technology to commit traditional crimes like fraud and theft. It includes everything from hacking into accounts and stealing data to sending scam emails and holding files hostage for ransom.

What are the top 5 cyber crimes?

The most common cyber crimes include phishing attacks that steal credentials, ransomware that locks files until payment is made, identity theft using stolen personal information, hacking and unauthorized access to systems, and online fraud schemes. These crimes affect individuals, small businesses, and large organizations daily, with phishing serving as the entry point for many successful attacks.

Who investigates cyber crime?

Cyber crime is investigated by federal agencies like the FBI and Secret Service, state and local law enforcement with cyber crime units, and private cyber crime investigators who work with businesses and individuals. Professional investigators help identify the scope of intrusion, preserve digital evidence, and coordinate with law enforcement when needed, especially in cases involving significant financial loss or data breaches.

Want to talk through your risk profile?

Contact Universal Investigations Agency for a confidential consultation.

Discuss Your Situation