哈佛大学肯尼迪学院-识别影响以财务为动机的网络犯罪网络出现的条件(英)-2021.8-71页_3mb
报告摘要
Summary of Cybercrime Hotspots
Core Content
This report, authored by Aoibheann Thinnes and published by the Belfer Center for Science and International Affairs at Harvard Kennedy School, examines the conditions that influence the emergence and operation of financially-motivated cybercriminal networks in Nigeria, India, and Mexico. It highlights the growing threat of organized cybercrime to the U.S. financial system and proposes policy recommendations for the United States Secret Service (USSS) to more effectively counter these threats.
The report identifies organized cybercrime groups as a significant and persistent threat, surpassing nation-states and terrorists in financial impact. These groups are characterized by their structured operations, use of complementary skills, and reliance on new technologies to execute and target their schemes. The report also emphasizes the challenges in identifying the physical locations of cybercriminals due to the lack of a centralized dataset and the use of proxy data that is often fragmented and unreliable.
Main Findings
General Insights
- Location Uncertainty: There is no singular dataset capturing the physical location of cybercriminals, and proxy data is limited due to the complexity and fragmentation of cybercrime data.
- Consistent TTPs: Organized cybercrime groups have relatively consistent tactics, techniques, and procedures (TTPs), but they adapt by leveraging new technologies.
- Network Structure: Cybercriminals operate in networks with complementary skills and roles, often centered around language communities, where trust is a key factor in recruitment and operations.
- Socioeconomic Factors: Access to the internet and technical skills are prerequisites for cybercrime. High poverty, unemployment, and weak cybersecurity infrastructure, laws, and enforcement contribute to the persistence and growth of organized cybercrime.
Country-Specific Insights
Nigeria
- High poverty and unemployment rates drive increased cybercrime.
- Nigeria remains a hub for social engineering scams, with cybercrime groups becoming more sophisticated and efficient.
- The rise in Business Email Compromise (BEC) scams, exacerbated by the pandemic, and the migration of cybercriminals to other countries are increasing the threat.
India
- A gap exists between the availability of technical skills and the demand for technical jobs, contributing to cybercrime.
- India’s legitimate IT industry coexists with growing criminal call centers that support cyber operations.
- Weak enforcement of cyber laws and lack of cybersecurity-trained judges and courts hinder prosecution efforts.
Mexico
- Cybercrime has seen a significant increase since 2018, with Mexico being a primary location for cybercriminal attacks.
- Traditional organized crime groups are expanding into cybercrime, using the internet to further their illicit activities.
- As cybercriminals in Mexico become more connected and sophisticated, they are likely to pose a greater threat beyond the Spanish-speaking world.
Policy Recommendations
The report aligns its recommendations with the USSS Office of Investigations' (INV) FY 2021–2027 Strategic Plan and proposes the following:
Goal 1: Investigations
-
Objective 1.1: Detect, Investigate, and Arrest Those Committing Financial Crimes
- Align incentives with INV objectives
- Increase coordination in online criminal forums and marketplaces
- Track social media in known cybercrime hubs
- Pursue less sophisticated cybercrimes rigorously with DOJ and local partners
-
Objective 1.2: Identify and Seize Assets to Prevent Illicit Profit and Victim Financial Losses
- Prioritize targeting illicit marketplaces for cybercrime tools
- Investigate trends in cryptocurrency exchange and regulation to interdict funding
-
Objective 1.3: Strengthen Stakeholder Ability to Prevent Financial Crimes
- Coordinate with stakeholders to enhance cybersecurity infrastructure
- Publicize fraud detection efforts to deter future crimes
Goal 3: Staffing and Training
-
Objective 3.1: Develop Investigative Teams for Transnational Cyber Fraud
- Coordinate language specialists across regional offices
- Collaborate with local partners to intervene at earlier stages of cybercrime development
-
Objective 3.2: Increase Technical and Analytical Training for Cyber Fraud Investigations
- Train investigators to identify risk factors and intervention points
- Monitor technological developments and emerging vulnerabilities
- Enhance coordination between INV and the Office of Strategic Planning and Policy (OSP)
Goal 4: Outreach
-
Objective 4.1: Strengthen Unity of Effort with Law Enforcement and Government Partners
- Increase collaboration, training, and data sharing with the private sector
- Support DOJ and State Department efforts in interagency cybercrime enforcement
- Expand information sharing with international partners
- Promote the expansion of the Budapest Convention
-
Objective 4.2: Develop Law Enforcement Partners' Capabilities
- Advocate for increased cyber training for law enforcement, prosecutors, and judges
-
Objective 4.3: Cultivate Stakeholder Relationships
- Launch public outreach campaigns on cybersecurity threats
- Promote lawful opportunities for individuals with technical skills
Methodology
The report uses a combination of informational interviews and literature review to gather insights. Due to the lack of direct data on cybercriminal locations, the author relied on proxy data such as the origin of cyberattacks and financial flows from victims. The case studies of Nigeria, India, and Mexico were selected based on:
- Anecdotal evidence from experts
- Data from U.S. government sources indicating perpetrator and threat actor locations
- Corroborating evidence from cybersecurity industry reports
However, the report acknowledges the limitations of data availability and the inconsistency of cybercrime statistics, which affect the reliability of comparative analysis. The findings are therefore presented as preliminary hypotheses rather than definitive conclusions, calling for further quantitative research.
Key Challenges
- Data Fragmentation: Lack of a centralized dataset and reliable proxy data makes it difficult to accurately map cybercriminal locations.
- Legal Complexity: Differences in legal frameworks across countries complicate cross-border enforcement and prosecution.
- Anonymity and Jurisdiction: Cybercriminals often operate across borders, using servers in multiple jurisdictions, making it hard to determine legal responsibility.
Conclusion
The report provides a comprehensive overview of the factors that contribute to the rise of organized cybercrime groups in specific countries and outlines strategic steps for the USSS to address this growing threat. It underscores the need for international collaboration, enhanced training and resources, and improved data collection and sharing to effectively combat financially-motivated cybercrime.
试读结束,高清完整版pdf/doc/ppt,请点下载