Every 11 seconds, a business somewhere in the world falls victim to a ransomware attack. Every day, over 2,000 people report being defrauded online. These aren’t abstract statistics – they reflect real people losing money, privacy, and peace of mind. Understanding how cybercrime actually works – the methods used, the systems exploited, and the damage caused – is the first step toward recognizing it, resisting it, and holding perpetrators accountable. This is especially critical in the context of gender-based violence, where digital tools have become powerful weapons of harassment, coercion, and control.
Table of Contents
- What we mean by cybercrime
- Attack vectors and tactics: how cybercriminals get in
- Phishing
- Ransomware
- Social engineering
- The role of anonymity and digital networks
- The dark web and encrypted networks
- Jurisdictional complexity
- Impact on individuals and businesses
- Impact on individuals
- Impact on businesses and critical infrastructure
- Why human behavior remains the weakest link
What we mean by cybercrime
Cybercrime refers to any criminal activity that involves a computer, networked device, or the internet. It ranges from identity theft and financial fraud to stalking, harassment, and extortion carried out through digital channels. What makes cybercrime particularly difficult to tackle is that it operates across borders, often without leaving obvious physical traces. The perpetrator could be in one country, the victim in another, and the server hosting the attack in a third – each governed by different laws and enforcement capacities.
Cybercrime is not a monolithic phenomenon. It includes crimes committed against computers (hacking, data breaches), crimes committed using computers (fraud, threats, non-consensual image sharing), and crimes where computers are incidental to the offense but still play a role. This breadth is precisely why understanding the specific techniques criminals use matters so much.
Attack vectors and tactics: how cybercriminals get in
Cybercriminals rely on a core set of techniques that exploit both technical vulnerabilities and human psychology. These entry points – known in security terminology as attack vectors – are the methods through which unauthorized access or harm is achieved.
Phishing
Phishing remains one of the most widespread and effective tactics in the cybercriminal’s arsenal. It involves impersonating a trusted entity – a bank, an employer, a government agency – to trick the target into handing over credentials, clicking a malicious link, or opening an infected attachment. According to the FBI’s Internet Crime Complaint Center (IC3), phishing attackers may pose as a victim’s phone carrier, employer, or even VPN portal to harvest login information. In 2024, phishing and spoofing topped the FBI’s crime charts with over 193,000 complaints filed.
A more targeted variant, spear phishing, involves researching specific individuals to craft highly personalized messages that bypass skepticism. Clayton State University’s cybersecurity resources note that spear phishing emails are so convincing that even standard spam filters repeatedly fail to catch them. Attackers gather information from social media, company websites, and data breaches to tailor messages that feel legitimate to the recipient.
Phishing has also evolved beyond email. Vishing (voice phishing) involves phone calls where criminals impersonate bank representatives or tech support agents. According to risk advisory firm Kroll, 2024 saw a rise in CEO-spoofing attacks that used AI-generated voice clones to trick employees into authorizing fraudulent transfers – a technique once confined to spy thrillers but now accessible to organized criminal groups.
Ransomware
Ransomware is malicious software that encrypts a victim’s files, rendering them inaccessible until a ransom is paid. It is currently ranked as the top cybersecurity concern for organizations worldwide. Fortinet’s cybersecurity glossary explains that ransomware is most commonly delivered via phishing emails, drive-by downloads from infected websites, or through compromised remote access tools. Once inside a system, it can spread rapidly across a network, locking out entire organizations within minutes.
The FBI’s 2024 IC3 Annual Report documented 3,156 ransomware complaints, with losses exceeding $12.4 million in directly reported damages alone – a figure that does not account for lost business, recovery costs, or reputational harm. The five most reported ransomware variants in 2024 were Akira, LockBit, RansomHub, FOG, and Fog. In the healthcare sector specifically, 67% of institutions reported ransomware attacks in the first three quarters of 2024, with average ransom demands exceeding $5.2 million.
A particularly troubling development is ransomware-as-a-service (RaaS), where criminal groups operate like businesses, offering ransomware tools to affiliates who then carry out attacks and split the profits. This model has dramatically lowered the technical barrier for committing ransomware attacks, contributing to a 131% growth in new ransomware groups since early 2024, according to threat intelligence data from Cognyte.
Social engineering
Social engineering is the umbrella term for techniques that manipulate human behavior rather than exploit software vulnerabilities. As Palo Alto Networks’ Unit 42 incident response data shows, social engineering was the top initial access vector between May 2024 and May 2025, accounting for 36% of all incidents – and it succeeds not because of technical sophistication, but because it exploits trust, urgency, and authority.
Common social engineering tactics include pretexting (fabricating a scenario to gain trust), SIM swapping (convincing a mobile carrier to transfer a victim’s phone number to the attacker’s device, bypassing multi-factor authentication), and impersonation (posing as an employee or IT staff to extract credentials). The FBI has specifically warned that SIM swapping is being used to bypass financial account protections, enabling criminals to drain bank accounts and cryptocurrency wallets. In one widely cited case, an AI-generated voice clone of a bank director was used to authorize a $35 million fraudulent transfer – illustrating how AI has amplified the effectiveness of social engineering at scale.
The role of anonymity and digital networks
One of the defining features of cybercrime – and a key reason it is so difficult to prosecute – is the structural anonymity that digital networks provide. Cybercriminals operate across multiple layers of technological obfuscation, each designed to obscure their identity and location.
The dark web and encrypted networks
The dark web refers to parts of the internet that are not indexed by standard search engines and can only be accessed using specialized software like the Tor browser, which routes traffic through multiple encrypted nodes to mask the user’s location. As the National Institute of Justice explains, the dark web’s anonymity not only encourages illegal activity but keeps many law enforcement agencies largely unaware of its scope, even while their jurisdictions are directly affected.
On dark web marketplaces, cybercriminals buy and sell stolen credentials, hacking tools, ransomware kits, counterfeit documents, drugs, and explicit content – often using cryptocurrencies like Bitcoin or Monero to conduct untraceable transactions. In 2023, dark web markets generated revenues of $1.7 billion, rebounding strongly after major takedowns in previous years. These markets function with ratings systems and customer service infrastructure that mimic legitimate e-commerce platforms.
Cryptocurrencies add a critical layer of financial anonymity. They are pseudonymous, cross-border, and largely irreversible once transferred – qualities that make them the preferred payment method across virtually every cybercrime category. According to TRM Labs, nearly 150,000 FBI complaints in 2024 involved cryptocurrency, with associated losses reaching $9.3 billion – a 66% increase from the prior year.
Jurisdictional complexity
Even when authorities identify a cybercriminal, bringing them to justice is far from straightforward. A single cybercrime transaction can involve a seller in one country, a buyer in another, and servers hosted in a third – each subject to different legal standards, extradition treaties, and enforcement capacities. As SL Cyber’s analysis notes, this cross-border structure creates significant jurisdictional challenges that require complex international coordination to navigate.
Law enforcement has made notable strides through international collaboration. In 2024, German authorities, working with agencies in Lithuania and the United States, dismantled the Nemesis dark web marketplace and seized over $120,000 in cryptocurrency assets. Operation Cronos – a multinational effort – took down major ransomware group LockBit, seizing 34 servers and 200 cryptocurrency accounts. However, these wins are often temporary: former LockBit affiliates quickly regrouped and launched independent operations, highlighting the resilience of organized cybercrime ecosystems.
Beyond the dark web, criminals also exploit legitimate platforms – cloud storage services, social media, messaging apps, and even gaming networks – to coordinate attacks, distribute malware, and communicate without detection. The use of multiple public platforms to stage different parts of an attack (as seen in recent ransomware campaigns distributing payloads across GitHub and Dropbox) further complicates law enforcement’s ability to pursue and dismantle criminal operations.
Impact on individuals and businesses
The consequences of cybercrime extend far beyond financial loss – though the financial toll alone is staggering. The FBI’s 2024 IC3 report recorded a new high of $16.6 billion in reported losses, a 33% increase from 2023, with over 859,000 complaints filed – more than 2,000 per day. These numbers represent only what was reported; a significant number of victims never contact authorities due to embarrassment, fear, or lack of awareness.
Impact on individuals
For individuals, cybercrime can be financially devastating and emotionally destabilizing. Investment fraud – including “pig butchering” scams that use fake romantic or financial relationships to manipulate victims into investing in fraudulent cryptocurrency platforms – topped the individual loss charts in 2024, with $6.57 billion in reported losses. Business email compromise (BEC) scams cost individuals and organizations nearly $2.77 billion in the same year.
Older adults bear a disproportionate burden. CyberScoop’s analysis of the IC3 data shows that people aged 60 and older filed 147,127 complaints in 2024 – a 46% increase from 2023 – with total losses reaching nearly $4.9 billion. Among this group, 7,500 individuals each lost more than $100,000, with an average individual loss of $83,000.
Beyond money, cybercrime causes significant psychological harm. Victims of online fraud, identity theft, and cyber-enabled harassment commonly report anxiety, shame, social withdrawal, and loss of trust in digital systems. For survivors of gender-based cybercrimes – including non-consensual image sharing, doxxing, and online stalking – the trauma can be severe and long-lasting, often mirroring the psychological impact of physical violence.
Impact on businesses and critical infrastructure
For organizations, a cyberattack rarely results in a single, isolated loss. The cascading effects include operational downtime, legal liability, regulatory fines, customer churn, and lasting reputational damage. According to global data breach statistics, the average cost of a data breach reached $4.88 million in 2024. Ransomware breaches take an average of 326 days to fully contain – nearly a year of disruption for affected organizations.
Critical infrastructure sectors face heightened risk. In 2024, over 4,800 organizations operating in energy, healthcare, finance, and manufacturing reported cybercrime incidents to the FBI, with data breaches and ransomware attacks being the most common. When a hospital’s systems are encrypted by ransomware, patient care is directly compromised. When a water utility is targeted, public safety is at stake. Cybercrime in these contexts is not merely a financial issue – it is a matter of public health and national security.
Small businesses are not insulated from these threats. Data from HornetSecurity indicates that companies with 1 to 50 employees account for 55.8% of ransomware targets. Many lack the dedicated security infrastructure of large corporations, making them attractive and accessible targets. Among those struck by ransomware, 1 in 5 paid the ransom, with 60% paying between $10,000 and $100,000 – sums that can be existential for a small operation.
Reputational damage compounds the financial impact. When customer data is exposed in a breach, the loss of consumer trust can outlast the immediate financial harm by years. Businesses that suffer high-profile breaches often face reduced investor confidence, difficulty attracting clients, and increased scrutiny from regulators – all of which translate into long-term economic harm that never appears in a single loss figure.
Why human behavior remains the weakest link
Across virtually every form of cybercrime, human behavior – not technological failure – is the most commonly exploited vulnerability. The 2025 Data Breach Investigation Report found that 68% of data breaches involved accidental actions, stolen credentials, social engineering, or malicious privilege misuse. Technical defenses – firewalls, antivirus software, encryption – can be bypassed far more easily by tricking a person into clicking a link than by breaking through code.
This is why cybercriminals invest heavily in psychological manipulation. They study their targets, impersonate trusted figures, manufacture urgency, and exploit emotional states – fear, loneliness, greed, and compassion – to override rational caution. The rise of AI-generated phishing emails (now accounting for over 82% of phishing content, according to recent studies) has made these manipulations even more convincing and harder to detect, even for experienced users. Understanding this dynamic is not about blaming victims. It is about recognizing that the design of cybercrime deliberately targets cognitive vulnerabilities that all humans share, and that awareness and structural safeguards are both necessary to reduce harm.
What do you think? Given that social engineering exploits human psychology rather than just technical systems, how should educators, employers, and policymakers address the human dimension of cybersecurity – especially for communities most vulnerable to digital harm? And considering that cybercrime frequently crosses national borders while laws remain jurisdiction-bound, what kinds of international frameworks would be most effective in holding perpetrators accountable?
References
- https://www.ic3.gov/PSA/2024/PSA240411
- https://www.clayton.edu/its/it-security/cyber/index.php
- https://www.helpnetsecurity.com/2025/02/27/2024-phishing-trends-what-to-expect-in-2025/
- https://www.fortinet.com/resources/cyberglossary/ransomware
- https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
- https://www.cognyte.com/blog/law-enforcement-dark-web-cybercrime/
- https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/
- https://nij.ojp.gov/topics/articles/taking-dark-web-law-enforcement-experts-id-investigative-needs
- https://www.trmlabs.com/resources/blog/a-record-breaking-year-for-cybercrime-key-findings-from-the-fbis-2024-ic3-report
- https://slcyber.io/overcoming-the-challenges-of-cybercriminals-trafficking-illegal-goods-from-the-dark-web/
- https://cyberscoop.com/fbi-ic3-cybercrime-report-2024-key-statistics-trends/
- https://sprinto.com/blog/social-engineering-statistics/
- https://secureframe.com/blog/social-engineering-statistics
Leave a Reply