Cybercrime
Cybercrime is illegal activity that targets or makes use of computers, computer networks, or internet-connected devices. Common examples include identity theft, phishing, malware, hacking, and social engineering. It can involve using technology as the tool to commit an offense, or making the technology itself the target of the offense.
Cybercrime refers to criminal activity that either targets or uses a computer, a computer network, or a networked device, encompassing offenses in which technology is the instrument of the crime and those in which it is the object. Recognized categories include hacking, malware, identity theft, social engineering, phishing, and software piracy (the unauthorized reproduction or distribution of software). The definition here is descriptive and drawn from general and law-enforcement sources rather than from a single harmonized statutory instrument; the precise legal elements, offense classifications, and reporting mechanisms vary by jurisdiction and should be confirmed against the applicable national framework (for example, national cybercrime reporting portals and the mandates of investigative agencies).
Why it matters
Cybercrime sits at the intersection of predicate offending and money laundering, making it a central concern for AML and financial crime compliance functions. Offenses such as identity theft, phishing, and malware can generate illicit proceeds that criminals then seek to move through the financial system, and the same techniques are frequently used to compromise customer accounts, defeat authentication controls, and facilitate fraud. Because technology can serve either as the instrument of an offense or as its target, cybercrime blurs the line between the underlying criminal act and the financial flows that follow it.
For obliged entities, the significance is operational as well as legal. Compromised credentials, account takeover, and social-engineering schemes can result in transactions that appear legitimate on their face but originate from criminal activity, complicating customer due diligence, transaction monitoring, and suspicious activity detection. The proceeds of cybercrime may need to be identified and reported through the applicable suspicious activity or suspicious transaction reporting regime, and firms may face both regulatory expectations and reputational exposure where controls fail to detect the illicit use of their systems.
It is important to note that cybercrime is a descriptive typology rather than a single harmonized offense. The precise legal elements, classifications, and reporting mechanisms vary by jurisdiction, and detection of a suspicious pattern or a compromised account does not by itself establish that a crime has occurred. Firms should confirm specific obligations against the applicable national framework, including any national cybercrime reporting portals and the mandates of relevant investigative agencies.
Who it's relevant to
Inside Cybercrime
Common questions
Answers to the questions practitioners most commonly ask about Cybercrime.