Cybercrime: Definition, 9 Real World Examples and Forensic Next Steps

Cybercrime: Definition, 9 Real World Examples and Forensic Next Steps

Cybercrime is any illegal act that uses a computer, network, or digital device to access, alter, steal, or disrupt data or services. Targets range from individuals and small businesses to hospitals and government agencies, and motives typically fall into financial gain, espionage, or pure disruption. The sections below set out the main categories, concrete examples, and what to do if you become a victim.


TL;DR:

  • Successful cybercrimes often exploit small gaps through social engineering, outdated software, or weak passwords, making prevention largely about good cyber habits.
  • Most attacks follow a pattern of reconnaissance, delivery, exploitation, and persistence, primarily using phishing or malicious links to gain initial access.
  • Data from a breach, not stolen assets, usually enables identity theft and business email compromise, with organized crime rings and insiders playing key roles.
  • Immediate response involves disconnecting affected devices, changing passwords from a secure device, and reporting the incident to authorities without deleting evidence.
  • Proper evidence preservation and expert forensic analysis are essential for legal actions and recovery, highlighting the importance of professional help after a cyberattack.

Computerforensicslab
Preserve Evidence After Cybercrime
Computer Forensics Lab investigates breaches, recovers digital data, and analyses evidence for legal, business, and private client needs.
Explore digital forensics

Table of Contents

Cybercrime definition and examples: how offences are classified

Law enforcement agencies split cybercrime into two broad categories, and the distinction shapes how an investigation actually runs. The Crown Prosecution Service uses this framework because it determines which evidence matters most and which legal charges apply.

Cyber-dependent crime treats the computer or network itself as the target. The offence cannot happen without digital infrastructure.

  • Distributed Denial of Service (DDoS) attacks that flood a server until it collapses
  • Unauthorised hacking into systems to steal or damage data
  • Creating and spreading malware designed to disable networks

Cyber-enabled crime uses technology to scale up offences that existed long before computers did.

  • Online fraud, where a scam that once relied on post or telephone now runs through email
  • Cyberstalking and harassment conducted via social media or messaging apps
  • Identity theft carried out through data stolen in a breach rather than a stolen wallet

For cyber-dependent incidents, investigators prioritise volatile memory, exploit code, and network logs. Cyber-enabled cases lean more on transactional records and link analysis between suspects, victims, and accounts, according to the CPS. Getting that classification right early on determines which digital trail gets preserved first.

Examples of cybercrimes you’re likely to encounter

Reading about cybercrime in the abstract rarely helps. Here are nine recognisable examples of cyber crime, each with a plain-English definition and a real-world illustration.

  1. Phishing. Fraudulent emails or texts trick someone into handing over login details or payment information. A typical case involves a message pretending to be from a bank, directing the victim to a fake login page.
  2. Malware. Malicious software installed on a device without consent, often through an infected attachment or a compromised download. It can log keystrokes, steal files, or open a backdoor for later access.
  3. Ransomware. Malware that encrypts a victim’s files and demands payment for the decryption key. The FBI has documented ransomware crippling hospitals and local councils, not just large corporations.
  4. Identity theft. Criminals use stolen personal data, often sourced from a breach, to open credit lines or file fraudulent tax returns in someone else’s name.
  5. Business Email Compromise (BEC). Attackers impersonate an executive or supplier to trick an employee into transferring funds. Finance teams at mid-sized firms are common targets because approval chains are easier to spoof.
  6. DDoS attacks. Attackers overwhelm a website or service with traffic until it goes offline, sometimes as a smokescreen for a separate breach happening simultaneously.
  7. Cryptojacking. Malicious code hijacks a device’s processing power to mine cryptocurrency without the owner’s knowledge, quietly draining performance and electricity; learn more about crypto bot vulnerabilities.
  8. Child exploitation material. Digital platforms are used to produce, distribute, or access illegal content involving minors, an offence category the ICE Homeland Security Investigations unit treats as one of its highest priorities.
  9. Cyberespionage. State-backed or corporate actors infiltrate networks to steal trade secrets or intelligence, often lying undetected for months before extracting data.

Who commits cybercrime and why

Cybercriminals aren’t a single type of person. Motivations and skill levels vary enormously, and that variation shapes which targets get chosen and which tactics get used.

  • Lone opportunists exploit weak passwords or unpatched software for quick financial gain.
  • Organised fraud rings run large-scale phishing or card-fraud operations with defined roles, from developers to money launderers.
  • Nation-state actors pursue espionage, sabotage, or disruption of critical infrastructure. The FBI has tracked state-sponsored groups targeting energy grids and defence contractors.
  • Insider threats come from employees or contractors misusing legitimate access.

Modular criminal marketplaces, such as phishing-as-a-service kits, now let low-skill actors rent attack tools rather than build them, according to ICE HSI. This has pushed the barrier to entry lower than ever.

How cyberattacks actually unfold

Most successful attacks follow a recognisable sequence: reconnaissance, delivery, exploitation, persistence, then exfiltration or disruption. Attackers first gather information about a target, often through public social media profiles or leaked data. They then deliver a malicious payload, typically via email, a compromised website, or an insecure IoT device on the same network.

Social engineering drives much of this. Phishing (email), vishing (phone calls), and smishing (text messages) all exploit trust rather than a technical flaw. RAND’s analysis of social engineering describes it as the human element attackers rely on precisely because technical defences can’t patch human judgement. Once inside, attackers often use exploit kits or rented botnets to maintain access and move laterally before extracting data or triggering damage. The delivery vector barely changes: email attachments, malicious links, compromised legitimate sites, and poorly secured smart devices remain the most common entry points.

Five stages of a cyberattack sequence

The real cost of cybercrime

Cybercrime rarely stays contained to one victim. A single breach can trigger financial loss, service outages, reputational damage, and, in cases involving hospitals or utilities, genuine safety risk.

Consumer surveys cited by the Cambridge Dictionary indicate that a large proportion of people have experienced some form of cybercrime, underlining how routine these incidents have become.

Supply-chain attacks amplify the damage further: compromising one software vendor can affect thousands of downstream customers simultaneously. Critical infrastructure, energy, water, healthcare, remains an especially attractive target precisely because disruption there carries outsized consequences.

Prevention basics and what to do if you’re a victim

Most cybercrime succeeds because of small, avoidable gaps rather than sophisticated hacking. CISA’s guidance recommends a handful of habits that close most of them: enable multi-factor authentication wherever it’s offered, use strong and unique passwords for each account, keep devices and applications updated, and treat unexpected links or attachments with suspicion.

If you suspect you’ve been targeted, act in this order:

  1. Isolate the affected device. Disconnect it from Wi-Fi or unplug the network cable to stop further data loss or spread.
  2. Change passwords from a separate, clean device. Never reuse the compromised machine to reset credentials.
  3. Preserve everything. Screenshot suspicious messages, save logs, and note timestamps before anything is deleted, our step-by-step guide to identifying cybercrime evidence covers this in more depth.
  4. Report it promptly. Contact your bank if money is involved, then report to your national cybercrime reporting body, such as the IC3 in the United States, or your local police cybercrime unit.

Pro Tip: Do not delete anything, even messages that feel embarrassing or incriminating to have opened. Investigators often recover more from what looks like “just spam” than from a wiped inbox.

Prompt reporting matters beyond your own case. The FBI notes that early reports help agencies spot patterns across multiple victims, which is often how larger fraud rings get identified in the first place.

How digital forensic investigations actually work

Once an incident is reported, investigators work from several evidence sources: device storage, cloud account data, server and firewall logs, email headers, and file metadata that reveals when something was created, moved, or altered. Timestamps and header data often matter more than the obvious files themselves, because they establish sequence and origin.

Evidence sources aligned into forensic timeline

Chain of custody is what keeps this evidence usable in court. Every device or file must be documented from the moment it’s seized to the moment it’s presented as evidence, with no gaps that a defence lawyer could exploit. This is why timing matters: evidence handled by an untrained party, or left too long before capture, can lose its evidentiary value entirely.

A digital forensics firm typically provides:

  • Data recovery from damaged, deleted, or encrypted storage
  • Malware analysis to identify how an attack was carried out
  • Expert witness reports suitable for court or tribunal proceedings

Our guide on how police investigate cyber crime walks through this process from initial report to case resolution.

Why vigilance alone won’t protect your evidence

Awareness genuinely reduces risk, but it doesn’t replace proper evidence handling once something has already gone wrong. The most common mistake we see is a victim deleting a suspicious email or wiping a device out of instinct, destroying the very trail that could have identified the attacker or supported a legal claim. Vigilance stops the next attack; preservation protects your case for the one that’s already happened. If you’re unsure what to keep or how to keep it, ask before you act.

— Computer

Getting professional help with an incident

Everyday precautions reduce your exposure, but once a breach or fraud has actually happened, preserving evidence correctly is what determines whether it can be recovered or acted on legally. Expert digital forensics services are available, offering data recovery, forensic analysis, and expert witness reports for individuals, businesses, and legal teams handling a live incident. If you’ve been targeted and need someone to recover deleted data, examine a device forensically, or prepare a report suitable for court, our digital forensics services page sets out how to get started and what to expect from an initial consultation.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources