A Large-Scale Measurement of Cybercrime Against Individuals
Authors
Title of the Paper
A Large-Scale Measurement of Cybercrime Against Individuals
Paper Information
- Subject Areas: Human-Computer Interaction (HCI), cybersecurity, and digital crime measurement
- Keywords: cybercrime, network scale-up method, digital inequality, economic impact, crime investigation, user research, internet technologies, measurement methodology, social statistics, digital security
- Publication Details: April 29–May 5, 2022, CHI Conference on Human Factors in Computing Systems (CHI '22)
Research Background and Issues
-
Current State and Issues:
- Empirical data on the prevalence and economic impact of cybercrime in the U.S. is limited;
- Issues exist with self-reported cybercrime data or reports submitted to government agencies, such as widespread underreporting;
- Understanding the actual scale, types, and impacts of cybercrime is critical for designing technologies to protect users and prioritizing resource allocation.
-
Significance of the Research:
- Data insufficiency directly affects the direction of security technology design and may lead to decisions based on the interests of tech companies or governments rather than prioritizing users;
- Vulnerable groups within "digital inequality" lack sufficient attention, potentially exacerbating existing societal inequities.
-
Research Motivation:
- To fill gaps in the measurement of cybercrime prevalence, monetary losses, and demographic disparities;
- To enhance the credibility of data in academic research and practice, aiding users in addressing cybersecurity risks.
Solution
-
Method Overview:
- The study measures cybercrime through a nationally representative survey of 11,953 U.S. internet users, combining social network reporting techniques and direct reporting methods;
- Analysis focuses on six typical cybercrime types: bank account or credit card fraud, goods not delivered, non-payment, overpayment, advance fee scams, and extortion.
-
Innovations:
- Quantifying the scale of cybercrime: Combining direct reporting and the network scale-up method to provide repeatable and comparable victimization data for U.S. consumers;
- Visibility adjustment: Addressing the "low visibility" challenge of the network scale-up method by refining estimation techniques;
- Multiple evaluation dimensions: Examining the impact of cybercrime from economic losses and demographic characteristics (e.g., age, gender, education, and race).
-
Implementation Steps and Techniques:
- Survey Design: Developing structured questionnaires to capture detailed victim experiences, including various question categories;
- Data Collection: Using the AmeriSpeak national sample to collect data with probability sampling and stratified weighting adjustments;
- Data Cleaning and Validation: Conducting qualitative analysis to describe responses and filter out potential false or erroneous reports;
- Cross-Comparative Analysis: Comparing results with other academic and government datasets, such as the FBI's IC3 report and FTC fraud investigations.
Research Findings
-
Key Findings:
- The annual prevalence of six types of cybercrime among U.S. consumers is generally low (most below 1%), with notable exceptions:
- Credit card or bank account fraud: 12.1% annual prevalence, though a significant number incurred no actual financial loss (only 1.08% experienced monetary loss);
- Goods not delivered: 3.21% annual prevalence among victims, with a median loss of $57.
- The other four types (e.g., advance fee scams, online extortion) had prevalence rates below 0.4%.
- The annual prevalence of six types of cybercrime among U.S. consumers is generally low (most below 1%), with notable exceptions:
-
Demographic Disparities:
- Older adults (60+ years) and African Americans had higher victimization rates, especially for bank fraud and non-delivery scams;
- Older victims were less likely to be involved in "selling goods"-related scams (e.g., non-payment and overpayment).
-
Methodological Contributions:
- The network scale-up method proved to be a viable approach for measuring cybercrime, though low visibility remains a challenge. Victims disclosed their experiences to others infrequently, potentially influenced by the emotional impact or social stigma of the crime.
-
Limitations and Future Directions:
- Limitations:
- The study only investigated major types of cybercrime affecting consumers, excluding other forms of cybercrime;
- Self-reporting may be subject to recall bias due to the survey method;
- Adjustments for low visibility in the network scale-up method may involve some unavoidable errors.
- Future Directions:
- Expanding the scope to include corporate victims and complex cybercrime behaviors;
- Exploring psychological and emotional impact dimensions;
- Optimizing statistical correction methods for the network scale-up method to reduce errors.
- Limitations:
Through this research, the paper proposes new methods for reliably measuring the scale and distribution of cybercrime, offering opportunities for designing digital security and protection policies. These insights are highly valuable for scholars, technology developers, and policymakers in related fields.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can web extension methods and direct reporting data quantify the scale of cybercrime experienced by U.S. consumers?Category: Misinformation, Platform Harm, Risk, and TrustSimilar questionsarrow_forward
- Which demographic characteristics (e.g., age, gender, education, and race) correlate with victimization rates for different types of cybercrime?Category: Misinformation, Platform Harm, Risk, and TrustSimilar questionsarrow_forward
- What are the economic impacts of cybercrime, and what disparities exist among victim groups?Category: Misinformation, Platform Harm, Risk, and TrustSimilar questionsarrow_forward
Practical Problems
1- Insufficient cybercrime data leaves the design direction for user security technologies unclear.Category: Misinformation, Platform Harm, Risk, and TrustSimilar questionsarrow_forward
- 71%
Moving beyond a “one-size fits all” approach: Exploring Individual Differences in Privacy
CHI '18· Privacy by Design & User Control +2
- 67%
Machine Heuristic: When We Trust Computers More than Humans with Our Personal Information
CHI '19· Privacy by Design & User Control +1
- 67%
The Annoying, the Disturbing, and the Weird: Challenges with Phone Numbers as Identifiers and Phone Number Recycling
CHI '21· Privacy by Design & User Control +1
- 67%
To Self-persuade or Be Persuaded: Examining Interventions for Users' Privacy Setting Selection
CHI '22· Privacy by Design & User Control +1
- 67%
A US-UK Usability Evaluation of Consent Management Platform Cookie Consent Interface Design on Desktop and Mobile
CHI '23· Privacy by Design & User Control +1
- 67%
Exploring User Motivations Behind iOS App Tracking Transparency Decisions
CHI '23· Privacy by Design & User Control +1
- 67%
Measuring Compliance with the California Consumer Privacy Act Over Space and Time
CHI '24· Privacy by Design & User Control +1
- 67%
Bystander Privacy in Video Sharing Era: Automated Consent Compliance through Platform Censorship
CHI '25· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)