Three Types of Computer Crime

Three Types of Computer Crime:
Piracy, Break-ins, and Sabotage in Cyberspace


Which specific types of criminal activities will count as genuine instances of computer crime, and how could we catalogue those crimes?

On the criteria suggested above, one type would include the set of activities involving the use of computer technology to make one or more unauthorized copies of (i.e., "pirating") proprietary software.

Another type would include the range of activities involving the use of computer technology by one or more individuals to gain unauthorized access to (i.e., break into) another party's computer system, whether for amusement or for personal gain.

And a third type would include those activities in which one or more individuals uses computer technology to unleash a software program designed to sabotage a computer system or computer network by disrupting system activities on a privately owned computer system or on the Internet, or by damaging or destroying data or system resources, or both. In each of these three types of criminal acts, the crime can be carried out only through the use of computer technology.

Crimes that fit our definition would fall into one of three distinct categories:

(1) Software Piracy--using computer technology to (a) produce one or more unauthorized copies of proprietary computer software, or (b) distribute unauthorized software or make copies of that software available for distribution over a computer network.

(2) Electronic Break-Ins--using computer technology to gain unauthorized access either to an individual's or an organization's computer system, or to a password-protected Web site.

(3) Computer Sabotage--using computer technology to unleash one or more programs that (a) disrupt the flow of electronic information across one or more computer networks, including the Internet, or (b) destroy or damage data and computer system resources.

Each of these three categories of computer crime is discussed in greater detail in a longer version of this essay (in Spinello and Tavani, forthcoming). Let us briefly consider how each of the four crimes discussed in the introductory section of this study fit into one of these three categories.

Recall the four examples: (i) distributing MP3 files (which include copyrighted material) on the Internet via the Napster Web site, (ii) breaking into to U.S. government and military computer systems, (iii) unleashing the "love bug" computer virus (iv) "attacking" commercial Web sites so that they would issue "denial of service" requests. On the model of computer crime advanced in this study, each of these recent incidents falls into one or more of the three distinct types of computer crime articulated. For example, the distribution of MP3 files involved in the Napster case falls under the category of software piracy (category 1), while the unleashing of the "love bug" virus clearly falls under computer sabotage (category 3). Unauthorized entries into military and government computer systems are a clear example of electronic break-ins (category 2).

But how should we classify the cyber-attacks directed at the targeted commercial Web sites? That is, how would such a criminal act map into one of our threefold distinctions regarding the categories of computer crime that we have articulated? Because the attacks on these Web sites disrupted activities on the Internet by resulting in "denial of service" requests for users who wish to access those particular sites for legitimate purposes, these recent cyber-attacks would seem to fall into our third category: computer sabotage. However, since these attacks also involved the unauthorized use of (i.e., the breaking into) third party computer systems (in universities and other organizations) to send "spurious requests" to the Web sites in question, these attacks would also fall into
our second category of computer crime--viz., computer break-ins. So the recent cyber-attacks on commercial Web sites would seem to span two distinct categories of computer crime.

Concluding Remarks

We began this study by considering whether having a distinct category of computer crime is necessary or even useful. We then noted that arguments for having such a category of crime could be advanced from legal, moral, and descriptive/ informational perspectives. Appealing to Moor's insight regarding certain "conceptual muddles" that arise from computer technology, we saw that having a descriptive category of computer crime could help to eliminate some of the conceptual confusions with respect to criminal activities associated with computer technology. We then set out to define the boundaries of computer crime. Showing that Forester and Morrison's definition was inadequate, we argued that for any criminal act to count as an instance of computer crime, it must be such that it can be carried out only through the use of computer technology.

In applying that definition, we Saw that any genuine instance of a computer crime would typically fall into one of three types: software piracy, electronic break-ins, and computer sabotage. 8 We have also noted that computer technology, especially the Internet, has provided a new forum for certain illegal activities which, at first glance, might seem like instances of computer crime. On closer inspection, however, some of these criminal acts turned out not to be computer crimes at all--at least not in the strict sense of that that category of criminal activity which we have defended in this essay. We can now see why some of those crimes--e.g., certain crimes involving pedophiles, drug traffickers, child pornographers, and cyber-stalkers that we briefly described in the introductory section of this essay--are not, strictly speaking, computer crimes despite the fact that computer technology was a means used for carrying out those criminal acts. The threefold division of computer crime advanced in this essay could be challenged by certain recent online incidents, 9 and future cases of criminal activity involving computer technology may cause us to reexamine the tripartite scheme. One recent form of criminal activity that seems potentially to border on computer crime is a criminal act involving the use of digital telephony.

Base (1997) points out that in the use of cellular phones, a popular technique for avoiding charges is "cloning"--i.e., reprogramming one's cellular phone to transmit another customer's name. When true "computer telephony" (the merging of computers and telephones, also known as Internet phones or I-phones) arrives, we may need to reexamine our proposed definition of computer crime and we may discover the need to modify, or possibly even expand on, the three types of activities that we have defended as genuine instances of computer crime. For the time being, however, one virtue of having a working model of computer crime in place is that we can appeal to a consistent set of criteria in determining which new or evolving forms of illegal activities that involve existing computer technology should and should not count as genuine instances of computer crime. Our primary interest in this essay has been to establish criteria for computer crime as a descriptive category. It may well be that for reasons beyond those considered in this study, law makers will decide to frame a definition of computer crime or cybercrime as a legal category that makes any criminal activity on the Internet a form of cybercrime.

In the same way that certain law makers and law-enforcement representatives have supported a legal category of handgun crime in which the mere presence of a handgun in a criminal act would be sufficient for that act be prosecuted as a handgun crime, law makers may decide to frame an Internet crime law in such a way that the mere use of the Internet to carry out a criminal act would be sufficient to have that criminal act prosecuted as an instance of Internet crime or cybercrime.

However, our purpose in considering computer crime as a descriptive category, rather than as a legal or as a moral category, has been to gain a clearer understanding of those conditions which separate genuine computer crimes from those criminal activities in which computer technology is: (a) merely present in some form, or (b) used in a way simply to assist in carrying out a type of criminal activity that otherwise could have been carried out without the presence or use of computer technology. In this sense, then, having a descriptive category of computer crime can help us eliminate certain confusions currently associated with a range of criminal activities, many of which involve computer technology in ways that such technology either is merely present in the crime or is used as a tool that assists or possibly even enhances certain criminal acts, rather than providing the means essential to carrying out those acts.
(Source: Defining the Boundaries of Computer Crime: Computers and Society, September 2000)