• Skip to main content
  • Skip to primary sidebar

Criminal Justice

iResearchNet




Criminal Justice > Criminology > Cyber Criminology > Cybercrime Offenders and Motivations

Cybercrime Offenders and Motivations




Cybercrime Offenders and MotivationsCybercrime offenders and motivations represent a central concern within Cyber Criminology, as the demographic profiles, psychological characteristics, and goal structures of those who commit digitally mediated offenses differ in important respects from the offender populations studied in traditional Criminology. Early portrayals of cybercriminals drew heavily on the hacker stereotype — young, technically gifted males motivated by intellectual curiosity and countercultural ideology. Empirical research conducted over the past two decades has revealed a far more heterogeneous offender population that includes organized criminal enterprises, state-sponsored operatives, ideologically driven hacktivists, disgruntled insiders, and opportunistic individuals drawn to cybercrime by low barriers to entry and perceived anonymity. This article examines the demographic and psychological profiles of cybercrime offenders, surveys the major motivational frameworks that scholars have developed to explain digital offending, and considers how the professionalization and marketization of cybercrime have reshaped the offender landscape in the United States and globally.

Introduction

Understanding who commits cybercrime and why they do so is a prerequisite for effective prevention, investigation, and prosecution. Yet the offender dimension of cybercrime has proven especially difficult to study empirically. Most cybercrime goes unreported, and most reported cybercrime goes unsolved, meaning that the population of known offenders represents a small and potentially unrepresentative sample of actual offenders. Arrest and prosecution data, the traditional empirical foundation of offender research in criminology, capture only the fraction of cybercriminals who are identified, apprehended, and charged — a fraction that skews toward less sophisticated offenders and those operating within U.S. jurisdiction. Self-report studies offer complementary data but face their own methodological challenges, including the difficulty of sampling hidden populations and the sensitivity of the behaviors under investigation.

Despite these limitations, a substantial body of research has accumulated on cybercrime offenders and their motivations. This research draws on multiple methodologies — analysis of court records and sentencing data, interviews with convicted offenders, ethnographic studies of hacking communities and underground forums, analysis of digital traces left by offenders, and survey research on self-reported cyber-deviance. The resulting picture is one of considerable diversity across offense types, with the demographic profile and motivational structure of a ransomware affiliate differing markedly from those of a cyberstalker, an insider threat actor, or a teenager engaged in distributed denial-of-service attacks. This article synthesizes these findings, organizing the discussion around demographic profiles, psychological and personality characteristics, major motivational categories, the organizational structures through which many offenders operate, and the theoretical frameworks that criminologists have applied to explain cybercrime participation.




Demographic Profiles of Cybercrime Offenders

Age and Gender Patterns

The available evidence consistently identifies cybercrime offending as skewing young and male, though both dimensions show more variation than early stereotypes suggested. Analysis of FBI arrest data and federal prosecution records indicates that the median age of cybercrime defendants in U.S. federal courts falls in the mid-to-late twenties, younger than the median for most white-collar crime categories but older than the median for street crime (Marcum, Higgins, & Ricketts, 2014). The age distribution varies substantially by offense type: distributed denial-of-service (DDoS) attacks and low-level hacking show the youngest offender profiles, with significant involvement by juveniles and young adults under twenty-five, while business email compromise and investment fraud offenders tend to be older, often in their thirties and forties, reflecting the social engineering skills and organizational knowledge these offenses require.

Gender disparities in cybercrime offending are pronounced. Studies consistently find that males account for approximately 80 to 95 percent of identified cybercrime offenders, depending on the offense category and data source (Holt, Bossler, & May, 2012). This gender gap mirrors the broader male predominance in criminal offending but appears especially stark in technically oriented offense categories such as hacking and malware development. However, the gap narrows for cyber-enabled offenses such as online fraud and identity theft, where women constitute a larger minority of offenders. Hutchings and Chua (2017) cautioned that gender estimates derived from arrest data may overstate the male predominance if women are less likely to be identified and prosecuted, a selection effect that is difficult to quantify given the overall low clearance rate for cybercrime.

The intersection of age and technological competence creates a distinctive pattern in cybercrime careers. Many offenders report initial involvement in cyber-deviance during adolescence — experimenting with hacking tools, participating in underground forums, or engaging in low-level fraud — before escalating to more serious offending in early adulthood. Décary-Hétu and Dupont (2012) documented this trajectory through analysis of online forum participation, finding that offenders who persisted in cybercrime exhibited increasing specialization and network centrality over time. The developmental trajectory differs from the age-crime curve observed in traditional offending, where criminal participation typically peaks in late adolescence and declines thereafter; cybercrime careers may peak later and persist longer, reflecting the continued accumulation of technical skills and criminal network ties.

Socioeconomic and Geographic Distribution

The socioeconomic profile of cybercrime offenders departs substantially from the demographic patterns associated with street crime. While traditional property and violent crime correlates strongly with poverty, unemployment, and neighborhood disadvantage, cybercrime offending requires access to digital technology and at least moderate technical literacy, effectively establishing a minimum resource threshold for participation. Lusthaus (2018) documented how many Eastern European cybercriminals possessed university-level technical education, often in computer science or engineering, and had entered cybercrime after finding that legitimate employment in their countries of origin offered inadequate compensation relative to their skills.

Within the United States, the geographic distribution of cybercrime offending does not follow the spatial patterns of traditional crime. Cybercrime can be committed from any location with internet access, and investigators have identified offenders operating from affluent suburbs, college campuses, and rural communities as well as from the urban neighborhoods associated with conventional criminal activity. The IC3’s referral data suggest geographic clustering of certain offense types — business email compromise operations linked to West African diaspora communities, for instance, and technical hacking operations concentrated in regions with strong computer science educational infrastructure — but these patterns reflect network effects and recruitment dynamics rather than the neighborhood-level ecological factors that drive traditional crime concentration.

The global dimension of cybercrime offending complicates demographic analysis. A significant share of cybercrime victimizing Americans originates from outside U.S. jurisdiction, with major source regions including Eastern Europe (particularly Russia, Ukraine, and Romania), West Africa (particularly Nigeria), East Asia, and South America. The motivational profiles and organizational structures of offenders in these regions differ, shaped by local economic conditions, educational systems, law enforcement capacity, and cultural norms around digital offending. Aiken, McMahon, Haughton, O’Neill, and O’Carroll (2016) argued that understanding cybercrime offender demographics requires attention to these transnational dynamics, as purely domestic analyses miss the structural factors that drive cybercrime participation in source countries.

Psychological and Personality Characteristics

Cognitive and Personality Traits

Psychological research on cybercrime offenders has identified several personality dimensions associated with digital offending, though the literature is limited by the difficulty of accessing representative offender samples. The most consistent finding involves the Dark Triad personality traits — narcissism, Machiavellianism, and psychopathy — which have been linked to various forms of cyber-deviance in multiple studies. Buckels, Trapnell, and Paulhus (2014) found that sadistic personality traits predicted online trolling behavior, while Seigfried-Spellar and Lankford (2018) reported elevated narcissism and Machiavellianism scores among self-reported hackers relative to non-offending controls.

Low self-control, the central explanatory variable in Gottfredson and Hirschi’s (1990) general theory of crime, has received substantial attention in cybercrime research. Bossler and Holt (2010) found that low self-control predicted both cyber-deviance perpetration and cyber victimization in a college student sample, consistent with the theory’s prediction that impulsive, risk-seeking individuals are more likely to both offend and place themselves in vulnerable situations. However, the relationship between low self-control and cybercrime is more complex than the general theory predicts. Technically sophisticated cybercrimes — developing novel malware, conducting multi-stage intrusion campaigns, maintaining persistent access to compromised networks — require sustained attention, deferred gratification, and meticulous planning that are inconsistent with the impulsivity that low self-control implies. Holt and Kilger (2012) argued that the applicability of self-control theory varies across cybercrime types, with strong predictive power for impulsive online offenses (harassment, simple fraud) but weak explanatory value for offenses requiring sustained technical effort.

Moral disengagement mechanisms appear particularly relevant to cybercrime participation. The physical distance between offender and victim in most cybercrimes, combined with the abstract and often invisible nature of digital harm, may facilitate the cognitive processes through which offenders minimize their sense of wrongdoing. Bandura’s (1999) framework of moral disengagement — encompassing moral justification, euphemistic labeling, advantageous comparison, displacement of responsibility, diffusion of responsibility, disregard for consequences, dehumanization, and attribution of blame — maps effectively onto the rationalizations that cybercriminals employ. Chua and Holt (2016) documented how underground forum participants justified their activities through appeals to victimless crime narratives (“I’m only stealing from banks, not people”), claims of corporate hypocrisy, and assertions that their victims were negligent or complicit in their own victimization.

The Insider Threat Profile

Insider threats — offenses committed by current or former employees, contractors, or business partners with authorized access to organizational systems — constitute a psychologically distinct offender category. The Carnegie Mellon University Software Engineering Institute’s CERT Division has maintained the most extensive empirical database on insider threats in the United States, analyzing over 3,000 cases to develop behavioral profiles and risk indicators. Their research identifies three primary insider threat types: the saboteur motivated by revenge or grievance, the theft actor motivated by financial gain, and the inadvertent insider whose negligent behavior creates security vulnerabilities without criminal intent (Cappelli, Moore, & Trzeciak, 2012).

The psychological dynamics of insider sabotage are particularly well-documented. CERT research found that insider saboteurs typically experienced a triggering event — termination, demotion, negative performance review, interpersonal conflict — that preceded their malicious activity by days to months. Many exhibited observable behavioral indicators including increased working hours (particularly after-hours access), conflicts with supervisors, expressions of disgruntlement to colleagues, and policy violations in the period preceding the attack. Shaw, Ruby, and Post (1998) identified a composite personality profile they termed the “critical pathway” model, in which personal predispositions (narcissism, entitlement, difficulty accepting criticism) interact with professional stressors and organizational failures (inadequate management response to warning signs) to produce insider offending.

Financial insiders present a different profile. Unlike saboteurs, who are typically motivated by revenge and operate with relative disregard for detection, financially motivated insiders often plan their activities carefully and may sustain theft operations over extended periods. The median duration of insider theft before detection exceeds thirty months in CERT’s dataset, reflecting the access advantages insiders enjoy and the difficulty of distinguishing malicious data exfiltration from legitimate job functions. The financial insider profile skews older than the external offender population, with many cases involving mid-career employees in positions of trust — system administrators, database managers, financial officers — who exploit their authorized access for personal enrichment.

Motivational Frameworks

Financial Motivation and the Professionalization of Cybercrime

Financial gain is the dominant motivation for cybercrime by volume of offenses, value of losses, and number of participants. The IC3’s 2023 annual report documented over $12.5 billion in reported losses from financially motivated cybercrime, a figure that has increased year over year for more than a decade and almost certainly undercounts actual losses given chronic underreporting. The range of financially motivated cybercrime spans from low-sophistication romance scams and advance-fee fraud through technically complex ransomware operations and cryptocurrency theft, with corresponding variation in offender profiles, organizational structures, and monetization methods.

The professionalization of financially motivated cybercrime represents one of the most significant developments in the offender landscape over the past decade. Lusthaus (2018) documented how cybercrime in Eastern Europe and elsewhere has evolved from the informal, loosely organized activity of the early 2000s into a structured industry with defined roles, labor markets, and business models. Cybercrime-as-a-service platforms now offer subscription-based access to ransomware, phishing kits, botnets, and money laundering infrastructure, enabling individuals with minimal technical skill to conduct sophisticated attacks. This marketization has expanded the population of potential offenders by lowering the barriers to entry and has generated new offender types — the “affiliate” who rents criminal tools, the “initial access broker” who sells compromised credentials, the “bullet-proof hoster” who provides infrastructure resistant to law enforcement takedown.

The economic rationality of cybercrime participation has been analyzed through a deterrence framework. Holt, Burruss, and Bossler (2019) examined the risk-reward calculus that potential offenders face, finding that the perceived certainty of punishment for cybercrime was substantially lower than for comparable traditional offenses, while perceived rewards were higher. The combination of high rewards, low detection probability, and uncertain punishment — particularly for offenders operating from jurisdictions with limited law enforcement capacity or willingness to cooperate with American authorities — creates an incentive structure that rational choice theory predicts will attract offenders. The policy implication is that reducing cybercrime requires not only increasing enforcement capacity but also altering the economic calculus through target hardening, disruption of criminal markets, and reduction of monetization opportunities.

Ideological and Political Motivations

Ideologically motivated cybercrime encompasses hacktivism, cyberterrorism, and the online activities of extremist organizations. Hacktivism — the use of hacking techniques to advance political or social causes — has been the most visible ideological category since the emergence of Anonymous in the late 2000s. Hacktivist actions include website defacement, DDoS attacks against government and corporate targets, data theft and public disclosure (“doxing”), and the disruption of online services associated with perceived enemies. The motivational profile of hacktivists combines political conviction with elements of subcultural identity and performative transgression, making it difficult to separate ideological commitment from social belonging and status-seeking within activist communities (Jordan & Taylor, 2004).

The relationship between online radicalization and cybercrime motivation has attracted increasing attention since the mid-2010s. Violent extremist organizations across the ideological spectrum — jihadist, white supremacist, accelerationist — have used digital platforms for recruitment, propaganda dissemination, and operational coordination. While most online extremist activity does not constitute cybercrime in the narrow sense (speech-based activity is generally protected under the First Amendment), the operational security practices, cryptocurrency fundraising, and technical capabilities developed within extremist communities create pipelines into criminal conduct. Gill, Corner, Conway, Thornton, Bloom, and Horgan (2017) found that a significant proportion of terrorism offenders in their dataset had engaged in online research and communication activities that preceded and facilitated their offenses.

Nation-state cyber operations represent a distinct motivational category that overlaps uneasily with criminal frameworks. Russian, Chinese, North Korean, and Iranian state-sponsored groups conduct espionage, sabotage, and influence operations through cyber means that would constitute serious criminal offenses if committed by private actors. The motivational structure is institutional rather than personal — operatives act under orders within organizational hierarchies pursuing state strategic objectives. North Korean state-sponsored groups present a particularly complex case, as the Lazarus Group and affiliated entities have conducted financially motivated cybercrime (bank heists, cryptocurrency theft) to generate revenue for the North Korean regime, blending espionage motivation with financial crime in ways that challenge clean typological separation (Insikt Group, 2020).

Expressive and Personal Motivations

Not all cybercrime is instrumentally motivated. A substantial category of digital offending is driven by expressive motivations — the desire for excitement, status, revenge, sexual gratification, or emotional satisfaction rather than material gain. Thrill-seeking and curiosity-driven hacking, particularly among younger offenders, has been documented in multiple qualitative studies of hacker subcultures. Turgeman-Goldschmidt (2005) interviewed Israeli hackers and found that many described their initial involvement in terms of intellectual challenge and the pleasurable sensation of solving technical puzzles, with financial or destructive motivations developing only later in their offending careers.

Revenge-motivated cybercrime spans a range of severity from minor harassment to devastating attacks on former employers or intimate partners. The phenomenon of “revenge porn” — the nonconsensual distribution of intimate images, now more precisely termed image-based sexual abuse — exemplifies how personal grievance motivates technologically mediated harm. McGlynn, Rackley, and Houghton (2017) documented the gendered dynamics of image-based abuse, finding that perpetrators were overwhelmingly male and victims overwhelmingly female, with motivational drivers including desire for control, punishment for perceived relationship transgressions, and sexual gratification through humiliation. The criminalization of nonconsensual intimate image distribution, now addressed by statutes in most U.S. states, reflects legislative recognition of the distinct harm caused by this motivational category.

Online sexual offending against children involves complex motivational structures that have been studied extensively in clinical and forensic psychology. Seto (2013) distinguished among offenders who use the internet to access child sexual abuse material, those who use online platforms to groom children for contact offenses, and those who produce and distribute exploitative content. The motivational profiles of these subgroups overlap but are not identical: CSAM consumers may be driven primarily by deviant sexual interest, while grooming offenders often exhibit a combination of sexual motivation and antisocial interpersonal patterns that facilitate manipulation of vulnerable targets. Wolak, Finkelhor, Mitchell, and Ybarra (2008) found that many online child exploitation offenders did not fit the stereotypical predator profile and instead represented a diverse population with varying levels of criminal sophistication and varying pathways into offending.

Organizational Structures and Criminal Networks

From Lone Wolves to Organized Operations

The organizational structures through which cybercriminals operate have evolved substantially from the lone-wolf hacker model that dominated early cybercrime discourse. While individual offenders continue to account for a significant share of certain offense types — cyberstalking, low-level fraud, unauthorized access motivated by curiosity — the most consequential cybercrime by economic impact is conducted through organized groups with differentiated roles and structured operations. Leukfeldt, Kleemans, and Stol (2017) analyzed Dutch cybercrime cases and identified a continuum of organizational sophistication ranging from loosely connected networks of opportunity through structured criminal groups with defined hierarchies and stable membership.

The organizational structure of ransomware operations illustrates the contemporary model. Ransomware-as-a-service (RaaS) groups such as LockBit, BlackCat/ALPHV, and their successors operate on a franchise model in which core developers create and maintain the ransomware platform, negotiate with victims, and manage cryptocurrency laundering, while affiliates — independent contractors recruited through underground forums — conduct the actual intrusions and deploy the malware. Affiliates receive a percentage of ransom payments, typically 60 to 80 percent, with the remainder going to the platform operators. This organizational form allows RaaS groups to scale their operations without centralized management of individual attacks, creating a distributed criminal enterprise that is resilient to law enforcement disruption of individual nodes.

Underground forums and encrypted communication platforms serve as the labor markets, supply chains, and social infrastructure of organized cybercrime. Motoyama, McCoy, Levchenko, Savage, and Voelker (2011) conducted one of the earliest large-scale analyses of underground forum ecosystems, documenting the specialized markets in which actors buy and sell stolen data, exploit code, botnet access, and money laundering services. The trust and reputation systems that have developed within these markets — including escrow services, vendor ratings, and dispute resolution mechanisms — mirror legitimate marketplace institutions and provide the social infrastructure that enables transactions between anonymous actors who have no basis for personal trust.

The Role of Social Networks and Recruitment

Entry into cybercrime is mediated by social networks that provide the knowledge, tools, and opportunities necessary for offending. Holt and Kilger (2012) documented how participation in online hacking communities serves both an educational and a socializing function, transmitting technical skills and criminal know-how while also providing the subcultural norms, rationalizations, and social rewards that sustain offending careers. Décary-Hétu and Dupont (2012) applied social network analysis to underground forums and found that successful cybercriminals occupied structurally advantageous positions within communication networks, with high betweenness centrality predicting both criminal productivity and longevity.

Recruitment into organized cybercrime operations follows multiple pathways. Some offenders are recruited directly from legitimate technology employment, drawn by the prospect of substantially higher earnings from criminal activity. Others transition from low-level cyber-deviance — gaming cheats, account theft, small-scale fraud — into more serious offending as they develop skills and network connections. Lusthaus and Varese (2021) found that geographic proximity and face-to-face social ties remained important for cybercrime organization despite the ostensibly borderless nature of digital offending, with many criminal groups recruiting from local social networks and maintaining offline operational components alongside their digital activities.

The pipeline from online gaming and hacking subcultures into criminal offending has particular implications for juvenile justice policy. The United Kingdom’s National Crime Agency has documented cases of teenagers recruited through gaming platforms into DDoS-for-hire services and initial access brokerage, entering criminal careers through activities that participants initially frame as competitive gaming or harmless technical experimentation. Diversionary programs such as the NCA’s Cyber Choices initiative attempt to redirect young people with technical aptitude away from criminal pathways and toward legitimate cybersecurity careers, reflecting a recognition that early intervention in the recruitment pipeline may be more effective than post-hoc prosecution.

Theoretical Perspectives on Cybercrime Offending

Routine Activities and Rational Choice Approaches

Criminological theories originally developed to explain traditional offending have been applied to cybercrime with varying degrees of success. Routine activities theory (Cohen & Felson, 1979) — which holds that crime occurs when a motivated offender encounters a suitable target in the absence of a capable guardian — has been adapted to digital environments by reconceptualizing each element for online interaction. Yar (2005) argued that the theory translates imperfectly to cyberspace, where the convergence of offender and target occurs virtually rather than physically, where “guardianship” encompasses technical security measures alongside human monitoring, and where the spatial and temporal assumptions embedded in routine activities theory require fundamental revision.

Despite these conceptual challenges, empirical applications of routine activities theory to cybercrime have produced consistent findings. Holt and Bossler (2008) found that online routine activities — time spent online, types of online activities, exposure to risky situations — predicted cybercrime victimization in ways analogous to how offline routine activities predict traditional victimization. Pratt, Holtfreter, and Reisig (2010) reported that routine activities variables explained a significant share of variation in online fraud victimization. The theory’s practical value lies in its orientation toward situational prevention: if cybercrime depends on the convergence of motivated offenders, suitable targets, and absent guardians, then reducing victimization requires interventions that make targets less suitable (hardening defenses), increase guardianship (improving monitoring and detection), or disrupt the environments in which convergence occurs (platform design, internet governance).

Rational choice theory has been applied to cybercrime decision-making with particular attention to the risk-reward calculus that potential offenders face. The perception of low detection risk is a recurring theme in offender interviews and self-report studies. Maimon, Alper, Sobesto, and Cukier (2014) conducted an experimental study using honeypot systems to examine how the presence of warning banners affected unauthorized access attempts, finding that some forms of deterrence messaging reduced intrusion duration but did not eliminate intrusion attempts. The finding is consistent with a bounded rationality model in which offenders respond to proximate cues about detection risk but do not conduct systematic risk assessments before offending — a pattern with implications for both deterrence policy and the design of technical countermeasures.

Subcultural and Learning Theories

Subcultural and social learning theories have provided productive frameworks for understanding how individuals acquire the techniques, attitudes, and rationalizations that support cybercrime participation. Sutherland’s differential association theory, which holds that criminal behavior is learned through interaction with others who define criminal activity favorably, applies with particular clarity to online hacking communities where participants share technical knowledge, celebrate successful exploits, and develop collective norms that normalize unauthorized access and data theft. Holt (2007) documented how participation in hacker subcultures transmitted both technical skills and ideological justifications — including the “information wants to be free” ethos — that facilitated entry into criminal activity.

Akers’ social learning theory, which extends differential association to include imitation, reinforcement, and the balance of definitions favorable and unfavorable to criminal conduct, has been tested empirically in cybercrime contexts. Bossler and Holt (2010) found that association with peers who engaged in cyber-deviance was a strong predictor of an individual’s own cyber offending, even after controlling for self-control and other individual-level variables. Skinner and Fream (1997), in one of the earliest quantitative studies of computer crime among college students, reported that social learning variables — particularly differential association and definitions favorable to offending — explained more variance in computer crime participation than any other theoretical framework tested.

The online environments through which cybercrime is learned and transmitted add a distinctive dimension to subcultural analysis. Unlike traditional criminal subcultures that form through geographic proximity, cybercrime subcultures coalesce in digital spaces — forums, chat channels, encrypted messaging groups — that permit participation across geographic boundaries and enable rapid dissemination of technical knowledge. Steinmetz (2015) applied Bourdieu’s concept of cultural capital to hacker subcultures, arguing that technical skill, specialized knowledge, and hacking accomplishments function as forms of subcultural capital that confer status and influence within these communities. The convertibility of subcultural capital into criminal opportunity — demonstrated expertise attracts recruitment offers, generates reputation that facilitates trust in underground markets, and provides access to exclusive resources — creates incentive structures that sustain participation even in the absence of immediate financial reward.

Conclusion

The population of cybercrime offenders is far more diverse than early stereotypes suggested, encompassing individuals across a wide range of ages, socioeconomic backgrounds, skill levels, and motivational orientations. Financially motivated offending dominates by volume and impact, driven by a professionalized criminal ecosystem that has lowered barriers to entry and created specialized roles for actors at every level of technical sophistication. Ideological, expressive, and personal motivations account for substantial additional offending that differs in character and consequence from profit-driven cybercrime. Organizational structures range from individual actors through loosely networked collaborations to sophisticated criminal enterprises that mirror legitimate business models.

Theoretical perspectives from traditional criminology — routine activities theory, rational choice approaches, social learning theory — have been adapted to cybercrime with productive if imperfect results. The unique features of digital environments — perceived anonymity, physical distance from victims, global reach, and the availability of criminal tools and services through underground markets — create conditions that existing theories capture partially but do not fully explain. The continued development of offender-focused cybercrime research depends on methodological innovation to access the hidden populations that current data sources underrepresent, and on theoretical integration that synthesizes insights from criminology, computer science, psychology, and organizational sociology into frameworks adequate to the complexity of digital offending.

References

  1. Aiken, M., McMahon, C., Haughton, C., O’Neill, L., & O’Carroll, E. (2016). A consideration of the social impact of cybercrime: Examples from hacking, piracy, and child abuse material online. Contemporary Social Science, 11(4), 373–391. https://doi.org/10.1080/21582041.2015.1117648
  2. Bandura, A. (1999). Moral disengagement in the perpetration of inhumanities. Personality and Social Psychology Review, 3(3), 193–209. https://doi.org/10.1207/s15327957pspr0303_3
  3. Bossler, A. M., & Holt, T. J. (2010). The effect of self-control on victimization in the cyberworld. Journal of Criminal Justice, 38(3), 227–236. https://doi.org/10.1016/j.jcrimjus.2010.03.001
  4. Buckels, E. E., Trapnell, P. D., & Paulhus, D. L. (2014). Trolls just want to have fun. Personality and Individual Differences, 67, 97–102. https://doi.org/10.1016/j.paid.2014.01.016
  5. Cappelli, D. M., Moore, A. P., & Trzeciak, R. F. (2012). The CERT guide to insider threats: How to prevent, detect, and respond to information technology crimes. Addison-Wesley.
  6. Chua, Y. T., & Holt, T. J. (2016). A cross-national examination of the techniques of neutralization to account for hacking behaviors. Victims & Offenders, 11(4), 534–555. https://doi.org/10.1080/15564886.2015.1121944
  7. Cohen, L. E., & Felson, M. (1979). Social change and crime rate trends: A routine activity approach. American Sociological Review, 44(4), 588–608. https://doi.org/10.2307/2094589
  8. Décary-Hétu, D., & Dupont, B. (2012). The social network of hackers. Global Crime, 13(3), 160–175. https://doi.org/10.1080/17440572.2012.702523
  9. Federal Bureau of Investigation. (2024). Internet Crime Complaint Center 2023 annual report. U.S. Department of Justice. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf
  10. Gill, P., Corner, E., Conway, M., Thornton, A., Bloom, M., & Horgan, J. (2017). Terrorist use of the Internet by the numbers. Criminology & Public Policy, 16(1), 99–117. https://doi.org/10.1111/1745-9133.12249
  11. Gottfredson, M. R., & Hirschi, T. (1990). A general theory of crime. Stanford University Press.
  12. Holt, T. J. (2007). Subcultural evolution? Examining the influence of on- and off-line experiences on deviant subcultures. Deviant Behavior, 28(2), 171–198. https://doi.org/10.1080/01639620601131065
  13. Holt, T. J., & Bossler, A. M. (2008). Examining the applicability of lifestyle-routine activities theory for cybercrime victimization. Deviant Behavior, 30(1), 1–25. https://doi.org/10.1080/01639620701876577
  14. Holt, T. J., Bossler, A. M., & May, D. C. (2012). Low self-control, deviant peer associations, and juvenile cyberdeviance. American Journal of Criminal Justice, 37(3), 378–395. https://doi.org/10.1007/s12103-011-9117-3
  15. Holt, T. J., Burruss, G. W., & Bossler, A. M. (2019). An examination of the factors associated with the perceived risk of cybercrime victimization. Deviant Behavior, 40(12), 1494–1510. https://doi.org/10.1080/01639625.2018.1520268
  16. Holt, T. J., & Kilger, M. (2012). Know your enemy: The social dynamics of hacking. The Honeynet Project. https://www.honeynet.org/papers/socialdynamics/
  17. Hutchings, A., & Chua, Y. T. (2017). Gendering cybercrime. In T. J. Holt (Ed.), Cybercrime through an interdisciplinary lens (pp. 167–188). Routledge.
  18. Insikt Group. (2020). North Korea’s Lazarus Group and criminal revenue generation. Recorded Future.
  19. Jordan, T., & Taylor, P. (2004). Hacktivism and cyberwars: Rebels with a cause? Routledge.
  20. Leukfeldt, R., Kleemans, E. R., & Stol, W. P. (2017). Cybercriminal networks, social ties, and online forums: Social ties versus digital ties within phishing and malware networks. British Journal of Criminology, 57(3), 704–722. https://doi.org/10.1093/bjc/azw009
  21. Lusthaus, J. (2018). Industry of anonymity: Inside the business of cybercrime. Harvard University Press.
  22. Lusthaus, J., & Varese, F. (2021). Offline and local: The hidden face of cybercrime. Policing: A Journal of Policy and Practice, 15(1), 4–14. https://doi.org/10.1093/police/paz042
  23. Maimon, D., Alper, M., Sobesto, B., & Cukier, M. (2014). Restrictive deterrent effects of a warning banner in an attacked computer system. Criminology, 52(1), 33–59. https://doi.org/10.1111/1745-9125.12028
  24. Marcum, C. D., Higgins, G. E., & Ricketts, M. L. (2014). Juveniles and cyberstalking in the United States: An analysis of theoretical predictors of patterns of online perpetration. International Journal of Cyber Criminology, 8(1), 21–35.
  25. McGlynn, C., Rackley, E., & Houghton, R. (2017). Beyond ‘revenge porn’: The continuum of image-based sexual abuse. Feminist Legal Studies, 25(1), 25–46. https://doi.org/10.1007/s10691-017-9343-2
  26. Motoyama, M., McCoy, D., Levchenko, K., Savage, S., & Voelker, G. M. (2011). An analysis of underground forums. Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement (pp. 71–80). https://doi.org/10.1145/2068816.2068824
  27. Pratt, T. C., Holtfreter, K., & Reisig, M. D. (2010). Routine online activity and internet fraud targeting: Extending the generality of routine activity theory. Journal of Research in Crime and Delinquency, 47(3), 267–296. https://doi.org/10.1177/0022427810365903
  28. Seigfried-Spellar, K. C., & Lankford, C. M. (2018). Personality and online environment factors differ for posters, trolls, lurkers, and confessors on Yik Yak. Personality and Individual Differences, 124, 54–56. https://doi.org/10.1016/j.paid.2017.11.049
  29. Seto, M. C. (2013). Internet sex offenders. American Psychological Association.
  30. Shaw, E. D., Ruby, K. G., & Post, J. M. (1998). The insider threat to information systems: The psychology of the dangerous insider. Security Awareness Bulletin, 2(98), 1–10.
  31. Skinner, W. F., & Fream, A. M. (1997). A social learning theory analysis of computer crime among college students. Journal of Research in Crime and Delinquency, 34(4), 495–518. https://doi.org/10.1177/0022427897034004005
  32. Steinmetz, K. F. (2015). Craft(y)ness: An ethnographic study of hacking. British Journal of Criminology, 55(1), 125–145. https://doi.org/10.1093/bjc/azu061
  33. Turgeman-Goldschmidt, O. (2005). Hackers’ accounts: Hacking as a social entertainment. Social Science Computer Review, 23(1), 8–23. https://doi.org/10.1177/0894439304271529
  34. Wolak, J., Finkelhor, D., Mitchell, K. J., & Ybarra, M. L. (2008). Online “predators” and their victims: Myths, realities, and implications for prevention and treatment. American Psychologist, 63(2), 111–128. https://doi.org/10.1037/0003-066X.63.2.111
  35. Yar, M. (2005). The novelty of ‘cybercrime’: An assessment in light of routine activity theory. European Journal of Criminology, 2(4), 407–427. https://doi.org/10.1177/1477370805056056

Related Articles

  • Cybercrime Typologies
  • Cybercrime Victimization
  • Cybercrime and Organized Crime
  • Online Radicalization and Extremism
  • Cybercrime Prevention and Digital Literacy




Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube
  • Criminology
    • Clinical Criminology
    • Comparative Criminology
    • Crime as a Social Phenomenon
    • Crime in Criminology
    • Criminology and Criminal Justice Careers
    • Criminology and Criminal Justice Degrees
    • Criminology and Criminal Justice Education
    • Criminology and Public Policy
    • Criminology as Social Science
    • Cyber Criminology
      • Algorithmic Bias in Criminal Justice
      • Artificial Intelligence and Crime
      • Big Data and Criminal Justice
      • Body-Worn Cameras and Policing
      • Child Sexual Exploitation Online
      • Corporate Cybercrime and Data Breaches
      • Crime in the Digital Age
      • Cryptocurrency and Crime
      • Cyberbullying in America
      • Cybercrime and Organized Crime
      • Cybercrime and the Dark Web
      • Cybercrime Investigation and Digital Forensics
      • Cybercrime Offenders and Motivations
      • Cybercrime Prevention and Digital Literacy
      • Cybercrime Reporting and Statistics in America
      • Cybercrime Typologies
      • Cybercrime Victimization
      • Cyberstalking and Online Harassment
      • Cyberterrorism and National Security
      • Digital Criminology and Public Policy
      • Digital Divide and Crime
      • Digital Evidence in American Courts
      • Digital Society and Crime
      • Digital Surveillance and Crime Control
      • Digital Vigilantism in America
      • Emerging Cybercrime Threats
      • Facial Recognition and Law Enforcement
      • Federal Cybercrime Law in America
      • Hacking and Unauthorized Access
      • Identity Theft in America
      • International Cybercrime Cooperation
      • Malware and Ransomware Attacks
      • Nation-State Cyberattacks and U.S. Security
      • Online Drug Markets
      • Online Fraud and Financial Cybercrime
      • Online Radicalization and Extremism
      • Phishing and Social Engineering
      • Platform Accountability and Online Harm
      • Privacy, Civil Liberties, and Digital Crime Control
      • Sextortion and Image-Based Abuse
      • Social Media and Criminal Behavior
      • The Dark Web and Digital Crime
    • History of Criminology
    • Psychology and Criminology
    • Sociology and Criminology
    • Urban Criminology