• Skip to main content
  • Skip to primary sidebar

Criminal Justice

iResearchNet




Criminal Justice > Criminology > Cyber Criminology > Cybercrime Victimization

Cybercrime Victimization




Cybercrime VictimizationCybercrime victimization encompasses the experiences, consequences, and risk factors associated with being targeted by criminal acts conducted through or against digital systems. Within the broader study of Cyber Criminology, victimization research addresses questions that mirror those in traditional victimology — who is victimized, how often, with what consequences, and through what mechanisms — while confronting measurement challenges, reporting dynamics, and harm typologies that differ substantially from those associated with conventional crime. National victimization data from the Bureau of Justice Statistics, the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3), and industry surveys collectively document a victimization landscape of extraordinary scale, with hundreds of millions of Americans exposed to some form of cyber-enabled or cyber-dependent criminal conduct annually. This article examines the prevalence and measurement of cybercrime victimization in the United States, analyzes the demographic and behavioral risk factors that shape victimization patterns within Criminology, and assesses the financial, psychological, and social consequences that victimization produces.

Introduction

The study of cybercrime victimization occupies an increasingly central position in both criminological research and criminal justice policy. As digital technology has become embedded in virtually every dimension of American economic and social life, exposure to cybercrime has expanded from a risk concentrated among early technology adopters to a near-universal condition. The IC3 received over 880,000 complaints in 2023, with reported losses exceeding $12.5 billion — figures that represent substantial increases over prior years and that almost certainly understate actual victimization given the well-documented reluctance of both individuals and organizations to report cyber offenses to law enforcement (Federal Bureau of Investigation, 2024).

Despite the scale of the problem, cybercrime victimization remains poorly measured relative to traditional crime categories. The National Crime Victimization Survey (NCVS), the primary instrument for measuring criminal victimization in the United States, was designed for interpersonal and property crime and incorporates only limited measures of identity theft and online fraud. No equivalent national survey captures the full range of cyber victimization — from phishing and malware infection through cyberstalking, sextortion, and data breach exposure. This measurement gap has constrained theoretical development, as scholars lack the representative data necessary to test competing explanations of victimization risk and to assess the effectiveness of prevention interventions.




This article surveys the current state of knowledge about cybercrime victimization, organized around six themes: the measurement landscape and its limitations, prevalence estimates across major offense categories, demographic and behavioral risk factors, the consequences of victimization, reporting behavior and its determinants, and the theoretical frameworks that scholars have applied to explain patterns of cyber victimization.

Measurement of Cybercrime Victimization

National Surveys and Official Data Sources

The measurement of cybercrime victimization in the United States relies on a patchwork of data sources, none of which individually captures the full scope of the problem. The NCVS, administered by the Bureau of Justice Statistics (BJS) to approximately 240,000 individuals annually, includes a supplemental module on identity theft that was first fielded in 2008 and has been repeated periodically. The Identity Theft Supplement (ITS) provides the most methodologically rigorous population-based estimates of identity theft victimization, documenting that approximately 23.9 million Americans — roughly 9 percent of the population aged sixteen and older — experienced some form of identity theft in 2021, the most recent year for which data are available (Harrell, 2023). However, the ITS captures only identity theft and does not measure other forms of cyber victimization.

The IC3 provides the most detailed data on the distribution of cybercrime complaints across offense types, but its data reflect reported rather than experienced victimization and are subject to severe selection effects. Complainants self-select into the IC3 reporting system, and the demographic profile of complainants — disproportionately older, wealthier, and more educated than the general population — likely reflects who knows about the IC3 and is motivated to file a complaint rather than who is actually victimized. Anderson, Barton, Böhme, Clayton, van Eeten, Levi, Moore, and Savage (2019) estimated that fewer than 15 percent of cybercrime victims report their experiences to any law enforcement agency, and that the proportion reporting specifically to the IC3 is far lower.

Industry surveys provide complementary data that is useful but methodologically limited. The Verizon Data Breach Investigations Report (DBIR), the Ponemon Institute’s annual Cost of a Data Breach study, and surveys by the Cybersecurity and Infrastructure Security Agency (CISA) document organizational victimization with varying degrees of rigor. These surveys tend to oversample large organizations with dedicated security teams, potentially understating victimization rates among small and medium enterprises that lack the monitoring capacity to detect breaches. The absence of a unified, population-based cybercrime victimization survey remains the most significant gap in American criminal justice data infrastructure.

The Dark Figure and Underreporting Dynamics

The dark figure of cybercrime — the difference between actual and recorded victimization — is widely acknowledged to exceed that of virtually any traditional crime category. Underreporting operates through multiple mechanisms. Many victims are unaware that they have been victimized: data breaches may not be detected for months or years, malware infections may operate silently, and financial losses may be absorbed into general account activity without being recognized as fraudulent. The Ponemon Institute (2024) reported a mean time to identify a data breach of 204 days across its global sample, meaning that organizational victims may be unaware of their status for nearly seven months after initial compromise.

Among victims who are aware of their victimization, reporting rates remain low for reasons that parallel and extend the underreporting dynamics observed in traditional crime. Perceived futility — the belief that law enforcement cannot or will not investigate — is the most commonly cited reason for non-reporting in survey research. Holt and Bossler (2016) found that fewer than 10 percent of cybercrime victims in their college student sample reported their experiences to police, with most citing the belief that nothing would be done. Organizational victims face additional disincentives: public disclosure of a breach may trigger regulatory investigations, shareholder lawsuits, and reputational damage that exceeds the cost of the breach itself. Although mandatory breach notification laws — now enacted in all fifty states — have increased disclosure of data breaches, they apply only to specific categories of incidents and do not address the broader underreporting of cybercrime to law enforcement.

The consequences of underreporting extend beyond measurement accuracy. When cybercrime victimization is systematically undercounted, the result is misallocation of law enforcement resources, underestimation of the problem’s severity in policy discussions, and inadequate support services for victims. The gap between the scale of cybercrime victimization documented in industry surveys and the comparatively modest figures that appear in official crime statistics creates a misleading picture that may reduce political urgency around cybercrime prevention and response.

Prevalence and Patterns of Victimization

Individual Victimization Across Offense Types

Individual cybercrime victimization spans a broad spectrum of offense types with varying prevalence rates. Identity theft is the most commonly measured category, with the BJS Identity Theft Supplement estimating that 23.9 million persons experienced identity theft in 2021. Within this category, existing account fraud — unauthorized use of an existing credit card, bank account, or other financial account — was by far the most prevalent form, affecting approximately 16.5 million persons. New account fraud, in which offenders open new accounts using stolen personal information, affected roughly 5.7 million persons and was associated with substantially higher average losses and longer resolution times (Harrell, 2023).

Phishing and social engineering victimization is difficult to measure precisely because many recipients of phishing messages do not recognize them as criminal attempts. The Anti-Phishing Working Group (APWG) documented over 4.7 million phishing attacks globally in 2023, a figure that captures reported attacks against organizational targets and substantially undercounts attacks against individuals. Survey research suggests that a significant minority of internet users — estimates range from 5 to 30 percent depending on the definition employed — have clicked on a phishing link or provided information to a fraudulent website at some point, though most do not suffer financial loss as a result (Hong, 2012).

Interpersonal cyber victimization — including cyberstalking, cyberbullying, online harassment, and image-based sexual abuse — affects a smaller but still substantial share of the population. The BJS Supplemental Victimization Survey estimated that approximately 3.4 million Americans experienced stalking in 2019, with a significant and growing proportion of stalking incidents involving technology-facilitated conduct including unwanted contacts through social media, email monitoring, and GPS tracking (Langton, Planty, & Sandholtz, 2023). The Pew Research Center’s surveys have consistently found that approximately 40 percent of American adults report experiencing some form of online harassment, ranging from name-calling and embarrassment to physical threats and sustained harassment campaigns, with younger adults, women, and racial minorities reporting disproportionate exposure to severe forms.

Organizational Victimization

Organizations of all sizes and sectors are victimized by cybercrime, though victimization patterns vary substantially by organizational characteristics. The Verizon DBIR’s 2024 analysis of over 30,000 security incidents found that financially motivated attacks accounted for approximately 95 percent of breaches, with ransomware and extortion involved in roughly one-third of all incidents. Small businesses — defined as organizations with fewer than 1,000 employees — experienced a higher rate of certain attack types relative to their security resources, though large enterprises reported higher absolute numbers of incidents reflecting their larger attack surfaces and more extensive monitoring capabilities.

Healthcare organizations have emerged as particularly frequent targets, driven by the high value of medical records on underground markets and the operational urgency that makes healthcare providers more likely to pay ransoms. The Department of Health and Human Services’ Office for Civil Rights documented 725 major healthcare data breaches affecting over 133 million records in 2023 alone. Educational institutions, state and local governments, and critical infrastructure operators similarly face elevated victimization rates, reflecting their combination of valuable data, limited cybersecurity budgets, and legacy technology infrastructure.

The cost of organizational victimization extends beyond direct financial losses. The Ponemon Institute’s 2024 Cost of a Data Breach study estimated the average cost of a data breach at $4.88 million globally, incorporating direct costs (detection, notification, remediation), indirect costs (business disruption, lost customers), and regulatory penalties. For heavily regulated industries such as healthcare and financial services, regulatory fines and compliance costs can exceed the direct costs of the breach itself. These figures capture only the costs to the victimized organization and do not account for the downstream harm to individuals whose personal information is compromised — a limitation that systematically understates the total social cost of organizational cybercrime victimization.

Risk Factors for Cybercrime Victimization

Demographic Risk Factors

Demographic patterns of cybercrime victimization diverge from those observed in traditional crime in several important respects. While traditional property and violent crime victimization is concentrated among young, low-income, urban, and minority populations, cybercrime victimization shows a more complex demographic profile that varies by offense type. For financial cybercrime, age operates differently than in street crime: older adults are disproportionately victimized by certain fraud types — particularly romance scams, tech support fraud, and investment scams — while younger adults experience higher rates of account compromise, social media-based fraud, and identity theft. The IC3’s 2023 data showed that complainants over age sixty reported the highest total losses of any age group ($3.4 billion), driven by especially high losses in investment fraud and tech support schemes.

Income and education present a paradoxical relationship with cyber victimization. Higher-income individuals have greater financial exposure and engage in more online transactions, increasing their attack surface for financial cybercrime. But they also tend to have greater awareness of cyber threats and more resources for protective measures. The BJS Identity Theft Supplement found that identity theft victimization rates were modestly higher among individuals with household incomes above $75,000 compared to those below $25,000, a pattern that reverses the income gradient observed for most traditional crime types (Harrell, 2023). Education shows a similar pattern: college-educated respondents reported higher identity theft rates, likely reflecting both greater online activity and better recognition of victimization events.

Gender differences in cyber victimization mirror some traditional patterns while diverging in others. Women are disproportionately victimized by cyberstalking, image-based sexual abuse, and online sexual harassment, while men report higher rates of financial fraud victimization and are more likely to be targeted by advance-fee and investment scams. Racial and ethnic differences have received less systematic attention, but available evidence suggests that Black and Hispanic Americans experience higher rates of certain cyber victimization types while being less likely to report to law enforcement — a pattern that parallels reporting disparities observed across the criminal justice system more broadly.

Behavioral and Situational Risk Factors

Individual online behavior constitutes the strongest and most consistent predictor of cybercrime victimization across studies. Time spent online, the range and riskiness of online activities, password management practices, and willingness to share personal information each contribute independently to victimization risk. Holt and Bossler (2008) found that online routine activities — particularly time spent in online chat rooms and engagement with deviant online content — predicted victimization by online harassment even after controlling for demographic variables. Pratt, Holtfreter, and Reisig (2010) reported that online purchasing frequency and the number of financial accounts maintained online predicted fraud victimization, consistent with routine activities theory’s prediction that exposure to potential offenders increases victimization risk.

The concept of “cyber-hygiene” — the set of practices individuals adopt to protect themselves online, including use of strong passwords, multi-factor authentication, software updates, and skepticism toward unsolicited communications — has been studied as a protective factor against victimization. Empirical evidence for the protective effect of cyber-hygiene is mixed. While some practices clearly reduce specific risks (multi-factor authentication dramatically reduces account takeover), the overall relationship between self-reported security behavior and victimization experience is weaker than might be expected, reflecting the fact that many victimization events exploit vulnerabilities beyond the individual victim’s control — compromised third-party databases, zero-day software vulnerabilities, and sophisticated social engineering campaigns that defeat even security-conscious targets.

Organizational victims’ risk factors are better understood than individual ones, reflecting the more systematic data collection that occurs in enterprise security environments. The Verizon DBIR has consistently identified human factors — particularly credential reuse, susceptibility to phishing, and misconfiguration of cloud services — as the dominant contributors to organizational breaches. Patch management failures, insufficient network segmentation, and inadequate logging and monitoring capabilities create the technical conditions that enable intrusions, while organizational factors such as security budget constraints, leadership disengagement from cybersecurity, and cultural tolerance for workarounds contribute to persistent vulnerability.

Consequences of Cybercrime Victimization

Financial Impact

The financial consequences of cybercrime victimization range from trivial to devastating and are distributed unevenly across victim populations. For individual victims, the IC3’s 2023 data documented a mean reported loss of approximately $14,000 per complaint, but this figure masks enormous variance. The majority of phishing and social engineering victims suffer relatively modest direct losses — often less than $500 — while victims of investment fraud, romance scams, and business email compromise report losses in the tens or hundreds of thousands of dollars. Older victims are particularly vulnerable to catastrophic financial loss: the IC3 documented over 100 cases in 2023 in which individual victims lost more than $1 million, with the majority involving victims over age sixty targeted by cryptocurrency investment schemes.

Beyond direct financial losses, victims incur substantial indirect costs including time spent resolving fraud, fees for credit monitoring services, costs of replacing compromised documents, and in severe identity theft cases, ongoing difficulties obtaining credit, employment, and housing. The BJS Identity Theft Supplement estimated that victims spent a median of four hours resolving identity theft incidents, with the distribution heavily right-skewed: approximately 10 percent of victims spent forty hours or more on resolution activities (Harrell, 2023). For victims whose stolen identities are used to commit crimes — so-called “criminal identity theft” — the consequences can include wrongful arrest, criminal records in the victim’s name, and protracted legal battles to establish innocence.

The distributional consequences of financial cybercrime victimization warrant attention from a justice perspective. While higher-income victims suffer larger absolute losses, lower-income victims experience proportionally greater financial harm relative to their resources. A $2,000 fraud loss may represent an inconvenience for a high-income household but a financial catastrophe for a household living paycheck to paycheck. Federal reimbursement protections — including the Fair Credit Billing Act’s $50 liability cap for unauthorized credit card charges and the Electronic Fund Transfer Act’s protections for debit card fraud — provide important but incomplete safeguards, and victims who are unaware of their rights or who fail to report within statutory timeframes may bear the full cost of their victimization.

Psychological and Social Consequences

The psychological impact of cybercrime victimization has received increasing research attention as scholars have recognized that financial loss statistics alone fail to capture the full burden of cyber victimization. Cross, Richards, and Smith (2016) documented elevated rates of anxiety, depression, shame, and diminished trust among online fraud victims, with psychological distress persisting long after financial losses were resolved. The emotional impact was most severe among victims of interpersonal cybercrimes — cyberstalking, image-based abuse, and romance fraud — where the violation of trust and the intimate nature of the harm produced psychological consequences analogous to those observed in victims of contact sexual offenses and domestic violence.

Cyberstalking victimization produces a particularly well-documented pattern of psychological harm. Victims report pervasive fear, hypervigilance, disruption of daily routines, social withdrawal, and in severe cases, symptoms consistent with post-traumatic stress disorder (Dreßing, Bailer, Anders, Wagner, & Gallas, 2014). The persistence and inescapability of technology-facilitated stalking — which can follow victims across platforms, devices, and physical locations through GPS monitoring — distinguishes it from traditional stalking in ways that intensify the psychological burden. Victims may feel that no space, digital or physical, is safe from intrusion, producing a chronic state of threat that erodes psychological well-being over time.

Image-based sexual abuse imposes distinctive psychological harms that reflect the permanent, replicable, and uncontrollable nature of digital content. Victims describe persistent anxiety about the continued circulation of intimate images, shame and self-blame, damage to personal and professional relationships, and in some cases, suicidal ideation (Bates, 2017). The inability to ensure complete removal of distributed images — once content is shared online, copies may proliferate across platforms, mirror sites, and private collections — means that victims face the ongoing possibility of re-victimization through redistribution, creating a form of chronic harm without parallel in most traditional crime categories.

Reporting Behavior and Criminal Justice Response

Determinants of Victim Reporting

The decision to report cybercrime victimization to law enforcement is shaped by a constellation of factors that produce the chronic underreporting documented across virtually all data sources. Perceived seriousness of the offense, perceived likelihood of a useful law enforcement response, awareness of reporting mechanisms, and the emotional burden of the reporting process itself all influence reporting decisions. Van de Weijer, Leukfeldt, and Bernasco (2019) found that financial loss magnitude was the strongest predictor of reporting among cybercrime victims, with victims who suffered larger losses substantially more likely to contact police. However, even among victims with losses exceeding $10,000, reporting rates remained below 50 percent, suggesting that financial loss alone is insufficient to overcome the barriers to reporting.

Institutional factors compound individual-level barriers. Many local police departments lack the training, technology, and jurisdictional authority to investigate cybercrimes effectively, particularly those involving offenders in other states or countries. Victims who do report to local police frequently describe unsatisfying encounters in which officers acknowledge the complaint but communicate — explicitly or implicitly — that investigation is unlikely. The fragmentation of cybercrime reporting across multiple federal agencies (IC3, FTC, CISA, Secret Service) creates confusion about where to report and the perception that complaints disappear into bureaucratic systems without producing investigative action.

The consequences of low reporting rates extend beyond individual cases. When law enforcement agencies lack complete information about the prevalence and distribution of cybercrime, their capacity to allocate investigative resources effectively is compromised. Patterns that might be detectable across aggregated complaints — serial offenders, emerging fraud schemes, geographic clusters of victimization — remain invisible when the majority of incidents go unreported. Efforts to improve reporting rates — including the IC3’s simplified online complaint system, the FTC’s IdentityTheft.gov portal, and public awareness campaigns — have produced incremental gains but have not fundamentally altered the underreporting dynamic.

Victim Services and Support

The criminal justice system’s support infrastructure for cybercrime victims has developed unevenly and remains substantially less mature than services available to victims of traditional violent and property crime. The Victims of Crime Act (VOCA) provides federal funding for victim services, but the distribution of VOCA funds has historically favored programs serving victims of violent crime, with cybercrime victims receiving a comparatively small share of available resources. Identity theft victims can access specialized assistance through the FTC’s identity theft recovery process and through identity theft affidavit procedures that facilitate disputes with creditors, but these services address only one category of cyber victimization.

Victim advocacy organizations have expanded their scope to include cybercrime, but coverage remains inconsistent. The Cyber Civil Rights Initiative provides support for victims of image-based sexual abuse, while organizations such as the Identity Theft Resource Center offer counseling and recovery assistance for identity theft victims. However, many cybercrime victims — particularly those targeted by phishing, investment fraud, and romance scams — lack access to dedicated support services and must rely on general-purpose victim assistance programs that may not be equipped to address the distinctive dynamics of cyber victimization. The development of specialized cyber victim support services represents an important gap in the American criminal justice system’s response to digital crime.

Theoretical Frameworks for Understanding Cyber Victimization

Routine Activities and Lifestyle-Exposure Theories

Theoretical explanations of cybercrime victimization have drawn most heavily on routine activities theory and its close relative, lifestyle-exposure theory. As adapted for digital environments, these frameworks propose that cyber victimization results from the convergence of motivated offenders, suitable targets, and absent guardians in online spaces — with each element reconceptualized for the distinctive features of digital interaction. Suitable targets in cyberspace include individuals with valuable digital assets (financial accounts, personal data, social media influence), organizations with exploitable systems, and any internet user who can be deceived into providing information or clicking malicious links. Guardianship encompasses both technical protections (firewalls, encryption, authentication systems) and human oversight (security awareness, organizational monitoring, platform moderation).

Yar (2005) raised important questions about whether routine activities theory translates effectively to cyberspace, where the spatial and temporal convergence that the theory assumes operates differently than in physical environments. Online, offenders and targets need not occupy the same geographic space or even the same temporal frame — automated attacks can target thousands of victims simultaneously without the offender being “present” in any meaningful sense. Holt and Bossler (2008) responded by arguing that while the mechanics of convergence differ online, the core theoretical logic remains sound: individuals who engage in riskier online activities, spend more time in unguarded online environments, and present more attractive targets experience higher victimization rates. Their empirical findings supported this interpretation, establishing routine activities theory as the dominant framework for cybercrime victimization research.

Lifestyle-exposure theory contributes the additional insight that victimization risk is structured by the broader patterns of daily life that determine online exposure. Individuals whose work, social, and recreational activities are more extensively mediated by digital technology face greater exposure to potential offenders and more opportunities for victimization. Ngo and Paternoster (2011) demonstrated that lifestyle variables — including online shopping frequency, social media use, and engagement with online dating — predicted various forms of cyber victimization in a large sample of university students, supporting the theory’s core proposition that victimization is a function of lifestyle-generated exposure.

General Theory of Crime and Cybervulnerability

Gottfredson and Hirschi’s (1990) general theory of crime, which attributes both offending and victimization to low self-control, has been applied to cybercrime victimization with mixed results. The theory predicts that individuals with low self-control — characterized by impulsivity, risk-seeking, short time horizons, and insensitivity to others — are more likely to be victimized because they engage in risky behaviors, associate with deviant peers, and fail to take precautions against victimization. Bossler and Holt (2010) found that low self-control predicted several forms of cyber victimization, including harassment and malware infection, but the effect was modest and varied across victimization types.

The applicability of self-control theory to cybercrime victimization is limited by the fact that many cyber victims are targeted precisely because of careful, responsible online behavior rather than reckless risk-taking. A diligent employee who clicks a spear-phishing email crafted to impersonate their CEO, a cautious consumer who enters credit card information on a legitimate website that is subsequently breached, and a privacy-conscious individual whose data is compromised through a third-party database breach are all victimized through mechanisms that self-control theory cannot explain. Pratt, Turanovic, Fox, and Wright (2014) argued that self-control theory’s explanatory power declines as victimization events become less dependent on victim behavior and more dependent on offender capability and structural vulnerability — a pattern particularly pronounced in cybercrime, where many victimization pathways bypass individual behavior entirely.

Conclusion

Cybercrime victimization in the United States operates at a scale that existing measurement instruments capture only partially and that the criminal justice system addresses only incompletely. Hundreds of millions of Americans are exposed annually to some form of cyber-enabled criminal conduct, with financial, psychological, and social consequences that range from minor inconvenience to devastating harm. The risk factors for victimization are complex, reflecting interactions among demographic characteristics, online behaviors, technical vulnerability, and the evolving tactics of cybercriminal actors. Theoretical frameworks adapted from traditional victimology — particularly routine activities theory and lifestyle-exposure approaches — provide useful but incomplete explanations that must be supplemented by attention to the structural and technical dimensions of cyber vulnerability that operate independently of individual victim behavior.

The most pressing priorities for the field include the development of a population-based cybercrime victimization survey that captures the full range of cyber offenses, the expansion of victim services to address the distinctive needs of cybercrime victims, and the improvement of reporting systems to reduce the dark figure that currently renders the true scope of victimization invisible to policymakers and law enforcement. Progress on each front requires sustained investment and institutional coordination that has been slow to materialize, leaving a gap between the reality of cyber victimization and the criminal justice system’s capacity to measure, prevent, and respond to it.

References

  1. Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M. J. G., Levi, M., Moore, T., & Savage, S. (2019). Measuring the changing cost of cybercrime. In The 18th Annual Workshop on the Economics of Information Security. https://doi.org/10.17863/CAM.41598
  2. Bates, S. (2017). Revenge porn and mental health: A qualitative analysis of the mental health effects of revenge porn on female survivors. Feminist Criminology, 12(1), 22–42. https://doi.org/10.1177/1557085116654565
  3. Bossler, A. M., & Holt, T. J. (2010). The effect of self-control on victimization in the cyberworld. Journal of Criminal Justice, 38(3), 227–236. https://doi.org/10.1016/j.jcrimjus.2010.03.001
  4. Cross, C., Richards, K., & Smith, R. G. (2016). The reporting experiences and support needs of victims of online fraud. Trends and Issues in Crime and Criminal Justice, No. 518. Australian Institute of Criminology.
  5. Dreßing, H., Bailer, J., Anders, A., Wagner, H., & Gallas, C. (2014). Cyberstalking in a large sample of social network users: Prevalence, characteristics, and impact upon victims. Cyberpsychology, Behavior, and Social Networking, 17(2), 61–67. https://doi.org/10.1089/cyber.2012.0231
  6. Federal Bureau of Investigation. (2024). Internet Crime Complaint Center 2023 annual report. U.S. Department of Justice. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf
  7. Gottfredson, M. R., & Hirschi, T. (1990). A general theory of crime. Stanford University Press.
  8. Harrell, E. (2023). Victims of identity theft, 2021. Bureau of Justice Statistics, U.S. Department of Justice. https://bjs.ojp.gov/library/publications/victims-identity-theft-2021
  9. Holt, T. J., & Bossler, A. M. (2008). Examining the applicability of lifestyle-routine activities theory for cybercrime victimization. Deviant Behavior, 30(1), 1–25. https://doi.org/10.1080/01639620701876577
  10. Holt, T. J., & Bossler, A. M. (2016). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
  11. Hong, J. (2012). The state of phishing attacks. Communications of the ACM, 55(1), 74–81. https://doi.org/10.1145/2063176.2063197
  12. Langton, L., Planty, M., & Sandholtz, N. (2023). Stalking victimization, 2019. Bureau of Justice Statistics, U.S. Department of Justice. https://bjs.ojp.gov/library/publications/stalking-victimization-2019
  13. Ngo, F. T., & Paternoster, R. (2011). Cybercrime victimization: An examination of individual and situational level factors. International Journal of Cyber Criminology, 5(1), 773–793.
  14. Ponemon Institute. (2024). Cost of a data breach report 2024. IBM Security.
  15. Pratt, T. C., Holtfreter, K., & Reisig, M. D. (2010). Routine online activity and internet fraud targeting: Extending the generality of routine activity theory. Journal of Research in Crime and Delinquency, 47(3), 267–296. https://doi.org/10.1177/0022427810365903
  16. Pratt, T. C., Turanovic, J. J., Fox, K. A., & Wright, K. A. (2014). Self-control and victimization: A meta-analysis. Criminology, 52(1), 87–116. https://doi.org/10.1111/1745-9125.12030
  17. Van de Weijer, S. G. A., Leukfeldt, R., & Bernasco, W. (2019). Determinants of reporting cybercrime: A comparison between identity theft, consumer fraud, and hacking. European Journal of Criminology, 16(4), 486–508. https://doi.org/10.1177/1477370818773610
  18. Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
  19. Yar, M. (2005). The novelty of ‘cybercrime’: An assessment in light of routine activity theory. European Journal of Criminology, 2(4), 407–427. https://doi.org/10.1177/1477370805056056
  20. Yar, M., & Steinmetz, K. F. (2019). Cybercrime and society (3rd ed.). SAGE Publications.

Related Articles

  • Cybercrime Typologies
  • Cybercrime Offenders and Motivations
  • Identity Theft in America
  • Cybercrime Reporting and Statistics in America
  • Cybercrime Prevention and Digital Literacy




Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube
  • Criminology
    • Clinical Criminology
    • Comparative Criminology
    • Crime as a Social Phenomenon
    • Crime in Criminology
    • Criminology and Criminal Justice Careers
    • Criminology and Criminal Justice Degrees
    • Criminology and Criminal Justice Education
    • Criminology and Public Policy
    • Criminology as Social Science
    • Cyber Criminology
      • Algorithmic Bias in Criminal Justice
      • Artificial Intelligence and Crime
      • Big Data and Criminal Justice
      • Body-Worn Cameras and Policing
      • Child Sexual Exploitation Online
      • Corporate Cybercrime and Data Breaches
      • Crime in the Digital Age
      • Cryptocurrency and Crime
      • Cyberbullying in America
      • Cybercrime and Organized Crime
      • Cybercrime and the Dark Web
      • Cybercrime Investigation and Digital Forensics
      • Cybercrime Offenders and Motivations
      • Cybercrime Prevention and Digital Literacy
      • Cybercrime Reporting and Statistics in America
      • Cybercrime Typologies
      • Cybercrime Victimization
      • Cyberstalking and Online Harassment
      • Cyberterrorism and National Security
      • Digital Criminology and Public Policy
      • Digital Divide and Crime
      • Digital Evidence in American Courts
      • Digital Society and Crime
      • Digital Surveillance and Crime Control
      • Digital Vigilantism in America
      • Emerging Cybercrime Threats
      • Facial Recognition and Law Enforcement
      • Federal Cybercrime Law in America
      • Hacking and Unauthorized Access
      • Identity Theft in America
      • International Cybercrime Cooperation
      • Malware and Ransomware Attacks
      • Nation-State Cyberattacks and U.S. Security
      • Online Drug Markets
      • Online Fraud and Financial Cybercrime
      • Online Radicalization and Extremism
      • Phishing and Social Engineering
      • Platform Accountability and Online Harm
      • Privacy, Civil Liberties, and Digital Crime Control
      • Sextortion and Image-Based Abuse
      • Social Media and Criminal Behavior
      • The Dark Web and Digital Crime
    • History of Criminology
    • Psychology and Criminology
    • Sociology and Criminology
    • Urban Criminology