• Skip to main content
  • Skip to primary sidebar

Criminal Justice

iResearchNet




Criminal Justice > Criminology > Cyber Criminology > Malware and Ransomware Attacks

Malware and Ransomware Attacks




Malware and Ransomware AttacksMalware and ransomware attacks represent the technical backbone of modern cybercrime, providing the tools through which offenders compromise systems, exfiltrate data, encrypt files for extortion, and establish persistent access to victim networks. As a central concern within Cyber Criminology, malware encompasses any software designed to damage, disrupt, or gain unauthorized access to computer systems — a category that includes viruses, worms, trojans, spyware, adware, rootkits, keyloggers, and the ransomware variants that have come to dominate the contemporary threat landscape. Ransomware alone has evolved from a marginal nuisance into an industrial-scale criminal enterprise, with global payments exceeding $1.1 billion in 2023 according to blockchain analytics firm Chainalysis (2024). This article examines the technical taxonomy of malware, the evolution and economics of ransomware, the organizational and societal impacts of these attacks, and the legal, investigative, and defensive frameworks through which the United States and the broader field of Criminology address these threats.

Introduction

The history of malware tracks the history of networked computing itself. The first self-replicating programs appeared in the 1970s as academic experiments, and the first viruses designed to spread through personal computer systems emerged in the early 1980s. The Morris Worm of 1988 — which inadvertently disabled approximately 6,000 internet-connected computers, representing roughly ten percent of the network at the time — prompted the creation of the Computer Emergency Response Team (CERT) and catalyzed the first federal prosecution under the Computer Fraud and Abuse Act. In the decades since, malware has evolved in sophistication, diversity, and destructive potential, driven by the twin engines of criminal monetization and state-sponsored offensive capability.

The contemporary malware landscape is characterized by professionalization, specialization, and marketization. Criminal developers create and sell malware through underground markets, offering ransomware-as-a-service platforms, banking trojan subscriptions, and custom malware development services. The division of labor between malware developers, distributors, and operators has produced an ecosystem in which the individual deploying malware against a target may have no technical understanding of how the malware functions — they have simply purchased or rented a tool from a specialist. This industrialization has expanded the threat beyond the technically skilled to encompass any actor willing to invest in criminal tools, fundamentally reshaping the risk landscape for individuals, organizations, and governments.




Technical Taxonomy of Malware

Self-Propagating Malware: Viruses and Worms

The traditional distinction between viruses and worms rests on propagation mechanism. Viruses attach to host files and spread when those files are transferred between systems — through shared storage media, email attachments, or downloaded software. Worms propagate independently across networks by exploiting vulnerabilities in network services, requiring no human interaction to spread from one system to another. The WannaCry worm of May 2017 illustrated the devastating potential of network-propagating malware: exploiting an unpatched vulnerability in Microsoft’s Server Message Block protocol (known as EternalBlue, a tool reportedly developed by the National Security Agency and leaked by the Shadow Brokers group), WannaCry infected approximately 230,000 computers across 150 countries within days, encrypting files and demanding ransom payments in Bitcoin (Berr, 2017).

The distinction between viruses and worms has become less analytically useful as modern malware frequently combines propagation methods. Contemporary threats may arrive as email attachments (virus-like behavior), exploit network vulnerabilities to spread laterally within organizational networks (worm-like behavior), and download additional payloads from command-and-control servers (trojan-like behavior). The MITRE ATT&CK framework addresses this convergence by classifying malware according to its tactical capabilities — initial access, execution, persistence, lateral movement — rather than by traditional taxonomic categories, providing a more functionally relevant classification system for security practitioners and investigators.

The evolution of self-propagating malware reflects broader trends in the cybercrime ecosystem. Early viruses were frequently created for notoriety or destructive amusement rather than financial gain, and their payloads ranged from harmless screen displays to data destruction. The shift toward financially motivated malware, accelerating through the 2000s, produced self-propagating threats designed to build botnets (networks of compromised computers controlled by a central operator), harvest credentials, or install cryptocurrency mining software. The Conficker worm, which infected millions of computers beginning in 2008, exemplified this transition: its creators built an enormous botnet but monetized it primarily through the installation of scareware and spam distribution rather than through direct data theft or encryption.

Trojans, Spyware, and Remote Access Tools

Trojans — malware disguised as or embedded within legitimate software — represent the most diverse and widely deployed malware category. Unlike self-propagating malware, trojans rely on social engineering or exploitation to reach their targets, typically arriving through phishing emails, malicious websites, or compromised software downloads. Banking trojans such as Zeus, Dridex, and TrickBot have been among the most financially consequential malware families, intercepting online banking sessions to steal credentials and redirect financial transfers. The Zeus banking trojan alone was estimated to have infected over 3.6 million computers in the United States at its peak, enabling the theft of hundreds of millions of dollars from individual and corporate bank accounts (FBI, 2014).

Spyware and surveillance malware monitor user activity, capture keystrokes, record screen content, activate cameras and microphones, and exfiltrate collected data to attacker-controlled servers. The Pegasus spyware developed by the NSO Group has attracted particular attention due to its use by government clients against journalists, human rights activists, and political dissidents worldwide. While the deployment of commercial spyware by state actors raises distinct legal and ethical issues from criminal malware distribution, the technical capabilities are comparable, and the line between state-sanctioned surveillance tools and criminal surveillance malware is increasingly blurred.

Remote access trojans (RATs) provide attackers with persistent, interactive access to compromised systems, enabling file browsing, command execution, screenshot capture, and real-time monitoring. RATs are deployed by both criminal actors and state-sponsored groups, serving as the foundational tool for long-term intrusion campaigns in which attackers establish and maintain access to target networks over months or years. The availability of open-source and commercial RATs — some marketed as legitimate “remote administration tools” despite their obvious utility for unauthorized access — has lowered the barrier to entry for persistent access operations, enabling actors with limited technical sophistication to conduct surveillance and data theft campaigns.

Botnets and Infrastructure Malware

Botnets — networks of malware-infected computers coordinated by a command-and-control infrastructure — serve as the distributed computing platform for a wide range of criminal operations. Botnet operators rent access to their networks for DDoS attacks, spam distribution, credential stuffing campaigns, and cryptocurrency mining, generating recurring revenue from infrastructure that can encompass millions of compromised devices. The Mirai botnet, which emerged in 2016, represented a significant expansion of the botnet threat by targeting Internet of Things (IoT) devices — security cameras, routers, digital video recorders — that were protected by default or easily guessed passwords, assembling a network of compromised devices capable of generating record-breaking DDoS attack volumes (Antonakakis et al., 2017).

The takedown of major botnets has been a priority for law enforcement and cybersecurity organizations. Operations such as the disruption of the Emotet botnet in January 2021 — coordinated by Europol, the FBI, and law enforcement agencies from eight countries — demonstrate the scale of international cooperation required to dismantle criminal infrastructure that spans hundreds of thousands of infected systems across dozens of jurisdictions. However, botnet operators have demonstrated resilience, rebuilding infrastructure after takedowns or migrating to more decentralized architectures that resist centralized disruption. Emotet itself re-emerged less than a year after its takedown, highlighting the difficulty of achieving permanent disruption of criminal infrastructure.

The Evolution of Ransomware

Early Ransomware and the Shift to Cryptocurrency

The ransomware threat has undergone a transformation in scale, sophistication, and impact that distinguishes it from all other malware categories. Early ransomware, dating to the AIDS Trojan of 1989, was technically primitive and logistically limited by the difficulty of collecting payments anonymously. The emergence of Bitcoin in 2009 removed this constraint, providing a payment mechanism that was pseudonymous, borderless, and resistant to the reversal and seizure processes through which law enforcement could interdict traditional payment channels. CryptoLocker, which appeared in September 2013, was the first ransomware to combine strong encryption with cryptocurrency payment demands at significant scale, infecting approximately 250,000 systems and generating an estimated $3 million in ransom payments before its infrastructure was disrupted in 2014 (Jarvis & Neville, 2014).

The period from 2013 to 2018 saw the proliferation of ransomware variants — CryptoWall, Locky, Cerber, SamSam, and others — that targeted both individual consumers and organizations with varying levels of sophistication. This period established the basic ransomware business model: encrypt the victim’s files, display a ransom demand (typically ranging from a few hundred to several thousand dollars for individual victims), and provide a decryption key upon payment. The economics were compelling for attackers: even low payment rates across large victim pools generated substantial revenue, while the automation of infection and payment processes minimized the operational effort required per victim.

The shift toward targeting organizations rather than individuals, beginning around 2018, represented a strategic evolution that dramatically increased both ransom amounts and total criminal revenue. SamSam ransomware pioneered the targeted approach, with its operators conducting reconnaissance on victims, identifying critical systems, and timing encryption for maximum operational impact. The Atlanta municipal government’s infection by SamSam in March 2018 — which disrupted city services for weeks and cost an estimated $17 million in remediation — demonstrated that organizational ransomware could cause public harm well beyond the direct financial losses captured by ransom demands.

Ransomware-as-a-Service and the Modern Ecosystem

The ransomware-as-a-service (RaaS) model, which emerged in the late 2010s and now dominates the ransomware landscape, represents the full industrialization of ransomware operations. RaaS platforms — including REvil, Conti, LockBit, BlackCat/ALPHV, and their successors — are operated by core developer groups that create and maintain the malware, manage victim negotiation portals, and process ransom payments. Affiliates recruited through underground forums conduct the actual intrusion and deployment operations, receiving a percentage of successful ransom payments — typically 60 to 80 percent — with the remainder going to the platform operators.

The RaaS model has generated several consequences for the ransomware threat landscape. It has expanded the population of actors capable of conducting ransomware attacks by decoupling the technical skill required to develop ransomware from the operational skill required to deploy it. It has increased the pace of attacks by enabling parallel campaigns across dozens of affiliates operating simultaneously. And it has complicated law enforcement response by distributing criminal activity across multiple actors in different jurisdictions, none of whom possesses complete knowledge of the overall operation. The LockBit operation, which was partially disrupted by an international law enforcement operation in February 2024, had recruited hundreds of affiliates and was responsible for approximately 25 percent of all ransomware incidents globally at its peak.

The double extortion model — encrypting victim data while simultaneously stealing copies and threatening public release — has become standard practice among major ransomware groups. Introduced by the Maze group in late 2019, double extortion ensures that even victims with viable backups face pressure to pay, as the threat of data exposure carries reputational, regulatory, and legal consequences independent of operational disruption. Some groups have added triple extortion by threatening DDoS attacks or directly contacting the victim’s customers and partners to amplify pressure. These escalating pressure tactics have increased average ransom payments, which Coveware estimated at approximately $740,000 in the first quarter of 2024, though this figure reflects averaging across wide variation from thousands to tens of millions of dollars.

High-Profile Incidents and Their Consequences

Critical Infrastructure Attacks

Several ransomware incidents have had consequences extending well beyond the directly victimized organizations, demonstrating the potential for digital crime to produce physical-world impacts. The Colonial Pipeline attack of May 2021 — in which the DarkSide ransomware group encrypted systems belonging to the operator of the largest fuel pipeline on the U.S. East Coast — prompted a precautionary shutdown that disrupted fuel supply across multiple southeastern states, triggered panic buying and gasoline shortages, and prompted a Declaration of Emergency by the Department of Transportation. Colonial Pipeline paid a ransom of approximately $4.4 million in Bitcoin, of which the FBI subsequently recovered approximately $2.3 million through cryptocurrency tracing and seizure.

The Change Healthcare attack of February 2024, attributed to the BlackCat/ALPHV ransomware group, disrupted healthcare claims processing across the United States for weeks, affecting pharmacies, hospitals, and insurance companies nationwide. The incident exposed the concentration risk inherent in critical digital infrastructure: Change Healthcare processes approximately 15 billion healthcare transactions annually, and its disruption cascaded through the healthcare payment system in ways that affected patient care at facilities that had no direct relationship with the compromised company. UnitedHealth Group, Change Healthcare’s parent company, reported costs exceeding $870 million related to the incident.

These high-profile attacks have shifted the policy discourse around ransomware from a law enforcement concern to a national security priority. The Biden administration’s 2021 executive order on cybersecurity, the establishment of the Counter Ransomware Initiative bringing together more than forty allied nations, and proposals for mandatory incident reporting for critical infrastructure operators all reflect the recognition that ransomware poses systemic risks that exceed the capacity of individual organizations or law enforcement agencies to manage.

Municipal and Educational Targets

Municipal governments and educational institutions have been disproportionately targeted by ransomware, reflecting their combination of valuable data, limited cybersecurity budgets, and operational urgency that increases willingness to pay. The Multi-State Information Sharing and Analysis Center (MS-ISAC) documented hundreds of ransomware incidents affecting state, local, tribal, and territorial (SLTT) government entities annually, with consequences ranging from service disruption to permanent data loss. The city of Baltimore’s May 2019 ransomware infection — which disabled email, voicemail, and payment systems for weeks and cost an estimated $18 million in remediation and lost revenue — exemplified the extended disruption that ransomware can impose on government operations.

School districts have been especially frequent targets, with the K-12 Cybersecurity Resource Center documenting a steady increase in ransomware incidents affecting American schools. The Los Angeles Unified School District, the second-largest school system in the United States, suffered a ransomware attack in September 2022 that compromised sensitive student data including psychological evaluations and disciplinary records. The exposure of minor students’ personal and behavioral data raises particular concerns about long-term harm that distinguishes educational data breaches from breaches affecting adult populations.

Law Enforcement Response

Federal Investigation and Disruption

The federal response to malware and ransomware threats operates through multiple agencies with overlapping jurisdictions. The FBI’s Cyber Division leads criminal investigations of significant malware and ransomware operations, working in coordination with the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) for prosecution. The Secret Service’s Cyber Fraud Task Forces investigate financially motivated malware and ransomware cases. CISA provides defensive guidance, maintains the Known Exploited Vulnerabilities catalog, and operates the Pre-Ransomware Notification Initiative, which alerts organizations showing indicators of imminent ransomware deployment.

Disruption operations — targeting criminal infrastructure rather than individual offenders — have emerged as a central element of federal ransomware strategy. The FBI’s seizure of DarkSide’s cryptocurrency wallet following the Colonial Pipeline attack, the coordinated international takedown of the Hive ransomware network’s infrastructure in January 2023, and the disruption of LockBit’s operations in February 2024 demonstrate the operational model. These actions aim to degrade criminal capability, undermine trust within the RaaS ecosystem, and signal to potential affiliates that participation carries risks. The effectiveness of disruption operations is debated: while individual operations impose real costs on criminal groups, the decentralized and resilient nature of the RaaS model means that disrupted groups frequently reconstitute under new names or their affiliates migrate to competing platforms.

International Cooperation and Jurisdictional Challenges

The transnational character of ransomware operations demands international cooperation that remains incomplete. Major ransomware groups are widely assessed to operate from or with the tolerance of Russia, where domestic law enforcement has historically shown little interest in prosecuting actors who target foreign victims. The absence of an extradition treaty between the United States and Russia, combined with Russian policy against extraditing its citizens, creates a jurisdictional safe haven that limits direct law enforcement action against many of the most prolific ransomware operators. The Counter Ransomware Initiative has produced joint policy statements, intelligence sharing arrangements, and coordinated disruption operations among participating nations, but its effectiveness is constrained by the non-participation of the countries that harbor the most significant ransomware groups.

International legal mechanisms including mutual legal assistance treaties provide frameworks for cross-border evidence collection and asset recovery, but these processes operate on timescales poorly suited to digital investigations. The Budapest Convention on Cybercrime offers an additional cooperation framework, and the proposed Second Additional Protocol to the Convention would streamline cross-border data access procedures. However, the fundamental tension between national sovereignty over criminal investigation and the borderless nature of cybercrime operations remains unresolved, creating persistent gaps that ransomware operators exploit.

Organizational Defense and Resilience

Technical Prevention Measures

Organizational defense against malware and ransomware encompasses a layered approach spanning prevention, detection, and recovery capabilities. Endpoint detection and response (EDR) platforms provide real-time monitoring of individual devices, using behavioral analysis and signature matching to identify and quarantine malware before it can execute its payload. Network-level defenses including email filtering, web proxy controls, and network segmentation limit the pathways through which malware can enter and propagate within organizational environments. Patch management programs that prioritize the rapid remediation of known exploited vulnerabilities address the most commonly exploited attack surface.

Backup and recovery capabilities provide the essential resilience layer that determines whether a ransomware attack results in operational disruption measured in hours or weeks. Organizations that maintain current, tested, and offline backups can restore encrypted systems without paying ransom, provided that attackers have not also compromised or destroyed backup systems — a tactic that sophisticated ransomware groups increasingly employ as a countermeasure. The “3-2-1” backup rule — three copies of data, on two different media types, with one copy stored offsite — provides a foundational framework, though the specific implementation must account for the volume of data, recovery time objectives, and the threat of backup compromise that characterizes contemporary ransomware operations.

Organizational Governance and Incident Response

Effective ransomware defense requires governance frameworks that extend beyond technical controls to encompass organizational leadership, resource allocation, and cultural change. Boards of directors and senior executives at publicly traded companies face increasing regulatory pressure to demonstrate cybersecurity oversight, including the SEC’s 2023 rules requiring disclosure of material cybersecurity incidents and board-level cybersecurity expertise. Incident response planning — including tabletop exercises that simulate ransomware scenarios, pre-negotiated relationships with incident response firms and legal counsel, and documented decision frameworks for ransom payment — enables organizations to respond effectively under the time pressure and operational disruption that ransomware creates.

The question of whether to pay ransom remains the most contested policy issue in ransomware defense. Law enforcement agencies consistently advise against payment, arguing that it funds criminal operations, incentivizes future attacks, and does not guarantee data recovery. However, organizations facing existential operational disruption — hospitals unable to access patient records, manufacturers with halted production lines, municipalities with disabled emergency services — may calculate that payment is the least harmful option. The tension between the collective interest in refusing ransom and the individual organization’s interest in rapid recovery has resisted resolution, though proposals for mandatory payment reporting and potential regulatory prohibition of ransom payments continue to circulate in policy discussions.

Emerging Threats and Future Trajectory

AI-Enhanced Malware and Adaptive Attacks

The integration of artificial intelligence capabilities into malware development and deployment represents the most significant emerging technical threat. AI-enhanced malware can adapt its behavior to evade detection systems, generate polymorphic code that changes its signature with each execution, and automate the reconnaissance and lateral movement phases of intrusion campaigns that currently require human operator involvement. Large language models can be used to generate convincing phishing content for initial access, analyze target environments to identify high-value assets, and automate the customization of attack parameters for specific victims.

The defensive implications are significant. Detection systems trained on historical malware behavior may be less effective against AI-generated variants that fall outside their training data. The speed at which AI-enhanced attacks can progress through the intrusion lifecycle — from initial access to data exfiltration to encryption — may compress the detection window within which defenders can identify and respond to active intrusions. Conversely, AI-enhanced defensive tools offer the potential for more rapid threat detection and response, creating an arms race dynamic in which both offensive and defensive capabilities escalate simultaneously.

IoT and Operational Technology Risks

The expansion of the Internet of Things and the increasing connectivity of operational technology (OT) systems — industrial control systems, building management systems, medical devices, and critical infrastructure components — create new malware attack surfaces with potentially severe physical consequences. The Stuxnet worm, discovered in 2010 and attributed to a joint U.S.-Israeli operation, demonstrated that malware could cause physical destruction by manipulating industrial control systems, in this case centrifuges at Iran’s Natanz nuclear enrichment facility. While Stuxnet was a state-sponsored operation rather than a criminal act, it established the technical precedent for malware-mediated physical harm.

The proliferation of IoT devices — estimated at over 15 billion globally — creates an enormous attack surface characterized by devices that frequently run outdated software, use default credentials, and lack the computational resources to support traditional security controls. The Mirai botnet’s exploitation of IoT devices demonstrated the aggregate threat that compromised devices can pose when coordinated at scale. As IoT deployment expands into critical infrastructure sectors including energy, water, transportation, and healthcare, the potential consequences of IoT-targeted malware escalate from service disruption to physical safety risks that blur the boundary between cybercrime and physical harm.

Conclusion

Malware and ransomware attacks have evolved from the hobbyist viruses and experimental worms of computing’s early decades into an industrialized criminal threat that imposes billions of dollars in costs annually and poses risks to critical infrastructure, public services, and national security. The ransomware-as-a-service model has democratized access to sophisticated attack capabilities, enabling a growing population of criminal actors to conduct operations that were previously limited to technically skilled individuals and organized groups. High-profile incidents targeting critical infrastructure, healthcare, and government services have elevated ransomware from a law enforcement concern to a national security priority, prompting significant policy responses at both domestic and international levels.

The trajectory of the malware and ransomware threat is shaped by countervailing forces: improving defensive technologies and organizational practices against escalating attack sophistication, expanding criminal marketplaces, and emerging capabilities enabled by artificial intelligence. The effectiveness of the response depends on sustained investment in defensive capabilities, international cooperation that addresses the jurisdictional safe havens from which major operations are conducted, and organizational governance that treats cybersecurity as a core operational function rather than a technical afterthought.

References

  1. Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., & Zhou, Y. (2017). Understanding the Mirai botnet. Proceedings of the 26th USENIX Security Symposium (pp. 1093–1110).
  2. Berr, J. (2017, May 16). WannaCry ransomware attack losses could reach $4 billion. CBS News.
  3. Chainalysis. (2024). The 2024 crypto crime report. https://www.chainalysis.com/blog/crypto-crime-2024/
  4. Coveware. (2024). Q1 2024 ransomware report. https://www.coveware.com/blog/ransomware-report-q1-2024
  5. Cybersecurity and Infrastructure Security Agency. (2023). #StopRansomware guide. U.S. Department of Homeland Security. https://www.cisa.gov/stopransomware
  6. Federal Bureau of Investigation. (2014). Gameover Zeus botnet disrupted. U.S. Department of Justice. https://www.fbi.gov/news/stories/gameover-zeus-botnet-disrupted
  7. Federal Bureau of Investigation. (2024). Internet Crime Complaint Center 2023 annual report. U.S. Department of Justice. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf
  8. Furnell, S. (2002). Cybercrime: Vandalizing the information society. Addison-Wesley.
  9. Holt, T. J., & Bossler, A. M. (2016). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
  10. Jarvis, K., & Neville, M. (2014). CryptoLocker ransomware. Dell SecureWorks Counter Threat Unit Special Report.
  11. K-12 Cybersecurity Resource Center. (2023). The state of K-12 cybersecurity: 2023 year in review. https://www.k12six.org/
  12. Maurer, T. (2018). Cyber mercenaries: The state, hackers, and power. Cambridge University Press.
  13. Multi-State Information Sharing and Analysis Center. (2024). 2023 SLTT cybersecurity trends report. Center for Internet Security.
  14. Richardson, R., & North, M. M. (2017). Ransomware: Evolution, mitigation and prevention. International Management Review, 13(1), 10–21.
  15. Savage, K., Coogan, P., & Lau, H. (2015). The evolution of ransomware. Symantec Security Response White Paper.
  16. U.S. Department of Justice. (2023). U.S. Department of Justice disrupts Hive ransomware variant. Press release. https://www.justice.gov/opa/pr/us-department-justice-disrupts-hive-ransomware-variant
  17. U.S. Department of Justice. (2024). International law enforcement operation targets LockBit ransomware. Press release.
  18. Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
  19. Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
  20. Zetter, K. (2014). Countdown to zero day: Stuxnet and the launch of the world’s first digital weapon. Crown.

Related Articles

  • Hacking and Unauthorized Access
  • Cybercrime Typologies
  • Corporate Cybercrime and Data Breaches
  • Cybercrime and Organized Crime
  • Emerging Cybercrime Threats




Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube
  • Criminology
    • Clinical Criminology
    • Comparative Criminology
    • Crime as a Social Phenomenon
    • Crime in Criminology
    • Criminology and Criminal Justice Careers
    • Criminology and Criminal Justice Degrees
    • Criminology and Criminal Justice Education
    • Criminology and Public Policy
    • Criminology as Social Science
    • Cyber Criminology
      • Algorithmic Bias in Criminal Justice
      • Artificial Intelligence and Crime
      • Big Data and Criminal Justice
      • Body-Worn Cameras and Policing
      • Child Sexual Exploitation Online
      • Corporate Cybercrime and Data Breaches
      • Crime in the Digital Age
      • Cryptocurrency and Crime
      • Cyberbullying in America
      • Cybercrime and Organized Crime
      • Cybercrime and the Dark Web
      • Cybercrime Investigation and Digital Forensics
      • Cybercrime Offenders and Motivations
      • Cybercrime Prevention and Digital Literacy
      • Cybercrime Reporting and Statistics in America
      • Cybercrime Typologies
      • Cybercrime Victimization
      • Cyberstalking and Online Harassment
      • Cyberterrorism and National Security
      • Digital Criminology and Public Policy
      • Digital Divide and Crime
      • Digital Evidence in American Courts
      • Digital Society and Crime
      • Digital Surveillance and Crime Control
      • Digital Vigilantism in America
      • Emerging Cybercrime Threats
      • Facial Recognition and Law Enforcement
      • Federal Cybercrime Law in America
      • Hacking and Unauthorized Access
      • Identity Theft in America
      • International Cybercrime Cooperation
      • Malware and Ransomware Attacks
      • Nation-State Cyberattacks and U.S. Security
      • Online Drug Markets
      • Online Fraud and Financial Cybercrime
      • Online Radicalization and Extremism
      • Phishing and Social Engineering
      • Platform Accountability and Online Harm
      • Privacy, Civil Liberties, and Digital Crime Control
      • Sextortion and Image-Based Abuse
      • Social Media and Criminal Behavior
      • The Dark Web and Digital Crime
    • History of Criminology
    • Psychology and Criminology
    • Sociology and Criminology
    • Urban Criminology