Cybercrimeology

Cybercrimeology

By CybercrimeologyScienceTechnologyEducation
Download on the App Store

Cybercrimeology episodes

  • The Human beneath the Hoodie: Profiling pathways into cybercrime

    otes:

    Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.

    Her research focuses on understanding the human behind the keyboard through developmental history, motivation and lived experience.

    Initial motivations among hackers often centre on curiosity, challenge seeking and belonging rather than financial gain.

    Many participants reported early interest in technology, solitary online activity and experiences they described as destabilising events.

    Melissa distinguishes between lawful and criminal pathways using indicators such as modifying games, low self-control and a history of property offending.

    Her work highlights misunderstandings about intent, the role of gamification and the abstraction of harm when offending takes place online.

    She argues that cybercrime is a societal problem requiring early education, parental and teacher capability building and partnerships with tech and gaming companies.

    Diversion programs are essential to guide youth with technical interest toward prosocial cybersecurity roles rather than criminalisation.

    About our guest:
    Dr Melissa Martineau
    https://www.linkedin.com/in/melissa-martineau-369bb5258/
    https://www.captechu.edu/webinar-series-melissa-martineau

    Papers or resources mentioned in this episode:
    Martineau, M. (2023). The pathways of cyber dependent offenders. Journal of Cybercriminology, 3(3), 32.
    https://www.mdpi.com/2673-6756/3/3/32

    Martineau, M. (2024). Distinguishing lawful and criminal hacker trajectories. Journal of Cybercriminology, 4(4), 45.
    https://www.mdpi.com/2673-6756/4/4/45

    Other:
    Dr Martineau wanted to share something called PRISMA (Preferred Reporting Items for Systematic reviews and Meta-Analyses) which is a helpful guideline designed to improve the reporting of systematic reviews. You can find out more about it here.   
    http://www.prisma-statement.org

    34 min
  • Courses, Clicks and Consequences: Empiricizing Enterprise Security

    Episode Notes:

    • Dr Ho describes an empirical research agenda focused on how security actually operates in organisations. He explains his experience with getting this research off the ground to allow them to perform the research in this setting.
    • Study setting and scope: eight-month randomised controlled trial at UC San Diego Health involving ~19,500 employees and ten distinct phishing campaign lures.
    • Annual awareness training: the study found no significant relationship between how recently staff completed the mandated course and their likelihood of failing a simulated phishing campaign.
    • Embedded training (when someone clicks a phishing simulation and is immediately redirected to training): the measurable improvement was very small (≈2% reduction in failure rate) and varied significantly by lure and engagement.
    • Engagement challenge: The vast majority of embedded-training sessions were extremely short or incomplete, a key factor in explaining limited effect size.
    • Variability of lure difficulty: Some phishing lures elicited very low click-rates (~1.8%) while others up to ~30.8%, indicating that the phishing stimulus matters as much as, or more than, the training intervention.

    Practical takeaway: Organizations should treat training (especially annually mandated modules) as only one part of a broader defence strategy, and design empirical measurement systems (including controls, realistic lures, and sustained engagement) before assuming large effect sizes.

    About our Guest:

    Dr Grant Ho Profile: https://cs.uchicago.edu/people/grant-ho/

    Papers or resources mentioned in this episode:

    Ho, G.; Mirian, A.; Luo, E.; Tong, K.; Lee, E.; Liu, L.; Longhurst, C.A.; Dameff, C.; Voelker, G.M. (2025). Understanding the Efficacy of Phishing Training in Practice: A Randomized Controlled Trial at a Large Health Organisation. Presented at the IEEE Symposium on Security & Privacy (May 2025). Full PDF: https://people.cs.uchicago.edu/~grantho/papers/oakland2025_phishing-training.pdf

    Other: 

    I mentioned some figures about the spending on cybercsecurity education and training, You can find those here.  

    Canadian Survey of Cyber Security and Cybercrime (CSCSC)
    https://www23.statcan.gc.ca/imdb/p2SV.pl?Function=getSurvey&SDDS=5244

    Get convenient Excel Tables of the Statistics from 2017 and 2019. 

    https://www.serene-risc.ca/en/statistics-canada

    Other Other:

    Dr Ho was great to chat with and has a long history of researching phishing, Some of his older work that is more technical in nature, as so we didn't talk about in the episode, but in the case that it  might be interesting to you, here are some links: 

    Ho, G., Sharma, A., Javed, M., Paxson, V., & Wagner, D. (2017). Detecting Credential Spearphishing Attacks in Enterprise Settings. In Proceedings of the 26th USENIX Security Symposium (USENIX Security ’17), Vancouver, BC, Canada, August 16-18, 2017. USENIX Association. ISBN 978-1-931971-40-9.
    PDF: https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-ho.pdf USENIX+2USENIX+2
    Presentation page: https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/hoUSENIX+1

    Ho, G., Cidon, A., Gavish, L., Schweighauser, M., Paxson, V., Savage, S., Voelker, G. M., & Wagner, D. (2019). Detecting and Characterizing Lateral Phishing at Scale. In Proceedings of the 28th USENIX Security Symposium (USENIX Security ’19), Santa Clara, CA, USA, August 14-16, 2019. USENIX Association. ISBN 978-1-939133-06-9.
    PDF: https://www.usenix.org/system/files/sec19-ho.pdf USENIX+1
    Presentation page: https://www.usenix.org/conference/usenixsecurity19/presentation/ho USENIX

    1 hr 5 min
  • The many minds of MITRE: building multidisciplinary human insider-risk research

    Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber. 

    Episode Notes

    • Dr Caputo's path from social psychology to applied security, including intelligence analysis and building a behavioural-science team at MITRE.
    • What MITRE is: a not-for-profit operating six federally funded R&D centres that provide independent, public-interest research alongside government.
    • Why early “indicator” hunting on endpoints often chased the last bad case; shifting to experiments and known-bad/created-bad data to learn patterns of behaviour change.
    • The LinkedIn recruiter field experiment: ethically approved creation of recruiter personas, staged outreach in three messages, and follow-up interviews to understand reporting barriers.
    • What user-activity monitoring can and cannot tell you; the role of human judgement and programme design.
    • Insider-risk is not only “malicious users”: designing programmes for negligent, mistaken or outsmarted behaviours as well.
    • Current lines of work include improving employee recognition and reporting of malicious elicitations and exploring whether insider-risk telemetry offers early signals of suicide risk.
    • Why multidisciplinary teams beat solo efforts in insider-risk operations.

    About our guest:

    Dr. Deanna D. Caputo

     

    MITRE Insider Threat Research & Solutions profile: https://insiderthreat.mitre.org/dr-caputo/ 

    LinkedIn: https://www.linkedin.com/in/dr-deanna-d-caputo

    Papers or resources mentioned in this episode:

    Caputo, D. D. (2024). Employee risk recognition and reporting of malicious elicitations: Longitudinal improvement with new skills-based training. Frontiers in Psychology. https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2024.1410426/full 

    MITRE Insider Threat Research & Solutions. (2025). Suicide risk and insider-risk telemetry overview. https://insiderthreat.mitre.org/suicide-risk/ 

    MITRE. (2024). Managing insider threats is a team sport. https://www.mitre.org/news-insights/impact-story/managing-insider-threats-team-sport 

    MITRE Insider Threat Research & Solutions. (2024). Capability overview two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-CapabilityTwoPager-24-0659_2024-02-01.pdf 

    MITRE Insider Threat Research & Solutions. (2024). Insider Threat Behavioural Risk Framework two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-InTFramework_TwoPager-24-0674_2024-03-18.pdf

    45 min
  • Follow the Honey: Experiments in Cybercriminal Decision-Making

    Show Notes:

    • Daniëlle began her academic path in psychology, later moving into criminology through her interest in decision making and online behaviour.
    • Her PhD research at NSCR focuses on cybercriminal decision making, using honeypots and experiments in real online environments.
    • Early experiments tested how different rewards affected access attempts on fake accounts.
    • A major focus has been on the impact of Operation Cookie Monster (2023), which disrupted the Genesis Market. Danielle’s work examined how this law enforcement operation influenced behaviour and moderation practices on hacker forums.
    • She emphasizes the value of experiments in the field, which allow researchers to test criminological theories with live offender behaviour, while balancing strict ethical and legal safeguards.

    About our guest:

    Danielle Stibbe

    • NSCR Profile Page: https://nscr.nl/en/medewerker/danielle-stibbe-msc/
    • Google Scholar: https://scholar.google.com/citations?user=1fsHJEgAAAAJ&hl=en
    • LinkedIn: https://www.linkedin.com/in/danielle-stibbe/?originalSubdomain=nl

    Papers or resources mentioned in this episode:

    • Onaolapo, J., Mariconti, E., & Stringhini, G. (2016). What happens after you are pwnd: Understanding the use of leaked webmail credentials in the wild. Proceedings of the 2016 Internet Measurement Conference. https://doi.org/10.1145/2987443.2987475
    • Europol (2023). Operation Cookie Monster: Genesis Market taken down in coordinated international action.https://www.europol.europa.eu/media-press/newsroom/news/operation-cookie-monster-genesis-market-taken-down-in-coordinated-international-action
    • Oxford Handbook of Criminal Decision Making (2016). Eds. Bruinsma & Weisburd. Oxford University Press.

    Other:

    The open science framework https://osf.io

     

    31 min
  • Crime Online: Hashtag Like and Subscribe, or don't
    Episode NotesAbout our guest:

    Dr. Francesco Carlo Campisi

    PhD in Criminology, Université de Montréal

    Researcher, International Centre for Comparative Criminology

    🔗 https://www.cicc-iccc.org/fr/personnes/etudiants-supervises/carlo-campisi

    🔗 https://www.linkedin.com/in/francesco-carlo-campisi-aa3576125/

    Topics discussed in this episode:
    • From street gangs to digital deviance: a research trajectory
    • Why “recruitment” doesn’t fit how modern movements grow
    • How groups like QAnon and Anonymous influence participation online
    • Using social media metrics to measure engagement
    • Emotional capital, visibility, and symbolic participation
    • Updating resource mobilization theory for digital contexts
    • Hashtag hijacking and online visibility strategies
    • Stochastic terrorism and the challenge of lone-wolf violence
    Papers or resources mentioned in this episode:
    • Campisi, F. (2024). Unveiling the digital underworld – Exploring cyberbanging and recruitment of Canadian street gang members on social media. Canadian Journal of Criminology and Criminal Justice, 66. https://doi.org/10.3138/cjccj-2023-0033
    • Campisi, F., Fortin, F., & Néron, M.-E. (2022). Hacktivists from the inside: Collective identity, target selection and tactical use of media during the Quebec Maple Spring protests. Presented at the ICCC Symposium. Available on ResearchGate
    • Campisi, F., & Beauregard, E. (2025). QAnon’s use of hashtag hijacking on X and its impact on online engagement. SSRN preprint. Link
    • McCarthy, J. D., & Zald, M. N. (1977). Resource mobilization and social movements: A partial theory. American Journal of Sociology, 82(6), 1212–1241.
    • Vigil, J. D. (1988). Barrio gangs: Street life and identity in Southern California. University of Texas Press. https://www.ojp.gov/ncjrs/virtual-library/abstracts/barrio-gangs-street-life-and-identity-southern-california-0

    Other:

    If you are curious about the video that was taken down, you should watch this video.

    https://www.youtube.com/watch?v=PIyrzMThHq8

    30 min
  • The Human in_security - deception, weapons, crime & culture

    About our guest:

    Dr. Iain Reid

    Senior Lecturer in Cybercrime

    University of Portsmouth

    https://www.port.ac.uk/about-us/structure-and-governance/our-people/our-staff/iain-reid

     

    Topics discussed in this episode:

    • How principles of military deception map onto cybersecurity
    • Why the phrase “the human is the weakest link” oversimplifies risk
    • What it’s like to research developer perspectives on secure software
    • The psychology of decision-making in phishing attacks
    • How time pressure influences risky digital behaviour
    • The limits of “security culture” as an organizational solution
    • How cyber deception fits within defence-in-depth

     

    Papers or resources mentioned:

    Reid, I., Okeke-Ramos, A., & Serafin, M. (2024). Exploring the ethics of cyber deception technologies for defensive cyber deception. In P. Bednar, J. Kävrestad, E. Bergström, M. Rajanen, H. V. Hult, A. M. Braccini, A. S. Islind, & F. Zaghloul (Eds.), Proceedings of the 10th International Conference on Socio-Technical Perspectives in Information Systems (STPIS 2024) (pp. 140-148). (CEUR Workshop Proceedings). https://ceur-ws.org/Vol-3857

    Whaley, B. (2007). Stratagem: deception and surprise in war. Artech.

    Rowe, N.C., Rrushi, J. (2016). Measuring Deception. In: Introduction to Cyberdeception. Springer, Cham. https://doi.org/10.1007/978-3-319-41187-3_11

    Ashenden, D., Ollis, G., & Reid, I. (2022, October). Dancing, not Wrestling: Moving from Compliance to Concordance for Secure Software Development. In Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering (pp. 1-9).

    Paris Call for Trust and Security in Cyberspace

    https://pariscall.international

     

    Other

    I would like to thank Dudley the French Bulldog for the invaluable (unavoidable) contribution to this episode.

    28 min
  • Visualizing Conti: Revealing the Business of Ransomware-as-a-Service through New Analytical Techniques
    In this episode:
    • How Estelle became involved in ransomware research between degrees
    • The scale and origin of the ContiLeaks dataset
    • Using machine learning and topic modelling to analyse criminal group communications
    • What the internal chat data revealed about the organizational structure of Conti
    • Surprising insights about roles, specializations, and tasking within a criminal enterprise
    • Why making cybercrime research accessible through data visualization matters
    About our guest:

    Estelle Ruellan

    • https://www.linkedin.com/in/estelle-ruellan/
    Papers or resources mentioned in this episode:

    Ruellan, E., Paquet-Clouston, M., & Garcia, S. (2024).Conti Inc.: understanding the internal discussions of a large ransomware-as-a-service operator with machine learning. Crime Science, 13, 16. https://doi.org/10.1186/s40163-024-00212-y

    Flare Data Explorer – Explore cybercrime datasets visually:

    https://flare.io/flare-data-explorer/

    Other:
    • Wikipedia – Conti (ransomware): https://en.wikipedia.org/wiki/Conti_(ransomware)
    • Wikipedia – Topic model: https://en.wikipedia.org/wiki/Topic_model
    28 min
  • Fake It Until You Break It: The pay-to-publish paper mills exploiting the over metrification of Science

    Notes:

    • Paper mills are fraudulent commercial enterprises that fabricate scientific papers and sell authorship, citations, and other academic credentials—often at scale.
    • Sarah Eaton and Sabina Alam first collaborated through COPE (Committee on Publication Ethics) and later worked together in United2Act, an international initiative focused on tackling paper mills.
    • The conversation draws parallels between scientific paper mills and contract cheating in higher education, both of which undermine academic integrity for financial gain.
    • Eaton and Alam discuss how metrics-based performance systems in universities and publishing environments create conditions ripe for abuse.
    • Publishers and universities historically avoided transparency, but the scale of the problem has led to greater collaboration between stakeholders.
    • The duo share insights into early warning signs of fraudulent submissions and describe the development of technological and administrative countermeasures.
    • Particular attention is given to the harm paper mills cause: from corrupting citation networks to potentially endangering lives with fabricated data in medical journals.
    • The “Andrew Vickers Curse” is discussed as a case study illustrating how citation manipulation by paper mills can entangle innocent researchers.
    • The episode closes with a call for broader participation in the second phase of United2Act, particularly from research funders, IT specialists, and institutional stakeholders.

    About our guests:

    Dr. Sarah Elaine Eaton

    https://profiles.ucalgary.ca/sarah-eaton

    https://drsaraheaton.com/about/

    Dr. Sabina Alam

    https://www.taylorandfrancis.com/about/ethics-integrity/

    https://www.csescienceeditor.org/article/dr-sabina-alam-shaping-critical-thinking-about-science/

     

    Papers or resources mentioned in this episode:

    United2Act initiative: https://united2act.org

    Magazinov, Alexander. (2023). The Andrew Vickers Curse: secret revealed!, For Better Science

    https://forbetterscience.com/2023/07/31/the-vickers-curse-secret-revealed/

     

    Other:

    Glossary of terms and acronyms:

    • COPE – Committee on Publication Ethics: An international body that provides advice to editors and publishers on all aspects of publication ethics.
    • STM – International Association of Scientific, Technical and Medical Publishers: A global trade association supporting academic publishing and information dissemination.
    • Q1/Q2 Journal – Journals ranked in the top (Q1) or second (Q2) quartile based on impact metrics such as citation counts or journal reputation.
    • Term paper mill – A business that sells pre-written or custom academic papers, often used in contract cheating by students.
    • Contract cheating – A form of academic dishonesty where students outsource assessments to third parties.
    • Retraction – The removal of a published article from the scientific record, typically due to error or misconduct.
    • Desk reject – When a manuscript is rejected by a journal editor before it is sent out for peer review.
    • Citation ring – A group of papers or authors who cite each other extensively to artificially inflate citation metrics.
    • Paper Mills - Organisations or individuals that aim to profit from the creation, sale, peer review and/or citation of manuscripts at scale which contain low value or fraudulent content and/or authorship, with the aim of publication in scholarly journals.

    A big thank you to the United2Act people for coming out of their comfort zone and chatting to me about this.  This bravery is how science as an interdisciplinary pursuit driven by curiosity and collaboration happens.  

    40 min
  • DeReact, DeFatigue and Deceive: Psychology for Better Cybersecurity Design

    Episode Notes:

    • Dr. Reeves’ Background – Trained as a psychologist, his interest in cybersecurity emerged from a talk connecting human error to security breaches.
    • Cybersecurity Fatigue Defined – A form of disengagement where employees lose motivation to follow security practices due to overload and conflicting advice.
    • Not Just Apathy – Fatigue often affects people who initially cared about cybersecurity but were worn down by excessive or ineffective interventions.
    • Training Shortcomings – Lecture-style, one-way training is frequently perceived as boring, irrelevant, or contradictory to users' experiences.
    • Compliance vs. Effectiveness – Many organizations implement security training to meet legal requirements, even if it fails to change behavior.
    • Reactance in Security – Users may intentionally ignore advice or rules to assert control, especially when training feels micromanaging or patronizing.
    • Better Through Design – Reeves argues that secure systems should reduce the need for user decisions by simplifying or removing risky options altogether.
    • Remove Rather Than Train – Limiting administrative rights is often more effective than trying to educate users out of risky behaviors.
    • Mismatch With Reality – Generic training that conflicts with real policies or system restrictions can confuse or alienate users.
    • Cognitive Load and Decision-Making – Under stress or fatigue, users rely on mental shortcuts (heuristics), which attackers exploit.
    • Personal Example of Being Fooled – Reeves recounts nearly falling for a scam due to time pressure, illustrating how stress weakens judgment.
    • Cybersecurity Buddy System – Recommends encouraging users to consult peers when making sensitive decisions, especially under pressure.
    • Cyber Deception Strategies – Reeves now researches ways to mislead and trap attackers inside systems using decoys and tripwires.
    • Applying Psychology to Attackers – The same behavioral models used to study users can help predict and manipulate attacker behavior.
    • Empowering Defenders – Deception technologies can help security teams regain a sense of agency, shifting from reactive defense to proactive engagemen

    About our guest:

    Dr. Andrew Reeves

    • https://www.linkedin.com/in/andrewreevescyber/
    • https://research.unsw.edu.au/people/dr-andrew-reeves
    • https://www.unsw.edu.au/research/ifcyber

    Papers or resources mentioned in this episode:

    Reeves, A., Delfabbro, P., & Calic, D. (2021). Encouraging employee engagement with cybersecurity: How to tackle cyber fatigue. SAGE Open, 11(1).

    https://doi.org/10.1177/21582440211000049

    Reeves, A., Calic, D., & Delfabbro, P. (2023). Generic and unusable: Understanding employee perceptions of cybersecurity training and measuring advice fatigue. Computers & Security, 128, 103137.

    https://doi.org/10.1016/j.cose.2023.103137

    Reeves, A., & Ashenden, D. (2023). Understanding decision making in security operations centres: Building the case for cyber deception technology. Frontiers in Psychology, 14, 1165705.

    https://doi.org/10.3389/fpsyg.2023.1165705

    Other:

    UNSW Institute for Cyber Security (IFCYBER)

    https://www.unsw.edu.au/research/ifcyber

    39 min
  • Wake up Calling: Impacting businesses by communicating cybersecurity risk
    Episode Notes
    • SMEs struggle with cybersecurity due to time, cost, and lack of expertise, despite recognizing its importance.
    • An automated cybersecurity scan was developed to assess SME websites and email security without requiring them to opt-in.
    • Physical reports were mailed instead of emailed to avoid phishing concerns and increase credibility.
    • Reports included security ratings on ten key areas and recommendations for improvement.
    • Businesses were encouraged to consult their existing IT providers for fixes rather than relying on external services.
    • Different risk communication strategies were tested to encourage SMEs to act on the findings.
    • “Anticipated Regret” messaging (“Fix it now or regret it later”) led to the highest cybersecurity improvements.
    • All groups, including the control group, showed some improvement, suggesting broader awareness of cybersecurity issues.
    • Engagement was low, with only a small number of businesses reaching out after receiving the report.
    • Legal concerns about scanning businesses without consent were addressed—publicly available cybersecurity data can be legally assessed.
    • Ethical approval confirmed the project was non-commercial and aimed solely at helping businesses improve security.
    • A follow-up version of the project will introduce an opt-out option before scanning businesses.
    • Industry associations may partner with the project to increase credibility and adoption.
    • The intervention will be scaled up, with more businesses included and a longer time frame for assessing impact.
    • Future plans include adapting the intervention internationally, using lessons learned to assist SMEs in other regions.
     About Our Guest

    Dr. Susanne van ’t Hoff-de Goede

    https://www.linkedin.com/in/susanne-van-t-hoff-de-goede/

    https://www.thuas.com/research/centre-expertise/team-cyber-security

     Resources and Research Mentioned

    Examining Ransomware Payment Decision-making Among SMEs

    Matthijsse, S. R., Moneva, A., van ’t Hoff-de Goede, M. S., & Leukfeldt, E. R.

    European Journal of Criminology.

    Explaining Cybercrime Victimization Using a Longitudinal Population-based Survey Experiment

    van ’t Hoff-de Goede, M. S., van de Weijer, S., & Leukfeldt, R.

    Journal of Crime and Justice, 47(4), 472-491 (2024).

    How Safely Do We Behave Online? An Explanatory Study into the Cybersecurity Behaviors of Dutch Citizens

    van der Kleij, R., van ’t Hoff-de Goede, S., van de Weijer, S., & Leukfeldt, R.

    In: International Conference on Applied Human Factors and Ergonomics (2021), pp. 238-246.

    The Online Behaviour and Victimization Study

    van ’t Hoff-de Goede, M. S., Leukfeldt, E. R., van der Kleij, R., …

    In:Cybercrime in Context: The human factor in victimization, offending, and … (2021).

     Other

    Dutch Government Cybersecurity Resource

    https://english.ncsc.nl

    (English-language site for the Netherlands’ National Cyber Security Centre)

    Secure Internetting (in Dutch)

    https://veiliginternetten.nl/

    22 min

About Cybercrimeology

From the publisher's feed

Cybercrimeology is a podcast about cybercrime, its research and its researchers. We talk to top researchers from around the world to learn about different forms of cybercrime and their research. We learn about cybercrime theory, organized crime online, Darknet drug markets, cybercrime awareness and crime prevention, technology-facilitated intimate partner violence and much more.