International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1717774

1717774 Vol 9 · Issue 11 Download Paper

Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It

Harnoor Singh Mini Srivastva

Subject area: Arts, Social Sciences and Humanities  ·  Area of research: Cybercrime

DOI: https://doi.org/10.64388/IREV9I11-1717774

Abstract

Every day, millions of people lose money, data, and peace of mind to cybercrime. The standard response — more laws, tougher penalties, better software — has not stopped the problem from growing. This paper argues that the real causes run deeper: most people simply do not know enough about online risks to protect themselves; weak password habits leave accounts wide open; individuals and businesses alike lack the practical skills to respond when something goes wrong; and criminals are quick to twist every new piece of technology into a weapon. None of these are purely technical problems. They are human and institutional ones, and they call for human and institutional answers. The paper examines each cause in plain terms, draws on legal frameworks from India and other jurisdictions, and offers practical steps for lawmakers, law enforcement, schools, and the private sector.

Keywords

Cybercrime, Digital Literacy, Password Security, Cybersecurity Law, Information Technology Act, Social Engineering, Technology Misuse, Cyber Policy.

References

[1] Information Technology Act, 2000 (Act No 21 of 2000), as amended by the Information Technology (Amendment) Act, 2008 (Act No 10 of 2009).

[2] Indian Penal Code, 1860 (Act No 45 of 1860), ss 415–420, 463. Personal Data Protection Bill, 2019 (India).

[3] Computer Misuse Act 1990 (c 18) (United Kingdom).

[4] Regulation (EU) 2016/679 (General Data Protection Regulation)

[5] OJ L119/1. Council of Europe, Convention on Cybercrime (Budapest Convention) ETS No 185 (2001). NIST Special Publication 800-63B, Digital Identity Guidelines (2017, updated 2020). B. Books

[6] Brenner SW, Cybercrime: Criminal Threats from Cyberspace (Praeger 2010). Clough J, Principles of Cybercrime (2nd edn, Cambridge University Press 2015).

[7] Hadnagy C, Social Engineering: The Science of Human Hacking (2nd edn, Wiley 2018).

[8] Mitnick KD and Simon WL, The Art of Deception: Controlling the Human Element of Security (Wiley 2002).

[9] Wall DS, Cybercrime: The Transformation of Crime in the Information Age (Polity Press 2007). Yar M and Steinmetz KF, Cybercrime and Society (3rd edn, SAGE 2019). C. Articles

[10] Bada M, Sasse AM and Nurse JRC, 'Cyber Security Awareness Campaigns: Why Do They Fail to Change Behaviour?' (2019) 14 International Journal of Cyber Criminology 79.

[11] Florencio D and Herley C, 'A Large-Scale Study of Web Password Habits' (2007) WWW Conference Proceedings 657.

[12] Hadlington L, 'Human Factors in Cybersecurity' (2017) 3(7) Heliyon e00346.

[13] Hutchings A and Hayes H, 'Routine Activity Theory and Phishing Victimisation' (2009) 9 Current Issues in Criminal Justice 433.

[14] Sasse MA, Brostoff S and Weirich D, 'Transforming the Weakest Link' (2001) 4 BT Technology Journal 122. D. Reports

[15] National Crime Records Bureau, Crime in India 2022 (MHA 2023).

[16] NASSCOM, Cybersecurity in India: Landscape, Threats and Opportunities (2021). Verizon, Data Breach Investigations Report 2023 (Verizon Business 2023).

[17] World Economic Forum, Global Risks Report 2023 (WEF 2023). ENISA, Threat Landscape 2023 (ENISA 2023).

[18] NITI Aayog, Data Empowerment and Protection Architecture Discussion Paper (2020). ENDNOTES

[19] 1 Information Technology Act, 2000 (Act 21 of 2000) s 43; Information Technology (Amendment) Act, 2008, s 66 (computer-related offences).

[20] 2 Jonathan Clough, Principles of Cybercrime (2nd edn, CUP 2015) 3–10.

[21] Verizon, Data Breach Investigations Report 2023 (Verizon Business 2023) 6 (74% of all breaches involve the human element).

[22] Maria Bada, Angela Sasse and Jason Nurse, 'Cyber Security Awareness Campaigns: Why Do They Fail to Change Behaviour?' (2019) 14 International Journal of Cyber Criminology 79, 83–84.

[23] National Crime Records Bureau, Crime in India 2022 (MHA 2023) ch 11, Table 11.2.

[24] Dinei Florencio and Cormac Herley, 'A Large- Scale Study of Web Password Habits' (2007) WWW Conference Proceedings 657, 658.

[25] MA Sasse, S Brostoff and D Weirich, 'Transforming the Weakest Link' (2001) 4 BT Technology Journal 122, 127.

[26] Chris Hadnagy, Social Engineering: The Science of Human Hacking (2nd edn, Wiley 2018) ch 2.

[27] Council of Europe, Budapest Convention, ETS No 185, Arts 2–6.

[28] ENISA, Threat Landscape 2023 (ENISA 2023) 12–19 (ransomware identified as prime threat category for the fourth consecutive year).

[29] World Economic Forum, Global Risks Report 2023 (WEF 2023) 8.

How to cite this paper

Harnoor Singh, Mini Srivastva "Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It" Iconic Research And Engineering Journals Volume 9 Issue 11 2026 Page 3506-3512 https://doi.org/10.64388/IREV9I11-1717774
Harnoor Singh, Mini Srivastva "Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026, doi: https://doi.org/10.64388/IREV9I11-1717774
Harnoor Singh, Mini Srivastva (2026). Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It. Iconic Research And Engineering Journals, 9(11). doi: https://doi.org/10.64388/IREV9I11-1717774
Harnoor Singh, Mini Srivastva "Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It" Iconic Research And Engineering Journals, vol. 9, no. 11, May. 2026. Crossref, https://doi.org/10.64388/IREV9I11-1717774
@article{1717774,
      author = {Harnoor Singh, Mini Srivastva},
      title = {Why Cybercrime Keeps Winning: A Plain Look at the Root Causes and What the Law Can Do About It},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {11},
      pages = {3506-3512},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1717774.pdf},
      abstract = {Every day, millions of people lose money, data, and peace of mind to cybercrime. The standard response — more laws, tougher penalties, better software — has not stopped the problem from growing. This paper argues that the real causes run deeper: most people simply do not know enough about online risks to protect themselves; weak password habits leave accounts wide open; individuals and businesses alike lack the practical skills to respond when something goes wrong; and criminals are quick to twist every new piece of technology into a weapon. None of these are purely technical problems. They are human and institutional ones, and they call for human and institutional answers. The paper examines each cause in plain terms, draws on legal frameworks from India and other jurisdictions, and offers practical steps for lawmakers, law enforcement, schools, and the private sector.},
      keywords = {Cybercrime, Digital Literacy, Password Security, Cybersecurity Law, Information Technology Act, Social Engineering, Technology Misuse, Cyber Policy.},
      month = {May},
      doi = {https://doi.org/10.64388/IREV9I11-1717774}
  }