Skip to main content

Cyberfraud and the implications for effective risk-based responses: themes from UK research

Michael Levi ; Alan Doig ; Rajeev Gundur ; David Wall ; Matthew Williams (2016) — Crime, Law and Social Change

Citation activity

Total citations · Google Scholar
Unavailable
Average per calendar year
Citation count unavailable

Counts reflect Google Scholar’s coverage and do not measure research quality. Source, calculation and limitations

What do these research terms mean?
Preprint
A manuscript shared before formal peer review and publication. Check whether a later published version is available.
Dataset
A collection of data or examples for others to inspect or reuse. It can appear in Library search and topic mapping, but RSRC does not use dataset records as evidence in Research Insights.
Dissertation or thesis
Research submitted for an academic degree. This describes its format, not its reliability.
Journal article
An article published in a journal. This label alone does not establish peer review, study quality, or how well the findings apply elsewhere.
Qualitative research
Examines experiences, meanings, or processes, often through interviews or observations. It can explain how something happens without estimating how common it is.
Quantitative research
Uses numerical measurements to describe patterns or test relationships. A relationship between two measurements does not by itself show that one causes the other.
Systematic review
Uses a planned, documented method to find and assess research addressing a question. Its conclusions still depend on the included studies and what the search covered.
Meta-analysis
Statistically combines results from multiple studies. Combining studies does not remove weaknesses in their design or make unlike populations interchangeable.
Not classified
This record has no recognized label in this filter. It does not mean the publication used no method, or that no research exists.

Definitions draw on DataCite resource types; Cochrane review methods; NLM: association and causation. RSRC’s dataset and classification rules are explained in our methodology.

Citation tools


              
              

Transparency

Evidence and review status

This page contains AI-generated content. No human content review or subject-matter-expert review is recorded.

Source basis
Downloaded PDF
Source updates
No notice found at last check
AI-generated page content
Yes
Automated checks
Passed
Administrative approval
Yes
Human content review
Not recorded
Subject-matter-expert review
Not recorded
How this was prepared
Source basis

RSRC downloaded and privately stored a copy of the paper for internal analysis. The PDF is not offered to viewers from this page.

  • PDF added to RSRC:
Source updates

No incoming update notice was found in the dated Crossref response. Coverage is incomplete, particularly for corrections and expressions of concern; this is not a guarantee that the source is valid or unchanged.

  • Last source-status attempt:
AI-generated page content

AI-generated research notes displayed on this page: Synopsis, Identified gaps, Methods, Limitations, Future work. The paper itself is not described as AI-generated.

  • Document analysis recorded:
  • Synopsis generation recorded:
  • Page record updated:
Automated checks

The current, source-bound synopsis passed the recorded versioned publication checks.

  • Checks completed:
View passed checks (3)
  • Length, completeness, repetition, refusal, boilerplate, and active-markup screening
  • Numerical claims checked against the available source text
  • English-source lexical grounding check
Administrative approval

An authenticated administrator approved the bibliographic record for public Library display. This is not a review of every research claim.

  • Approved for public display:
Human content review

No human review is recorded for the AI-generated content displayed on this page.

Subject-matter-expert review

RSRC has not recorded review of this content by a subject-matter or methods expert.

Review-state definitions
Found a possible error? Request a correction.

Synopsis

This article investigates the nature of cyberfraud—fraud with a cyber dimension—by analyzing data reported to Action Fraud and other UK sources to illuminate how a risk-based response might be improved. The authors aim to outline the range of risks and threats in cyberfraud and to consider what a more effective, risk-based enforcement and prevention approach would entail, not only in the UK but in contexts with similar dynamics. They emphasize that cyberfraud can be global in scope, though not all cases are international, and that the threat landscape is shaped by evolving technologies, open networks, and the diffusion of cybercrime across public and private actors. Drawing on observed patterns and costs of victimisation, the paper argues that the optimal law enforcement response is inherently strategic and collaborative. It contends that a purely reactive, police-led approach is unlikely to address the breadth of cyberfraud, given the high volume of low-value cases, limited recoveries, international dimensions, and resource constraints. The authors advocate for clearer roles among police, other public bodies, private sector partners, and internet service providers, as well as a focus on prevention, awareness, and resilience. They highlight the potential value of targeted, awareness-based interventions and caution that current data limitations hinder firm conclusions about what works, necessitating ongoing collection and analysis to guide policy. The article also notes limitations in the evidence base, the dynamic and heterogeneous nature of cyberfraud, and the need for multi-faceted strategies that balance deterrence, protection, and user education. It concludes with a call for strategic, cross-agency coordination and for recognizing the costs and practicalities of implementing cybersecurity measures at scale, while remaining grounded in the available data.

Identified Gaps

The paper identifies weak and incomplete measurement of cyberfraud, poor capture in crime surveys and police data, and little agreed evidence about what responses work. It also finds insufficient information on offenders’ profiles, organization, specialization, networks, information sources, and cross-fraud activity. Comparable historical data are lacking, limiting conclusions about trends.

Methods

The study analyzes 106,681 fraud and fraud-related incidents reported to UK Action Fraud from October through December 2014. It classifies incidents as cyber-assisted, cyber-enabled, cyber-dependent, or not applicable; examines first-contact methods, fraud categories, financial losses, recoveries, and self-reported harm; and compares cyber involvement across offenses. The analysis was supplemented by interviews with economic-crime control agencies, financial and industrial firms, cybercrime-prevention bodies, and current and retired UK police officers.

Limitations

Action Fraud data are a snapshot of reported incidents and contain missing-data inconsistencies. Reporting depends on victims recognizing fraud and choosing to report it. Cyber involvement is inferred largely from first contact, may be underestimated, and relies on victim or classifier judgments. The data cannot reliably identify offender location, profiles, networks, specialization, operating methods, or full criminal profits. Recovery data cover few cases and may be inaccurate or drawn from different periods.

Future Work

Test the effectiveness of individual security behaviors and security-adoption mechanisms using national longitudinal datasets. Develop faster and better intelligence on offending and offender networks using fresh and existing sources. Assess the costs, impacts, and added value of investigation, prosecution, disruption, and asset recovery, especially in cross-border cases.

See how this publication connects to RSRC's living evidence syntheses through current citations and research-topic mapping.