Skip to main content

Empty Streets, Busy Internet: A Time-Series Analysis of Cybercrime and Fraud Trends During COVID-19

Steven Kemp ; David Buil-Gil ; Asier Moneva ; Fernando Miró-Llinares ; Nacho Díaz-Castaño (2021) — Journal of Contemporary Criminal Justice

Citation activity

Total citations · Google Scholar
Unavailable
Average per calendar year
Citation count unavailable

Counts reflect Google Scholar’s coverage and do not measure research quality. Source, calculation and limitations

What do these research terms mean?
Preprint
A manuscript shared before formal peer review and publication. Check whether a later published version is available.
Dataset
A collection of data or examples for others to inspect or reuse. It can appear in Library search and topic mapping, but RSRC does not use dataset records as evidence in Research Insights.
Dissertation or thesis
Research submitted for an academic degree. This describes its format, not its reliability.
Journal article
An article published in a journal. This label alone does not establish peer review, study quality, or how well the findings apply elsewhere.
Qualitative research
Examines experiences, meanings, or processes, often through interviews or observations. It can explain how something happens without estimating how common it is.
Quantitative research
Uses numerical measurements to describe patterns or test relationships. A relationship between two measurements does not by itself show that one causes the other.
Systematic review
Uses a planned, documented method to find and assess research addressing a question. Its conclusions still depend on the included studies and what the search covered.
Meta-analysis
Statistically combines results from multiple studies. Combining studies does not remove weaknesses in their design or make unlike populations interchangeable.
Not classified
This record has no recognized label in this filter. It does not mean the publication used no method, or that no research exists.

Definitions draw on DataCite resource types; Cochrane review methods; NLM: association and causation. RSRC’s dataset and classification rules are explained in our methodology.

Citation tools


              
              

Transparency

Evidence and review status

This page contains AI-generated content. No human content review or subject-matter-expert review is recorded.

Source basis
Downloaded PDF
Source updates
No notice found at last check
AI-generated page content
Yes
Automated checks
Passed
Administrative approval
Yes
Human content review
Not recorded
Subject-matter-expert review
Not recorded
How this was prepared
Source basis

RSRC downloaded and privately stored a copy of the paper for internal analysis. The PDF is not offered to viewers from this page.

  • PDF added to RSRC:
Source updates

No incoming update notice was found in the dated Crossref response. Coverage is incomplete, particularly for corrections and expressions of concern; this is not a guarantee that the source is valid or unchanged.

  • Last source-status attempt:
AI-generated page content

AI-generated research notes displayed on this page: Synopsis, Identified gaps, Methods, Limitations, Future work. The paper itself is not described as AI-generated.

  • Document analysis recorded:
  • Synopsis generation recorded:
  • Page record updated:
Automated checks

The current, source-bound synopsis passed the recorded versioned publication checks.

  • Checks completed:
View passed checks (3)
  • Length, completeness, repetition, refusal, boilerplate, and active-markup screening
  • Numerical claims checked against the available source text
  • English-source lexical grounding check
Administrative approval

An authenticated administrator approved the bibliographic record for public Library display. This is not a review of every research claim.

  • Approved for public display:
Human content review

No human review is recorded for the AI-generated content displayed on this page.

Subject-matter-expert review

RSRC has not recorded review of this content by a subject-matter or methods expert.

Review-state definitions
Found a possible error? Request a correction.

Synopsis

This publication examines how the COVID-19 pandemic and related lockdowns may have reshaped cybercrime and fraud opportunities in the United Kingdom. The authors pose questions about whether increases in cybercrime and fraud during the early pandemic period exceed normal crime variability and whether different fraud types and victim groups were affected in distinct ways. They use univariate ARIMA time-series models fitted to crime reports submitted to Action Fraud from April 2017 through March 2020 to generate 95% prediction intervals for April–July 2020, allowing them to assess whether observed counts exceeded historical expectations. They also supplement crime data with routine-activities indicators (e.g., online shopping, air travel, cinema attendance) to contextualize shifts in opportunities and victims. The results indicate that total cybercrime and total fraud in the UK rose above forecasted levels in the spring of 2020, with cybercrime peaking in March–May and fraud peaking around May–June before returning within the predictive bounds by July. Among fraud types, online shopping fraud surged and remained elevated above prior predictions for a time, while dating fraud showed a pronounced but shorter-lived rise. Ticket fraud declined to near zero during the early pandemic months, and door-to-door fraud remained within predicted ranges. Victimization patterns differed by actor: trends for individual victims rose above expected levels, whereas organizational victimization generally did not, except for online shopping fraud where organizations showed a notable uptick. The authors acknowledge limitations, including reliance on officially reported data that may undercount actual crime and potential reporting changes during the pandemic. They argue for a crime-specific, opportunity-based approach to prevention and note that the return toward pre-COVID activity levels may influence future cybercrime dynamics, highlighting the role of telework as a guardian and the need for targeted policy and practice responses.

Identified Gaps

The paper identifies a lack of time-series analysis of cybercrime and fraud during COVID-19. It also highlights uncertainty about why individual and organizational trends diverged, including possible differences in victimization, detection, and reporting. The authors call for greater offense, victim, and country specificity rather than broad claims about pandemic-related cybercrime increases.

Methods

The study analyzed monthly Action Fraud reports in the United Kingdom from April 2017 to July 2020. It used univariate ARIMA models, selected through a Hyndman-Khandakar stepwise algorithm using AICc, to forecast April-July 2020 counts from pre-lockdown data and compare observed reports with 95% prediction intervals. Analyses covered total cybercrime, total fraud, four fraud types, and individual versus organizational victims. Routine-activity indicators were descriptively compared with fraud trends.

Limitations

The study relies on police-reported Action Fraud data, while fraud and cybercrime reporting is low and therefore leaves a substantial unobserved dark figure. Changes in crime-recording practices over time could distort historical trend analysis. The dataset excluded reports without valid postcodes, and the proportion excluded was unknown. Organizational victim samples were too small to estimate models for dating, ticket, and door-to-door fraud.

Future Work

Examine organizational characteristics associated with cybercrime and fraud victimization during COVID-19; distinguish actual victimization changes from reporting and detection changes; assess whether homeworking shifted risk from organizations to under-protected individuals; and investigate whether existing offenders intensified activity or new actors entered fraud markets during the early pandemic.

See how this publication connects to RSRC's living evidence syntheses through current citations and research-topic mapping.