Encrypting Ransomware
Malware encrypts the victim's files and changes their extensions; a ransom is demanded for the decryption key while the device otherwise still works.
Human Impacts Cyber Framework · v1.0
A reference classification of cyber attacks that target people rather than enterprises. Forty attack types are organised into six threat domains and mapped across four dimensions — the attacker's goal, the delivery vector, the target asset, and the primary harm to the victim.
Foundational source: The Cyber Helpline — Recovery Guides. Each attack type links to its corresponding victim-support guide.
Malicious software and coercion used to deny access to data or devices, or to extract payment through threats.
Malware encrypts the victim's files and changes their extensions; a ransom is demanded for the decryption key while the device otherwise still works.
A ransom note appears the moment the device is switched on, locking the victim out of the device entirely until payment.
An attacker obtains sensitive information about the victim and demands payment or action to prevent its release.
Threats to share intimate images or video of the victim unless money is paid or demands are met.
Software is placed on a device to steal information or cause damage, without the owner's knowledge.
An attacker gains control of an online account or device without the owner's permission.
Unauthorised access to a webmail account such as Gmail, Hotmail or Yahoo.
Unauthorised access to a social media account such as Facebook, X or Instagram.
Unauthorised access to the victim's online banking.
Unauthorised access to an online cryptocurrency wallet or exchange account.
Unauthorised access to a gaming account such as Steam, Fortnite or PlayStation Network.
Unauthorised access to a shopping account such as Amazon or eBay.
Someone gains access to the victim's home wireless network without permission.
An attacker takes over the victim's mobile number so calls, texts and 2FA codes route to the attacker.
A general case where an online account is suspected of being accessed without permission.
A general case where a computer, phone or tablet is suspected of being accessed or controlled remotely.
The internet and connected devices used to bully, intimidate, monitor, impersonate or humiliate a person.
Bullying or abuse online, including trolling and abusive direct messages.
Persistent online stalking accompanied by severe threats to the victim's personal safety.
Sharing someone's personal information, secrets or sensitive images online without consent.
Fake profiles created to harass the victim, or impersonating the victim to cause distress.
Someone with access to the victim's social account posts content that causes distress or reputational damage.
Someone pretends to be a different person to trick the victim into a personal relationship.
An adult builds a relationship with a minor online to manipulate, exploit or abuse them.
Exposure to hate speech, offensive material, adult content aimed at children, or harmful online 'challenges'.
An ex-partner shares sexually explicit images or video of the victim without consent to cause distress.
Physical or software surveillance — listening devices, hidden cameras, or location trackers/stalkerware.
Direct deception by email, phone or text that manipulates the victim into compromising their own security.
A deceptive email that tricks the victim into clicking, downloading or disclosing credentials.
A fraudulent phone call that manipulates the victim into disclosing information or taking harmful action.
A fraudulent text message that tricks the victim into clicking a link or disclosing information.
Deception intended to produce financial or personal gain for the criminal at the victim's expense.
The victim is defrauded through a cryptocurrency scheme or fake exchange.
Unauthorised transactions made using the victim's bank card details.
An attacker steals and uses the victim's identity, often to open accounts or obtain credit.
The victim is deceived when buying on an auction or marketplace site such as eBay or Amazon.
Scams that exploit a topical event or crisis (e.g. Covid-19) to add urgency and credibility.
Job-fraud schemes that deceive the victim while applying for work at home or abroad.
Fraud committed against the victim while they are taking out a loan.
The victim is defrauded while making what they believe to be a legitimate investment.
Exposure of personal data through mistakes, third-party breaches, or inaccurate public reporting.
A device is lost, creating risk to any information stored on or accessible from it.
The victim accidentally shares sensitive or confidential information online.
A website publishes fake or inaccurate information about the victim.
A company, app or service the victim uses is hacked, exposing the victim's data (third-party breach).
Not attack types — the actions a victim takes across any incident to preserve evidence and recover losses.
Cross-cutting response: how to save and protect digital evidence before reporting cybercrime to the authorities.
Cross-cutting response: steps to try to recover money lost in an online scam or cybercrime.