1 of 45

What is the Impact of Cybercrime on the Global Economy?

Gavin Connolly, Dara Clarke, Stephen Byrne

TY

2 of 45

Table of Contents

  • Introduction
  • Economic Impact of Cybercrime to Ireland
  • Economic Impact of the HSE ransomware attack of 2021
  • The Cost of Cybersecurity for Ireland
  • Interview with Mark Lane, Lecturer in cybersecurity at TUD
  • Cost of cybersecurity for everyday people
  • Survey on Cybersecurity for everyday people
  • Impact of Cybercrime on the UK
  • The Economics of Cybercrime for Russia
  • Economic Impact of Cybercrime on the Russian-Ukraine War
  • Cybercriminal bosses
  • Russian ransomware
  • The Economics of Ransomware
  • Economics of large Cyberattacks worldwide
  • The impact of AI on cybersecurity
  • The impact of AI on cybercrime
  • Global Goals
  • Major Cyberattacks during 2024
  • Conclusion
  • Reflections
  • References

3 of 45

Introduction

  • For this project we wanted to investigate the economic impact of cybercrime on the world, given the scale of cyberattacks that have occurred in the past few decades and the damage they have caused. In most cases, cybercrime is for economic benefits and victims of it suffer economic losses. Our aim for this project is to find out the economic cost of cybersecurity and the income that cybercrime generates cybercriminals. We are also interested in the main countries involved in cybercrime, and the differences between them. From an economic perspective, we will investigate the impact cybercrime has had on corporations, governments and wars. There has been a significant increase in cybersecurity training and software available in the past decade, so we wonder whether there will be an evolution from artillery in international conflict, to cybercrimes behind a computer screen. There have been countless large-scale cyber-attacks in recent years and the income it provides cybercriminals is a huge problem and is something that will need to be rectified or the cyberattacks will continue.

4 of 45

Economic impact of Cybercrime to Ireland

  • In 2020, in Ireland alone, there was a total cost of €9.6 billion for cybercrime. This was a period during lockdown in which many people were at home, using online credit cards for online shopping. Also, workers of large corporations, including cybersecurity workers were forced to work from home which has limitations. Businesses were exploited significantly in this year and there was a huge increase from 2019 to 2020 in cybercrime. There was a 55% increase in online fraud from 2019 to 2020 which may have been a combination of an increased number of people buying online due to lockdown and there being an increase in workers resorting to cybercrime organisations in foreign countries, most notably, Russia. There was also a 45% increase in the number of phishing complaints from 2019 to 2020 in Ireland, a significant increase.

5 of 45

Economic Impact of Cybercrime to Ireland

  • The most common cyberattack is ransomware which increased from approximately €995 million in 2014 to over €2 billion by 2020 in Ireland alone. Between 2020 and 2021, there was a 1,318% increase in ransomware attacks which conveys the destruction that ransomware is causing. There was an 86% increase in online investment fraud total from the same period in 2020 to 2021. A study from Hiscox Insurance found that out of 300 Irish businesses surveyed, 43% of them experienced at least one cyber-attack, which equates to 129 businesses out of the 300. In 2023, a study from Grant Thornton Ireland revealed that 59.2% of businesses surveyed had experienced a cyber-attack in the past year and unfortunately almost 20% of businesses surveyed didn’t have cybersecurity measures in place.

6 of 45

Economic Impact of the HSE ransomware attack of 2021

  • One of the most famous cyberattacks in Ireland came in 2021, when the HSE was subject to a ransomware attack which had an estimated cost of €102 million and that they had suffered 473 data-protection lawsuits against them. It is estimated that the HSE would need to spend €657 million on cybersecurity upgrades. The group known to have been responsible for the attack were identified as ‘Wizard Spider’, a group believed to have been operating out of Russia. While the vaccination records were not affected, 700 GB of unencrypted data had been taken. This included PHI (Protective Health Information).The cost of cybercrime in Ireland is massive, and cybersecurity measures must be put in place among both the private and public sectors.

7 of 45

The Cost of Cybersecurity for Ireland

  • An indirect way to increase the number of businesses investing in cybersecurity is to fine them if they breach the General Data Protection Regulation (GDPR). The structure was set up in 2018, for EU countries and the UK and have increased the maximum fine in Ireland for data protection breaches of €100,000 to €20 million, a massive increase. This means that businesses are realising that it isn’t the direct cost alone that a cyber-attack may inflict, it’s the added costs such as GDPR breaches that boost the cost. The result of the new structure means that businesses have increased their cybersecurity measures.  In October 2024, a Cyber Security Review Grant was announced for Irish businesses, which is a partnership between Enterprise Ireland and the NCSC. The grant allows businesses 80% of a fixed project fund of €3,000 for cybersecurity measures which can help protect them against future attacks. The grant was operated on a first come, first served basis which meant that businesses had to act fast if they wanted funding.

8 of 45

The Cost of Cybersecurity for Ireland

  •  The threat cybercrime poses to businesses around Ireland has had a potent impact on their annual budgets. A PWC Ireland CEO survey revealed that 90% of Irish businesses feel that they are vulnerable to cyber-attacks. The study also revealed that 69% of Irish businesses are increasing their cybersecurity budgets, in comparison to the world average of 80%. A common conception of incoming government legislation will be that the new Irish government will undoubtedly introduce new legislation for Irish businesses. Cybersecurity is becoming a vital cost for the government, considering the consequences for businesses around the country.

9 of 45

The Cost of Cybersecurity for Ireland

  • The Irish government set out to improve cybersecurity in 2015 with the ongoing crisis of cybercrime, putting government databases at risk. The National Cyber Security Centre (NCSC) was established and works to help the government protect their critical data from external attacks. In February 2021, the government announced that it would spend €193 million on cybersecurity research, artificial intelligence, data privacy and ethics. The 2024 National budget included a €10.7 million investment in the National Cyber Security Centre (NCSC) which will allow for increased funding into cybersecurity in both the private and public sector.

10 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

As part of our research into this project, we interviewed Mark Lane, lecturer in cybersecurity at the Technological University of Dublin (TUD) and founder of Zerodays CTF, which for the last 10 years has brought young people all over Ireland into the cybersecurity scene. We wanted to hear his input into the importance of cybersecurity and how businesses across Ireland are vulnerable if the investment into cybersecurity isn't made. We asked him five questions about the most important aspects of cybersecurity in Ireland. We would like to sincerely thank Mark for taking his time to answer our questions.

11 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

1. Are cyberattacks becoming a threat to the Irish government? 

Yes, cyberattacks are an increasing threat to the Irish government. In recent years, Ireland has experienced a sharp rise in cyber incidents targeting government agencies and critical infrastructure. One of the most high-profile attacks was the 2021 ransomware attack on the Health Service Executive (HSE), which disrupted healthcare services nationwide and cost the government millions in recovery efforts. This attack demonstrated how cybercriminals are not just targeting businesses but also public institutions, leading to potential risks for national security, economic stability, and public safety. 

Additionally, Ireland’s growing digital economy and role as a European tech hub make it an attractive target for both cybercriminals and state-sponsored actors. Government agencies manage vast amounts of sensitive data, and any breach could have severe consequences. While steps have been taken to improve national cybersecurity, including the establishment of the National Cyber Security Centre (NCSC), continuous investment in defensive capabilities, training, and public-private collaboration is essential to counter this evolving threat landscape. 

12 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

2. Is the Irish government investing enough into cybersecurity?

While the Irish government has made progress in strengthening national cybersecurity, current investment levels still fall short of what is required to adequately defend against increasingly sophisticated cyber threats. The National Cyber Security Strategy 2019-2024 outlines Ireland’s approach to improving its cyber resilience, but critics argue that funding and resources remain insufficient, particularly when compared to other European nations.

For example, in 2023, the Irish government allocated €22 million to the National Cyber Security Centre (NCSC)—a significant increase from previous years but still relatively low compared to the UK’s £2.6 billion National Cyber Strategy investment. Cybercriminals and nation-state actors are continuously evolving their tactics, and without substantial long-term funding, Ireland risks falling behind in its ability to protect critical infrastructure, businesses, and government systems. Increased investment in cybersecurity talent development, public-private partnerships, and proactive threat detection measures is essential to ensure Ireland remains resilient against cyber threats.

13 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

3. Which country poses the biggest threat to Irish businesses?

While cyber threats can originate from anywhere, Russia and China are often cited as the biggest state-sponsored cyber threats to Irish businesses, particularly in sectors involving sensitive data, finance, and technology. Russia has been linked to cyber espionage campaigns targeting European countries, and with Ireland being home to key global tech and financial services companies, it is an attractive target for intelligence gathering and disruption.

China, on the other hand, has been accused of engaging in cyber espionage to steal intellectual property and trade secrets from businesses worldwide. Given Ireland’s role as a major hub for multinational corporations, particularly in pharmaceuticals, software, and finance, Chinese cyber actors may seek to exploit vulnerabilities in these industries.

However, it’s not just state-sponsored threats that Irish businesses need to worry about—cybercriminal groups from around the world, including Russia, Eastern Europe, North Korea, and beyond frequently deploy ransomware and phishing attacks against Irish firms. The Conti ransomware gang, for instance, was linked to the devastating 2021 HSE cyberattack. In short, Irish businesses face cyber risks from multiple international actors, and robust cybersecurity measures are critical to mitigating these threats.

14 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

4. Do Irish businesses need to be made more aware of the threats cyber-attacks can pose?

Absolutely. While awareness of cyber threats has improved in recent years, many Irish businesses, particularly SMEs (small and medium-sized enterprises), remain underprepared for cyberattacks. According to research, a significant percentage of Irish companies lack adequate cybersecurity measures, making them easy targets for ransomware, phishing, and data breaches. Many business owners believe they are “too small” to be attacked, but cybercriminals often target SMEs precisely because they tend to have weaker defenses.

More needs to be done to educate Irish businesses on basic cybersecurity hygiene, incident response planning, and threat awareness. The government and industry groups should work together to provide accessible training programs, resources, and incentives for businesses to invest in cybersecurity. Initiatives like Cyber Ireland and the National Cyber Security Centre (NCSC) could play a bigger role in driving awareness. Without proactive education and investment in cybersecurity, many Irish businesses remain at serious risk of financial and reputational damage from cyber incidents.

15 of 45

Interview with Mark Lane, Lecturer in cybersecurity at TUD

5. What is the most cost-efficient method of cybersecurity for low-profile Irish businesses with small budgets?

For low-profile Irish businesses with limited budgets, implementing cybersecurity best practices doesn’t have to be expensive—many effective measures are low-cost or even free. The most cost-efficient approach involves a combination of basic security tools, employee training, and common-sense cyber hygiene practices.

  • Enable Multi-Factor Authentication (MFA): MFA is one of the simplest and most effective ways to prevent unauthorised access to accounts. Many platforms, including email providers and cloud services, offer it for free.
  • Use Strong Passwords and a Password Manager: Encourage employees to use unique passwords and store them securely with free or low-cost password managers like Bitwarden or LastPass. Practice good password hygiene and enforce password policies.
  • Keep Software Updated: Regularly updating operating systems, applications, and security software helps patch vulnerabilities before they can be exploited.
  • Install a Free or Affordable Antivirus Solution: Tools like Windows Defender (built into Windows) or free versions of Avast and Bitdefender provide decent protection against malware.
  • Implement Regular Data Backups: Use cloud-based or external hard drive backups to ensure critical business data is recoverable in case of an attack.
  • Conduct Cybersecurity Awareness Training: Employees are often the weakest link in cybersecurity. Free resources like CyberAware by the UK NCSC or training from Cyber Ireland can help staff recognise phishing emails and other threats.
  • Limit User Access: Not all employees need access to sensitive company data. Implementing role-based access controls (RBAC) reduces the risk of insider threats. Utilise the principle of least privilege where users are only given the minimum access that they need. 
  • Use a Basic Firewall and Network Security Measures: Many internet service providers offer built-in security features with their business plans. Small businesses can also use affordable firewall solutions like pfSense for added protection.

By implementing these low-cost but highly effective cybersecurity measures, even the smallest businesses can significantly reduce their risk of falling victim to cyberattacks. For those with slightly larger budgets, outsourcing cybersecurity to a managed security provider (MSP) can also be a cost-effective option.

16 of 45

Cost of Cybersecurity for everyday people

  • Due to the threat of cyber-attacks on everyday Irish residents, there have been various software and apps to have come available to combat cyber-attacks on people's data. However, they come at a price and is another example of how cybercrime has impacted people all around the world. One of the most renowned software tools that combats cyber-attacks is Norton. Norton have a tool that prevents viruses. They will block users from clicking on certain links and will put a green rick beside any website that is ''Norton Safe Search''. However the tool costs people €29.99 per year. Gen Digital is an app that uses AI insights to help people prevent cyber-attacks and keeps their data secure. A study by TechJury in 2023, revealed that 76% of computers worldwide have anti-virus software installed. They also revealed that in 2020, the cybersecurity market had risen to $40 Billion. It isn't just the cyber-attacks themselves that have an impact on people financially. It's the tools they use to combat it.

17 of 45

Survey on Cybersecurity for everyday people

We decided to carry out a survey; to highlight the knowledge people have on cybercrimes and how important it is to have cybersecurity measures in place at home. We received 43 responses which gave us a good indication of reliable data. We also wanted to investigate whether people had suffered cyber-attacks themselves and the financial reprocussions of these attacks. In question 1, we asked fellow students if they had previously heard of a cyberattack.

18 of 45

Survey on Cybersecurity for everyday people

In question 2, we asked students if they had ever previously experienced a cyberattacks, to understand the percentage of people in our school that had experienced a cyberattack. The majority of students stated that they had previously experienced a cyberattack, which shows the importance to invest in high-quality cybersecurity software on devices.

19 of 45

Survey on Cybersecurity for everyday people

In question 3, we surveyed students on the types of cyber-attacks that they had experienced. 3 had experienced Malware, 15 experienced Scam Email/ Text Message, 2 experienced social engineering, 5 experienced password stealing and 4 had experienced other types of cyberattacks. While Scam Email/ Text Message proved to be the most common type of household cyberattack, this question conveyed the range of methods used to infiltrate people's data.

20 of 45

Survey on Cybersecurity for everyday people

In question 4, we asked people if they had previously lost money to a cyberattack. While we were relieved to see the majority of people hadn't, we were disappointed to see that 16 people had lost money to a cyberattack, which out of a pool of 43, is a significant number.

21 of 45

Survey on Cybersecurity for everyday people

In question 5, we asked people the amount of money that they had lost to cyberattacks, if any. The majority of people lost funds in the range of €0-€15. 8 people lost money in the range of €50-€100. 1 person lost money in the range of €100-€200 wile 3 people lost over €200. We were very taken aback to see that 3 people out of 42 had lost over €200 to a cybercrime.

22 of 45

Survey on Cybersecurity for everyday people

In question 6, we asked students if they had purchased anti-virus software for their device. This provides us with the cybersecurity aspect of the survey, finding out if people are aware of the risks associated with cybercrime if anti-virus software is not purchased. A staggering 63% of people had not invested in anti-virus software which is a huge issue and is maybe the reason why 3 people suffered a collective loss of at least €600 from cyberattacks.

23 of 45

Survey on Cybersecurity for everyday people

In question 7, we asked students what anti-virus software brand they had chosen if they had elected to purchase the software. Norton SafeSearch proved to be the most popular with 38% of people choosing it. 14% chose Avast Antivirus and 24% chose McAffee Antivirus. Nobody uses Bitdefender antivirus and 24% of people use a different brand to the ones we provided.

24 of 45

Impact of Cybercrime on the UK

  • Cybercrime in the UK is estimated to cost £27 billion annually. The UK, being a neighbouring country of Ireland, has an impact on our cybersecurity measures. According to the NCSC of the UK, the Uk is the third most targeted country of cyber-attacks after the US and Ukraine. In 2023, 23% of businesses and 24% of charities had been targeted by cyber-attacks. Smaller, local businesses and charities are the most vulnerable to cyber-attacks as most would not have the sufficient cybersecurity measures in place. Allianz, an insurance company, stated in a recent report, that cyberattacks pose the most profound risk on businesses in the UK in 2024. A report by Microsoft in the same year also highlighted that 87% of businesses in the UK are 'at high risk' or vulnerable to a cyber-attack. TeckForce, a workforce management company, revealed that in 2024 in the UK there had been 2,814 incidents and 8,214,886,660 breached records of cybersecurity. Another report by TwentyFour IT services highlighted that 50% of British business experienced a cyber-attack in 2024. The value of these cyber-attacks for a medium-range business was approximately £10,830. The most common cybercrime technique that was employed proved to be phishing. 84% of businesses in the UK experienced phishing attempts in 2024.

25 of 45

The Economics of Cybercrime for Russia

  • Russia have the highest rate of cybercrime in the world and we wondered what benefit does the cybercrime industry provide Russian cybercriminals. While the financial implications of cybercrime is quite relevant, we must refer to the other side of the cashflow. The expected revenue for Russia in the cybercrime market is 3.55 billion for 2024 alone. There is an expected annual growth rate (CAGR) of 5.32% between 2024 and 2029 of cybercrime related revenue in Russia. According to experts in the USA, the Russian government is reluctant to prosecute cybercrime. In 2012, Vladimir Drinkman was a known cybersecurity criminal. He was arrested while on holiday in Amsterdam, however The Russian government attempt to block the USA's extradition request by filing their own. Many believe this was to delay prosecution and maximize revenue.

26 of 45

The Economics of Cybercrime for Russia

  • Analysis conducted in 2022 reported that approximately 74% of ransomware attacks were affiliated with Russian-based hackers.   Researches also believe that $400 million worth of crypto currency payments went to groups who were potentially linked with Russian groups. Russia consistently denies these links. Russia and the US don't often collaborate when it comes to dismantling cybercrime organisations, however, in 2021, Russian authorities acknowledged the request of the US and made certain arrests of the renowned cybercrime group, REvil. In November 2021, researches discovered Igor Turashev, who is one of the leaders of Evil Corp, to be operating several businesses out of Moscow City's federation tower. A renowned address in the city.

27 of 45

The Economics of Cybercrime for Russia

  • Due to Russia’s relatively low annual average salary of $14,771, there is a desire to earn money, even if there may be consequences. Russia seem to be more relaxed than western countries at prosecuting cybercriminals and therefore this means that there is an opportunity for skilled cybercriminals to make significantly more money. A study done in 2016, found that criminals involved in ransomware attacks can earn approximately $90,000 per year. This is around $75,000 greater than the average salary. Ransomware attacks are when personal data is held hostage until a ransom is paid.

28 of 45

Economic impact of cybercrime on the Russia-Ukraine war

  • According to the NCSC of the UK, just an hour before the war between Russia and Ukraine started, an attack was launched against Viasat. The NCSC believes that Russia was behind the attack. The cyber-attack was originally designed to affect the Ukranian military. In May 2022, a Russian cybercrime group called XakNet launched an attack on Ukranian State Registers. This impacted data such as business records, property ownership etc. Everyday the war in Ukraine costs in the range of $500 million - $1 Billion everyday. Artillery and heavy cargo transportation are the main costs involved. This is why cybercrime poses a cheaper and effective method of disrupting critical infrastructure and is a key aspect of Russia’s foreign policy.

29 of 45

Cyber criminal bosses

  • Cybercriminal bosses commit these cybercrimes for many reasons but fundamentally there are three reasons as to why they do it. They are financial gain, espionage and sabotage. They aim to obtain sensitive information, such as financial data or intellectual property, that they can use to generate profit. Cybercriminals may sell this information on the dark web or use it to commit fraud or extortion. This causes panic and confusion among those effected as the cybercriminals collect their earnings in a matter of a few clicks. Seeing as Russia have one of the highest rates of cybercrime in the world, Russian ransomware bosses can make an annual income of $90k, or even 13 times the average wage in the country.

30 of 45

Russian ransomware

  • During a five-month investigation, Flashpoint analysts monitored the strategy behind Russian ransomware campaigns and the network of a specific Russian ransomware boss. The healthcare industry was the most targeted by recent waves of ransomware campaigns, due to the numerous confidential records it keeps. Hackers have developed a new type of ransomware, sold by Russian ransomware bosses to hackers with lower skills, who then use it as they wish via their distribution methods, Flashpoint found. By introducing RaaS, newly recruited hackers learn how these campaigns work and how to attack Western corporations. Users with botnet installs emails and social media phishing campaigns, compromised dedicated servers and file-sharing websites. “Ransomware is clearly paying for Russian cyber-criminals,” said Vitali Kremez, cybercrime intelligence analyst at Flashpoint.

31 of 45

Russian Ransomware

  •  “As RaaS campaigns become more widespread and accessible to even low-level cyber-criminals, such attacks may result in difficult situations for individuals and corporations not yet ready to deal with these new waves of attacks.” The petty hackers become part of a network affiliated to a ransomware boss who takes over communication with the victims after the campaigns have been launched. The boss, in charge of approving bitcoin payments, money laundering through bitcoin exchangers and issuing decryption keys, usually keeps around 60% of the ransom. This particular boss might also ask for extra money, although a ransom has already been paid. Consequently, some victims who paid for the decryption key never received it, Flashpoint discovered.

32 of 45

The Economics of Ransomware

  • Ransomware has grown in popularity among cybercriminals in recent years. According to cybercrimemagazine, the financial implications of ransomware is predicted to exceed $265 billion by 2031. In 2021, the global cost of ransomware reached $20 billion which is a significant 57x increase on that of 2015. A study carried out by Veeam suggested that out of 350 business victims interviewed, 96% stated that ransomware attacks had been targeting backup repositories. A low 14% stated that they retrieved their data without paying the ransom while a staggering 28% were required to pay the ransom but never retrieved their data. The issue with cybercrime like this is that there isn't the services to go to if your business is in trouble. You can only report the problem. That is why cybersecurity measures are a must for every business across the globe.

33 of 45

Economics of large Cyber attacks worldwide

  • The NotPeya cyber-attack of 2017 impacted many major companies around the globe. The US valued damages of the attack at over $10 billion which makes it one of the largest cyber-attacks ever recorded. The BBC stated that the recent attack cost TNT approximately $300 million. Merck, a biopharmaceutical, settled a claim of $1.4 billion with their insurers regarding the damages of the attacks. Maersk, a shipping company stated that their NotPeya attack damages are worth in the vicinity of $300 billion. The WannaCry attack of May 2017 has caused $4 billion worth of damages and there has been 300,000 computers affected. The WannaCry attack had a significant impact on many large corporations including the NHS who suffered damages of £92 million.

34 of 45

The impact of AI on cybersecurity

  • AI (artificial intelligence) is a fast-evolving technology that is slowly taking over our lives, but we wondered what impact AI has on cybersecurity. AI-driven tools can process vast amounts of data quickly and accurately, enabling organisations to identify and respond to security threats faster than ever before. Due to the cost of cybersecurity expected to reach $10.5 trillion globally in 2025, AI might prove to be the future of cybersecurity, and a cheaper, more effective way of combatting cyberattacks.

35 of 45

The impact of AI on cybercrime

  • While AI may be a useful tool in the cybersecurity industry, cybercriminals are quickly realising that the tool can be used in cybercrime also. AI tools such as ChatGPT are employed to generate malware by cybercriminals. It is quicker and more effective than doing it manually. Unfortunately, AI may be becoming a cost-effective, efficient way of carrying out cybercrime. While cybercrime is a growing concern as it is, AI might make it even stronger, and more difficult to trace.

36 of 45

Global Goals

  • Currently, there are 17 global goals set up to address global challenges such as poverty, hunger, inequality etc. The Global Goal that is involved with cybercrime is peace, justice and strong institutions. This goal aims to reduce cybercrimes throughout the world and build trust between victims. For example, people want to trust that their text messages they receive from 'supposed' companies are factual. It is not just for economic purposes. Maintaining people's privacy is vital and reducing access to personal data will ensure this. Financial implications of cybercrime are posing a huge threat to businesses and governments around the world. In order to, achieve the Global Goal, the world must work together by increasing cybersecurity and prosecuting cybercrime. Then, the global economy will be in a better place.

37 of 45

Major Cyberattacks during 2024

In February 2024, Change Healthcare of the United States of America suffered a catastrophic cyberattack. The culprit was identified as a Russian group known as BlackCat (ALPHV). Change Healthcare primarily look after electronic payments and medical claims within the healthcare sector of the US. This data infiltration led to nationwide disruptions. Medical claims and electronic payments were halted. UnitedHealth Group estimated the direct cost of the attack at approximately $2.87 billion and the company paid a further $6 billion in assistance of healthcare providers that had been affected due to the attack. UnitedHealth CEO Andrew Witty later confirmed that the organisation paid the ransom to BlackCat at a cost of $22 million, further increasing profitability for the cybercrime group. This attack exposed the weakness in cybersecurity measures in healthcare while also highlighting the economic efficiency of BlackCat. 

38 of 45

Major Cyberattacks during 2024

  • Snowflake, a major global cloud platform, suffered a devastating data breach in May 2024. The data breach affected over 100 of their clients which included copanies such as Santander Bank, Ticketmaster and AT&T. A US/UK based cybercrime group known as Scattered Spider infultrated the accounts of Snowflake and leaked vast amounts of sensitive data. The cybercrime group demanded ransoms between $300,000 and $5 millon from affected companies. CNBC reported that the shares of snowflake fell by 1.8% following the attack. The Spider group also alleegdly wanted to sell the data for $2 million. This attack posed a huge risk to companies worldwide and was another example of the dangers associated with cybercrime in 2024. The attack also proved that the cybercrime groups associated with these attacks are having their desired effect and are making a lot of money, considering the difficulty to track them down. Cybersecurity costs are a must for all businesses globally amidst the ongoing cybercrime crisis.

39 of 45

Major Cyberattacks during 2024

  • The NHS suffered another critical cyberattack in June 2024 and once more highlighted the lack of cybersecurity in the Global Health Sector, given the value of data within. The attack was carried out by a group known as Qilin Ransomware Gang. This attack was known for the dammage It caused to daily affairs along with the financial implications. Cancer-treatment operations and C-sections had to be rescheduled across the UK and test results were delayed. The Qilin group is believed to be associated with Russia and are another example of the detrimental impact of Russia in the cybercrime industry. They demanded a $50 million ransom. When it was declined, the group posted their findings online. Hence, the NHS received massive scrutiny from the media in the months that followed.

40 of 45

Major Cyberattacks during 2024

  • On July 19th, 2024, a faulty update from CrowdStrike's Falcon sensor software caused worldwide disruptions for a lot of Microsoft Windows users. Users across the world were greeted with what was called "Blue Screen of Death". About 8.5 million systems crashed globally. This outage severly impacted various critical sectors, including aviation, hospitals, banking and manufacturing . Even some radio/Tv stations, grocery stores and petrol pumps were affected . This particular incident showcased just how far reaching the impact of vulnerbilities in digital systems can be and how the can effect different organisations in economies all over the world. This attack sprung all from a software bug which was then breached

41 of 45

Major Cyberattacks during 2024

In September of 2024  Transport for London (TfL) experienced a cyberattack that disrupted services. The greatest impact was on disabled passengers who relied on TfL's Dial-A-Ride service, yet again highlighting the huge impact cyberattacks can have on daily life. Initially, TfL believed that no data had been compromised; however, further investigation revealed the extent of the breach. The attack had allegedly compromised the personal data of approximately 5,000 customers, including sensitive information such as home addresses and banking details. Concerned that this could be a ransomware attack, the IT security teams at TfL took swift action by shutting down and restricting access to several systems to contain the damage. However, this resulted in significant operational disruptions and financial losses. TfL reported that the incident cost the organisation £30 million. £5 million has been since spent spent on response efforts, investigations, and implementing enhanced cybersecurity measures. 

42 of 45

Conclusion

In conclusion, we found that cybercrime has a significant impact on the global economy. Unfortunately, the figure is growing with every passing year, and measures must be put in place to ensure that cybercrimes are put to a stop. For context, regular, day-to-day crime in the UK costs the nation approximately £38 billion. Police, Investigators, Courts, prisons and more are there to resist the amount of crime. However, many won't know that the annual cost of cybercrime in the UK is $27 billion and is over 2/3 of the annual cost of crime. Despite some cybersecurity measures in place, cybercrime does not receive near the attention that regular crime does, exposing the risks cybercrime poses.

43 of 45

Conclusion

We conclude that cybersecurity must be increased as cybercrime gangs are recruiting people who don't require a lot of experience or qualifications. They provide them with the ransomware software, and they steal. Cybercrime now costs the US 0.78% of the national GDP. This figure is increasing. International cooperation to prosecute cybercriminals and affiliated gangs must be increased, as international cybercrime is the most difficult to trace. We conclude that Irish businesses are vulnerable and that people at home must purchase anti-virus software for their devices at home. Yet, the measures the NCSC has taken are positive, and hopefully will limit cyberattacks in upcoming years.

44 of 45

Reflections

  • From doing this project, we learned many new skills that will most certainly be helpful for us in the future and that we will carry with us for the rest of our projects in transition year. One key example of the skills we learned was about teamwork and friendship  throughout the project. We found out that having three people in our group was challenging at times but persevered through resilience and completed the project.
  • Another important lesson was about our research that we carried out, making sure we cross checked it several times in making sure that it was fully correct. We learned to check multiple sources of information to confirm statistics we implemented.
  • Once we began researching more and more about the topic, our interests grew in the subject, and we found it much easier to comprehend.
  • The most difficult part of this project was finding time to complete it. We decided at the start of every class we had together to set each person a task on what they had to research and complete. We found that this system ensured that everyone did equal amount of work and that we all provided our own skills. These goals really  pushed us and made us stronger as a group.
  • Next time we would maybe broaden our survey as we felt that the survey was our own field research and gave us a massive insight into the knowledge students our age have on the subject.
  • Completing this project gave us a great deal of satisfaction and accomplishment. We learned a lot from research, and we are now more aware of the topic ourselves. Some of the statisitcs we researced were an eye-opener for us as we were not previously aware of such numbers. I would advise all students to complete a YEOTY project in future years as it is a very beneficial to learn and develop your skills.

45 of 45

References