SLIDE 1
CSZone.co.uk
Click to advance · Arrow keys also work
CAIE 9618 · Paper 1 · Topic 1.6.2

Cybercrime &
Computer Misuse

Computer Misuse Act 1990 · Types of Cybercrime · Hacking · Prevention

CSZone Cambridge International AS & A Level Computer Science 9618
Computer Misuse Act 1990

UK Law on Computer Crime

The Computer Misuse Act 1990 (CMA) was passed in the UK to criminalise unauthorised access to and modification of computer systems. It defines three main offences:

SECTION 1 — Unauthorised Access
Accessing a computer or its data without permission. e.g. Logging into someone else's account without consent. Up to 2 years' imprisonment.
SECTION 2 — Unauthorised Access with Intent to Commit a Further Offence
Gaining access with the intent to commit another crime, e.g. accessing a bank account to commit fraud. Up to 5 years' imprisonment.
SECTION 3 — Unauthorised Modification of Data
Intentionally altering, deleting, or corrupting data. Includes installing malware, deleting files. Up to 10 years' imprisonment.
Types of Cybercrime

Common Attacks and Methods

Crime TypeDescriptionExample
HackingUnauthorised access to systems/networksBreaking into a database to steal user data
Identity TheftStealing personal info to impersonate victimUsing stolen credentials to take out loans
PhishingDeceptive emails to trick victimsFake bank email requesting login details
RansomwareMalware that encrypts data and demands paymentWannaCry attack on NHS systems (2017)
DDoS AttackFlooding a server with traffic to take it offlineBotnets targeting e-commerce sites
Online FraudDeception for financial gain using technologyFake online shops that steal payment details
Data BreachExposing sensitive data without authorisationLeaking customer database to dark web
Social Engineering

Exploiting Human Psychology

Social engineering attacks manipulate people rather than systems. No technical hacking required — just deception.
PHISHING
Mass fraudulent emails pretending to be from trusted sources (banks, HMRC). Tricks victims into clicking links or entering credentials.
SPEAR PHISHING
Targeted phishing — researched, personalised email aimed at a specific individual or company to increase believability.
PRETEXTING
Attacker creates a fabricated scenario (e.g. "IT support calling") to convince victim to reveal information or grant access.
BAITING & TAILGATING
Baiting: leaving infected USB drives hoping victim plugs them in. Tailgating: following authorised person into secure area.
Prevention and Countermeasures

Defending Against Cybercrime

Firewalls — filter incoming/outgoing traffic based on rules; blocks unauthorised connection attempts
Encryption — protects data in transit and at rest; even if intercepted, data is unreadable without the key
Multi-Factor Authentication (MFA) — requires multiple verification steps; stolen password alone is insufficient
Strong password policies — minimum length, complexity, regular rotation; reduce brute-force success
Security patching — applying updates promptly to close known vulnerabilities that attackers exploit
Staff training and awareness — educating users to recognise phishing, social engineering, and suspicious activity
Penetration testing — ethical hackers probe systems to identify vulnerabilities before malicious actors do
Exam Practice

Cambridge-style questions

Question 1
State three offences under the Computer Misuse Act 1990 and give an example of each.
6 marks
1+1
Section 1: Unauthorised access — e.g. using another student's credentials to log into the school network without permission
1+1
Section 2: Unauthorised access with further intent — e.g. accessing a company's payroll system intending to commit fraud
1+1
Section 3: Unauthorised modification — e.g. installing ransomware that encrypts a hospital's patient records
Common Mistakes

Don't lose easy marks

1
Saying the Computer Misuse Act makes all hacking illegal — the CMA specifically targets unauthorised access. Ethical hacking and penetration testing are legal when explicitly authorised by the system owner. The key word is authorisation.
2
Confusing phishing and hacking — phishing is social engineering (tricking a human), not technical exploitation of a system. Candidates often say phishing "hacks into" an account — it doesn't; it tricks the user into giving access voluntarily.
3
Listing prevention measures without explaining how they help — for 2-mark answers, state the method AND its effect: "multi-factor authentication means a stolen password is insufficient on its own to access the account".
Topic Summary — 1.6.2

What You Need to Know

COMPUTER MISUSE ACT 1990
S1: Unauthorised access (2 yrs)
S2: + intent to commit offence (5 yrs)
S3: Unauthorised modification (10 yrs)
SOCIAL ENGINEERING
Phishing, spear phishing, pretexting
Baiting (USB drops), tailgating
Exploits people not technology
CYBERCRIME TYPES
Hacking, identity theft, phishing
Ransomware, DDoS, fraud, data breach
COUNTERMEASURES
Firewall, encryption, MFA
Strong passwords, patching
Staff training, pen testing
CSZone

Next Video

1.6.3
Environmental Impacts of Computing
Energy Consumption · E-waste · Carbon Footprint · Sustainable IT
Head to CSZone.co.uk for the complete worksheet, quiz, and interactive tools