Disproportionate Impact of Cybercrime on Low-Income and Marginalized Communities
Eno Dynowski
I researched the way in which cyberattacks, and cybercrime disproportionately affect lower-income, vulnerable, and marginalized demographics. Additionally I looked into how that disproportionate attack surface, exacerbates already existing socio-economic disparities in low-income communities. Lastly, I researched some of the strategies that are in place to enhance resilience and equitable access to the services affected by cyberattacks in these communities.
I wanted to understand how cyberattacks impact the daily lives of individuals in low-income communities, particularly in terms of power outages, inadequate wastewater treatment, and lack of access to food and agricultural services. I sought to uncover the underlying factors contributing to the heightened vulnerability of these communities and explore potential solutions or strategies for improving their resilience.
In order to understand how cyberattacks exacerbate existing disparities in low-income communities, I delved into the specific consequences of power disruptions, inadequate wastewater treatment, and food/agricultural service limitations. I also examined the systemic issues that contribute to the vulnerability of these communities, aiming to identify the root causes and potential interventions.
My research revealed that cyberattacks disproportionately affect low-income communities by disrupting essential services such as power, wastewater treatment, and food/agricultural services. These disruptions intensify existing socio-economic disparities, leading to discomfort, health risks, and loss of livelihoods for vulnerable populations. The lack of access to healthcare resources further compounds the public health risks, emphasizing the urgent need for equitable access to fundamental services in marginalized areas.
Malwarebytes, a leader in cyber-protection released the findings of a 2021 report that they titled, "The Demographics of Cybercrime." In it, they highlighted that "Women, black, Asian, and minority ethnic (BAME) people, and those from disadvantaged backgrounds bear a disproportionate burden when it comes to the impact of cybercrime." (Kenyon). This report focused on cybercrime wherein the individual was the victim, such crimes as hacked social media accounts, identity theft, or malicious links in text messages/emails. That being said, it is not unreasonable to assume that the same disproportionality extends to the effects of larger scale cybercrime.
Additionally, studies of non-cyberattack-induced power outages found that "being Black or African American was associated with 1.7x higher odds of experience an outage for at least 24 consecutive hours compared to White or Caucasian households." (Krasniqi). For the individual, or even the community affected, the source of a power outage does not matter, and it is the impact that is most important. If critical infrastructure like the power grid is already that much more insecure in Black communities, then outages induced by cyberattacks can reasonably be assumed to have the same disproportionate impact on those communities.
Lastly, I wanted to see what was being done in this area to help address the issue. To me, the obvious answer to how to help mitigate it would be twofold: First, it is imperative that we strengthen our critical infrastructure and invest in it at a high level such that it is not nearly as exposed to risk as it currently is. This will work to reduce the overall impact that cyberattacks against America's critical infrastructure can have. Second, it is important to address how, even with a reduced risk profile, the attacks that do occur will still disproportionately affect minority and low-income communities. As such, any proposed solution needs to also address the underlying socio-economic factors that put those communities at greater risk of adverse effects of outages.
One potential objection to my view could be that addressing the impact of cyberattacks on low-income communities requires a broader and more systemic approach that goes beyond enhancing resilience in specific services. Critics may argue that a comprehensive strategy should also include addressing root causes of socio-economic disparities and implementing policies that promote long-term equity and inclusivity. Additionally, the United States is not alone in being a victim of critical infrastructure cyberattacks. In fact, it is likely somewhat responsible. Leaked exploits developed by the NSA to use as part of the United States' cyber arsenal were used by the Russian government to take down the Ukrainian power grid as part of a coordinated cyberattack called NotPetya in 2017. (Goodin).
Resources
Goodin, Dan. "Notpetya Developers May Have Obtained NSA Exploits Weeks before Their Public Leak [Updated]." Ars Technica, 30 June 2017, arstechnica.com/information-technology/2017/06/notpetya-developers-obtained-nsa-exploits-weeks-before-their-public-leak/.
This is an article from Ars Technica in 2017 that covers the NotPetya attacks. Specifically, it describes the way that exploits developed by the NSA's Tailored Access Operations (TAO) group, otherwise known as The Equation Group, were used by the Russian Government to propagate their ransomware called NotPetya throughout Ukrainian systems and take down their power grid.
Kenyon, Tilly. "Cybercrime Is Impacting Communities Differently, Study Finds." Cyber Magazine, BizClik Media Ltd., 28 Sept. 2021, cybermagazine.com/cyber-security/cybercrime-impacting-communities-differently-study-finds.
This source is written by Tilly Kenyon and is a survey of the findings of a report originally published by Malwarebytes. Tilly analyzed and summarized the report and highlighted most of the key findings. It describes how cybercrime affects certain demographics differently. It focuses primarily on the types of cybercrime that affect the individual, like identity theft.
Krasniqi, Qëndresa. "Reflecting on the Racial Disparities in Texas Power Outages." NCDP, Columbia Climate School National Center for Natural Disaster Preparedness. , 27 Mar. 2023, ncdp.columbia.edu/ncdp-perspectives/disaster-response-and-equity-texas-power-outrages/.
This source covers a research project done by the National Center for Natural Disaster Preparedness at the Columbia University Climate School. It is not specific to cybersecurity, but neither are the impacts of critical infrastructure outages. It focuses on the impact that the power outages in Texas had on marginalized communities there, and how they were disproportionately affected.
