Official Public Cyber Intelligence Reporting Portal
Secure • Confidential • Public Reporting
INVESTIGATION AREA

Cybercrime Investigation & Reporting

Cybercrime includes illegal activities carried out using computers, mobile devices, networks, or the internet. These offenses may involve hacking, malware, ransomware, phishing, unauthorized system access, identity compromise, and other technology-enabled crimes.

Learn how cybercrime occurs, recognize common warning signs, preserve digital evidence, strengthen your cybersecurity, and submit a report through the National Cyber Intelligence Center.

Cybercrime Resources

Access cybercrime reporting tools, digital safety guidance, prevention resources, and information to help protect your devices, accounts, and personal information from cyber threats.

Report Cybercrime

Report hacking, malware, ransomware, phishing, unauthorized account access, online attacks, or other cybercrime incidents.

Start Report

Cybersecurity Guidance

Learn practical cybersecurity measures to protect computers, mobile devices, online accounts, and sensitive personal information.

Learn More

Evidence Collection

Learn what digital evidence to preserve, including screenshots, logs, emails, transactions, and device information.

View Guidance

Security Resources

Explore educational resources covering phishing, malware, ransomware, password security, and online safety best practices.

Explore Resources

What Is Cybercrime?

Cybercrime refers to criminal activities that use computers, mobile devices, digital networks, or the internet to target individuals, businesses, or organizations. These crimes may involve unauthorized access, theft of sensitive information, financial fraud, disruption of services, or the distribution of malicious software.

Modern cybercriminals use a wide range of techniques, including phishing emails, malware, ransomware, credential theft, social engineering, and exploitation of software vulnerabilities. Their objectives may include stealing money, accessing confidential information, disrupting systems, or taking control of online accounts.

Cybercrime affects people of all ages and organizations of every size. Victims may experience financial losses, compromised personal information, identity misuse, operational disruptions, or unauthorized access to online services and digital assets.

Prompt reporting and preservation of digital evidence help support cybercrime intelligence, identify related incidents, improve awareness of emerging threats, and assist investigative partners where appropriate.

Think You've Been Targeted by Cybercrime?

If you suspect unauthorized access, malware infection, phishing, ransomware, or any other cyber incident, preserve available evidence, secure your accounts, and submit a cybercrime report as soon as possible.

Common Indicators of Cybercrime

Cyber incidents are not always immediately obvious. Recognizing these warning signs early can help limit damage, protect sensitive information, and preserve valuable evidence.

1

Unauthorized Account Access

Unexpected login notifications, password changes, or unfamiliar devices connected to your accounts may indicate unauthorized access.

2

Suspicious Emails or Messages

Phishing emails, fake security alerts, malicious attachments, or unexpected requests for personal information are common cybercrime indicators.

3

Unexpected Financial Activity

Unrecognized online purchases, transfers, cryptocurrency transactions, or payment requests should be investigated immediately.

4

Device Performance Changes

Slow computers, frequent crashes, unknown software, disabled security tools, or encrypted files may indicate malware or ransomware activity.

5

Multiple Authentication Requests

Unexpected multi-factor authentication requests, password reset emails, or verification codes you did not initiate may signal an attempted account compromise.

Common Types of Cybercrime

Cybercriminals use many different techniques to compromise systems, steal information, and exploit victims. Understanding these methods can help reduce your risk.

Phishing

Fraudulent emails, text messages, or websites designed to steal passwords, financial information, or authentication codes.

Malware

Malicious software that damages systems, steals information, monitors activity, or provides attackers with unauthorized access.

Ransomware

Malware that encrypts files or systems and demands payment for their release.

Account Takeover

Criminals gain access to email, banking, or social media accounts using stolen passwords or compromised credentials.

Unauthorized System Access

Attackers exploit software vulnerabilities, weak passwords, or exposed services to access computers and networks without permission.

Business Email Compromise

Fraudsters impersonate executives, vendors, or employees to manipulate financial transactions or obtain confidential business information.

Who Can Be Affected?

Cybercrime affects individuals, businesses, educational institutions, government agencies, and organizations of every size. Anyone using internet-connected devices can become a target.

Individuals

Personal devices, online banking, email accounts, social media profiles, and digital identities are frequently targeted by cybercriminals.

Businesses

Organizations face risks including ransomware, business email compromise, data breaches, and theft of confidential information.

Educational Institutions

Schools and universities often store valuable personal information and may be targeted through phishing, ransomware, or network intrusions.

Government & Public Services

Public sector organizations may experience attacks intended to disrupt services, steal sensitive data, or compromise critical infrastructure.

Protecting Yourself from Cybercrime

Strong cybersecurity practices can significantly reduce your risk of becoming a cybercrime victim.

  • Use strong, unique passwords for every account.
  • Enable multi-factor authentication whenever possible.
  • Keep operating systems, browsers, and applications updated.
  • Install reputable antivirus and endpoint protection.
  • Avoid opening unexpected email attachments or links.
  • Regularly back up important files to secure locations.
  • Monitor financial accounts and online services for suspicious activity.
  • Use secure Wi-Fi networks and avoid transmitting sensitive information over unsecured public connections.

What To Do Immediately

Acting quickly can reduce additional damage, preserve digital evidence, and improve your ability to recover compromised accounts or systems.

1

Secure Affected Accounts

Change passwords immediately, enable multi-factor authentication, and review account activity for unauthorized access.

2

Disconnect Compromised Devices

If malware or ransomware is suspected, disconnect affected devices from the internet to help prevent additional damage.

3

Preserve Digital Evidence

Save screenshots, emails, chat messages, transaction records, log files, and any other relevant information.

4

Notify Relevant Organizations

Contact banks, employers, service providers, or IT administrators if financial accounts or organizational systems may be affected.

5

Submit an NCIC Report

Provide a detailed report with supporting evidence to assist cybercrime intelligence and analysis.

Information That Can Help Your Report

Preserving digital evidence before deleting files, reinstalling software, or resetting devices can significantly improve the quality of your report.

  • Email messages and complete email headers.
  • Screenshots of suspicious websites, messages, or alerts.
  • Transaction records or payment confirmations.
  • IP addresses, domain names, or URLs if available.
  • Chat conversations and social media messages.
  • Malware files or ransom notes (if safe to preserve).
  • System logs and login notifications.
  • Device information and operating system details.
  • Usernames, email addresses, phone numbers, or cryptocurrency wallet addresses involved.
  • Dates, times, and a timeline of the incident.

What Happens After You Submit a Report?

1

Report Received

Your cybercrime report is securely received and assigned a unique NCIC reference number.

2

Evidence Assessment

Submitted digital evidence is reviewed for completeness, relevance, and intelligence value.

3

Cyber Intelligence Analysis

Analysts identify attack patterns, related incidents, threat indicators, and emerging cybercrime trends.

4

Appropriate Action

Reports may contribute to intelligence products, awareness initiatives, or referral to appropriate investigative partners where applicable.

Cybercrime FAQs

What types of incidents should I report?

Report hacking, phishing, ransomware, malware infections, account compromise, unauthorized access, online attacks, and other suspected cybercrime incidents.

What evidence should I include?

Include screenshots, emails, system logs, transaction records, URLs, usernames, IP addresses, and any other information related to the incident.

Should I delete malware before reporting?

If it is safe to do so, preserve available evidence before removing malware or reinstalling systems.

Can I update my report later?

Yes. Keep your NCIC reference number available if you need to provide additional information after submission.

REPORT CYBERCRIME

Ready to Report a Cybercrime Incident?

If you believe you have been affected by hacking, phishing, ransomware, malware, unauthorized account access, or another cyber incident, submit a secure report through the National Cyber Intelligence Center. Detailed reporting helps support cyber intelligence, trend analysis, and investigative coordination.