Primary tabs
2026
Botha, J., Singh, K., & Leenen, L. (2026). Evaluating an Investigative Process for Cryptocurrency-Related Crimes. In Proceedings of the 21st International Conference on Cyber Warfare and Security (ICCWS 2026) (Vol. 21). North Carolina, United States of America: Academic Conferences International. http://doi.org/10.34190/iccws.21.1.4538
This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors (Botha, Singh, & Leenen, 2025a), through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence. The current study focuses on a new, active case involving an elderly South African (SA) woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme. The case is presently under investigation by the Directorate for Priority Crime Investigation (DPCI), a specialised unit of the South African Police Services (SAPS) tasked with addressing serious economic crimes and commonly referred to as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness in real-world conditions. The analysis further reflects on legal, technical, and procedural challenges encountered during the investigation, offering critical insights for law enforcement, regulators, and cybersecurity professionals. It also highlights broader systemic vulnerabilities that facilitate such scams, particularly among elderly and non-technical populations. The findings underscore the need for enhanced public education, improved regulatory oversight, and international cooperation in combating cryptocurrency fraud. Ultimately, the paper contributes to the evolving discourse on financial crime in the digital age and aims to support the development of more secure and accountable crypto-investment environments.
@{537,
author = {Johnny Botha and Kreaan Singh and Louise Leenen},
title = {Evaluating an Investigative Process for Cryptocurrency-Related Crimes},
abstract = {This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors (Botha, Singh, & Leenen, 2025a), through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence. The current study focuses on a new, active case involving an elderly South African (SA) woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme. The case is presently under investigation by the Directorate for Priority Crime Investigation (DPCI), a specialised unit of the South African Police Services (SAPS) tasked with addressing serious economic crimes and commonly referred to as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness in real-world conditions. The analysis further reflects on legal, technical, and procedural challenges encountered during the investigation, offering critical insights for law enforcement, regulators, and cybersecurity professionals. It also highlights broader systemic vulnerabilities that facilitate such scams, particularly among elderly and non-technical populations. The findings underscore the need for enhanced public education, improved regulatory oversight, and international cooperation in combating cryptocurrency fraud. Ultimately, the paper contributes to the evolving discourse on financial crime in the digital age and aims to support the development of more secure and accountable crypto-investment environments.},
year = {2026},
journal = {Proceedings of the 21st International Conference on Cyber Warfare and Security (ICCWS 2026)},
volume = {21},
pages = {45-56},
month = {2026},
issue = {1},
publisher = {Academic Conferences International},
address = {North Carolina, United States of America},
doi = {10.34190/iccws.21.1.4538},
}
Botha, J., Berkman, A., & Leenen, L. (2026). Leveraging Open-Source Intelligence to Combat Cryptocurrency Investment Scams. In Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026) (Vol. 25). Nottingham, United Kingdom: Academic Conferences International. http://doi.org/10.34190/eccws.25.1.4883
This paper presents a follow-up study to earlier research on cryptocurrency crime, again drawing on the case of an elderly woman defrauded by an online platform known as RSI-Platform. Whereas the initial study focused mainly on on-chain analysis within the blockchain environment, the present work shifts attention to off-chain approaches, applying open-source intelligence (OSINT) techniques to deepen investigations into crypto-related fraud. By systematically examining diverse input data, such as names, phone numbers, email addresses, and URLs, this study conducts link analysis and aims to build detailed profiles of potential suspects, thereby advancing understanding of the strategies and methods used in cryptocurrency scams. The analysis aims not only to trace the scammers' digital footprints but also to reveal networks and connections to other fraudulent platforms that support these activities. Moreover, this research seeks to raise public awareness about the scale and operation of fake online investment schemes in the crypto sector. By exposing the vulnerabilities exploited by offenders and illustrating how OSINT can be used to detect and disrupt such scams, the paper adds to ongoing discussions on cybersecurity and consumer protection in the fast-changing field of digital finance. Additionally, the findings are intended to offer practical insights for law enforcement agencies, policymakers, and the wider public, encouraging a more informed and proactive response to the threats posed by crypto-related fraud.
@{536,
author = {Johnny Botha and Abraha Berkman and Louise Leenen},
title = {Leveraging Open-Source Intelligence to Combat Cryptocurrency Investment Scams},
abstract = {This paper presents a follow-up study to earlier research on cryptocurrency crime, again drawing on the case of an elderly woman defrauded by an online platform known as RSI-Platform. Whereas the initial study focused mainly on on-chain analysis within the blockchain environment, the present work shifts attention to off-chain approaches, applying open-source intelligence (OSINT) techniques to deepen investigations into crypto-related fraud. By systematically examining diverse input data, such as names, phone numbers, email addresses, and URLs, this study conducts link analysis and aims to build detailed profiles of potential suspects, thereby advancing understanding of the strategies and methods used in cryptocurrency scams. The analysis aims not only to trace the scammers' digital footprints but also to reveal networks and connections to other fraudulent platforms that support these activities. Moreover, this research seeks to raise public awareness about the scale and operation of fake online investment schemes in the crypto sector. By exposing the vulnerabilities exploited by offenders and illustrating how OSINT can be used to detect and disrupt such scams, the paper adds to ongoing discussions on cybersecurity and consumer protection in the fast-changing field of digital finance. Additionally, the findings are intended to offer practical insights for law enforcement agencies, policymakers, and the wider public, encouraging a more informed and proactive response to the threats posed by crypto-related fraud.},
year = {2026},
journal = {Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026)},
volume = {25},
pages = {96-106},
month = {June 2026},
issue = {1},
publisher = {Academic Conferences International},
address = {Nottingham, United Kingdom},
doi = {10.34190/eccws.25.1.4883},
}
Mawhayi, B., Botha, J., & Leenen, L. (2026). A Hybrid, Transparent Trust and Risk Assessment Framework for Cryptocurrency Exchanges. In Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026) (Vol. 25). Nottingham, United Kingdom: Academic Conferences International. http://doi.org/10.34190/eccws.25.1.4840
Cryptocurrency exchanges act as critical intermediaries within the digital asset ecosystem, yet users currently rely on largely opaque, platform-defined trust scores to assess their reliability and risk. Existing industry frameworks, notably those produced by CoinGecko and CoinMarketCap, provide useful signals related to liquidity and volume integrity but suffer from limited transparency, fixed weighting schemes, and the absence of sentiment-based assessment. This paper presents HTREx (Hybrid Trust and Risk Evaluation framework for exchanges), a semi-automated, modular trust and risk assessment framework for cryptocurrency exchanges that addresses these limitations. The framework integrates five dimensions of exchange integrity: user sentiment, regulatory compliance, technical security, transparency, and incident history. Sentiment is quantified using transformer-based natural language processing applied to user-generated content from mobile application reviews and online forums. Compliance is assessed through structured extraction of regulatory and operational disclosures from Terms of Service documents using large language models. Security, transparency, and incident history are evaluated through a combination of publicly verifiable indicators, third-party assessments, and a recency-weighted incident scoring model. All components are normalised and aggregated into a composite score using user-adjustable weights, enabling personalised risk prioritisation while retaining a defensible default configuration for comparative analysis. The framework is demonstrated using four prominent exchanges, Kraken, Coinbase, Binance, and Uniswap, highlighting clear differences between centralised and decentralised platforms and illustrating how sentiment, compliance, and historical incidents materially influence overall trust assessments. The results suggest that transparent, extensible, and user-configurable scoring models can provide a more interpretable and context-sensitive evaluation of exchange risk than existing monolithic trust scores, with direct relevance for both retail and institutional participants.
@{535,
author = {Bongani Mawhayi and Johnny Botha and Louise Leenen},
title = {A Hybrid, Transparent Trust and Risk Assessment Framework for Cryptocurrency Exchanges},
abstract = {Cryptocurrency exchanges act as critical intermediaries within the digital asset ecosystem, yet users currently rely on largely opaque, platform-defined trust scores to assess their reliability and risk. Existing industry frameworks, notably those produced by CoinGecko and CoinMarketCap, provide useful signals related to liquidity and volume integrity but suffer from limited transparency, fixed weighting schemes, and the absence of sentiment-based assessment. This paper presents HTREx (Hybrid Trust and Risk Evaluation framework for exchanges), a semi-automated, modular trust and risk assessment framework for cryptocurrency exchanges that addresses these limitations. The framework integrates five dimensions of exchange integrity: user sentiment, regulatory compliance, technical security, transparency, and incident history. Sentiment is quantified using transformer-based natural language processing applied to user-generated content from mobile application reviews and online forums. Compliance is assessed through structured extraction of regulatory and operational disclosures from Terms of Service documents using large language models. Security, transparency, and incident history are evaluated through a combination of publicly verifiable indicators, third-party assessments, and a recency-weighted incident scoring model. All components are normalised and aggregated into a composite score using user-adjustable weights, enabling personalised risk prioritisation while retaining a defensible default configuration for comparative analysis. The framework is demonstrated using four prominent exchanges, Kraken, Coinbase, Binance, and Uniswap, highlighting clear differences between centralised and decentralised platforms and illustrating how sentiment, compliance, and historical incidents materially influence overall trust assessments. The results suggest that transparent, extensible, and user-configurable scoring models can provide a more interpretable and context-sensitive evaluation of exchange risk than existing monolithic trust scores, with direct relevance for both retail and institutional participants.},
year = {2026},
journal = {Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026)},
volume = {25},
month = {June 2026},
issue = {1},
publisher = {Academic Conferences International},
address = {Nottingham, United Kingdom},
doi = {10.34190/eccws.25.1.4840},
}
Vorster, J., & Leenen, L. (2026). The effect of Artifacts on Consensus formation: An Agent-based Simulation Approach. In Simulation and Modeling Methodologies, Technologies and Applications. SIMULTECH 2024. Lecture Notes in Networks and Systems (Vol. 1620). Cham, Switzerland: Springer. http://doi.org/10.1007/978-3-032-04777-9_7
This paper models consensus formation processes using multi-agents simulations. The use of artefacts in the formation of consensus is investigated. This approach allows the study of complex team dynamics. We found that through the consensus process there are phases characterised by the efficiency of team meetings and the productivity of team members. We show that artefacts can play a significant role to improve the time to reach consensus. Furthermore, teams that use artefacts can significantly reduce the effects of bad team structure. Different team structures are investigated and characterized based on how well it supports the consensus formation process.
@inbook{534,
author = {Johannes Vorster and Louise Leenen},
title = {The effect of Artifacts on Consensus formation: An Agent-based Simulation Approach},
abstract = {This paper models consensus formation processes using multi-agents simulations. The use of artefacts in the formation of consensus is investigated. This approach allows the study of complex team dynamics. We found that through the consensus process there are phases characterised by the efficiency of team meetings and the productivity of team members. We show that artefacts can play a significant role to improve the time to reach consensus. Furthermore, teams that use artefacts can significantly reduce the effects of bad team structure. Different team structures are investigated and characterized based on how well it supports the consensus formation process.},
year = {2026},
journal = {Simulation and Modeling Methodologies, Technologies and Applications. SIMULTECH 2024. Lecture Notes in Networks and Systems},
volume = {1620},
pages = {114-136},
publisher = {Springer},
address = {Cham, Switzerland},
doi = {10.1007/978-3-032-04777-9_7},
}
2025
Madzime, R., Meyer, T., & Leenen, L. (2025). An Override-aware Classifier for Transparent AI. In Proceedings of the Southern African Conference for Artificial Intelligence Research (SACAIR 2025), Volume II (Vol. II). Cape Town, South Africa. Retrieved from https://2025.sacair.org.za/online-proceedings/Papers/paper_17.pdf
Many real-world decisions follow rules that hold in general but allow exceptions, such as "birds usually fly, unless they are penguins." Most interpretable classifiers struggle to capture this pattern, leading to explanations that feel less aligned with human reasoning. This paper introduces the Defeasible Horn Classifier with Exceptions (DHCE), a symbolic model that makes this reasoning structure explicit. Each rule combines a default with its linked exceptions, so predictions can be explained step by step without relying on post-hoc tools. DHCE is learned using Answer Set Programming, which searches for globally optimal rule sets while balancing accuracy and simplicity. The resulting models consist of ranked Horn rules that provide full traceability: users can see both why a decision applies and why it may be overridden. We evaluate DHCE on standard classification benchmarks and find that it matches or outperforms leading interpretable models, a performance level that prior work shows to be competitive with classical machine learning classifiers. By making prediction decisions inherently retractable, DHCE delivers accuracy alongside explanations that mirror how people reason, making it suited for domains where understanding why a rule no longer applies is as important as the prediction itself.
@{552,
author = {Ruvarashe Madzime and Tommie Meyer and Louise Leenen},
title = {An Override-aware Classifier for Transparent AI},
abstract = {Many real-world decisions follow rules that hold in general but allow exceptions, such as "birds usually fly, unless they are penguins." Most interpretable classifiers struggle to capture this pattern, leading to explanations that feel less aligned with human reasoning. This paper introduces the Defeasible Horn Classifier with Exceptions (DHCE), a symbolic model that makes this reasoning structure explicit. Each rule combines a default with its linked exceptions, so predictions can be explained step by step without relying on post-hoc tools. DHCE is learned using Answer Set Programming, which searches for globally optimal rule sets while balancing accuracy and simplicity. The resulting models consist of ranked Horn rules that provide full traceability: users can see both why a decision applies and why it may be overridden. We evaluate DHCE on standard classification benchmarks and find that it matches or outperforms leading interpretable models, a performance level that prior work shows to be competitive with classical machine learning classifiers. By making prediction decisions inherently retractable, DHCE delivers accuracy alongside explanations that mirror how people reason, making it suited for domains where understanding why a rule no longer applies is as important as the prediction itself.},
year = {2025},
journal = {Proceedings of the Southern African Conference for Artificial Intelligence Research (SACAIR 2025), Volume II},
volume = {II},
pages = {349-360},
month = {2025},
address = {Cape Town, South Africa},
url = {https://2025.sacair.org.za/online-proceedings/Papers/paper_17.pdf},
}
Botha, J., Luoma-Aho, V., & Leenen, L. (2025). Top Crypto Scams in 2022-2024: Analysing Trends, Tactics, and Regulatory Responses. In 2025 IST-Africa Conference (IST-Africa). Nairobi, Kenya: IEEE. http://doi.org/10.23919/IST-Africa67297.2025.11060494
This study analyses the most prominent cryptocurrency scams from 2022 to 2024, highlighting certain trends and common manipulation tactics used by fraudsters during this period. The paper builds upon a previous study that examined the most prominent scams, during the COVID-19 pandemic, between 2020 and 2022, a period characterised by substantial market volatility and heightened investor interest. In contrast, the period from 2022 to 2024 was marked by a bear market, during which investor interest in cryptocurrency declined. Despite this downturn, several significant scams emerged, which are analysed. The findings reveal a significant reported financial loss, highlighting investors' vulnerabilities. The paper does a comparison analysis per year on the type of scams, monetary losses, the founding country of the scams, the number of users affected, and arrests made. By examining the financial impact of these scams, the study aims to provide insight into the scale and severity of fraud in the cryptocurrency market during this period. The paper highlights the dire need for enhanced public awareness and regulatory entities to combat the evolving landscape of cryptocurrency fraud. Lastly, the study aims to inform policymakers, industry stakeholders, and researchers about the pressing challenges in securing the cryptocurrency ecosystem.
@{544,
author = {Johnny Botha and Vilma Luoma-Aho and Louise Leenen},
title = {Top Crypto Scams in 2022-2024: Analysing Trends, Tactics, and Regulatory Responses},
abstract = {This study analyses the most prominent cryptocurrency scams from 2022 to 2024, highlighting certain trends and common manipulation tactics used by fraudsters during this period. The paper builds upon a previous study that examined the most prominent scams, during the COVID-19 pandemic, between 2020 and 2022, a period characterised by substantial market volatility and heightened investor interest. In contrast, the period from 2022 to 2024 was marked by a bear market, during which investor interest in cryptocurrency declined. Despite this downturn, several significant scams emerged, which are analysed. The findings reveal a significant reported financial loss, highlighting investors' vulnerabilities. The paper does a comparison analysis per year on the type of scams, monetary losses, the founding country of the scams, the number of users affected, and arrests made. By examining the financial impact of these scams, the study aims to provide insight into the scale and severity of fraud in the cryptocurrency market during this period. The paper highlights the dire need for enhanced public awareness and regulatory entities to combat the evolving landscape of cryptocurrency fraud. Lastly, the study aims to inform policymakers, industry stakeholders, and researchers about the pressing challenges in securing the cryptocurrency ecosystem.},
year = {2025},
journal = {2025 IST-Africa Conference (IST-Africa)},
pages = {1-9},
month = {28-30 May 2025},
publisher = {IEEE},
address = {Nairobi, Kenya},
doi = {10.23919/IST-Africa67297.2025.11060494},
}
Vorster, J., & Leenen, L. (2025). Optimizing Social Consensus: The Impact of Agent Selection and Topic Strategy on Time to Reach Agreement. In Proceedings of the 15th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH (Vol. 1). Spain: SCITEPRESS - Science and Technology Publications. http://doi.org/10.5220/0013650900003970
In the rapidly evolving landscape of organizational structures and project management, achieving timely consensus among team members is crucial for maintaining agility and responsiveness. During the consensus formation process, team members has the choice of who to talk to in an attempt to consolidate views on a topic. In this paper we ask the question, to what extent do strategies for selecting team members affect the speed of consensus formation? Similarly, once two team members engage in conversations on a specific set of topics, the question we ask is, to what extent do different strategies for selecting the topics for discussion affect the time to reach consensus within multi-agent systems. By simulating various strategies, we identify methods that optimize consensus speed, specifically highlighting the benefits of prioritizing unaligned agents and addressing contentious topics early in the process. Our findings reveal that these strategies significantly enhance consensus efficiency, while approaches focusing on aligning with similar views tend to prolong the process. Additionally, we observe that the initial distribution of agent views, provided the standard deviation is constant, has negligible effects on consensus time, suggesting that diversity of opinion is more critical than specific distribution patterns. These insights offer practical implications for improving decision-making processes in organizational and project contexts.
@{543,
author = {Johannes Vorster and Louise Leenen},
title = {Optimizing Social Consensus: The Impact of Agent Selection and Topic Strategy on Time to Reach Agreement},
abstract = {In the rapidly evolving landscape of organizational structures and project management, achieving timely consensus among team members is crucial for maintaining agility and responsiveness. During the consensus formation process, team members has the choice of who to talk to in an attempt to consolidate views on a topic. In this paper we ask the question, to what extent do strategies for selecting team members affect the speed of consensus formation? Similarly, once two team members engage in conversations on a specific set of topics, the question we ask is, to what extent do different strategies for selecting the topics for discussion affect the time to reach consensus within multi-agent systems. By simulating various strategies, we identify methods that optimize consensus speed, specifically highlighting the benefits of prioritizing unaligned agents and addressing contentious topics early in the process. Our findings reveal that these strategies significantly enhance consensus efficiency, while approaches focusing on aligning with similar views tend to prolong the process. Additionally, we observe that the initial distribution of agent views, provided the standard deviation is constant, has negligible effects on consensus time, suggesting that diversity of opinion is more critical than specific distribution patterns. These insights offer practical implications for improving decision-making processes in organizational and project contexts.},
year = {2025},
journal = {Proceedings of the 15th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH},
volume = {1},
pages = {135-144},
month = {2025},
publisher = {SCITEPRESS - Science and Technology Publications},
address = {Spain},
doi = {10.5220/0013650900003970},
}
Nkambule, M., van Vuuren, J. J., & Leenen, L. (2025). Creating a Cybersecurity Culture Framework in Higher Education. In Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025) (Vol. 20). Virginia, United States of America: Academic Conferences International. http://doi.org/10.34190/iccws.20.1.3268
The increasing cybersecurity threats to higher education institutions in Africa necessitate risk management frameworks that are resilient and sensitive to regional needs. This paper applies Modified General Morphological Analysis (MGMA) to identify essential elements for an adaptable cybersecurity framework, focusing on the African higher education context. African institutions face many challenges, like limited funding, underdeveloped digital infrastructures, and rising cyberattacks. Our proposed MGMA is a structured methodology to examine key cybersecurity dimensions: governance, policy, technical controls, capacity building, and resource allocation. This approach allows for assessing complex interrelations among these elements, aimed at practical solutions suitable for African institutions. This study focuses on risk management approaches to address the specific vulnerabilities of African higher education institutions (HEIs), such as restricted budgets, inadequate cybersecurity teams, and increasing reliance on digital systems. The study promotes collaborative efforts by creating institutional networks, sharing resources, and enhancing cybersecurity expertise across Africa. The findings will guide decision-makers in aligning cybersecurity investments with strategic institutional goals, providing a framework for protecting critical educational assets, strengthening resilience, and advancing digital infrastructure development across African higher education.
@{542,
author = {Mafika Nkambule and Joey van Vuuren and Louise Leenen},
title = {Creating a Cybersecurity Culture Framework in Higher Education},
abstract = {The increasing cybersecurity threats to higher education institutions in Africa necessitate risk management frameworks that are resilient and sensitive to regional needs. This paper applies Modified General Morphological Analysis (MGMA) to identify essential elements for an adaptable cybersecurity framework, focusing on the African higher education context. African institutions face many challenges, like limited funding, underdeveloped digital infrastructures, and rising cyberattacks. Our proposed MGMA is a structured methodology to examine key cybersecurity dimensions: governance, policy, technical controls, capacity building, and resource allocation. This approach allows for assessing complex interrelations among these elements, aimed at practical solutions suitable for African institutions. This study focuses on risk management approaches to address the specific vulnerabilities of African higher education institutions (HEIs), such as restricted budgets, inadequate cybersecurity teams, and increasing reliance on digital systems. The study promotes collaborative efforts by creating institutional networks, sharing resources, and enhancing cybersecurity expertise across Africa. The findings will guide decision-makers in aligning cybersecurity investments with strategic institutional goals, providing a framework for protecting critical educational assets, strengthening resilience, and advancing digital infrastructure development across African higher education.},
year = {2025},
journal = {Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025)},
volume = {20},
pages = {304-312},
month = {28-29 March 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Virginia, United States of America},
doi = {10.34190/iccws.20.1.3268},
}
Coetzer, C., & Leenen, L. (2025). Quantifying Cyber Security Risk through Interest Rate Calculation in Debt Management. In Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025) (Vol. 20). Virginia, United States of America: Academic Conferences International. http://doi.org/10.34190/iccws.20.1.3357
This paper introduces a novel Interest Rate Calculation Model for cyber security risk quantification, addressing the challenges of cyber security debt management. Unlike traditional qualitative risk assessments, this model applies financial principles to quantify risk impact dynamically, integrating seamlessly with industry frameworks. By framing cyber security risks in financial terms, the model enhances decision-making, promotes strategic resource allocation, and fosters stakeholder engagement. Through a structured methodology, it empowers organisations to assess, prioritise, and mitigate cyber security debt efficiently, ensuring long-term resilience in an evolving threat landscape.
@{541,
author = {Christo Coetzer and Louise Leenen},
title = {Quantifying Cyber Security Risk through Interest Rate Calculation in Debt Management},
abstract = {This paper introduces a novel Interest Rate Calculation Model for cyber security risk quantification, addressing the challenges of cyber security debt management. Unlike traditional qualitative risk assessments, this model applies financial principles to quantify risk impact dynamically, integrating seamlessly with industry frameworks. By framing cyber security risks in financial terms, the model enhances decision-making, promotes strategic resource allocation, and fosters stakeholder engagement. Through a structured methodology, it empowers organisations to assess, prioritise, and mitigate cyber security debt efficiently, ensuring long-term resilience in an evolving threat landscape.},
year = {2025},
journal = {Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025)},
volume = {20},
pages = {37-44},
month = {28-29 March 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Virginia, United States of America},
doi = {10.34190/iccws.20.1.3357},
}
Mawhayi, B., Botha, J., & Leenen, L. (2025). A Web Scraping Approach Towards Cryptocurrency Investigations. In Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025) (Vol. 24). Germany: Academic Conferences International. http://doi.org/10.34190/eccws.24.1.3557
The investigation of cryptocurrency crimes is still in its infancy with no standardised process or methodology to follow. This paper describes research that forms part of a broader project led by the second author (Botha, et al., 2025). The broader project's aim is to develop a methodology to follow when conducting cryptocurrency crime investigations. One of the steps in the proposed methodology is web scraping. The authors of this paper present a detailed exploration of web scraping techniques within the broader context of the proposed investigation methodology. In this paper, the focus is on developing a well-structured methodology for scraping social media platforms and online forums to gather data related to fraudulent activities; the goal is to find posts that include references to the wallet address of interest. This exploration uses an iterative approach; for every new cryptocurrency wallet address discovered or revealed through on-chain analysis, a parallel path is followed by scraping the Internet. If a mention of the cryptocurrency address should be discovered it is considered to be a key finding, creating a pivot point in the investigation. From a pivot point, further open-source intelligence (OSINT) techniques will be applied, though this aspect falls beyond the scope of this paper. If no relevant information or link is found, the scraping path will not be pursued, and the investigation proceeds with on-chain analysis to identify additional wallet addresses. Additionally, challenges encountered in web scraping, such as handling platform restrictions, ensuring data accuracy, and managing large volumes of data, are addressed. The goal of the proposed methodology is to enhance data extraction and analysis efficiency contributing to the proposed methodology for investigating cryptocurrency scams.
@{540,
author = {Bongani Mawhayi and Johnny Botha and Louise Leenen},
title = {A Web Scraping Approach Towards Cryptocurrency Investigations},
abstract = {The investigation of cryptocurrency crimes is still in its infancy with no standardised process or methodology to follow. This paper describes research that forms part of a broader project led by the second author (Botha, et al., 2025). The broader project's aim is to develop a methodology to follow when conducting cryptocurrency crime investigations. One of the steps in the proposed methodology is web scraping. The authors of this paper present a detailed exploration of web scraping techniques within the broader context of the proposed investigation methodology. In this paper, the focus is on developing a well-structured methodology for scraping social media platforms and online forums to gather data related to fraudulent activities; the goal is to find posts that include references to the wallet address of interest. This exploration uses an iterative approach; for every new cryptocurrency wallet address discovered or revealed through on-chain analysis, a parallel path is followed by scraping the Internet. If a mention of the cryptocurrency address should be discovered it is considered to be a key finding, creating a pivot point in the investigation. From a pivot point, further open-source intelligence (OSINT) techniques will be applied, though this aspect falls beyond the scope of this paper. If no relevant information or link is found, the scraping path will not be pursued, and the investigation proceeds with on-chain analysis to identify additional wallet addresses. Additionally, challenges encountered in web scraping, such as handling platform restrictions, ensuring data accuracy, and managing large volumes of data, are addressed. The goal of the proposed methodology is to enhance data extraction and analysis efficiency contributing to the proposed methodology for investigating cryptocurrency scams.},
year = {2025},
journal = {Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025)},
volume = {24},
pages = {445-454},
month = {25 June 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Germany},
doi = {10.34190/eccws.24.1.3557},
}
Coetzer, C., & Leenen, L. (2025). Managing Cybersecurity Debt in FinTech: A Practical Approach for Financial Risk Quantification and Strategic Decision Making. Journal of Information Warfare, 24(4).
Managing cybersecurity risks within financial technology organisations is increasingly complex, with traditional qualitative assessments falling short in quantifying the financial implications of cyber threats. This paper presents an approach to implementing a Cybersecurity Debt Management Model, which integrates cybersecurity with financial risk management methodologies, demonstrating a structured method for operationalising the model within a FinTech IT environment. The model quantifies the financial impact of unresolved cybersecurity vulnerabilities, facilitating decision making, targeted resource allocation, and regulatory compliance. The proposed approach provides organisations with insights into managing cybersecurity debt, thereby promoting resilience and alignment of technical measures with strategic objectives.
@article{539,
author = {Christo Coetzer and Louise Leenen},
title = {Managing Cybersecurity Debt in FinTech: A Practical Approach for Financial Risk Quantification and Strategic Decision Making},
abstract = {Managing cybersecurity risks within financial technology organisations is increasingly complex, with traditional qualitative assessments falling short in quantifying the financial implications of cyber threats. This paper presents an approach to implementing a Cybersecurity Debt Management Model, which integrates cybersecurity with financial risk management methodologies, demonstrating a structured method for operationalising the model within a FinTech IT environment. The model quantifies the financial impact of unresolved cybersecurity vulnerabilities, facilitating decision making, targeted resource allocation, and regulatory compliance. The proposed approach provides organisations with insights into managing cybersecurity debt, thereby promoting resilience and alignment of technical measures with strategic objectives.},
year = {2025},
journal = {Journal of Information Warfare},
volume = {24},
pages = {62-66},
issue = {4},
publisher = {ArmisteadTEC},
}
Botha, J., Singh, K., & Leenen, L. (2025). Analysis of a Cryptocurrency Investment Scam: Pig Butchering. In Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025) (Vol. 24). Germany: Academic Conferences International. http://doi.org/10.34190/eccws.24.1.3558
This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a facade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss. After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss. These manipulative tactics are referred to as pig butchering. The paper utilises qualitative data from interviews and correspondence with the victim, along with an examination of platform behaviours to highlight common patterns in cryptocurrency scams. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim. To contextualise the collected information, a link analysis was done, utilising the tool Maltego. The link analysis visually maps the entities associated with the suspect within a network of nodes and connections. By situating the Elite-Bit case within the broader context of cryptocurrency regulation and consumer protection, this paper underscores the urgent need for enhanced regulatory frameworks and public awareness initiatives. This study aims to contribute to the ongoing discourse on financial fraud in the cryptocurrency sector, providing insights that may assist in the prevention of future scams and the promotion of more secure investment and trading practices.
@{538,
author = {Johnny Botha and Kreaan Singh and Louise Leenen},
title = {Analysis of a Cryptocurrency Investment Scam: Pig Butchering},
abstract = {This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a facade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss. After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss. These manipulative tactics are referred to as pig butchering. The paper utilises qualitative data from interviews and correspondence with the victim, along with an examination of platform behaviours to highlight common patterns in cryptocurrency scams. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim. To contextualise the collected information, a link analysis was done, utilising the tool Maltego. The link analysis visually maps the entities associated with the suspect within a network of nodes and connections. By situating the Elite-Bit case within the broader context of cryptocurrency regulation and consumer protection, this paper underscores the urgent need for enhanced regulatory frameworks and public awareness initiatives. This study aims to contribute to the ongoing discourse on financial fraud in the cryptocurrency sector, providing insights that may assist in the prevention of future scams and the promotion of more secure investment and trading practices.},
year = {2025},
journal = {Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025)},
volume = {24},
pages = {61-70},
month = {25 June 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Germany},
doi = {10.34190/eccws.24.1.3558},
}
Botha, J., Singh, K., & Leenen, L. (2025). A Proposed Bitcoin Blockchain Investigation Methodology: Based on a Case Study Approach. In Journal of Information Warfare (Vol. 24). ArmisteadTEC, LLC Virginia Beach, Virginia, USA.
Criminal investigations involving cryptocurrencies are still premature with no standard investigative process to follow. This paper proposes a high-level methodology using open-source and analysed data to perform such investigations. It focuses on situations where Bitcoin is involved, but where other similar blockchains are concerned, the technical investigator should apply this methodology only after careful consideration. A case study approach is used to illustrate a cryptocurrency scamming platform, a giveaway scam, and divorce fraud. In all the cases, one needs to follow or trace the funds on the blockchain, referred to as on-chain analysis. The end goal of on-chain analysis is to find a destination address linked to identifiable information obtained from open-source data platforms-such as websites, social media, or a cryptocurrency exchange. Law enforcement can then be engaged to instruct the exchange to reveal all personal and transactional information linked to the address through a subpoena. A successful investigation will result in criminal prosecution and a potential recovery of funds. To maintain familiar investigation processes, the researchers looked at traditional (or non-technical) as well as technical investigation techniques.
@{523,
author = {JG Botha and Kreaan Singh and Louise Leenen},
title = {A Proposed Bitcoin Blockchain Investigation Methodology: Based on a Case Study Approach},
abstract = {Criminal investigations involving cryptocurrencies are still premature with no standard investigative process to follow. This paper proposes a high-level methodology using open-source and analysed data to perform such investigations. It focuses on situations where Bitcoin is involved, but where other similar blockchains are concerned, the technical investigator should apply this methodology only after careful consideration. A case study approach is used to illustrate a cryptocurrency scamming platform, a giveaway scam, and divorce fraud. In all the cases, one needs to follow or trace the funds on the blockchain, referred to as on-chain analysis. The end goal of on-chain analysis is to find a destination address linked to identifiable information obtained from open-source data platforms-such as websites, social media, or a cryptocurrency exchange. Law enforcement can then be engaged to instruct the exchange to reveal all personal and transactional information linked to the address through a subpoena. A successful investigation will result in criminal prosecution and a potential recovery of funds. To maintain familiar investigation processes, the researchers looked at traditional (or non-technical) as well as technical investigation techniques.},
year = {2025},
journal = {Journal of Information Warfare},
volume = {24},
pages = {1-18},
issue = {1},
address = {ArmisteadTEC, LLC Virginia Beach, Virginia, USA},
}
2024
Vorster, J., & Leenen, L. (2024). The Unreasonable Effectiveness of Artefacts and Documentation: An Exploration of Consensus Using Multi-Agent Simulations in a Two-Team Configuration. In Proceedings of the 14th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH (Vol. 1). France: SCITEPRESS - Science and Technology Publications. http://doi.org/10.5220/0012785300003758
Documentation and artefact generation is an essential part of business processes. This paper explores the use of artefacts as a means of reaching consensus through the use of Multi-Agent Simulations. In particular we investigate the time to reach consensus with and without the use of artefacts and show the efficiency of artefacts as a means of facilitating consensus, perhaps more importantly, to create efficient consensus processes in the face of difficult organizational communications channels. We found that polyarchies are highly efficient at consensus formation, but are not realistic for larger organizations. For these organisations a small team that facilitate consensus formation is nearly as efficient. The introduction of artefacts significantly improve consensus formation in situations where intra-team communications causes delays in consensus formation.
@{551,
author = {Johannes Vorster and Louise Leenen},
title = {The Unreasonable Effectiveness of Artefacts and Documentation: An Exploration of Consensus Using Multi-Agent Simulations in a Two-Team Configuration},
abstract = {Documentation and artefact generation is an essential part of business processes. This paper explores the use of artefacts as a means of reaching consensus through the use of Multi-Agent Simulations. In particular we investigate the time to reach consensus with and without the use of artefacts and show the efficiency of artefacts as a means of facilitating consensus, perhaps more importantly, to create efficient consensus processes in the face of difficult organizational communications channels. We found that polyarchies are highly efficient at consensus formation, but are not realistic for larger organizations. For these organisations a small team that facilitate consensus formation is nearly as efficient. The introduction of artefacts significantly improve consensus formation in situations where intra-team communications causes delays in consensus formation.},
year = {2024},
journal = {Proceedings of the 14th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH},
volume = {1},
pages = {313-323},
month = {2024},
publisher = {SCITEPRESS - Science and Technology Publications},
address = {France},
doi = {10.5220/0012785300003758},
}
Botha, J., & Leenen, L. (2024). An Analysis of a Cryptocurrency Giveaway Scam: Use Case. In Proceedings of the 23rd European Conference on Cyber Warfare and Security (ECCWS 2024) (Vol. 23). Jyvaskyla, Finland: Academic Conferences International. http://doi.org/10.34190/eccws.23.1.2524
A giveaway scam is a type of fraud leveraging social media platforms and phishing campaigns. These scams have become increasingly common and are now also prevalent in the crypto community where attackers attempt to gain crypto-enthusiasts' trust with the promise of high-yield giveaways. Giveaway scams target individuals who lack technical familiarity with the blockchain. They take on various forms, often presenting as genuine cryptocurrency giveaways endorsed by prominent figures or organizations within the blockchain community. Scammers entice victims by promising substantial returns on a nominal investment. Victims are manipulated into sending cryptocurrency under the pretext of paying for verification or processing fees. However, once the funds have been sent, the scammers disappear and leave victims empty-handed. This study employs essential blockchain tools and techniques to explore the mechanics of giveaway scams. A crucial aspect of an investigation is to meticulously trace the movement of funds within the blockchain so that illicit gains resulting from these scams can be tracked. At some point a scammer wants to cash-out by transferring the funds to an off-ramp, for example, an exchange. If the investigator can establish a link to such an exchange, the identity of the owner of cryptocurrency address could be revealed. However, in organised scams, criminals make use of mules and do not use their own identities. The authors of this paper select a use case and then illustrate a comprehensive approach to investigate the selected scam. This paper contributes to the understanding and mitigation of giveaway scams in the cryptocurrency realm. By leveraging the mechanics of blockchain technology, dissecting scammer tactics, and utilizing investigative techniques and tools, the paper aims to contribute to the protection of investors, the industry, and the overall integrity of the blockchain ecosystem. This research sheds light on the intricate workings of giveaway scams and proposes effective strategies to counteract them.
@{550,
author = {Johnny Botha and Louise Leenen},
title = {An Analysis of a Cryptocurrency Giveaway Scam: Use Case},
abstract = {A giveaway scam is a type of fraud leveraging social media platforms and phishing campaigns. These scams have become increasingly common and are now also prevalent in the crypto community where attackers attempt to gain crypto-enthusiasts' trust with the promise of high-yield giveaways. Giveaway scams target individuals who lack technical familiarity with the blockchain. They take on various forms, often presenting as genuine cryptocurrency giveaways endorsed by prominent figures or organizations within the blockchain community. Scammers entice victims by promising substantial returns on a nominal investment. Victims are manipulated into sending cryptocurrency under the pretext of paying for verification or processing fees. However, once the funds have been sent, the scammers disappear and leave victims empty-handed. This study employs essential blockchain tools and techniques to explore the mechanics of giveaway scams. A crucial aspect of an investigation is to meticulously trace the movement of funds within the blockchain so that illicit gains resulting from these scams can be tracked. At some point a scammer wants to cash-out by transferring the funds to an off-ramp, for example, an exchange. If the investigator can establish a link to such an exchange, the identity of the owner of cryptocurrency address could be revealed. However, in organised scams, criminals make use of mules and do not use their own identities. The authors of this paper select a use case and then illustrate a comprehensive approach to investigate the selected scam. This paper contributes to the understanding and mitigation of giveaway scams in the cryptocurrency realm. By leveraging the mechanics of blockchain technology, dissecting scammer tactics, and utilizing investigative techniques and tools, the paper aims to contribute to the protection of investors, the industry, and the overall integrity of the blockchain ecosystem. This research sheds light on the intricate workings of giveaway scams and proposes effective strategies to counteract them.},
year = {2024},
journal = {Proceedings of the 23rd European Conference on Cyber Warfare and Security (ECCWS 2024)},
volume = {23},
pages = {74-85},
month = {27-28 June 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Jyvaskyla, Finland},
doi = {10.34190/eccws.23.1.2524},
}


