Sign UpLogin With Facebook
Sign UpLogin With Google

Cyber crime questionnaire for a victim survey, with a scam quiz and answers

A cybercrime questionnaire asks people what actually happened to them online: which crimes, in what time frame, what it cost and who they told. Answering the core 12 takes around four minutes, and it follows the design national victim surveys use. A five-question scam quiz with answers is included for talks and classes.

  • 38questions
  • 12in the core
  • 4 minto answer the core
  • 5quiz questions with answers
Download the PDF

By Michael Hodge, BSc Psychology Updated September 2026

Scams, hacking and abuse: the 38-question bank

The twelve core items start ticked. Tack on the incident, reporting, banking, habits, quiz or about-you set as your study needs, or choose questions one at a time. Each row spells out the choices respondents get and why the item earns a slot on a victim survey.

The core 12: the last 12 months12 questions

Two checklists (ever, then this year), what it cost, who they told and why not the police, six statements on know-how and habits, and one question in their own words.

  • Has any of these ever happened to you online?

    Abuse or threatsID or card misuseHacked accountVirusScamNoneTick all that apply

    The screening question. Asking about a longer period first lets people tell older stories here instead of squeezing them into the last 12 months.3

  • Which of them happened in the last 12 months?

    Abuse or threatsID or card misuseHacked accountVirusScamNoneTick all that apply

    Your 12-month rate, overall and by type. Count the people who tick two or more: in the Australian survey, 42.1% of victims had more than one type in a year.1

  • The most recent time, how much money did you lose?

    NoneUnder $100$100 to $999$1,000 or moreNot a victim

    Bands are easier to answer than an exact sum and still show the spread. Most victims lose under $1,000, so the top band is the one to watch.1

  • Who did you tell or ask for help?

    Family, friendsBankPlatformPoliceReport siteNo oneNot a victimTick all that apply

    Formal help is the exception. Family and friends were the most common source of help for most Australian victims, and about one in 10 made an official report.1

  • If you did not go to the police, what was the main reason?

    Handled it myselfNot seriousDid not know I couldPolice cannot helpDid not know whereI did report it

    These are the reasons national surveys hear most. The last three are about information, and information is the easiest thing to change.1

  • I can usually spot a scam message.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    Confidence, not skill. Set it beside the quiz scores to see whether the two match in your group.

  • I know where to report a cybercrime.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    Not knowing how or where to report is one of the reasons victims give for staying silent.1

  • If I lost money online, I would tell police.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    Intent to report. The distance between this answer and question 5 shows how many good intentions never become a report.

  • My email and bank logins need a second step.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    Two-step login is one of the simplest protections. In Australia 57.8% of respondents used it on personal accounts.1

  • Each key account has its own password.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    A reused password lets one leak open every account. About half of Australian respondents (50.7%) kept them separate.1

  • I feel safe banking and shopping online.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    How safe people feel. A low score next to high scores on questions 9 and 10 means worry is outrunning the actual risk, so read the open answers.

  • What would make you more likely to report a cybercrime?

    Open answer

    A to-do list for police, banks and platforms, written by the people who currently stay silent.

The most recent incident (victims only)6 questions

For anyone who ticked something in question 2. Ask about one incident, the latest, so details from different events do not blend together.

  • What was the most recent incident?

    Abuse or threatsID or card misuseHacked accountVirusScam

    The same five families as the checklists. Fixed categories let you compare this year with next year even as the scams change.3

  • How did it reach you?

    Text messagePhone callEmailSocial media or appWebsite or marketplaceI do not know

    Tells you where a warning campaign should run: a text-message scam needs a different message from a fake online shop.

  • Who was behind it?

    A strangerSomeone I knowPartner, ex or familyI do not know

    In Australia 15.1% of online abuse incidents involved a partner, former partner or family member, and those victims need a different kind of help.1

  • Did you get any lost money back?

    All of itSome of itNone of itI lost no money

    Recovery depends on the crime: 82.0% of Australian identity crime victims got money back, against 38.4% of fraud and scam victims.1

  • How many hours did it take to sort out?

    Under 11 to 56 to 20Over 20Not sorted yet

    Time is a cost almost every victim pays, even when no money is lost.

  • How did it affect you?

    Money problemsStress or poor sleepTime off work or studyStrain with peopleStopped using a serviceNo real effectTick all that apply

    Harm beyond money. 56.8% of Australian victims reported at least one negative impact, most often a practical one.1

Reporting it (only if you reported)4 questions

For people who took the incident to police, a report site, their bank or the platform. Everyone else skips this set, so place a simple screening question ahead of it.

  • Where did you report it first?

    The policeGovernment report siteMy bankThe platformSomewhere else

    The door people actually use. It is often not the one an agency expects.

  • What happened after you reported it?

    Heard nothingTold nothing could be doneIt was looked intoSomeone was chargedDo not know

    Silence after a report is common: between 18.6% and 39.1% of Australian victims who went to police or ReportCyber heard nothing, did not know the outcome, or were told nothing could be done.1

  • How satisfied were you with how it was handled?

    Very dissatisfied12345Very satisfied1 = Very dissatisfied, 5 = Very satisfied

    One outcome number for the whole process. Read it next to question 20 to see which step let people down.

  • Would you report the next one?

    YesProbablyProbably notNo

    The answer that decides next year's reporting rate.

Online banking and payments4 questions

For studies of cyber crime in the banking sector. Bank customers answer these alongside the core 12.

  • How often do you use your bank's app or website?

    DailyWeeklyMonthlyRarelyNever

    Exposure. Split every other answer by this one before comparing groups.

  • In the last 12 months, did a payment you did not make appear?

    YesNoNot sure

    Suspicious transactions were the most common identity crime in the Australian survey, reported by 10.1% of respondents.1

  • If so, who noticed it first?

    I didMy bank didA shop didNot applicable

    Shows whether the bank's fraud alerts are faster than its customers.

  • I trust my bank to refund money lost to fraud.

    Strongly disagree12345Strongly agree1 = Strongly disagree, 5 = Strongly agree

    Trust in the refund process shapes whether customers report quickly, and quick reports are the ones money comes back from.

Everyday habits4 questions

Four habits that make an attack more or less likely. The first is protective and the next three raise the risk, so read them in opposite directions.

  • I install updates when my device asks.

    Never12345Always1 = Never, 5 = Always

    Only 38.6% of Australian respondents regularly updated their security software when prompted.1

  • I bank or pay on free public wifi.

    Never12345Always1 = Never, 5 = Always

    A higher-risk habit whose prevalence did not change between the 2023 and 2024 Australian surveys.1

  • I open emails from senders I do not know.

    Never12345Always1 = Never, 5 = Always

    The door most phishing comes through. Pair it with the quiz to see who most needs a scam talk.

  • I share a password with someone else.

    Never12345Always1 = Never, 5 = Always

    Shared passwords turn one careless moment into two people's problem.

Scam-spotting quiz (answers below)5 questions

Five everyday situations. The first words of every why line give the correct choice, and the key lower on this page shows where each answer comes from. Run it after a talk or in a lesson.

  • A text says a parcel is held until you pay a small fee by link. What do you do?

    Pay, it is smallTap the link to checkCheck the courier site myself

    Answer: check the courier's own site or app. Reach a company through details you know are real, never the ones in the message.5

  • Someone from "your bank" calls and asks for the code just texted to you. What is it?

    A normal checkA scamFine if they know my name

    Answer: a scam. Nobody genuine asks for your account verification code.8

  • An online seller wants payment in gift cards. What does that tell you?

    It is a scamThey want a quick saleIt is normal for used goods

    Answer: it is a scam. No real business or agency asks to be paid in gift cards.6

  • Your password leaks. What keeps the account safest?

    A longer usernameTwo-step loginA yearly password change

    Answer: two-step login. It stops a scammer who has the username and password.5

  • You paid a scammer by card an hour ago. What comes first?

    Wait for it to clearCall my card issuerMessage the seller

    Answer: call the card issuer straight away, on the number on the card, and ask for the money back.7

About you (optional)3 questions

Only for comparing groups such as age bands. Never publish a split so small that a single person could be picked out.

  • How old are you?

    16 to 2425 to 3435 to 5455 to 6465 or overPrefer not to say

    Younger respondents were more likely to report abuse, malware and scams in the Australian survey, so age is the first split to try.1

  • How do you describe your gender?

    WomanManIn another wayPrefer not to say

    Online abuse and malware rates differed by gender in national data. Split this way only when each group is big.1

  • Outside work, how many hours a day are you online?

    Under 11 to 34 to 6Over 6

    More hours online means more chances to meet an attempt, so compare victims with others at similar hours.

Compare your group with a national cybercrime survey

Australia ran the same national survey in 2023 and 2024, so it gives you a yardstick. The 2024 round had 10,335 respondents recruited from online panels.1

Measure (last 12 months)Australia 2024Your question
Victim of any type47.4%Question 2, any box but the last
Online abuse and harassment26.8%Question 2, abuse plus hacked account
Identity crime and misuse21.9%Question 2, ID or card misuse
Malware20.6%Question 2, virus
Fraud and scams9.5%Question 2, scam
Uses two-step login57.8%Question 9, agree or strongly agree
Separate passwords50.7%Question 10, agree or strongly agree

All figures are from Voce and Morgan.1 The national survey counts hacked social media accounts as online abuse, which is why the abuse row adds two of our boxes together.

Reading the comparison

Compare shares, not counts, and compare like with like. A seniors club, a college class and a bank's customer list each meet different crimes, so the most useful comparison is often your own group a year later, asked the same questions at the same time of year.

Designing it the way national victim surveys do

Victim surveys fail in predictable ways: fuzzy time frames, jargon, and questions that upset people for nothing. Four choices avoid all three.

A long paper timeline on a desk with its final twelve-month section raised and lit, and small padlock and envelope tokens along it

Ask about ever first, then the last 12 months

People tend to pull an older incident into the period you ask about, which researchers call telescoping. A review of European victim surveys recommends a screening question over a longer period before the question about the period you are measuring, because leaving it out led to high telescoping, and telescoping inflates the rate.3 That is the job of question 1, which comes before question 2.

Victims who sought help from police or ReportCyber

Fraud and scams
20.7%
Online abuse
17.4%
Identity crime
15.5%
Malware
13.1%
Voce and Morgan (2025), Australian Cybercrime Survey 2024, most recent incident.1

Count the crimes nobody reported

Police figures miss most of the picture. A Dutch study of 97,186 crime victims found cybercrimes among the least reported offences.4 In the 2024 Australian survey, between 13.1% and 20.7% of victims sought help from police or ReportCyber, depending on the crime, and about one in 10 made an official report.1 Your survey sees the rest, and question 5 tells you why they stayed away.

Four sorting trays in a row holding a broken padlock, a bank card, a small bug-shaped chip and a fishing hook on an envelope

Name the crime in plain words

Few people file a fake online shop under "cyber crime". Ask about a short list of fixed families with everyday examples, and update the examples as scams change while the families stay the same. The same review gives that advice for keeping results comparable from year to year.3

A printed questionnaire beside a cup of tea, with a small card showing a telephone handset and a heart resting on it

Look after the people answering

Offer a way out of every question, ask about the most recent incident only, and close with a help line. Victims who tell you what went wrong are doing you a favour, so show them the results and what changed because of them.

Giving a scam awareness talk at a library, school or seniors group? Show one quiz question as a live poll, collect the votes, then reveal the answer. Guests vote from their phones; our walkthrough on setting up a poll covers the rest.

Score the six know-how and habit statements

Enter how many respondents picked each point for questions 6 to 11. Agreeing is the safe answer on all six, so whichever bar sits lowest marks the habit or know-how gap to tackle first.

  1. 1Per statement, the bar is Agree plus Strongly agree as a share of all answers to it.
  2. 2Look at knowing where to report and intending to tell police together. If both are low, a one-page guide to reporting will do more than a warning poster.
  3. 3Compare the two login statements with the national figures in the table above to see whether your group is ahead or behind.
  4. 4Leave the open answers (question 12) until the end, group them by theme, then choose two actions and give each a date.

Cyber crime survey results

1 (lowest)2345 (highest)

Answer key for the scam quiz

Read the answers out after the vote, or print this table for the back of the room. Every answer comes from the US Federal Trade Commission's consumer advice.

QuestionAnswerWhy
1. Parcel fee by linkCheck the courier yourselfContact the company "using a phone number or website you know is real".5
2. The bank wants your codeA scam"Anyone who asks you for your account verification code is a scammer."8 Hang up and call the number on your card.
3. Pay in gift cardsA scam"No real business or government agency will ever tell you to buy a gift card to pay them."6
4. Leaked passwordTwo-step loginIt "makes it harder for scammers to log in to your accounts" even with the password.5
5. Paid a scammer by cardCall the issuer nowReport it at once on the number on the back of the card and ask for a refund.7

Turning the quiz into a talk

Put one question on screen, let the room vote, then show the answer and tell one true local story that fits it. The questions most people miss are the ones to repeat in your next newsletter.

For club members and library visitors who skip links

A printed form reaches people who rarely answer online surveys, from club members to library visitors. Both files fit letter or A4 paper.

Giving a talk? and keep the quiz answer key for the end.

First page of the printable questionnaire PDF

Printable questionnaire

Twelve core items with boxes to mark in pen, the optional sets behind them, and the quiz on its own final sheet for handing out after a talk.

Download PDF
First page of the results tally sheet PDF

Results tally sheet

Count the paper forms, turn the six statements into shares who agree, tally the 12-month checklist and note two actions.

Download PDF

Using it for a thesis or class project

Many cybercrime questionnaires end up in a thesis or a class paper. Match the sets to your research question, then keep the survey short enough that people finish it.

Research questionSets to useWhat to report
How common is cybercrime in this group?Core 12, About youShare ticking each box in question 2, split by age
Why do victims not report?Core 12, Reporting itQuestion 5 reasons for victims only, with question 20 outcomes
Cyber crime in the banking sectorCore 12, Online bankingQuestion 24 rate, who noticed first, refund trust
Do habits predict being a victim?Core 12, Everyday habitsHabit answers for victims and non-victims side by side

Ethics and consent

Questions about scams and abuse can bring back a bad experience. Say so on the first screen, make every question skippable, collect no names, and end the survey with the details of a local victim support or scam help line. That mirrors the consent page of the Australian survey, which warns that its questions can be upsetting and offers someone to talk to.2

Measuring awareness as a scale

If your supervisor wants a validated awareness score rather than a knowledge quiz, look at the Cybercrime Awareness Scale by Arpaci and Ates, tested on two samples of about 500 respondents each, with three factors: information systems crimes, personal data crimes, and privacy and security.9 Ask the authors before you use it; its items are not reproduced here.

A five-question cybercrime check

Short of time at a meeting or a stall? These five give you a 12-month rate, the cost, who people turn to, whether they know where to report, and what would change their minds.

  1. 01Which of them happened in the last 12 months?
  2. 02The most recent time, how much money did you lose?
  3. 03Who did you tell or ask for help?
  4. 04I know where to report a cybercrime.
  5. 05What would make you more likely to report a cybercrime?

Cybercrime questions that go wrong, and better versions

Small wording choices change what a victim survey finds. For other topics and formats, browse our library of survey questions.

Instead of

Have you ever been a victim of cyber crime?

Ask

Has any of these ever happened to you online? (a list of five kinds)

Someone who paid a fake seller or had a card misused may never call it cyber crime, so the label undercounts. A list of events works whatever people call them.

Instead of

What do you think motivates cyber criminals?

Ask

The most recent time, how much money did you lose?

Respondents can report what happened to them; they can only guess at an offender's motives. Keep opinion questions for a separate attitudes study.

Instead of

Do you use strong passwords, antivirus and updates?

Ask

Each key account has its own password.
I install updates when my device asks.

Three habits in one question. Someone who updates but reuses passwords has no honest answer.

Instead of

How often have you been hacked?

Ask

Which of them happened in the last 12 months?

No time frame, so one person counts a decade and another counts this month. A fixed window makes answers comparable.

Questions researchers and organisers ask

Short answers to what comes up before the questionnaire goes out.

What questions should a cyber crime questionnaire include?

Start with what happened: a checklist of crimes ever, then the same list for the last 12 months. Then ask about the most recent incident (cost, who was behind it, who they told) and why they did not report it. Add habits and awareness only after that.

What are the main types of cybercrime to ask about?

National surveys use four families: online abuse and harassment, identity crime and misuse, malware, and fraud and scams.1 We list hacked accounts on their own because people recognise them easily.

Can I use this questionnaire to study cyber crime in the banking sector?

Yes. Send the core 12 with the Online banking and payments set to bank customers. The unexplained payment question lines up with the most common identity crime in national data, so you can compare your rate with a published figure.

Is it all right to ask people about being scammed?

Yes, with care. Tell people up front what the survey covers, let them skip anything, keep it anonymous, and end with a help line. Most people are glad to be asked when they can see the answers will be used.

Can I run the survey in another language?

Yes. After the builder opens, translate each question and its answers, and keep the answer order unchanged. Swap in examples of scams common where your respondents live.

Ready to ask about cyber crime?

Share the twelve-question core by link, or print copies for your next talk or class. Our <a href="/Feedback-Survey-Questions">feedback survey questions</a> cover other ways to hear from the public.

Download the PDF
12 questions selected