Cybercrime
Dr Enas Mohamed Ahmed
Cybercrime is one of the most significant emerging forms of crime, causing extensive damage to critical infrastructure and national economies, with potentially devastating consequences. It is inherently transnational, making regional and international agreements and conventions essential to combating it.
Cybercrime is one of the major challenges arising from digital transformation and the increasing reliance on the internet. It takes many forms, the most prominent of which include information theft, hacking, blackmail, extortion, and threats involving the unlawful exploitation of computerised information.
Key Characteristics of Cybercrime
The use of computers and the internet as the primary tools for committing offences.
The secretive nature of the crime, as many incidents go unreported in order to protect the reputation of companies, banks, or other institutions.
The difficulty of identifying physical evidence, since most traces of the crime exist only in digital form.
Its transnational nature, enabling it to cross national borders and inflict serious harm on one or several states.
The requirement for specialised technical knowledge, expertise, and familiarity with information technology and the internet.
The absence of physical violence in most cases; instead, success depends on technical skill and intelligence, allowing offenders to overcome traditional geographical and temporal barriers.
Cybercrime has the capacity to pirate globally developed software and exploit it for financial gain or coercion. Consequently, the international community has made significant efforts to combat it. The United Nations Economic and Social Council (ECOSOC) recommended developing policies for crime prevention and establishing international criminal justice. Acting upon this recommendation, the United Nations established the Advisory Committee on the Prevention of Crime and the Treatment of Offenders in 1950. The Committee was tasked with combating crime, providing advice to the Secretary-General, and developing international measures to prevent criminal activity.
The Seventh United Nations Congress on the Prevention of Crime and the Treatment of Offenders, held in Milan, Italy, in 1985, adopted a set of guiding principles. These same principles were later endorsed at the Eighth Congress, held in Havana, Cuba, in 1990, which also introduced additional measures to keep pace with technological developments. Among the most important principles were:
Updating national criminal legislation and institutional measures.
Strengthening information and computer security.
Training personnel working in internet-related fields within major companies, banks, and national institutions.
Enhancing international cooperation to combat cybercrime effectively.
The Ninth United Nations Congress on the Prevention of Crime and the Treatment of Offenders, held in Cairo, further emphasised the need to protect individual privacy and intellectual property rights against information piracy.
Towards the end of 2001, the Budapest Convention on Cybercrime was adopted to address internet-related offences, particularly terrorism, credit card fraud, and unauthorised access to bank accounts. It remains the only multilateral treaty specifically dedicated to combating cybercrime.
Similarly, the League of Arab States adopted the Arab Convention on Combating Information Technology Offences on 21 December 2020, to strengthen cooperation among Arab states in the fight against cybercrime.
One of the most well-known cases highlighting the problem of conflicting jurisdiction involved the British citizen Lauri Love, aged 28, who, in October 2013, carried out cyberattacks against United States Army computer systems. He stole vast quantities of classified data from sensitive military websites, impersonated a senior US Army official, and obtained information from the National Aeronautics and Space Administration (NASA) to disrupt the operations of these institutions.
The United Kingdom refused to extradite him to the United States, while also declining to prosecute him domestically. In February 2018, the High Court of Appeal in England delivered a landmark ruling preventing his extradition because of his serious health condition, including severe depression, and the remorse he had expressed for his actions. The court subsequently sentenced him to ten years’ imprisonment for unlawfully accessing US Army computer systems and an additional two years for identity fraud.
Another jurisdictional challenge arises when a citizen of one state commits a terrorist cybercrime but targets victims in several other countries. In such circumstances, each affected state may claim jurisdiction on behalf of its own nationals. The Budapest Convention of 2001 addressed this issue by providing a cooperative framework under which states consult one another to determine the most appropriate court to hear the case. The Convention also harmonises national legislation and strengthens cooperation among the member states of the Council of Europe in combating cybercrime. It was adopted during the Council of Europe’s 109th Session in Strasbourg, France, in November 2001.
The greatest danger posed by cybercrime arises when it extends to a state’s military and security secrets, thereby breaching what may be described as the state’s security “immune system” and threatening its stability, sovereignty, and national security.
This became evident when the personal data of more than 100,000 British police officers was exposed in a major cyber breach after hackers infiltrated an online database containing sensitive personal information. The incident raised serious security concerns regarding the safety of police personnel following the compromise of the Police National Legal Database (PNLD), an electronic platform that cybercriminals had infiltrated. Prior to this, the Department for Education had also suffered a cyberattack. Such incidents underline the urgent need for states to strengthen their digital security capabilities significantly.
At the Arab level, the Ninth Meeting of the Arab Experts Group on Combating Information Technology Crimes was held in Tunis on 30–31 July 2026. Sudan participated with a high-level delegation led by the Deputy Minister of Justice, Mawlawi Ali Al-Khidr, who presented Sudan’s experience in establishing the Cyber Security Agency (SCA), the official body responsible for safeguarding the country’s cyberspace. The Sudanese Government also reaffirmed its commitment to enforcing stringent licensing standards and imposing severe penalties on violators.
At the African level, on 15 March 2023, Sudan signed the African Union Convention on Cyber Security and Personal Data Protection, commonly known as the Malabo Convention, named after the city of Malabo in Equatorial Guinea. The Convention was originally adopted in 2014 during the 23rd Ordinary Session of the Assembly of Heads of State and Government of the African Union held in Malabo. It entered into force on 8 June 2023 after being ratified by fifteen African states.
As the only legally binding regional framework for data protection outside Europe, the Convention consists of 38 articles and was developed over several stages. Its most distinctive feature is that it combines cybersecurity, electronic transactions, and personal data protection within a single legal instrument, organised into four chapters.
Cybersecurity is an issue that deserves sustained attention from the state and all its sectors, because the challenges of the future will increasingly emerge from distant digital domains rather than conventional battlefields.
Shortlink: https://sudanhorizon.com/?p=16723