Cybercrime and International Law: Jurisdiction, Treaties & State Responsibility

A ransomware operator sitting in one country encrypts a hospital's servers in a second country using command infrastructure rented in a third. The ransom note demands payment in cryptocurrency routed through exchanges in a fourth. By the time the victim's lawyers work out which country's police to call, the operator has already moved on.

This is not a rare edge case. It is the ordinary shape of cybercrime, and it exposes a structural weakness in a legal system still built around the idea that crime happens somewhere in particular.

International law was designed for a world of fixed borders, physical acts, and identifiable actors. Cyberspace routes around all three. The result is a genuine doctrinal strain: prosecutors know the law of jurisdiction, but the law offers little guidance when five states can each claim a valid jurisdictional hook over the same three-second intrusion.

This article sets out the architecture governing cybercrime and international law as it stands today — the jurisdictional bases available to prosecutors, the treaty regimes competing for global adoption, the doctrine of state responsibility and its notorious attribution problem, the procedural mechanics of cross-border evidence gathering, and the domestic statutes that actually put people in prison.

Key Doctrinal Takeaways

  • Jurisdiction over cross-border cybercrime is rarely singular. Under what practitioners call the ubiquity approach, the state of conduct, the state of effect, and the state of nationality can all simultaneously and validly claim jurisdiction — general international law does not rank them.
  • Pinning a cyberattack on a state, rather than on an individual criminal, requires meeting the demanding "effective control" standard articulated in Nicaragua v. United States (ICJ 1986) — not the looser "overall control" test developed in Tadić for classifying armed conflicts.
  • Two global treaties now sit side by side: the 2001 Budapest Convention and the United Nations Convention against Cybercrime (adopted 24 December 2024, opened for signature in Hanoi on 25–26 October 2025). One does not replace the other, and the UN Convention is not yet in force.
  • Most cross-border cybercrime prosecutions fail or stall not on doctrine but on procedure — the gap between how fast digital evidence disappears and how slowly a mutual legal assistance request moves.
Cybercrime and international law showing jurisdiction, the Budapest Convention, the UN Cybercrime Convention, and state responsibility for cyberattacks
Cybercrime and International Law: territoriality, the Budapest and UN Cybercrime Conventions, ICJ attribution standards, and cross-border digital evidence.
Contents

The crisis of digital sovereignty and the jurisdictional labyrinth

Westphalian sovereignty rests on a simple premise: a state controls what happens inside its own borders, and its laws stop where its territory stops. Cyberspace was not built on that premise. A single packet of data can leave a laptop in Lahore, transit routers in Frankfurt and Singapore, and land on a server in Virginia within a few hundred milliseconds, without anyone involved making a conscious choice about which sovereign's territory it crosses.

This is the core of the jurisdictional labyrinth in cybercrime and international law: the conduct, the infrastructure, the harm, and the offender are frequently located in four different states, and classical jurisdictional doctrine — built for a world of physical acts in physical places — was never designed to allocate authority cleanly among them.

Customary international law recognizes five conventional bases on which a state may lawfully assert prescriptive jurisdiction. All five appear, sometimes in the same case file, in cybercrime practice. The general framework is set out in more detail in our article on State Jurisdiction in International Law.

The territoriality principle and the ubiquity problem

Territorial jurisdiction is the default basis, and cybercrime forces it to split into two variants. Subjective territoriality looks to where the criminal act was initiated — where the keyboard was, so to speak. Objective territoriality, often called the effects doctrine, looks instead to where the harm materialized.

The case most often cited as the doctrinal ancestor of the effects doctrine is the Permanent Court of International Justice's 1927 judgment in The Case of the S.S. "Lotus" (France v. Turkey). The Court there reasoned that a state is not barred from exercising jurisdiction over conduct producing effects within its territory merely because the conduct itself occurred abroad, absent a prohibitive rule of international law.

Two qualifications are essential and are frequently omitted from summaries. First, Lotus arose from a high-seas collision in which the Turkish vessel was treated for jurisdictional purposes as Turkish territory, so the case is a weaker authority for a general effects doctrine than it is usually made to bear; the modern effects doctrine owes at least as much to twentieth century United States antitrust practice as to the PCIJ. Second, the broad Lotus presumption — that whatever is not prohibited to a state is permitted — has been extensively criticized and is no longer treated as an unqualified statement of modern law; contemporary practice increasingly requires a genuine connection between the state and the conduct. The relationship between judicial decisions, state practice and custom is discussed further in our article on the sources of public international law.

With those qualifications in place, the practical point stands. Because Lotus reasoning is permissive rather than allocative, it does not resolve competing claims — it multiplies them. When conduct, infrastructure, and harm sit in three different states, each of those states can construct a plausible jurisdictional basis. This simultaneous, unranked, multi-state claim is what practitioners describe as the ubiquity problem, and a number of domestic criminal codes address it directly by deeming an offence to have been committed within the territory if any constituent element or its result occurs there.

The Ubiquity Conflict Matrix

Picture a single intrusion: a hacker physically located in State A routes the attack through a cloud relay server rented in State B, striking a bank's core system whose data subjects and financial loss sit entirely in State C. State A has subjective territorial jurisdiction (conduct occurred there) and, if the hacker is its national, active nationality jurisdiction as well. State B can assert jurisdiction because its infrastructure was used to commit an offence under its own computer-misuse statute. State C has objective territorial jurisdiction because the injury was felt there, and possibly passive-personality jurisdiction over the harm to its nationals. None of these claims is legally superior to the others as a matter of general international law. Extradition, evidence custody, and diplomatic priority — not doctrine — usually decide who prosecutes first.

The active nationality principle

A state may prosecute its own nationals for conduct committed anywhere, including cyber offences committed entirely from abroad. This basis matters enormously in practice, since it lets the state of nationality prosecute domestically even where extradition to the victim state is politically or constitutionally impossible. Many constitutions and extradition statutes bar the surrender of nationals outright, which frequently makes active-nationality prosecution the only realistic route to accountability — and explains why the aut dedere aut judicare formula appears so often in transnational criminal law treaties.

The passive personality principle

Passive personality jurisdiction is asserted on the basis of the victim's nationality rather than the offender's location or nationality. It remains the most contested of the five bases in general international law, but cybercrime statutes increasingly lean on it, particularly for online fraud and cyber-enabled harassment provisions that protect a state's own citizens regardless of where the offender was physically located when the harmful message, transfer instruction, or malicious code was sent.

The protective principle

The protective principle allows a state to assert jurisdiction over conduct — wherever committed, by whomever — that threatens its essential security interests. In the cyber context this basis has grown sharply in importance: attacks on critical infrastructure (power grids, water systems, financial clearing systems) and, increasingly, attacks on election infrastructure are treated as falling within a state's protective jurisdiction even where the offender has no territorial or national connection to the victim state at all. The obvious difficulty is definitional: "essential security interest" has no agreed international content, and an expansive reading would swallow the other bases whole.

The universality principle: is cybercrime a crime against all states?

Universal jurisdiction permits any state to prosecute an offence regardless of any territorial, nationality, or protective link, but customary international law has traditionally reserved it for a narrow category of offences of concern to the whole international community — piracy, genocide, and comparable atrocity crimes. Cybercrime, including catastrophic ransomware and cyber-terrorism, has not been elevated to this category as a matter of binding custom or treaty, and no Rome Statute-style international crime of "cyberattack" currently exists.

The closest approach is treaty-based rather than customary: instruments addressing online child sexual abuse material push states toward something functionally resembling universal jurisdiction through aut dedere aut judicare and broad jurisdictional clauses. Those clauses are, however, narrower and more conditional than the phrase "universal jurisdiction" suggests — they typically require a defined jurisdictional link or an extradition refusal to trigger the duty to prosecute — and they remain obligations created by specific treaty text, not a freestanding jus cogens or erga omnes norm applicable to cybercrime generally.

Bases of jurisdiction applied to cybercrime
Basis Legal anchor Cyber application Typical defence challenge
Subjective territoriality Customary international law; Lotus (PCIJ 1927) Jurisdiction where the intrusion, malware deployment, or transmission originated Location of the accused's device at the time of the act is technically disputed or spoofed
Objective territoriality (effects doctrine) Lotus reasoning; statutory extraterritoriality clauses (e.g. PECA s.1(4)) Jurisdiction where financial loss, data compromise, or system damage was suffered Causal link between the foreign conduct and the domestic harm is contested
Active nationality Customary international law Prosecuting a state's own national for offences committed entirely abroad Evidence and witnesses are located outside the prosecuting state
Passive personality Contested customary basis; increasingly codified in domestic statutes Jurisdiction based on the nationality of the victim of online fraud or harassment Doctrinal legitimacy of the basis itself is challenged as overbroad
Protective principle Customary international law Attacks on critical infrastructure, financial systems, or election infrastructure Defining "essential security interest" with sufficient precision
Universality Narrow customary category; supplemented by specific treaty obligations Not generally available for ordinary cybercrime; partially approached via CSAM treaty clauses No binding customary rule extends universality to cybercrime as such

The evolution of global treaty architecture

Two treaties now dominate this field, and they were born from opposite political instincts.

The Budapest Convention: structure, strength, and sovereignty objections

The Council of Europe's Convention on Cybercrime, ETS No. 185 — commonly known as the Budapest Convention — was opened for signature on 23 November 2001 and entered into force on 1 July 2004. For two decades it was the most widely adopted binding cybercrime treaty open to accession by states outside the drafting region, and it remains the template on which a great many domestic computer-misuse statutes were built.

Its architecture is easiest to hold in mind by chapter, and this is a point frequently misstated. Chapter II deals with measures to be taken at the national level and is itself divided into three sections. Section 1 (Articles 2–13) establishes the substantive offences: illegal access, illegal interception, data interference, system interference, misuse of devices, computer-related forgery and fraud, offences related to child pornography (the Convention's own 2001 terminology; current practice, and the UN Convention, use "child sexual abuse material"), and offences related to infringements of copyright, together with attempt, aiding and abetting, and corporate liability.

Section 2 of Chapter II (Articles 14–21) supplies the procedural powers a state must have domestically to investigate any offence involving electronic evidence — expedited preservation of stored computer data (Article 16), expedited preservation and partial disclosure of traffic data (Article 17), production orders (Article 18), search and seizure of stored computer data (Article 19), and real-time collection of traffic and content data (Articles 20–21), all subject to the conditions and safeguards of Article 15. Section 3 (Article 22) then addresses jurisdiction, requiring parties to establish jurisdiction on territorial and nationality bases and to consult where several parties claim it.

Chapter III (Articles 23–35) governs international cooperation. Article 24 deals with extradition, Article 25 states the general obligation of mutual assistance to the widest extent possible, Article 27 supplies a fallback procedure where no mutual assistance treaty exists between requesting and requested states, Articles 29–30 create the expedited preservation mechanism at the international level, and Article 35 establishes the 24/7 point-of-contact network for urgent assistance.

The Convention's most controversial provision is Article 32(b), which permits a party to access or receive stored computer data located in another party's territory without that party's authorization, provided the accessing state obtains the lawful and voluntary consent of a person who has lawful authority to disclose the data through a computer system in its own territory. The Council of Europe's own Cybercrime Convention Committee has addressed the provision in a dedicated Guidance Note, treating it as a limited and carefully bounded departure from the ordinary requirement of mutual assistance rather than a general licence for transborder access. Russia never accepted the provision, treating it as a direct incursion on territorial sovereignty, and this objection has been repeatedly cited as a principal reason a number of states resisted acceding to a Council of Europe-drafted instrument — a resistance that eventually produced the push for a global alternative negotiated under UN auspices.

The Additional Protocols

Two protocols supplement the Convention and are routinely overlooked in summaries of this field. The First Additional Protocol (ETS No. 189, 2003) concerns the criminalization of acts of a racist and xenophobic nature committed through computer systems; several parties to the main Convention, including the United States, have not joined it, largely on freedom-of-expression grounds.

Far more consequential for practitioners is the Second Additional Protocol (CETS No. 224), opened for signature on 12 May 2022, on enhanced co-operation and disclosure of electronic evidence. It was drafted precisely to address the procedural bottleneck discussed later in this article, providing for direct co-operation with service providers and registrars in other parties, expedited state-to-state disclosure of subscriber information and traffic data in emergencies, and joint investigation teams — subject to a data-protection framework in Article 14. Any current treatment of cross-border digital evidence that stops at the 2001 Convention is out of date.

Regional instruments

The Budapest Convention was never the only binding instrument in this field. The Arab Convention on Combating Information Technology Offences (2010) and the African Union's Convention on Cyber Security and Personal Data Protection (the Malabo Convention, adopted 2014 and in force since June 2023) both address cybercrime within their regions, and the Commonwealth, ECOWAS and other bodies have produced model laws. Their existence matters to the political narrative: the UN process was not filling a total vacuum, but responding to a fragmented landscape in which the most detailed instrument had been drafted by a European body.

The UN Convention against Cybercrime: a new, contested global order

The United Nations Convention against Cybercrime traces its origin to a Russian-led initiative, formally advanced through General Assembly Resolution 74/247 in December 2019, which established an Ad Hoc Committee to draft a universal cybercrime treaty outside the Council of Europe framework. Five years of often adversarial negotiation followed, splitting states broadly into a bloc oriented toward civil-liberties safeguards and wary of expansive surveillance powers, and a state-sovereignty bloc — including Russia, China, and a substantial group of developing states — pushing for broader scope and fewer human-rights conditions on cooperation.

The General Assembly adopted the treaty by consensus through Resolution 79/243 on 24 December 2024. It opened for signature at a high-level ceremony in Hanoi on 25 and 26 October 2025 — which is why it is increasingly called the Hanoi Convention. Reported signature figures for the ceremony vary depending on the day and the source: UN News reported sixty-five states signing on the opening day, while the United Nations Office of Legal Affairs, as depositary, records seventy-one states and the European Union signing at the ceremony as a whole, one of the strongest opening figures for any multilateral treaty deposited with the Secretary-General in the past decade. The Convention remains open for signature at UN Headquarters in New York until 31 December 2026 and enters into force ninety days after the fortieth instrument of ratification is deposited.

That last point deserves more emphasis than the signature count. As of mid 2026 the Convention had accumulated roughly seventy-four signatories but only three ratifications — Qatar, Azerbaijan and Vietnam. Signature indicates political endorsement and a duty not to defeat the treaty's object and purpose; it does not bring the instrument into force. On present trajectory the Convention is years away from operating, and any prosecutor planning around it should treat it as prospective rather than available.

Substantively, the Convention goes beyond the Budapest Convention's core cyber-dependent offences to cover a wider category of technology-facilitated "serious crimes," mandates a global 24/7 cooperation network from the outset, and criminalizes the non-consensual dissemination of intimate images under Article 16, alongside child sexual abuse or exploitation material under Article 14. The Article 16 provision is a genuine expansion: it is the first global treaty to require states to criminalize what is colloquially called "revenge pornography" as a matter of international obligation, an area previously left to domestic legislation and regional instruments.

The human-rights critique of the Convention has been sustained and specific. Human Rights Watch, ARTICLE 19, the Electronic Frontier Foundation and the broader NGO coalition working through the Alliance of NGOs on Crime Prevention and Criminal Justice have flagged the Convention's breadth: its cooperation obligations can, in principle, be invoked for any offence a domestic system designates as serious by reference to a four-year imprisonment threshold, a threshold that in some legal systems captures criticism of government, peaceful protest, or investigative journalism. Critics have also pointed to the treatment of dual criminality across several categories of cooperation, data-protection safeguards for information shared between states that they regard as under-specified, and the absence of any mechanism to suspend a state party found to be systematically abusing the Convention's powers.

Defenders of the text respond that it contains an express human-rights clause, that grounds for refusal of assistance remain available to requested states, and that a genuinely universal instrument was preferable to leaving a large part of the world outside any binding framework. Whether the drafters achieved sufficient human-rights mainstreaming, or produced instead a very wide door for surveillance cooperation, is likely to be the defining debate of the Convention's first decade.

Budapest Convention (2001) versus UN Convention against Cybercrime (2024/2025)
Dimension Budapest Convention UN Convention against Cybercrime
Origin Council of Europe, drafted by European experts with observer states (US, Canada, Japan, others) UN General Assembly Ad Hoc Committee open to all member states, established by Resolution 74/247 (2019) on a Russian-led initiative
Adoption / entry into force Opened 23 November 2001; in force 1 July 2004 Adopted 24 December 2024 (Res. 79/243); opened for signature 25–26 October 2025; not yet in force (40 ratifications required)
Geographic reach Open to accession beyond Europe and widely ratified, but structurally a European instrument; several major states, including Russia and much of South Asia, never joined Universal by design; negotiated with participation of all UN member states
Transborder data access Article 32(b) permits limited unilateral access with data-holder consent — the most sovereignty-sensitive provision in the treaty; Second Additional Protocol (2022) adds direct co-operation with providers Relies on a mandatory 24/7 cooperation network and broad mutual-assistance obligations rather than unilateral access
Substantive scope Core cyber-dependent offences (Arts. 2–13) plus limited content and copyright offences Broader "serious crime" cooperation scope; first global treaty to require criminalization of non-consensual dissemination of intimate images (Art. 16)
Human rights safeguards Article 15 conditions and safeguards, operating alongside the Council of Europe's existing human-rights architecture and ECtHR supervision for its members Contains a human-rights clause, but widely criticized by civil society as under-specified; no suspension mechanism for abusive states

State responsibility and the attribution problem

When the alleged offender is not an ordinary criminal but is said to be acting for a state, the legal frame shifts entirely — from domestic criminal jurisdiction to the international law of state responsibility. The general framework is set out at length in our article on State Responsibility in International Law.

ARSIWA and the thresholds of wrongful cyber conduct

The International Law Commission's Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA, 2001) supply the governing framework. Article 8 provides that conduct is attributable to a state where a person or group is in fact acting on the instructions of, or under the direction or control of, that state in carrying out the conduct.

Attribution alone is not a breach. It must be paired with a primary obligation the operation violates, and three are usually in play, in ascending order of seriousness: a violation of another state's sovereignty (unauthorized intrusion into governmental systems, without more — although a minority of states, notably the United Kingdom, have questioned whether sovereignty operates as a standalone primary rule at all in the cyber context); a violation of the customary non-intervention principle, where the operation coercively interferes with a matter the target state is entitled to determine freely, such as the conduct of an election; and at the most serious end a use of force under Article 2(4) of the UN Charter, or an armed attack triggering the Article 51 right of self-defence, where the operation's consequences are comparable to a kinetic military strike. The coercion element that distinguishes unlawful intervention from ordinary influence is examined in our article on the Principle of Non-Intervention in International Law.

The triple-layered attribution crisis

Proving state responsibility for a cyber operation is not one inquiry but three, stacked on top of each other, and each layer can independently fail.

  1. Technical attribution — identifying the infrastructure and toolset used: source IP addresses, routing anomalies, malware code reuse, compilation timestamps, and operational tradecraft signatures. This layer is achievable with modern forensic capability, but infrastructure is routinely leased, compromised, or spoofed precisely to defeat it.
  2. Operational or human attribution — connecting the technical infrastructure to specific human operators or a specific organized group, typically through signals intelligence, human intelligence, or cooperating-witness testimony that intelligence services are frequently unwilling to expose in open court.
  3. Legal or state attribution — the final and hardest step: proving, to the ARSIWA Article 8 standard, that the identified operator was acting under the state's instructions, direction, or control, rather than merely with the state's tacit approval, tolerance, or general encouragement.

It is entirely possible — and routinely happens — for the first two layers to be resolved with high technical confidence while the third remains legally unprovable. This gap is what the phrase "attribution problem" actually refers to in professional usage, and it is the single greatest doctrinal obstacle to holding states accountable for cyber operations under public international law. It is worth adding that international law imposes no general obligation on a victim state to publish its evidence when it makes an attribution, which is one reason so many public attributions are political statements rather than legal claims.

Effective control versus overall control

The standard now codified in ARSIWA Article 8 was articulated fifteen years before the Articles were adopted. In Military and Paramilitary Activities in and against Nicaragua (Nicaragua v. United States of America), Merits, I.C.J. Reports 1986, p. 14, the International Court of Justice held that the United States could be held responsible for the Nicaraguan contras' own violations only upon proof of effective control over the specific operations in which those violations occurred; general funding, training, and equipping fell short. The ILC drew on that reasoning when drafting Article 8, and the commentary treats Nicaragua as its principal authority.

This is an exceptionally demanding standard in the cyber context, where state sponsors of Advanced Persistent Threat groups deliberately maintain plausible deniability through cut-outs, criminal proxies, and compartmentalized operational structures.

A materially lower threshold — overall control, requiring only that a state coordinate or help organize an armed group's activity as a whole — was applied by the International Criminal Tribunal for the former Yugoslavia in Prosecutor v. DuÅ¡ko Tadić, Case No. IT-94-1-A, Appeals Chamber Judgment, 15 July 1999, at paragraph 137. Crucially, Tadić developed that lower threshold to classify a conflict as international for the purposes of humanitarian law, not to establish state responsibility for an internationally wrongful act. The ICJ was later asked directly whether the lower Tadić standard should displace Nicaragua for state-responsibility purposes and declined, in Application of the Convention on the Prevention and Punishment of the Crime of Genocide (Bosnia and Herzegovina v. Serbia and Montenegro), Judgment, I.C.J. Reports 2007, p. 43, reaffirming effective control for that distinct inquiry while accepting that overall control may be appropriate for conflict classification.

The practical consequence for state-sponsored cyber operations is stark: even where overall coordination between a hacking group and a state's intelligence apparatus can be shown, that showing is legally insufficient to attribute the group's conduct to the state for responsibility purposes. Only proof of operational-level direction meets the bar — and operational-level direction is exactly what sophisticated state sponsors design their proxy relationships to conceal. This is why so few Advanced Persistent Threat campaigns, despite confident public attribution by cybersecurity firms and even by allied governments, have ever produced a state-responsibility finding capable of surviving legal scrutiny.

The due diligence obligation and the Corfu Channel principle

A separate and less demanding avenue exists where a state cannot be shown to control a cyber operation but can be shown to have knowingly tolerated it. The International Court of Justice held in Corfu Channel (United Kingdom v. Albania), Merits, I.C.J. Reports 1949, p. 4, that every state is under an obligation not to allow knowingly its territory to be used for acts contrary to the rights of other states.

Applied to cyberspace, this due diligence principle suggests that a state which knowingly harbours ransomware syndicates or tolerated hacking collectives operating from its territory — without taking reasonable measures to investigate or suppress them once it has actual knowledge — may itself incur international responsibility, independent of any showing that it directed the specific attacks. It is a considerably lower evidentiary bar than the Nicaragua effective-control test.

Two caveats belong here. First, states remain divided on whether cyber due diligence is a binding obligation or a voluntary norm of responsible state behaviour; several states, including the United Kingdom, have expressed scepticism, and the UN Group of Governmental Experts framed the relevant expectations as non-binding norms rather than obligations. Second, the obligation as usually formulated is one of conduct and knowledge, not result: it requires reasonable measures once the state actually knows, and a state that genuinely lacks knowledge or capacity is not automatically in breach. Due diligence is therefore a promising theory, not yet a settled one.

Exam Masterclass: Cybercrime Versus Cyber Warfare

Examiners routinely test whether a candidate can locate a given fact pattern on the correct side of the line. The Tallinn Manual 2.0's consequence-based approach (Rules 69–71) asks whether the operation's scale and effects are comparable to a kinetic military operation — ordinarily requiring physical damage, injury, or death. Data theft, espionage, financial fraud, and even large-scale service disruption fall on the cybercrime side of the line and are governed by ordinary criminal law and peacetime state-responsibility doctrine. Only operations producing destructive physical consequences — the 2010 Stuxnet operation against Iranian centrifuges being the standard example — approach the cyber warfare side, implicating the jus ad bellum and, potentially, the law of armed conflict. Note that the Tallinn Manual is a non-binding academic work by an international group of experts convened under NATO Cooperative Cyber Defence Centre of Excellence auspices; it is persuasive and widely cited, but it is not a source of international law under Article 38 of the ICJ Statute and should never be cited as though it were a treaty. Do not conflate the two frameworks in an answer: a candidate who analyzes a data-breach fact pattern under Article 51 self-defence, rather than under ordinary attribution and criminal jurisdiction doctrine, will lose marks for applying the wrong body of law.

Procedural enforcement and transnational digital evidence

Why the MLAT system is breaking down

Doctrine only matters if evidence can actually be obtained, and this is where cybercrime prosecution most often fails in practice. Digital evidence is volatile: server logs rotate out on automated schedules, cloud providers retain connection data for limited windows set by their own retention policies and by widely varying national data-retention rules, and a competent suspect can trigger remote-wipe scripts within seconds of learning an investigation exists.

Conventional mutual legal assistance processing, by contrast, routinely takes many months from formal request to executed response, passing through central authorities, translation requirements, and judicial authorization in the requested state before a single byte of data changes hands. The mismatch is not a minor inefficiency — it is a principal reason a large share of cross-border cybercrime investigations never produce usable evidence at all, and it is the problem the Budapest Convention's Second Additional Protocol and the direct-access regimes below were designed to attack.

24/7 preservation requests versus letters rogatory

Two very different procedural instruments are often confused. A letter rogatory is a formal judicial request from a court in one state to a court in another, seeking assistance in obtaining evidence or performing a judicial act; it is slow, formal, and typically routed through diplomatic or central-authority channels, making it wholly unsuited to volatile digital evidence.

A 24/7 preservation request, by contrast — created by Articles 29 and 35 of the Budapest Convention and mirrored in the UN Convention against Cybercrime's cooperation network — does not obtain evidence at all. It merely freezes it: an urgent request through a designated point of contact requires the holder of data to preserve it in its current state, buying time for the far slower formal mutual assistance or letter-rogatory request to catch up. Confusing the two is a common and consequential procedural error: a prosecutor who sends a formal letter rogatory as their first move, rather than an immediate preservation request, will often find the underlying data has already been overwritten by the time the formal request is answered.

Direct provider access: the CLOUD Act, the E-Evidence Regulation, and data localization

A newer and faster alternative route bypasses state-to-state cooperation altogether by compelling the data-holding company directly. The United States' Clarifying Lawful Overseas Use of Data Act of 2018 (the "CLOUD Act") amended the Stored Communications Act to require US-based providers to produce data responsive to US legal process regardless of where the data is physically stored — resolving the question left open when the Supreme Court dismissed United States v. Microsoft Corp. as moot in 2018 — and separately authorizes the US executive branch to enter bilateral agreements, such as the US–UK CLOUD Act Agreement, allowing each state's law enforcement to request data directly from providers based in the other, without going through the mutual assistance process.

The European Union has built a parallel structure through Regulation (EU) 2023/1543, establishing European Production and Preservation Orders that allow a judicial authority in one member state to compel a service provider established or represented in another to hand over data directly. Both regimes sit in tension with a countervailing trend toward data localization laws, under which a growing number of states require that data concerning their citizens or critical sectors be stored physically within national borders, in part to prevent exactly this kind of direct extraterritorial compulsion — a tension likely to define cross-border evidence law for the next decade.

Standard operating procedure for a public prosecutor securing foreign cloud evidence

  1. Identify the data holder and its jurisdiction of incorporation. Determine whether the relevant service provider is subject to a direct-access regime (such as the CLOUD Act or the EU e-evidence Regulation), offers a voluntary law-enforcement disclosure channel, or requires formal state-to-state cooperation.
  2. Issue an immediate preservation request through the domestic designated point of contact — or, where available, directly to the provider's law-enforcement portal — the moment volatile evidence is identified, before drafting any formal mutual assistance request. This step alone often determines whether the evidence will still exist by the time formal process concludes.
  3. Document the domestic legal basis for the request in a form that satisfies dual criminality where the requested state requires it. Many refusals occur simply because the requesting state's offence has no clear equivalent under the requested state's law as drafted.
  4. Submit the formal mutual legal assistance request through the applicable channel (a bilateral MLAT, Budapest Convention Article 27 procedure where both states are parties, or the UN Convention's mechanism once it enters into force), specifying precisely which preserved data is sought and the offence to which it relates.
  5. Where the provider is US-incorporated, evaluate a parallel direct request under any applicable CLOUD Act executive agreement, which can produce content evidence materially faster than the mutual assistance channel where both states are party to such an agreement.
  6. Maintain chain of custody documentation across every jurisdictional handoff, together with hash values taken at acquisition, since evidence obtained through a foreign preservation-and-production chain will face admissibility challenges domestically if the custody trail cannot be reconstructed for the trial court.
  7. Where the provider is unreachable through any of the above — commonly true of providers based in non-cooperating states — escalate to diplomatic channels or the 24/7 network's informal state-to-state liaison function, recognizing that this route usually yields intelligence rather than admissible evidence.

Comparative domestic bridges: CFAA, NIS2/GDPR, and PECA

United States: the CFAA and Van Buren v. United States

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, remains the principal federal cybercrime statute in the United States, criminalizing unauthorized access and access that "exceeds authorized access" to a protected computer. The scope of that second phrase was narrowed significantly by the Supreme Court in Van Buren v. United States, 593 U.S. 374 (2021). A police sergeant with lawful database access used his own valid credentials to look up a licence plate for an improper, personal purpose. The Court held that "exceeds authorized access" applies only where a person accesses files, folders, or databases that are off-limits to them altogether — a gates-up-or-down inquiry — and does not criminalize the misuse, for improper motives, of information a person was otherwise entitled to access. The decision materially narrowed the CFAA's reach against insider misuse and remains the central authority any CFAA-based prosecution or defence must address.

European Union: NIS2 and the extraterritorial reach of the GDPR

The EU's Network and Information Security Directive 2 (Directive (EU) 2022/2555, "NIS2") substantially expanded cybersecurity risk-management and incident-reporting obligations across essential and important entities, with a tiered reporting timeline — an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within one month. Separately, the General Data Protection Regulation extends its reach extraterritorially under Article 3 to any controller or processor established outside the EU that offers goods or services to, or monitors the behaviour of, individuals within the EU, backed by administrative fines under Article 83(5) of up to €20 million or 4% of total worldwide annual turnover, whichever is higher. Enforcement against entities with no EU establishment remains practically difficult, but the regime is nonetheless one of the most consequential extraterritorial instruments adjacent to this field.

Pakistan: the Prevention of Electronic Crimes Act, 2016

Pakistan's Prevention of Electronic Crimes Act, 2016 (Act No. XL of 2016) illustrates how a state outside both major treaty frameworks constructs its own jurisdictional and cooperation bridge. Section 1(4) extends the Act to any act committed outside Pakistan by any person, where the act constitutes an offence under the Act and affects a person, property, information system, or data located in Pakistan — a direct statutory codification of objective territoriality, alongside the Act's application to every citizen of Pakistan wherever he may be, which is the active nationality basis.

Section 42 establishes the international cooperation mechanism: the Federal Government may, upon receipt of a request through the designated agency, extend cooperation to a foreign government, a 24/7 network, a foreign agency or an international organization for investigations or proceedings concerning offences related to information systems, electronic communication or data, or for the collection of evidence in electronic form, expedited preservation and disclosure, real-time collection, or interception. The section also provides for a register of requests and grounds on which cooperation may be declined.

The enforcement architecture was substantially restructured by the Prevention of Electronic Crimes (Amendment) Act, 2025, assented to on 30 January 2025. Amendments to sections 29 and 30 replaced the Federal Investigation Agency's Cyber Crime Wing with the National Cyber Crime Investigation Agency (NCCIA), which had first been notified administratively in May 2024 and now holds exclusive investigative powers over PECA offences, headed by a Director General exercising the powers of an Inspector General of Police and empowered to maintain its own forensic laboratory whose reports are admissible in evidence. The same amendment created the Social Media Protection and Regulatory Authority and Social Media Protection Tribunals, and inserted section 26-A criminalizing the intentional dissemination of false information — a provision that has been challenged before the High Courts and criticized by press-freedom bodies as incompatible with Article 19 of the Constitution. Practitioners should note that the constitutional position on section 26-A is live and should verify its current status before relying on it.

Pakistan has not acceded to the Budapest Convention, and has not ratified the UN Convention against Cybercrime, which in any event remains far short of the ratifications needed for entry into force. The practical consequence for a Pakistani prosecutor is that cross-border digital evidence requests proceed through bilateral arrangements and the section 42 mechanism rather than through either multilateral treaty's streamlined channel — a materially slower path than that available to a Budapest Convention state party, and a genuine procedural bottleneck that domestic forensic capacity alone cannot solve. Where the relevant provider is a large US platform, the fastest route in practice is frequently the provider's own emergency-disclosure and preservation channel rather than any treaty mechanism.

Landmark case law analysis

K.U. v. Finland, European Court of Human Rights, 2 December 2008

Facts: An unknown person posted an advertisement on an internet dating site, without the applicant's knowledge, purporting to be placed by the applicant — then a twelve-year-old boy — and describing him in sexually suggestive terms with a link to his contact details. The applicant's father asked the internet service provider to identify the person who posted it; the provider refused, citing Finnish telecommunications confidentiality law, and the domestic courts held that no existing statutory provision compelled disclosure. Held: The European Court of Human Rights found a violation of Article 8 of the European Convention on Human Rights, holding that Finland had failed in its positive obligation to provide a framework capable of identifying and prosecuting the perpetrator of an offence against a child's private life, because its domestic law did not permit disclosure of the poster's identity even for that purpose. Significance: The judgment is the leading European authority establishing that a state's human-rights obligations can require it to legislate affirmatively for identity-disclosure mechanisms against internet intermediaries — reshaping how confidentiality and data-protection law must be balanced against the practical requirements of cybercrime investigation.

Riley v. California, 573 U.S. 373 (2014)

Facts: Consolidated with United States v. Wurie, the case concerned two defendants whose mobile phones were searched without a warrant incident to their arrests, with the resulting digital evidence used to support additional and more serious charges. Held: A unanimous Supreme Court held that the search-incident-to-arrest exception to the Fourth Amendment's warrant requirement does not extend to the digital contents of a cell phone, reasoning that modern phones hold a quantity and quality of personal information categorically different from anything an arrestee might have carried in a physical pocket, and that officers must generally secure a warrant before searching a seized device. Significance: Riley is the foundational US authority establishing that digital devices receive heightened constitutional protection distinct from ordinary physical evidence, and its reasoning has been widely cited internationally as courts elsewhere work out comparable digital-privacy thresholds for device searches.

United States v. Gorshkov and the related Ivanov prosecutions

Facts: In 2000, the FBI ran a sting operation styled as a fictitious computer-security company, "Invita," in Seattle. Two Russian nationals, Vasiliy Gorshkov and Alexey Ivanov, travelled to Seattle believing they were interviewing for jobs and, at the agents' request, demonstrated their capabilities on a computer secretly running keystroke-logging software, which captured the credentials they used to access their own servers in Chelyabinsk, Russia. Following their arrest, and without a warrant, FBI agents used the captured credentials to log into the Russian servers and copy the data held on them; published accounts of the volume copied vary considerably, and court records refer to a very large store of data ultimately at issue. A US search warrant was obtained roughly ten days later, before the agents reviewed the copied material.

Held: In United States v. Gorshkov, No. CR00-550C, 2001 WL 1024026 (W.D. Wash. May 23, 2001), the district court denied suppression on several independent grounds. It held that Gorshkov had no reasonable expectation of privacy in his use of the networked Invita computer, which he did not own and knew could be monitored; that the Fourth Amendment did not apply to the agents' extraterritorial access to and copying of data from computers located in Russia and owned by a non-resident alien, at least until the copied data was transmitted into the United States; that the copying did not amount to a seizure because it did not meaningfully interfere with anyone's possessory interest in the data; and that, in any event, the agents' conduct was reasonable given the risk that confederates in Russia would destroy the evidence. The related prosecution of Ivanov proceeded separately in the District of Connecticut, where the court upheld jurisdiction over conduct committed from Russia on an effects analysis (United States v. Ivanov, 175 F. Supp. 2d 367 (D. Conn. 2001)). Gorshkov was convicted on twenty counts and sentenced to thirty-six months' imprisonment with restitution of nearly USD 700,000.

Significance: The case remains the most cited example of a state conducting a warrantless, unilateral cross-border digital search. It is sometimes loosely associated with Budapest Convention Article 32(b) transborder access, but the association is anachronistic: the operation predates the Convention's November 2001 signature and its 2004 entry into force, and the United States was not exercising treaty authority that did not yet exist. The episode is better understood as an early illustration of exactly the sovereignty concerns — unilateral extraterritorial access to another state's computer systems without its consent — that later shaped both Article 32(b)'s narrow drafting and the persistent objections to it. Russia regarded the operation as an intrusion on its sovereignty and reportedly brought charges against the FBI agent involved.

Frequently asked questions

What is cybercrime and international law, in one sentence?

It is the body of jurisdictional, treaty, and state-responsibility doctrine that determines which state may investigate and prosecute conduct committed through information and communication technology, and when a cyber operation attributable to a state itself becomes an internationally wrongful act.

What is the Budapest Convention on Cybercrime, in summary?

It is the Council of Europe's Convention on Cybercrime, ETS No. 185, in force since 1 July 2004, harmonizing substantive cybercrime offences (Chapter II, Section 1), domestic procedural powers (Chapter II, Section 2) and international cooperation mechanisms including expedited data preservation and a 24/7 network (Chapter III), and open to accession by states outside Europe. Its Second Additional Protocol of 2022 adds direct co-operation with service providers in other parties.

How is jurisdiction established under international law when a cybercrime crosses multiple states?

Any of five traditional bases may apply — territoriality (subjective or objective/effects), active nationality, passive personality, the protective principle, or, exceptionally, universality. Multiple states frequently hold equally valid concurrent jurisdiction, and general international law imposes no binding hierarchy among them; allocation is resolved through consultation (Budapest Convention Article 22(5) expressly requires it), extradition practice, or simply which state secures custody of the offender or the evidence first.

Does PECA apply to a hacker who has never set foot in Pakistan?

Yes, on the face of the statute. Section 1(4) of the Prevention of Electronic Crimes Act, 2016 extends the Act to acts committed outside Pakistan by any person where the act constitutes an offence under the Act and affects a person, property, information system or data located in Pakistan. The prescriptive reach is therefore clear; the practical difficulty is enforcement, since securing the accused requires extradition and securing the evidence requires cooperation under section 42 rather than through a multilateral treaty channel.

What exactly is the attribution problem in international cyber law?

It is the practical and legal difficulty of proving, to the effective control standard articulated in Nicaragua v. United States (1986) and now codified in ARSIWA Article 8, that a state directed a specific cyber operation, as opposed to merely sponsoring, tolerating, or generally coordinating with the group that carried it out. Technical and human-level attribution can often be achieved with confidence while the final legal-attribution layer remains unprovable.

Does the UN Cybercrime Convention replace the Budapest Convention?

No. The two are independently negotiated, coexisting treaties, and a state may in principle be party to both. The UN Convention against Cybercrime — adopted 24 December 2024 and opened for signature in Hanoi on 25–26 October 2025 — has not yet entered into force, pending forty ratifications, of which only a handful had been deposited as of mid 2026.

What is the difference between an MLAT and a 24/7 preservation request?

A mutual legal assistance request is the formal mechanism for actually obtaining evidence and can take many months to execute. A 24/7 preservation request under instruments like Budapest Convention Articles 29 and 35 does not obtain evidence at all — it urgently freezes data in its current state so it survives long enough for the slower formal request to catch up.

Is state-sponsored hacking ever treated as "cyber warfare"?

Only rarely, and only where the operation's consequences are comparable to a kinetic military strike — the consequence-based test favoured by the Tallinn Manual 2.0 experts ordinarily requires physical damage, injury, or death, as with the 2010 Stuxnet operation against Iranian centrifuges. The overwhelming majority of state-linked cyber incidents, including major espionage and financial-theft campaigns, remain governed by ordinary criminal law and peacetime state-responsibility doctrine rather than the law of armed conflict.

Common misconceptions

"Tracing an attack to servers in a country proves that country's government did it." Infrastructure location identifies infrastructure, not an operator's state affiliation — infrastructure is routinely leased or compromised precisely to defeat this inference. State attribution requires meeting the Nicaragua effective-control standard, not mere geographic proximity.

"The overall-control test from Tadić can be used to attribute a hacking group's conduct to its sponsor state." Tadić's lower threshold was developed to classify armed conflicts under humanitarian law, and the ICJ expressly declined to import it into state-responsibility analysis in the 2007 Bosnian Genocide judgment. Only the stricter Nicaragua effective-control standard governs attribution for state-responsibility purposes.

"ARSIWA Article 8 created the effective control test." The sequence runs the other way. The ICJ articulated effective control in Nicaragua in 1986; the International Law Commission drew on that reasoning when it adopted Article 8 in 2001. A judgment cannot construe a text that did not yet exist.

"Article 32(b) of the Budapest Convention lets police search foreign servers whenever they like." It does not. The provision is confined to publicly available data and to data disclosed with the lawful and voluntary consent of a person with authority to disclose it. Anything beyond that requires mutual assistance or the consent of the territorial state.

"Any significant state-linked cyberattack justifies self-defence under Article 51." Self-defence requires an armed attack, a narrower category than a mere use of force, and under the prevailing consequence-based analysis most cyber incidents — including large-scale espionage and data theft — lack the physical destructive consequence needed to cross even the lower use-of-force threshold.

"A prosecutor should send a formal letter rogatory as the first step to preserve foreign digital evidence." By the time a letter rogatory is answered, volatile data is frequently gone. The correct first step is an immediate preservation request, with the formal mutual assistance or letter-rogatory request to follow once the underlying data is safely frozen.

"Signing the UN Cybercrime Convention makes it binding." Signature signals political endorsement and an obligation not to defeat the treaty's object and purpose. Binding force follows ratification, and the Convention itself requires forty ratifications before it enters into force at all.

Conclusion: the race between automated attacks and treaty ratification

Final Key Takeaway

Doctrine in this field has not failed for lack of sophistication. It has failed to keep pace. The effective-control standard was articulated for contra rebels in 1986, not for automated, machine-assisted intrusion tooling that can compromise thousands of systems before any human operator reviews the output. The Budapest Convention's procedural powers were drafted for an era of desktop computers and single-server hosting, not for cloud infrastructure spread across a dozen jurisdictions simultaneously — which is precisely why a Second Additional Protocol became necessary two decades later. The UN Convention against Cybercrime arrives as the first genuinely universal instrument in this field, but it arrives contested, far short of the forty ratifications it needs to enter into force, and already the subject of a sustained human-rights critique that will shape how, and whether, it is implemented. The architecture set out above — the five bases of jurisdiction, the attribution thresholds, the preservation mechanisms — remains the correct starting toolkit. What it increasingly lacks is speed. As automated attacks compress the interval between intrusion and irreversible harm into seconds, the multi-year cycles that produce binding treaties, and the multi-month cycles that produce a single mutual assistance response, are the real frontier this field must now confront.

Primary authorities and further reading

  • Convention on Cybercrime (Budapest Convention), ETS No. 185, opened for signature 23 November 2001, in force 1 July 2004
  • Additional Protocol concerning the criminalisation of acts of a racist and xenophobic nature committed through computer systems, ETS No. 189 (2003); Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence, CETS No. 224 (2022)
  • United Nations Convention against Cybercrime, adopted by General Assembly Resolution 79/243, 24 December 2024; opened for signature, Hanoi, 25–26 October 2025
  • Charter of the United Nations, Articles 2(4) and 51
  • International Law Commission, Articles on Responsibility of States for Internationally Wrongful Acts (2001), Article 8 and commentary
  • African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014, in force 2023); Arab Convention on Combating Information Technology Offences (2010)
  • Michael N. Schmitt (ed.), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations (Cambridge University Press, 2017) — non-binding expert work
  • Prevention of Electronic Crimes Act, 2016 (Act No. XL of 2016), Pakistan — Sections 1(4), 29, 30 and 42; Prevention of Electronic Crimes (Amendment) Act, 2025
  • Computer Fraud and Abuse Act, 18 U.S.C. § 1030 (United States); CLOUD Act (2018)
  • Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2016/679 (GDPR), Articles 3 and 83(5); Regulation (EU) 2023/1543 (e-evidence)
  • The Case of the S.S. "Lotus" (France v. Turkey), 1927 P.C.I.J. (ser. A) No. 10
  • Military and Paramilitary Activities in and against Nicaragua (Nicaragua v. United States of America), Merits, I.C.J. Reports 1986, p. 14
  • Prosecutor v. DuÅ¡ko Tadić, Case No. IT-94-1-A, ICTY Appeals Chamber, 15 July 1999
  • Application of the Convention on the Prevention and Punishment of the Crime of Genocide (Bosnia and Herzegovina v. Serbia and Montenegro), Judgment, I.C.J. Reports 2007, p. 43
  • Corfu Channel (United Kingdom v. Albania), Merits, I.C.J. Reports 1949, p. 4
  • K.U. v. Finland, European Court of Human Rights, Application No. 2872/02, Judgment of 2 December 2008
  • Riley v. California, 573 U.S. 373 (2014)
  • United States v. Gorshkov, No. CR00-550C, 2001 WL 1024026 (W.D. Wash. May 23, 2001); United States v. Ivanov, 175 F. Supp. 2d 367 (D. Conn. 2001)
  • Van Buren v. United States, 593 U.S. 374 (2021)

For connected topics, see our articles on State Jurisdiction in International Law, State Responsibility in International Law, the Principle of Non-Intervention in International Law, the Sources of Public International Law and the ICJ's Top 10 Landmark Decisions.

Read also:
The author is a law graduate with over seven years of legal experience. Through The Law Studies, the author writes on diverse legal topics, combining practical knowledge with comparative insights from Pakistan, the UK, the US, and other common law jurisdictions.