HomeCybercrime Law › Module 1 · Frameworks

Module 1 · What cybercrime is and the harmonisation frameworks

What this module covers and why it comes first. This module answers three questions the rest of the subject relies on. First it asks what we mean by "cybercrime". Second it asks how committing a crime online changes it. Third it asks how international law tries to bring national cybercrime laws into line through a process called harmonisation. The subject then runs in a fixed order from offences to jurisdiction to investigations to cooperation between states. Everything later assumes the vocabulary and the two treaties introduced here.

How to use this guide. The framed boxes give you a scaffold you can carry straight into an answer. The Debate section sets out the live controversies as two-sided contests and each closes with questions to test your own view. Read the guide once to learn the map and then return to the headings and boxes to revise from. Because the assessment includes a 3000-word research essay the Debate section is the part to mine hardest.

Instruments at a glance

Four instruments recur in this module. Meet them once here and then use the table to revise.

Instrument Key provisions What it does
Budapest Convention on Cybercrime (ETS 185, 2001) Ch I definitions (art 1); Ch II substantive offences (arts 2 to 13), procedural powers (arts 14 to 21), jurisdiction (art 22); Ch III international cooperation (arts 23 to 35) First binding multilateral cybercrime treaty. Harmonises core offences and investigation powers and builds a cooperation regime including a 24/7 contact network (art 35)
First Additional Protocol to the Budapest Convention (2003) Racist and xenophobic acts committed through computer systems Adds content offences that some states including the United States decline on free speech grounds
UN Convention against Cybercrime (2024) Nine chapters including criminalization (offences from art 7), procedural measures, international cooperation and human rights safeguards (arts 6 and 24) First cybercrime treaty adopted under UN auspices. Mirrors the Budapest offences but extends cooperation to any "serious crime"
Criminal Code Act 1995 (Cth), Part 10.7 Computer offences inserted by the Cybercrime Act 2001 (Cth) Australia's core computer-integrity offences. Australia acceded to the Budapest Convention with effect from 1 March 2013

Map of the debate

This module is conceptual so the frame to hold in mind is a set of essay questions rather than an order of analysis. There are four.

  1. Is "cybercrime" a coherent legal category or a label stretched across unrelated conduct.
  2. Are these new crimes or old crimes committed by new means.
  3. Does the world need a new convention. This opens the split between the states behind the Budapest Convention and those behind the UN treaty.
  4. How well does any harmonisation effort score on Clough's three measures of comprehensiveness, protection of rights and representativeness (Clough 2014).

Each returns developed in the Debate section.

The difficulties of defining cybercrime

What this section covers and why it matters. Before you can analyse a cybercrime you need a working definition and the first lesson is that no settled one exists. This section sets out the definitions in use. It gives a three-step test for placing any crime and it explains why the label is contested. The reason matters because how a crime is characterised often decides how it is charged.

Start with the difficulty itself. "Cybercrime" is not a precise legal term. It is used loosely and often for effect. It is not defined the same way twice across the literature (Urbas ch 1).

Two definitions are worth carrying. The first is descriptive and the second is a spectrum. Urbas offers a three-part conception. Cybercrime is conduct proscribed by law that uses digital technologies to commit an offence or is directed at those technologies themselves or is incidental to another crime (Urbas ch 1). The common classification runs along a spectrum. Cyber-dependent crimes can exist only because of computers. Cyber-enabled crimes predate computers but are transformed in scale by them (Gillespie ch 1).

To place any crime on that spectrum ask three questions in order.

A test for placing a crime.

  1. Could this crime exist at all without computers. If not it is cyber-dependent. A distributed denial of service attack floods a website with traffic until it fails and is the standard example.
  2. If it could exist offline has the internet transformed its scale or reach. If so it is cyber-enabled. Fraud is the standard example.
  3. Is the digital part an element of the offence or only evidence of it. Only the first makes the conduct a cybercrime in any strict sense (Gillespie ch 1).

Worked example. A person plots a bank robbery over a messaging app. The messages are evidence rather than part of the offence and as a consequence the robbery is not a cybercrime. Now change the facts. The same person floods the bank's website to extort it. The computer is now both the means and the target and the conduct is cyber-dependent (Gillespie ch 1).

Having placed a crime notice why the label resists a single definition. The boundary between "cybercrime" and "computer crime" is itself contested. Choi treats computer crime as a subset of cybercrime. Others read it the other way because computers are only one form of the wider technologies now in use (Gillespie ch 1). Gordon and Ford go further and would retire the term. They describe cybercrime as a continuum from conduct that is almost entirely technological to conduct that is at its core people-related (Gillespie ch 1).

The instability is partly historical. The same conduct was called computer crime, computer-related crime, digital crime, electronic crime and hi-tech crime before "cybercrime" took hold through fiction after Gibson coined the word "cyberspace" (Urbas ch 1). Sieber's survey shows the field grew in waves from the protection of privacy and economic interests to intellectual property, harmful content, criminal procedure and security. This is why no one definition has ever covered it (Urbas ch 1).

Several writers try to impose order through classification. Two are worth knowing.

  1. Wall sorts offences by type into cyber-trespass, cyber-deception and theft, cyber-pornography and cyber-violence. This captures most cybercrime but strains at the edges because a denial of service attack sits between trespass and damage (Gillespie ch 1).
  2. Sandywell sorts crimes by how far technology changes them into conduct the internet expands, conduct it transforms and conduct it creates outright (Gillespie ch 1).

Each scheme suits a different purpose and none is complete. That is the point to carry into an essay rather than a fixed taxonomy to reproduce.

Consolidation. There is no agreed definition of cybercrime. Use a working one. Say which you are using and defend it. Brenner shows the stakes are practical. Traditional offences including homicide can be committed by computer-related means and this raises whether the law needs new offences or only a longer reach for old ones (Urbas ch 1).

What makes cybercrime different and why enforcement is difficult

What this section covers and why. Even without a tidy definition cybercrime plainly behaves differently from offline crime and each way it differs is also a reason it is difficult to enforce. This section gives you a five-part checklist of those features. Each is tied to a concrete example. It then adds two further difficulties the checklist leaves out.

Clough identifies five features. Read them as a checklist because a strong answer names several rather than seizing on one.

The five features of cybercrime (Clough).

  1. Scale. The number of possible victims and offenders is enormous. Phishing shows it. An offender sends hundreds of thousands of messages knowing a tiny fraction will succeed and a tiny fraction still means thousands of victims (Gillespie ch 1).
  2. Accessibility. The internet reaches offenders and victims who would never have met offline.
  3. Anonymity. It is comparatively easy to mask identity online and often to do so with encryption. An investigator may see the conduct without being able to name the offender.
  4. Portability and transferability. Evidence moves and copies easily and often sits on a server in another country.
  5. Global reach. The conduct, the offender, the victim and the data may each sit in a different state.

Each feature is also an enforcement difficulty and scale is the sharpest. Consider a concrete case.

Worked example. In Operation Ore a single subscriber list produced over 7,000 names in the United Kingdom out of nearly 400,000 worldwide. The forces meant to investigate them began "creaking at the seams" in the phrase Gillespie quotes (Gillespie ch 1). One list produced thousands of suspects and that is what scale does to a police force.

Two difficulties sit outside Clough's list. The first is advancement. This is the speed at which offenders adopt each new technology. Yar traces a shift from an early one-directional form of cybercrime to a later form in which a person's visibility online becomes a source of vulnerability (Gillespie ch 1). The second is underreporting. Victims of hacking or stalking may not know they were targeted and fraud victims may not know where to report or may stay silent from embarrassment (Gillespie ch 1).

Consolidation. Five features plus advancement and underreporting explain why cybercrime is not simply traditional crime moved online. They are also why the later modules turn to jurisdiction, investigatory powers and cooperation between states.

The harmonisation frameworks

What this section covers and why. Because cybercrime crosses borders no state can address it alone and so international law tries to align national laws. That alignment is called harmonisation. This section explains the leading instrument and how Australia gives effect to it and how a newer rival now sits beside it. Two further terms recur. Mutual legal assistance is the formal process by which one state asks another for help to gather evidence. Dual criminality is the requirement that the conduct be a crime in both states before that help is given.

Start with the leading instrument and its shape. The Budapest Convention is the first binding multilateral cybercrime treaty. It harmonises the core offences and the procedural powers to investigate them and its cooperation regime supplements existing mutual assistance arrangements (Budapest Convention; Urbas ch 1).

Its structure is worth holding as a four-part map because later modules draw on each part.

The Budapest Convention at a glance.

  1. Chapter I. Definitions (art 1).
  2. Chapter II. Domestic measures. These are the substantive offences (arts 2 to 13), the procedural powers to investigate them (arts 14 to 21) and jurisdiction (art 22).
  3. Chapter III. International cooperation (arts 23 to 35) including a round-the-clock contact network for urgent cases (art 35).
  4. Chapter IV. Final provisions.

Australia gives effect to the Convention closely. The Cybercrime Act 2001 (Cth) inserted the computer offences now in Part 10.7 of the Criminal Code and drew on a model code developed with the states. Australia acceded to the Convention with effect from 1 March 2013 through the Cybercrime Legislation Amendment Act 2012 (Cth) (Urbas ch 1). Because almost every device now connects to a telecommunications network the Commonwealth's telecommunications power gives that legislation very wide reach (Urbas ch 1).

A newer instrument now sits beside it. The UN Convention against Cybercrime is the first such treaty adopted under UN auspices. Its offences from article 7 track the Budapest offences closely. Its cooperation chapter reaches further to any "serious crime" which means an offence carrying at least four years imprisonment (UN Convention against Cybercrime; Gillespie ch 1).

The two did not arrive by accident. The Budapest Convention became a model well beyond its own membership and shaped Commonwealth model laws and other regional instruments (Gillespie ch 1). Its limits were an ageing text and a drafting table that excluded major powers. Those limits drove the push for a treaty under UN auspices which Russia and China favoured and Western states resisted for fear it would legitimise tighter state control of the internet (Gillespie ch 1). The result was adopted in 2024. It mirrors the Budapest offences but reaches further in cooperation and this is why the two now coexist (UN Convention against Cybercrime; Gillespie ch 1).

To compare them in an answer run the same six axes down both.

Budapest Convention and UN Convention compared

Axis Budapest Convention (2001) UN Convention against Cybercrime (2024)
Sponsor and drafters Council of Europe, drafted with observer states including the United States United Nations, process initiated by a proposal from Russia
Status In force since 2004 with parties well beyond Europe Adopted by the General Assembly in December 2024
Offences Core computer offences in arts 2 to 13, forgery, fraud, child pornography and copyright Comparable offences from art 7 with additional content offences
Procedural powers Preservation, production, search and seizure, real-time collection and interception (arts 14 to 21) Similar domestic powers with wider provision for electronic evidence
International cooperation Cooperation for offences within the treaty plus a 24/7 network (art 35) Cooperation extends to any serious crime whether or not technology is involved
Human rights safeguards General reference to conditions and safeguards in domestic law Articles 6 and 24 provide safeguards criticised by rights groups as weak

Consolidation. One treaty is older and narrower and widely modelled. The other is newer and broader in cooperation and contested on rights. The offences are close. The difference lies in scope and safeguards.

Common confusions

These are the errors that cost marks. Each states the mistake and then the correction.

Confusion. "Computer crime" and "cybercrime" are settled terms. They are not. Which is the subset of which is genuinely disputed and so any single definition is a position to be argued rather than a given (Gillespie ch 1; Urbas ch 1).
Confusion. The cyber-dependent and cyber-enabled line is watertight. It is not. In the conjoined environment most crimes carry a digital element and so the line marks a spectrum rather than two sealed boxes (Gillespie ch 1).
Confusion. The Budapest Convention covers all cybercrime. It does not. It omits cyberterrorism, child grooming, cyberstalking and bullying, and spam. Its text also predates much modern offending (Urbas ch 1).
Confusion. The UN Convention replaces the Budapest Convention. It does not. The two coexist and their offences mirror each other. The live difference lies in the scope of cooperation and the strength of safeguards rather than in the core offences (Gillespie ch 1; UN Convention against Cybercrime).

Debate

This is the centre of gravity for the research essay. Each strand is a two-sided contest with the leading voices named and each closes with questions to test a position rather than settle it.

Is "cybercrime" a useful legal category? Gordon and Ford would retire the term because the conduct it gathers has little in common beyond some link to cyberspace (Gillespie ch 1). Against that a definition is what lets cybercrime be counted and compared across countries and tracked over time (Payne, in Gillespie ch 1). Gillespie takes a middle position. He would keep the word and abandon the rigid categories because online fraud need not be defined differently from offline fraud even where it must be investigated differently (Gillespie ch 1). The practical test is whether the label ever changes an outcome. If online fraud is still fraud and online stalking is still stalking the word may matter less for charging a defendant than for how the conduct is investigated and counted.

New crimes or old crimes by new means? Grabosky argues virtual criminality is basically the terrestrial crime we already know and differs in medium rather than in kind (Urbas ch 1). Brenner shows the same traditional offences including homicide can be committed by remote and computer-related means and this raises whether existing law reaches the "remote perpetrator" (Urbas ch 1). The disagreement is not merely academic because it decides whether a legislature should draft fresh offences or trust the ones it has. Where the medium is the only novelty the stronger case may be for new procedure and longer reach rather than new crimes. This theme returns in the investigation and jurisdiction modules.

Does the world need a new convention? The states behind the Budapest Convention argue it already supplies workable minimum standards and so a second treaty risks duplicated effort and weaker norms (Gillespie ch 1). Russia and China were not part of the Budapest drafting and pressed for a treaty under UN auspices where they would hold a seat (Gillespie ch 1). Western governments feared such a treaty could legitimise authoritarian control of the internet (Sukumar and Basu, in Gillespie ch 1). Underlying the dispute is a contest over who sets the global standard. A UN treaty carries broader legitimacy but breadth can dilute norms and can give cover to states that would use cooperation for repression.

How well does harmonisation actually work? Clough measures the Budapest Convention against three standards. He asks whether it is comprehensive and whether it protects rights and whether it is representative (Clough 2014). Each is a fault line. Comprehensiveness is limited by the offences the treaty omits. Rights protection depends on domestic safeguards that vary widely. Representativeness is the weakness the UN process was meant to cure and the one critics say it has deepened. The three also pull against each other. A treaty wide enough to be comprehensive may be too vague to protect rights and one representative enough to satisfy every state may agree only on a thin core.

The human rights critique of the UN Convention. Human Rights Watch and ARTICLE 19 argue the UN Convention is primed for abuse. It compels cross-border collection and sharing of data for any serious crime including conduct that some states criminalise in breach of human rights and its safeguards in articles 6 and 24 are weak (Human Rights Watch; ARTICLE 19). The sharpest concern is that a "serious crime" is fixed by a four-year penalty that a state can set for itself. One country's abusive law could then enlist another country's help to gather evidence. Supporters answer that it is the first genuinely global cooperation framework and that a shared instrument serves a borderless problem better than none. This strand pairs with Module 8 on encryption and Module 10 on cross-border access.

Discussion prompts

  1. Gillespie treats the boundary between "cybercrime" and "computer crime" as unsettled. Set out the competing definitions and argue for the one you find most defensible.
  2. Identify the features that make an online offence behave differently from its offline counterpart and explain which of them matters most for the criminal law.
  3. Choose two of Clough's five characteristics and show how each becomes a concrete difficulty for investigators and prosecutors.
  4. Explain the main obstacles to international cooperation on cybercrime and assess which is most difficult to resolve through a treaty.
  5. Evaluate the claim that the world needed a new cybercrime convention and draw on the reasons states gave for and against a UN instrument.
  6. Compare the Budapest Convention and the UN Convention against Cybercrime on scope, cooperation and human rights safeguards and say which model you would defend.

Check your understanding

Auto-marked drills. Answer, then read the authority in the feedback.