Introduction
HIPCAR – Cybercrime/e-Crimes
ability to act when those services are attacked or abused in other ways. But the importance of having the
ability to carry out investigations in order to identify offenders and collect digital evidence goes beyond
consumer protection. The Internet is a global market place and companies can offer services worldwide. If
countries want to create an environment that allows e-commerce to grow, in the long term they need to
ensure that crimes against such businesses do not go unpunished.
As a consequence, dealing with Cybercrime has made it to the top of the agenda in most countries. It is
important to underline that – unlike other topics – it is most likely that this topic will remain a priority for
years given that addressing the issue is not something that can be done only once and forever.
Cybercrime is constantly developing, and legal solutions will need continued adjustments from time to
time.
Reducing the response to technical solutions will most likely not solve the problems. Some of the
technical solutions being implemented as part of anti-cybercrime strategies often include firewalls
(preventing illegal access to computer systems) or encryption (to prevent illegal interception of
communications). But past experience has shown that – in addition to technical solutions – legislative
measures are also needed: an efficient penal legislation criminalising certain forms of computer crime and
cybercrime as well as the existence of related procedural instruments that enable law enforcement to
carry out investigations are essential requirements for the involvement of law-enforcement agencies in
the fight against computer crime and cybercrime. Those countries that do not have adequate legislation in
place risk, first of all, that law enforcement agencies will not be able to support citizens that have become
victims of computer crimes. But even more serious is the fact that the absence of criminalisation of
certain cybercrimes might protect offenders or even motivate them to move illegal activities from abroad
to countries with missing legislation. Preventing “safe havens” from where criminals are able to operate
with impunity has therefore become a key challenge in preventing cybercrime.12 Wherever “safe havens”
do exist, there is a threat that offenders will use them to evade investigation. One well-known example of
this is the “Love Bug” computer worm, developed by a suspect in the Philippines in 2000,13 which infected
millions of computers worldwide.14 Local investigations were hindered by the fact that the development
and spreading of malicious software was not at that time adequately criminalised in the Philippines.15
12
13
14
15
8
This issue was addressed by a number of international organisations. The UN General Assembly Resolution 55/63
points out: “States should ensure that their laws and practice eliminate safe havens for those who criminally misuse
information technologies”. The full text of the Resolution is available at:
www.unodc.org/pdf/crime/a_res_55/res5563e.pdf. The G8 10 Point Action plan highlights: “There must be no safe
havens for those who abuse information technologies”. See below: Understanding Cybercrime: A Guide for
Developing Countries, ITU 2009, Chapter 5.2.
For more information, see http://en.wikipedia.org/wiki/ILOVEYOU; regarding the effect of the worm on Critical
Information Infrastructure Protection, see: Brock, “ILOVEYOU” Computer Virus Highlights Need for Improved Alert
and Coordination Capabilities, 2000.
BBC News, “Police close in on Love Bug culprit”, 06.05.2000.
See for example: CNN, “Love Bug virus raises spectre of cyberterrorism”, 08.05.2000; Chawki, “A Critical Look at the
Regulation of Cybercrime”, www.crime-research.org/articles/Critical/2; Sofaer/Goodman, “Cyber Crime and Security
– The Transnational Dimension” in Sofaer/Goodman, “The Transnational Dimension of Cyber Crime and Terrorism”,
2001, page 10; Goodman/Brenner, The Emerging Consensus on Criminal Conduct in Cyberspace, UCLA Journal of Law
and Technology, Vol. 6, Issue 1; United Nations Conference on Trade and Development, Information Economy Report
2005, UNCTAD/SDTE/ECB/2005/1, 2005, Chapter 6, page 233.
> Model Policy Guidelines & Legislative Text