Eswatini National Cybersecurity Strategy (NCS) 2025 since majority of these cybercrimes are financially motivated and incur minimal risk of being caught or identified. There exist two types of cybercrimes namely crimes that can only be executed through the use of ICT devices where the devices are both the target of the crime and the tool for executing the crime (cyber dependent crimes); and traditional crimes whose reach and scale and expanded by the use of ICTs such as computers, computer networks (cyber enabled crimes). An example of cyber dependent crimes includes the deployment of ransomware for launching a specific attack (such as financial gain), whilst an example of cyber enabled crimes include cyber enabled fraud using computers. Similar to other nations across the world, cybercriminals that commit cybercrimes within Eswatini’s jurisdiction might either be based in Eswatini itself, or across the Southern African Development Community (SADC) region, or another part of the world. The Royal Eswatini Police Service has in recent years, been reporting and detecting cybercrime activities, including identifying the perpetrators. However, like other law enforcement forces across the world, the Royal Eswatini Police Service continues to face difficulties in conducting investigations, collecting electronic evidence and prosecuting cybercrimes. These challenges are exacerbated by the sophistication of the cyber-attacks and cross-border nature of the crimes committed. Today, cyber criminals continue to use increasingly sophisticated techniques to commit cybercrimes, and prefer jurisdictions where there is limited investigation and/or reciprocate prosecutorial capabilities. The Royal Eswatini Police Service is currently enhancing its capacity to investigate cybercrimes, and collaboration with other law enforcement agencies from the SADC region and Interpol to pursue and prosecute cyber criminals. Eswatini will continue to face cyber threats perpetuated by cybercriminals in the foreseeable future. The Wannacry ransomware attack of May 2017 was a global cyber-attack launched by cyber criminals which targeted computers running the Microsoft Windows operating system by encrypting data on these systems and demanding ransom payments in Bitcoin crypto currency. That is an example of the sort of attack cybercriminals are capable of executing, and demonstrates how cybercriminals are employing sophisticated techniques like ransomware and threats of distributed denial of service (DDoS) for extortion. In addition to these threats from organised cybercrime gangs, there are on-going threats resulting from common and less sophisticated cybercrimes, which target small organisations or individuals. These cybercrimes are consistent with global trends of increasing numbers of cyber criminals targeting individuals and businesses for financial pay-outs. These include crimes such as ATM fraud, identity theft, etc. Eswatini has drafted the Computer and Cyber Crime Bill, which addresses substantive and procedural provisions on cybercrime, and is awaiting enactment by Parliament before coming into law. Apart from this Bill, no legislation currently exists which specifically addresses cybercrime in Eswatini. 1.2.1.2 Hactivism Eswatini National Cybersecurity Strategy (NCS) 2025 7

Select target paragraph3