India Just Signed the World's First Global Cybercrime Treaty: A Global Rulebook for a Borderless Crime

Maj. Vineet Kumar & Ms. Muskan Sharma
Maj. Vineet Kumar & Ms. Muskan Sharma
Founder & Global Preisdent, CyberPeace | Research Analyst- Policy & Advocacy, CyberPeace
PUBLISHED ON
Sep 26, 2026
10

On 25 September 2026, at UN Headquarters in New York, External Affairs Minister S. Jaishankar signed the United Nations Convention against Cybercrime on the sidelines of the 81st session of the UN General Assembly, calling it a step that "strengthens international cooperation for a safer digital future."

 The signature places India among the growing list of nations joining what is officially the first comprehensive global treaty dedicated to cybercrime. What Jaishankar's brief statement did not mention is that this same treaty has spent the better part of three years drawing sustained, detailed criticism from human rights organisations, technology companies, and digital rights groups, who argue it risks becoming a tool for surveillance rather than a tool against crime.

A Conversation CyberPeace Has Been Having for Years

For CyberPeace, India’s signature is not an isolated development but the latest chapter in a conversation the organisation has been following since the Convention was still being negotiated.

In December 2024, CyberPeace published its analysis of the emerging UN Convention against Cybercrime, examining its objectives, proposed offences, mechanisms for international cooperation, electronic evidence and its relationship with the Budapest Convention. The analysis also highlighted an important principle embedded in the emerging framework: that stronger cybercrime enforcement must operate alongside due process, privacy and human-rights safeguards.

That conversation continued in October 2025, when CyberPeace published The Digital Leviathan: The UN Cybercrime Treaty and the Future of Global Governance. The piece examined the Convention not merely as a cybercrime instrument, but as part of a larger evolution in global digital governance, particularly around cross-border evidence, international cooperation and the changing architecture of cyber sovereignty.

And in August 2026, CyberPeace returned to the question from the operational side in The World Is Rewriting the Rules Against Cyber-Enabled Transnational Crime. The analysis placed the Convention alongside the wider international response to transnational cyber-enabled crime, including scam networks, financial fraud and increasingly sophisticated criminal ecosystems that operate across multiple jurisdictions.

What the Convention actually is

The treaty's full, formal title is unusually descriptive for a UN instrument: the United Nations Convention against Cybercrime, Strengthening International Cooperation for Combating Certain Crimes Committed by Means of Information and Communications Technology Systems and for the Sharing of Evidence in Electronic Form of Serious Crimes. The UN General Assembly adopted it unanimously on 24 December 2024, following three years of negotiation, and it opened for signature at a ceremony in Hanoi, Vietnam, in October 2025. It will remain open for signature at UN Headquarters through 31 December 2026, and comes into force ninety days after the fortieth country ratifies it.

At its core, the Convention gives signatory states a shared legal framework for two things: preventing and prosecuting offences committed through digital systems, and cooperating across borders when evidence, offenders, or victims of a crime are scattered across multiple jurisdictions, a structural problem that has long frustrated cybercrime investigations. It also includes provisions specifically addressing the recovery of criminal proceeds, adding a financial dimension that lets states cooperate not just on prosecuting offenders but on tracing and reclaiming stolen money that has moved across borders, often through mule accounts and shell transactions designed to outrun any single country's jurisdiction.

Why India signed, in its own words

Jaishankar's public reasoning was concise. Cybercrime, in the government's framing, does not respect national boundaries, and India's own cybercrime caseload, spanning cross-border financial fraud, romance scams, and organised online extortion networks often operating from outside India's borders, has repeatedly run into exactly the jurisdictional walls this Convention is designed to lower. Prof. Triveni Singh, a well known cybercrime expert and former IPS officer, put the practical case plainly: "Cybercrime does not stop at national borders. Criminals can operate from one country and target victims in another. This convention can help countries share evidence and work together faster. For India, stronger international cooperation can make it easier to investigate cross-border cyber fraud and trace stolen money." 

The part the announcement leaves out

Here is where the story gets considerably more complicated than a signing ceremony photo suggests. Since before the Convention's text was even finalised, a wide coalition of digital rights organisations, including the Electronic Frontier Foundation, Human Rights Watch, the Global Network Initiative, and Privacy International, has warned that the treaty's language is dangerously broad, and that its safeguards against misuse are considerably weaker than they need to be.

Cisco, one of the few major technology companies to comment publicly, stated the Convention does not do enough to "sufficiently protect basic human rights." UN Secretary-General António Guterres, notably, has himself urged countries to sign and ratify the Convention while simultaneously calling for its implementation to be "rooted in human rights," a somewhat unusual dual message from the very institution that produced the text, and one that implicitly acknowledges the concerns raised against it.

Where this leaves India

None of this means India's signature was unwarranted. The jurisdictional friction Prof. Triveni Singh described is real and well documented, and a shared international framework for evidence sharing genuinely could accelerate investigations that currently stall for months while agencies wait on slow, bilateral mutual legal assistance requests. India's existing domestic cybercrime coordination architecture is already substantial, spanning I4C, the National Cybercrime Reporting Portal, and newer mechanisms like the Citizen Financial Cyber Fraud Reporting and Management System and the Sahyog platform, and a global treaty that maps onto this existing infrastructure could genuinely close gaps that purely domestic tools cannot reach, particularly in cases where the perpetrator, the server, and the victim all sit in different countries, a pattern that has become close to the default in organised online financial fraud rather than the exception.

But the criticisms levelled at the Convention are not fringe objections; they come from some of the most established digital rights organisations in the world, and they focus specifically on the treaty's most powerful surveillance and cross-border cooperation provisions, the very mechanisms India will now need to operationalise domestically. Signing the Convention is also only the first procedural step; India's obligations under it will not take practical effect until the instrument is ratified domestically, a process that typically allows room for a signatory state to clarify how broadly or narrowly it intends to apply the treaty's more expansive provisions. How India chooses to implement those provisions, whether through the kind of judicial oversight and narrow, offence-specific application human rights groups have called for, or through the broader interpretation the treaty's text technically permits, will likely determine whether this Convention becomes a genuine tool against fraud and organised cybercrime, or a broader instrument whose reach eventually extends well past the digital offences it was signed to address.

References

‍

PUBLISHED ON
Sep 26, 2026
Category
TAGS
No items found.

Related Blogs