How a new UN cybercrime treaty could be used to crack down on dissent | #cybercrime | #infosec


Imagine this scenario. It’s early evening in a small city in central Turkey. An Iranian woman in her mid-20s walks to the corner café. Headphones in, she listens to Radiohead’s 2 + 2 = 5.

She hasn’t set foot in Iran since she left, nor is she breaking any laws in Turkey. Her only “offence” is a phone full of Instagram videos that criticise Iran’s compulsory hijab laws. Anyone can watch them, including millions of Iranians living under those rules.

Under the newly adopted United Nations Convention against Cybercrime (also called the Hanoi Convention, after the city where it was formally opened for signing), however, Iran may assert a legal right to pursue her for alleged
propaganda against the state”.

That might sound far-fetched. It isn’t. It’s one of the real risks buried in the treaty.

The closer you look, the more it echoes a George Orwell novel. Orwell imagined a world where the watching never stops. This treaty could give that world a legal stamp of approval.

What is this treaty?

The UN General Assembly adopted the Hanoi Convention in December 2024 and then opened it for signing last October.

Seventy-two countries signed it there. The treaty becomes binding once 40 countries ratify it. So far, only three have: Azerbaijan, Qatar and Vietnam. But dozens more countries are working through the process.

Proponents argue the convention is necessary to create a common set of international laws targeting hacking, digital sabotage, fraud and online child sexual exploitation. It would be the first binding global treaty covering cybercrime, with offences handled through states’ domestic laws and cooperation between countries.

Delegates pose for photos at the signing ceremony of the United Nations Convention against Cybercrime in Hanoi on October 25 2025.
Nhac Nguyen/ AFP via Getty Images

As the Australian immigration assistant minister, Matt Thistlethwaite, said in Hanoi last year:

The convention will harmonise cybercrime legislation, strengthen investigation and cooperation, and narrow the operating space for organised crime groups. It will eliminate unintentional safe havens and ensure a global uplift in capability.

Negotiators did include some human rights safeguards. States can technically refuse requests that would violate them.

However, there is a potential issue with the scope of the treaty in Article 2. Each country can define what counts as a “serious” crime – punishable by four years in prison or more – using its own laws.

For democracies, that might mean fraud or hacking. For authoritarian states, it can mean a tweet, Instagram post or a VPN download.

In fact, it was Russia that first proposed this treaty in 2017. Analysts believed its true aim was less about combating cybercrime and more about consolidating state control over information, with reduced external oversight.

The treaty’s vague definition of “serious” crime is made worse by the jurisdiction terms in Article 22.

The language here is mostly based on what’s known as “nationality-based jurisdiction”, which allows states to claim jurisdiction over their own citizens’ conduct abroad. For example, Iran can claim this to pursue its citizens abroad, such as the woman in the cafe allegedly spreading anti-regime propaganda.

Article 22, however, significantly expands jurisdiction to include what’s known as “passive personality jurisdiction”. This allows a country to claim jurisdiction over any supposed crime committed anywhere, by anyone, as long as the victim is one of its nationals.

For example, Russia could assert jurisdiction over an American journalist reporting from the United States who exposes a database leak affecting Russian citizens – not because she is Russian or committed any act in Russia, but simply because the victims are Russians.

How the treaty could further target dissent

These scenarios aren’t far-fetched for the people most exposed.

In April 2024, the Iranian regime launched a campaign to identify and punish women flouting the mandatory hijab law called the Noor Plan. It entailed deploying facial recognition technology at checkpoints and university gates, aerial drones over public squares, CCTV cameras on major roads, and a citizen-reporting app called Nazer.

Since the January 2026 protests against the regime, which left thousands dead, the Islamic republic has also been jailing people for using banned communication tools like Starlink to dodge internet censorship.

Russia’s crackdown on dissent is yet another example. Since the end of 2025, Russian courts have declared the Russian LGBT Network and five other queer collectives “extremist”.

If implemented, the UN cybercrime treaty could potentially allow Russian authorities to go after LGBTQ+ people abroad whose online activity is deemed “extremist” or classify “banned” online searches as serious crimes.

The government could also legally access data on servers outside Russian control. While countries could refuse data requests if the conduct isn’t a crime locally, the treaty encourages cooperation through the “widest measure of mutual legal assistance” in investigations. As such, signatories may feel compelled to share data even for non-criminal conduct.

Where to from here?

There are a number of things states can do to mitigate the potential for misuse of the treaty by countries such as Russia and Iran.

Amendments and protocols are possible once the treaty has been ratified by enough states. They would require the backing of at least 60 states parties and, if there is no consensus, a two-thirds vote to be approved.

Russia is reportedly already working on protocols to expand criminalisation under the treaty – these efforts must be blocked.

Countries that ratify the treaty can also make formal reservations to emphasise the need to respect human rights. And they can bolster their own domestic legal frameworks to ensure cooperation with other states under the treaty does not lead to human rights violations.

This is the final opportunity for the free world to raise objections or set up safeguards before it becomes too late.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW