For years, we have repeated that cybercrime knows no borders. Now, the United States has decided to use those very borders to combat it.
Secretary of State Marco Rubio recently announced a policy that will allow visas to be denied or revoked for foreign nationals deemed responsible for or complicit in cybercrime and digitally enabled crime.
The US decision is notable because it broadens the range of tools available to tackle cybercrime. Until now, the international response has relied primarily on police investigations, arrest warrants, extraditions, economic sanctions, asset freezes and judicial cooperation. Visa restrictions add another tool: the state’s ability to prevent those responsible for these networks, or those who finance or facilitate them, from entering its territory.
The message is unequivocal. Someone involved in an organisation dedicated to digital fraud may avoid arrest while protected in a country that refuses to cooperate, but their international mobility can still be restricted. In a world where the leaders of criminal organisations travel, invest, maintain business relationships or send their children to study abroad, an entry ban may have a greater deterrent effect than might initially appear.
The cybercrime ecosystem
The policy also reflects a significant shift in how cybercrime is understood. Digital fraud is no longer treated as a collection of individual scams committed by isolated offenders. Many campaigns are run by fully-fledged transnational organisations with a specialised division of labour: some people obtain personal data, others build profiles of victims, others develop technological tools and still others launder the proceeds through cryptocurrencies, shell companies or bank accounts opened by intermediaries.
Even the word “accomplice” is particularly significant here. The criminal ecosystem is not sustained solely by the person who sends the fraudulent message. It needs infrastructure providers, recruiters, account holders, buyers of credentials, platform operators, money launderers and people in positions of authority who tolerate or protect certain activities. Pursuing only the person who directly carries out the offence is unlikely to be effective against a threat of this scale.
The measure’s legal limits
However, the breadth of the concept itself raises legal questions that cannot be ignored. What does it mean to be an “accomplice” to cybercrime for immigration purposes? Will conscious involvement have to be established? Will it be enough to have provided services that were subsequently used by a criminal organisation? What standard of evidence will be required to impose the restriction?
These questions are particularly important because immigration measures can be adopted without the safeguards of criminal proceedings. Denying a visa is not legally equivalent to imposing a criminal conviction, but it can publicly or implicitly cast a person as criminally responsible. The risk is that a tool designed to overcome the difficulties of criminal prosecution may end up improperly replacing the judicial process.
Attributing responsibility in cyberspace is also extraordinarily complex. The more serious the consequences of an attribution, therefore, the more rigorous the verification of the information on which it is based must be.
The possible extension of these restrictions to immediate family members is even more controversial. The rationale is understandable when those relatives act as nominees, manage illicit assets or participate in structures used to conceal the proceeds. But a family relationship alone should not create a presumption of complicity. Responsibility is personal, and state measures must be based on each individual’s conduct, not on kinship. Otherwise, a preventive measure may come dangerously close to an unjust form of guilt by association.
International cooperation and safeguards
The new policy could prove useful if it forms part of a broader strategy with robust safeguards. Mobility restrictions can raise the cost of cybercrime, but they do not replace the need to investigate, preserve digital evidence, identify those responsible, recover assets and provide redress to victims. Nor can they replace international cooperation, which is increasingly important in efforts to dismantle criminal infrastructure.
Europe should watch this initiative closely. The Schengen Area could adopt coordinated mechanisms to prevent the entry of people credibly linked to major cybercrime networks. But any such measure would need to be accompanied by common criteria, review procedures, reliable information-sharing and safeguards against mistaken identity or insufficiently substantiated attribution.
The idea of using visa restrictions to combat cybercrime has merit. It shows that cybersecurity policy should not be limited to deploying better defensive systems: it must also target the incentives, profits and freedom of movement of those who sustain the criminal economy.
But its legitimacy will depend on how it is applied. Taking a firm stance against cybercriminals does not require safeguards to be abandoned; on the contrary, it requires them to be strengthened. In cyberspace, where it is as easy to conceal one’s identity as it is to misattribute it to someone else, effectiveness and the rule of law are not opposing goals. They are the two conditions required for a truly just response.
Click Here For The Original Source.
