·The Hindu

Cybercrime and a global governance crisis

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (Last 12–18 Months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas
Practice
5 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

UPSC Prelims + Mains Study Note


1. At a Glance

  • Core issue: A fracture in global multilateral consensus on combating cybercrime — symbolised by the divergent responses to the UN Convention against Cybercrime (2024) versus the older Budapest Convention (2001). [1]
  • India's position: India did not sign the 2024 UN Convention at the Hanoi signing ceremony, alongside the US, Japan, and Canada — signalling a geopolitical fault line in cyberspace governance. [4]
  • UPSC relevance: Spans GS-II (international institutions, India's foreign policy), GS-III (cyber security, internal security), and contemporary IR — a live, high-probability Mains topic for 2025-26.
  • Stakes: The emerging order risks polycentrism — multiple, competing cyber-governance regimes — leaving developing nations with fragmented legal tools against cross-border cybercrime. [4]

2. Why in the News

  • December 2024: UN General Assembly adopted the Convention against Cybercrime — the first multilateral criminal justice instrument in over two decades. [1][2]
  • 2025: The Convention was opened for signature at a formal ceremony hosted in Hanoi, Vietnam. It will enter into force 90 days after ratification by the 40th signatory. [1]
  • January 27, 2026: The Hindu analysis highlighted India's abstention and the fault lines this reveals in global cyber governance. [4]
  • The Convention received support from 72 countries at adoption — a narrow majority among 193 UN members, illustrating contested multilateralism. [4]

3. Background & Evolution

Year Milestone
2001 Budapest Convention on Cybercrime adopted by the Council of Europe — first binding international instrument; dominated by Western/European states. [5]
2017 Russia proposed a UN General Assembly resolution to negotiate a new, universal cybercrime treaty — challenging Budapest's Western-centric framework. [4]
2019 UNGA resolution passed to establish an Ad Hoc Committee to draft the new convention. [3]
2021 UNGA formally approved the terms of negotiation amid concerns over a "rushed" vote. [3]
2019–2024 8 formal sessions + 5 intersessional consultations held involving member states, civil society, and private sector. [4]
December 2024 UNGA adopted the UN Convention against Cybercrime — UN Secretary-General Guterres welcomed it as the first criminal justice treaty in 20+ years. [1][2]
2025 Signing ceremony in Hanoi, Vietnam; India, US, Japan, Canada among major non-signatories. [4]

4. Core Static Facts

UN Convention against Cybercrime (2024)

  • Full name: United Nations Convention against Cybercrime
  • Adopted by: UN General Assembly, December 2024 [1]
  • Proposed by: Russia via a 2017 UNGA resolution [4]
  • Support at adoption: 72 countries [4]
  • Entry into force: 90 days after 40th ratification [1]
  • Signing venue: Hanoi, Vietnam [1]
  • Scope: Online child sexual abuse, online scams, money laundering, electronic evidence [1]
  • Nature: First international criminal justice treaty in over 20 years [1][2]
  • Key supporters: Russia, China (joint advocates for reshaping global cyber governance) [4]
  • Notable non-signatories: India, USA, Japan, Canada [4]

Budapest Convention on Cybercrime (2001)

  • Full name: Convention on Cybercrime (ETS No. 185)
  • Adopted by: Council of Europe, 2001 [5]
  • Nature: Regional (European) in origin; open to non-member states for accession
  • Criticism: Western-centric; does not include major economies like India, Russia, China as parties

India's Domestic Framework

  • Primary law: Information Technology Act, 2000 (IT Act) — covers identity theft, impersonation, harmful content [6]
  • Implementing body: Ministry of Electronics and Information Technology (MeitY) — Cyber Laws Division [7]
  • Coordination body: Indian Cyber Crime Coordination Centre (I4C) — under Ministry of Home Affairs [8]
  • Reporting portal: cybercrime.gov.in — National Cyber Crime Reporting Portal [8]
  • Data agency: National Crime Records Bureau (NCRB) — publishes annual Crime in India report with cybercrime statistics [9]
  • Parent ministry (security): Ministry of Home Affairs (MHA) [6][8]

5. Multi-Dimensional Analysis

Geopolitical / Strategic

  • Russia–China axis jointly pushed the 2024 UN Convention to displace the Budapest Convention's Western primacy — a direct challenge to the liberal international order in cyberspace. [4]
  • India's non-signing reflects strategic ambiguity: India neither endorses the Budapest framework (to which it is not a party) nor the Russia-China-led alternative — a classic strategic autonomy posture. [4]
  • The fracture risks polycentrism — multiple competing cyber-governance regimes — complicating mutual legal assistance in cybercrime investigations for countries like India. [4]
  • INTERPOL welcomed the 2024 Convention, viewing it as a boost to international law enforcement cooperation. [3]

Legal / Constitutional

  • The Budapest Convention remains the operative global standard for 68+ signatory states; its electronic evidence and mutual legal assistance (MLA) provisions are widely implemented. [5]
  • India's IT Act, 2000 covers major cybercrime categories domestically but lacks robust bilateral/multilateral MLA mechanisms for cross-border enforcement — a gap the UN Convention could have addressed. [7]
  • The new UN Convention addresses crimes like child sexual abuse material (CSAM) online and money laundering — areas where India has active domestic legislation (POCSO, PMLA) but limited international legal reach. [8]
  • Civil society groups (including from India) raised concerns over the Convention's potential for misuse to suppress dissent — a significant objection from democratic nations. [4]

Technological / Scientific

  • Modern cybercrime increasingly involves AI-driven attacks — a 2024-25 PIB release specifically flagged AI-driven cybercrime as a rising threat to India's financial system. [10]
  • I4C (Indian Cyber Crime Coordination Centre) uses analytics and inter-agency coordination to counter cybercrime — but its mandate is domestic; cross-border enforcement requires treaty frameworks. [8]
  • The absence of a universally ratified framework means electronic evidence obtained in one country may not be admissible or shareable with another — a direct investigative bottleneck.

Governance / Ethical

  • The multilateral vs. plurilateral tension: the 2024 Convention follows multilateral consensus (UNGA), while Budapest relies on a club-based (European) model — both have legitimacy deficits for different reasons. [4]
  • Civil society and human rights groups warned that the Convention's broad surveillance provisions could be used by authoritarian states to monitor dissidents under the guise of cybercrime enforcement. [4]
  • India's abstention also signals discomfort with both poles — the Russian-led maximalist surveillance approach and the American-led data-localisation resistance. [4]

Economic

  • PIB data confirms Indian citizens face massive losses from cyber fraud — the National Cyber Crime Reporting Portal handles lakhs of complaints annually. [11]
  • Cross-border cybercrime (scam call centres, mule accounts, ransomware gangs) causes measurable economic damage; the absence of enforceable international treaties directly hampers recovery of funds and prosecution. [8]
  • AI-driven financial fraud targeting Indian banking customers was flagged as a growing threat by MHA in 2025. [10]

Administrative

  • I4C under MHA and CERT-In under MeitY represent a split administrative architecture — operational response (MHA) vs. technical/policy (MeitY) — creating coordination needs. [7][8]
  • State police handle cybercrime FIRs but lack capacity and international reach; all cross-border legal assistance routes through the MHA's treaty division — a single-point bottleneck. [6]

6. Recent Developments (Last 12–18 Months)

  • December 2024: UNGA adopted the UN Convention against Cybercrime by consensus of 72 supporting states; UN Secretary-General Guterres called it historic. [1][2]
  • 2025: Signing ceremony hosted in Hanoi, Vietnam; India, US, Japan, Canada did not sign. [1][4]
  • 2025 (PIB): MHA press release highlighted AI-driven cybercrime as a priority threat, outlining new measures to curb financial losses. [10]
  • 2024–25 (PIB): Government announced steps to curb cyber frauds in Digital India — including expansion of cybercrime.gov.in and citizen awareness campaigns. [11]
  • November 2024 (MHA/Rajya Sabha): Government replied to Parliament on steps to deal with cybercrime in a "comprehensive and coordinated manner" — referenced I4C and NCRB data. [8]
  • January 27, 2026: Analysis in The Hindu explicitly linked India's non-signature to the "global governance crisis" and the risk of polycentrism in cyberspace. [4]

7. Prelims Hooks

  1. The UN Convention against Cybercrime was adopted by the UN General Assembly in December 2024 — the first multilateral criminal justice treaty in over 20 years. [1]
  2. The Convention was originally proposed via a 2017 UNGA resolution initiated by Russia. [4]
  3. The Convention opens for signature in Hanoi, Vietnam; enters into force after 40 ratifications. [1]
  4. At adoption, 72 countries supported the Convention — India, USA, Japan, and Canada did not sign. [4]
  5. The Budapest Convention on Cybercrime (2001) was adopted under the Council of Europe — it is NOT a UN instrument. [5]
  6. India's primary domestic cybercrime law is the Information Technology Act, 2000 (administered by MeitY). [7]
  7. The Indian Cyber Crime Coordination Centre (I4C) functions under the Ministry of Home Affairs, not MeitY. [8]
  8. The National Cyber Crime Reporting Portal URL is cybercrime.gov.in, launched as part of I4C. [8]
  9. NCRB (National Crime Records Bureau) is the nodal agency for cybercrime statistics under Crime in India report. [9]
  10. The UN Convention took 8 formal sessions + 5 intersessional consultations to negotiate. [4]
  11. INTERPOL formally welcomed the adoption of the 2024 UN Cybercrime Convention. [3]
  12. The term polycentrism in cyber governance refers to the emergence of multiple competing international regimes with no single dominant framework. [4]
  13. Russia and China collaborated to bring the 2024 UN Cybercrime Convention to fruition as an alternative to the Budapest framework. [4]
  14. The Budapest Convention is criticised for being Western/European-centric; India, Russia, and China are not parties to it. [4][5]
  15. AI-driven cybercrime targeting India's financial sector was flagged by the Ministry of Home Affairs in a 2025 PIB release. [10]

8. Mains Relevance

GS Papers:

  • GS-II: International institutions and treaties; India's foreign policy; bilateral/multilateral groupings
  • GS-III: Cyber security; internal security; challenges to internal security through communication networks
  • GS-IV (marginal): Ethical issues in technology; transparency and governance

Specific syllabus headings:

  • GS-II: "Important International Institutions, agencies and fora — their structure, mandate"
  • GS-III: "Basics of cyber security; money-laundering and its prevention; role of external state and non-state actors in creating challenges to internal security"

Plausible Mains Question Stems:

  1. "The fractures in global cyber governance revealed by the 2024 UN Convention against Cybercrime indicate a widening gulf between multilateral principles and their practice. Examine India's strategic options in this evolving landscape." (GS-II, 250 words)
  2. "India's non-signature of the UN Convention against Cybercrime reflects a broader tension between digital sovereignty and international legal cooperation. Critically analyse." (GS-II/III, 250 words)
  3. "Evaluate the adequacy of India's domestic legal and institutional framework — IT Act 2000, I4C, and CERT-In — in combating the growing menace of cross-border cybercrime." (GS-III, 150 words)

9. Related Topics to Study Next

Topic Connection
Budapest Convention on Cybercrime (2001) The predecessor framework the 2024 treaty seeks to replace; examinable in IR context
Information Technology Act, 2000 & IT Amendment Act, 2008 India's domestic legal spine for cybercrime; Prelims-heavy
CERT-In (Indian Computer Emergency Response Team) Technical arm under MeitY; complements I4C on incident response
Digital Personal Data Protection Act, 2023 Interacts with cyber governance — data protection vs. law enforcement access
Cyber Sovereignty vs. Open Internet Debate Core ideological divide between democratic and authoritarian models of internet governance
India's Stance on Internet Governance (ITU vs. multi-stakeholder model) Same geopolitical fault line as the cybercrime treaty dispute
Money Laundering & FATF The 2024 Convention explicitly addresses cybercrime-linked money laundering; FATF is the parallel financial governance body
INTERPOL's role in cybercrime Operational counterpart to treaty frameworks; India is an INTERPOL member

10. Common Errors / Trap Areas

  1. Budapest Convention ≠ UN instrument: It was adopted by the Council of Europe in 2001, not the UN. Aspirants often confuse it with a UN treaty. India is not a party to it.
  2. I4C under MHA, not MeitY: The Indian Cyber Crime Coordination Centre (I4C) is under the Ministry of Home Affairs. CERT-In (technical response) is under MeitY. Mixing these two is a common slip.
  3. 72 supporters ≠ unanimous adoption: The Convention was supported by 72 countries, not the entire UNGA membership of 193 — do not confuse "adopted" (procedural majority) with "ratified" or "signed by all."
  4. Russia proposed — not Western democracies: The 2024 UN Convention was driven by Russia (2017 resolution); the Budapest Convention was a Western/European effort. The ideological allegiance of each framework is frequently reversed by aspirants.
  5. Entry into force requires 40 ratifications, not signatures: Signing the convention and ratifying it are distinct acts; the 90-day clock starts only after the 40th ratification, not signing.

Sources

  1. 1UN News — "UN General Assembly adopts milestone cybercrime treaty"news.un.org · tier 2
  2. 2UN India — "UN General Assembly adopts landmark convention on cybercrime"india.un.org · tier 2
  3. 3INTERPOL — "INTERPOL welcomes adoption of UN convention against cybercrime"interpol.int · tier 2
  4. 4The Hindu — "Cybercrime and a global governance crisis" (Vivan Sharan & Sukanya Thapliyal, Koan Advisory Group), January 27, 2026thehindu.com · tier 4
  5. 5UN Treaty Collection — Budapest Convention on Cybercrime (Council of Europe, ETS 185, 2001)treaties.un.org · tier 2
  6. 6MHA Lok Sabha Reply on Cybercrimemha.gov.in · tier 1
  7. 7MeitY — Cyber Laws Divisionmeity.gov.in · tier 1
  8. 8PIB — "Steps to Deal with Cyber Crimes in a Comprehensive and Coordinated Manner"pib.gov.in · tier 1
  9. 9NCRB — Crime in India 2022 (cybercrime statistics)ncrb.gov.in · tier 1
  10. 10PIB — "Rise of AI-Driven Cybercrime and Measures to Curb Financial Losses"pib.gov.in · tier 1
  11. 11PIB — "Curbing Cyber Frauds in Digital India"pib.gov.in · tier 1
At the end · practice MCQs
5 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

Also on 27 January

All 27 January articles →