A landmark United Nations Convention against Cybercrime opened for signature on 25 and 26 October 2025
The United States was notably absent from the list of signatories due to opposition from human rights advocates and the technology sector.
During a high-level conference and ceremony hosted by the Government of Viet Nam in Hanoi. A total of 72 states signed the treaty over the two days, marking a significant milestone in global efforts to combat digital crime.
The event drew senior officials, diplomats, and experts, underscoring multilateral commitment to addressing cyber threats. Notable signatories included the United Kingdom, the European Union, China, Russia, Brazil, Nigeria, and dozens of other nations from across regions.
A spokesperson for the US State Department confirmed that the country did not sign the convention and is continuing to review its provisions. This decision highlights ongoing concerns about the treaty’s implications for privacy, human rights, and international cooperation.
The convention will enter into force 90 days after ratification by the 40th signatory, with each state following its domestic procedures. It remains open for signature at UN Headquarters in New York until 31 December 2026. Implementation will be overseen by a Conference of the States Parties, supported by UNODC’s technical assistance and training programmes.
Statements From UN Officials
UN Secretary-General António Guterres addressed the ceremony, describing cyberspace as “fertile ground for criminals” that enables fraud, livelihood theft, and the drainage of billions from economies. He praised the convention as “a powerful, legally binding instrument to strengthen our collective defences against cybercrime,” emphasising its role in multilateralism and the need for swift ratification, particularly in developing countries.
Guterres also highlighted illicit financial flows via cryptocurrencies funding drug, arms, and terror trafficking, as well as ransomware disruptions to businesses, hospitals, and airports.
UN Office on Drugs and Crime (UNODC) Executive Director Ghada Waly described cybercrime as transforming organised crime, necessitating global coordination. She called the convention a “vital tool” to ensure “a safer digital world for all,” with a focus on capacity-building for the Global South. UN estimates place annual global cybercrime costs at $10.5 trillion.
Key Provisions Of The Convention
Adopted by the UN General Assembly on 24 December 2024, the convention is the first comprehensive global treaty on cybercrime. It criminalises cyber-dependent offences like ransomware and financial fraud, as well as cyber-enabled crimes such as terrorism, human trafficking, money laundering, and drug smuggling. Unique features include recognising non-consensual dissemination of intimate images as an offence and establishing the first global framework for collecting, sharing, and using electronic evidence in serious crimes.
It creates a 24/7 international cooperation network for rapid responses and promotes capacity-building, especially in developing nations.
Criticisms & Concerns
The convention has faced substantial criticism from the technology sector and human rights advocates. Tech industry representatives warn that it may criminalize legitimate cybersecurity research and subject companies to complex, legally risky data requests.
Human rights groups, including Access Now, argue it mandates broad electronic surveillance for non-digital crimes, potentially enabling authoritarian regimes to target critics, protesters, or dissidents extraterritorially. Concerns also centre on inadequate data protection safeguards for monitoring, storage, and cross-border information sharing, risking the erosion of digital freedoms and justifying “cyber authoritarianism.”
In a detailed expert comment, Craig Watt, Threat Intelligence Consultant at Quorum Cyber, offered the following analysis on the factors influencing U.S. deliberations over the treaty.
“Behind the scenes, several key issues appear to be shaping the U.S. position: how the treaty’s provisions align with existing U.S. legal frameworks, data-protection standards, and requirements for due process. There is also an emphasis on ensuring that mechanisms for international cooperation are compatible with domestic oversight and constitutional protections.”
“The breadth of the treaty’s provisions on information-sharing and investigative cooperation could be interpreted differently by signatories, depending on national legal systems. From Washington’s point of view, the calculus may be: we cannot sign until we are confident these risks are managed – either through amendments, bilateral safeguards, or strong implementation rules.”
Concerning the implications of U.S. non-signature Watt observed that “The absence of a U.S. signature does not preclude future participation. They could decide to accede later, upon completion of the legal and policy review. In the meantime, Washington continues to cooperate with partners through existing bilateral and multilateral channels, such as the Budapest Convention and regional cyber-crime frameworks.”
Watt continued, “From a policy perspective, U.S. participation in the treaty could provide additional avenues to influence the development of international standards for digital evidence sharing and cross-border cybercrime investigations. However, proceeding without further clarification of key provisions could raise operational and jurisdictional considerations, particularly regarding control over data hosted on U.S. soil.”
The decision underscores the importance of continued engagement in multilateral discussions to ensure that evolving frameworks remain consistent with U.S. legal processes and broader strategic objectives.”
When asked what message the US refusal to engage is sending to its allies and other partners partners who have already signed the treaty, Watt said “The decision not to join the treaty at this stage presents a nuanced signal to the international community. It may reflect a deliberate and cautious approach to ensuring that future commitments align with established legal and operational frameworks. At the same time, some allies may view the decision as an indication of U.S. reservations about emerging global cyber governance initiatives.”
Watt suggests a number of key developments to monitor moving forward:
- Will the U.S. move from ‘review’ to ‘intend to sign’ or ‘intend to accede’?
- How will the U.S. engage with partners who signed without U.S. involvement – will Washington construct parallel frameworks or bilateral hook-ins?
- Will U.S. firms and tech jurisdictions press the U.S. government to engage to avoid being boxed out of the emerging global cyber-cooperation efforts?
“Washington’s decision not to sign the UN Cybercrime Treaty at this time reflects a careful assessment of its broader implications for data governance, jurisdiction, and international cooperation. Continued engagement in multilateral discussions will be important to ensure that any future framework strengthens cross-border cooperation and enhances trust in the global digital ecosystem.” Watt concludes. 
Image: Ideogram
Source: Cyber Security Intelligence