ARTICLE : Cybercrime and criminal liability in the digital age : Author: Sumitra Biswas
Cybercrime and Criminal Liability in the Digital Age: Challenges, Regulatory Frameworks, and Jurisdictional Dilemmas
ARTICLE
Abstract
Cybercrime and Criminal Liability in the Digital Age: Challenges, Regulatory Frameworks, and Jurisdictional Dilemmas
The rapid proliferation of digital technologies, cloud computing, and artificial intelligence has reshaped global socio-economic interactions while simultaneously giving rise to sophisticated forms of cybercrime. This paper critically examines the evolution of cybercrime in the digital age and assesses the efficacy of existing legal frameworks in establishing criminal liability. Modern cyber offenses—ranging from data breaches, ransomware attacks, and identity theft to state-sponsored cyber espionage and AI-driven fraud—defy traditional, territorial definitions of criminal law.
This study identifies three core legal challenges
1. The attribution problem: Establishing individual or corporate criminal liability across borderless networks where perpetrators operate behind encrypted and anonymous infrastructure.
2. Jurisdictional friction: Managing conflict between domestic legal codes and transnational digital evidence gathering without compromising sovereign state rights or individual civil liberties.
3. Evolving corporate and intermediary responsibility: Defining the legal duties of tech platforms, cloud providers, and software developers regarding data protection, negligence, and automated decision-making.
Through a comparative analysis of international legal standards—such as the Budapest Convention and national cyber legislation—this paper highlights significant enforcement gaps and systemic delays in mutual legal assistance treaties (MLATs). The research concludes by proposing a modernized framework for criminal liability that incorporates strict data protection standards, streamlined cross-border digital evidence protocols, and adaptive statutory definitions capable of holding both traditional offender networks and automated digital entities accountable
Keywords: Cybercrime, Criminal Liability, Jurisdictional Conflicts, Digital Evidence, Corporate Accountability, Budapest Convention, Cybersecurity Law
Introduction
The rapid convergence of global telecommunication networks, cloud computing infrastructure, and artificial intelligence has fundamentally altered the architecture of modern society. While this digital transformation has catalyzed economic innovation and unprecedented connectivity, it has simultaneously dismantled the traditional physical boundaries that historically delimited human interaction and criminality. The emergence of the cyberspace domain—characterized by anonymity, decentralized systems, and instantaneous global reach—has fostered a sophisticated criminal ecosystem. Offenses that once required physical proximity, such as theft, extortion, and espionage, are now routinely executed remotely, at scale, and with systemic precision. Consequently, the digital age presents a profound challenge to classical criminal jurisprudence, forcing legal systems worldwide to re-examine fundamental concepts of liability, jurisdiction, and evidence gathering.
At the core of this legal dilemma lies the conceptual mismatch between traditional criminal law frameworks and the realities of digital technology. Historically, criminal liability relies on two foundational elements: actus reus (the physical execution of a guilty act) and mens rea (a culpably guilty state of mind), both typically tied to a specific geographical location and identifiable human agent. In cyberspace, however, these doctrines encounter severe operational strain. Modern cyber threats—ranging from sophisticated ransomware networks and decentralized finance (DeFi) exploits to automated, AI-driven phishing schemes—often obscure the link between the perpetrator and the harm caused. Furthermore, the borderless nature of packet-switched networks enables offenders to operate across multiple sovereign jurisdictions simultaneously, exploiting legal asymmetries to evade detection and prosecution.
[Traditional Criminal Law] [The Cyberspace Reality]
· Territorial jurisdiction Borderless, multi-node routes
· Clear actus reus & mens rea Encrypted & automated acts
· Physical evidence trails Volatile digital evidence.
· Direct perpetrator agency Decentralized & AI proxies
The problem is further compounded by the evolving liability of corporate and intermediary actors. In contemporary digital infrastructure, service providers, cloud host platforms, and software vendors function as the primary gatekeepers of cyberspace. Determining the boundaries of criminal negligence, failure-to-prevent liability, and intermediary duty of care when digital systems are weaponized remains a subject of intense statutory and judicial debate. Concurrently, efforts to establish global enforcement standardizations—ranging from the Budapest Convention on Cybercrime to the newly adopted UN Convention against Cybercrime—highlight both the necessity and difficulty of harmonizing cross-border investigation protocols while safeguarding fundamentally recognized rights to privacy and due process.
This study critically analyzes criminal liability within this digital landscape. Section I explores the taxonomy of contemporary cyber offenses, distinguishing between cyber-dependent and cyber-enabled crimes. Section II examines the doctrine of attribution and the evidentiary hurdles associated with identifying digital perpetrators. Section III evaluates jurisdictional conflicts and transnational enforcement mechanisms, such as Mutual Legal Assistance Treaties (MLATs) and global multilateral accords. Finally, Section IV assesses emerging frontiers in criminal responsibility, specifically addressing corporate liability, intermediary accountability, and the legal implications of autonomous digital agents. Ultimately, this paper argues that addressing cybercrime requires moving beyond fragmented domestic amendments toward a cohesive, technology-neutral legal framework capable of balancing state security with individual rights in an interconnected world.
1. Defining Cybercrime & The Digital Threat Landscape
Cybercrime is broadly categorized into two main types :
Cyber-Dependent Crimes: Offenses that can only be committed using computers, computer networks, or information communication technology (ICT).
Examples: Ransomware, DDoS (Distributed Denial of Service) attacks, malware distribution, hacking/unauthorized access.
Cyber-Enabled Crimes: Traditional crimes that are scaled up or facilitated through the use of computers or the internet.
Examples: Financial fraud, identity theft, cyberstalking, online sextortion, child sexual abuse material (CSAM), trafficking.
2. Fundamental Legal Challenges in Determining Liability
A. The Problem of Attribution
Anonymity & Proxy Routing: Tools like VPNs, the Tor network, spoofing, and botnets obscure the true identity and physical location of a perpetrator.
IP vs. Person: Proving that an IP address or machine belonged to or was operated by a specific individual at the time of the crime poses high standards of proof for criminal liability.
B. Jurisdictional & Borderless Issues
Extraterritoriality: Cybercriminals often operate in a different legal jurisdiction than their victims.
o Conflicts of Law: Prosecuting a offender requires extradition treaties, Mutual Legal Assistance Treaties (MLATs), or compliance with frameworks like the Budapest Convention on Cybercrime.
3. Expanding Boundaries of Criminal Liability
C. Evolution of Digital Evidence
Corporate Negligence: Tech platforms, cloud providers, and organizations face legal liability (civil and corporate criminal) if gross negligence in cybersecurity leads to systemic breaches or data leaks.
Director/Officer Duty of Care: Boards and executives can be held personally liable for failure to maintain adequate security controls or failure to report breaches in a timely manner.
B. Intermediary & Platform Liability
Safe Harbor Protections vs. Obligations: Digital intermediaries (social media companies, ISPs) historically enjoyed "safe harbor" protections. However, modern legal frameworks impose strict compliance obligations on platforms to monitor, flag, and remove illegal content (e.g., CSAM, deepfakes, hate speech).
C. Artificial Intelligence & Automated Liability
AI-Enabled Cybercrime: Deepfakes, automated phishing at scale, and AI-driven malware generation challenge existing legal definitions of intent (mens rea) and act (actus reus)
Autonomous:
Determining who holds liability—the developer, deployer, or the user—when an autonomous system carries out or aids a criminal act.
1. Overreach and Suppression of Fundamental Rights
o Threat to Freedom of Speech: Broadly worded statutory provisions against online harassment, "incitement," or offensive content are frequently weaponized by governments to silence political dissidents, journalists, and activists.
Erosion of Privacy Rights: Expanding law enforcement powers to combat cybercrime often entails broad surveillance mandates, bulk data collection, and intrusive search powers that undermine constitutional privacy rights.
Chilling Effect on Security Research: Cybercrime statutes (such as the US Computer Fraud and Abuse Act or similar anti-hacking laws) often penalize "unauthorized access" without clear definitions. As a result, ethical hackers and security researchers who identify vulnerabilities to fix them risk criminal prosecution.
2. Structural Deficiencies in Legal Liability Models
A. The "IP Address $\ neq $ Person" Fallacy
High standards of criminal proof require establishing mens rea (guilty mind) and actus reus (guilty act). In digital prosecution, law enforcement often relies on IP addresses or device IDs. However, IP addresses belong to hardware or connections, not people—spoofing, compromised Wi-Fi networks, and malware can frame innocent users for cybercrimes committed through their devices.
B. Vicarious & Strict Liability Overreach
Chilling Innovation for Intermediaries: Imposing heavy criminal or financial liability on internet service providers (ISPs), cloud platforms, or social media sites forces platforms into aggressive automated censorship to avoid prosecution, removing legitimate user content.
Executive Criminalization: Holding corporate officers personally criminally liable for data breaches creates unfair legal exposure when breaches stem from unprecedented zero-day exploits rather than deliberate negligence.
C. The Encryption Debate ("Backdoor" Vulnerabilities)
Governments pushing for law enforcement access to encrypted evidence often demand "backdoors" or key escrow systems. Legally mandating backdoors undermines end-to-end encryption for everyone, creating systematic security weaknesses that malicious actors can exploit.
3. Jurisdictional & Enforcement Pitfalls
Extraterritorial Overreach: Cybercrime laws often apply extraterritorially, creating jurisdictional conflicts where an act legal in Country A is treated as a severe cybercrime in Country B.
Asymmetry in Enforcement: Because true perpetrators obscure their locations using VPNs, Tor, and proxy chains, law enforcement often ends up prosecuting low-level actors, proxy account holders, or victims whose compromised machines were used in botnets, while major criminal syndicates remain untouched.
1. Cyber-Dependent Crimes ("Pure" Cybercrimes)
Definition: Offenses that can only exist within a digital ecosystem. Without computers, networks, or Information and Communication Technology (ICT), these crimes physically cannot occur.
Role of Technology: The computer system or network acts simultaneously as both the tool used to execute the attack and the target being attacked.
Core Objectives: Intruding into systems, impairing functionality, destroying data, or extorting access.
Key Examples:
Ransomware & Malware: Deploying malicious software to lock systems or encrypt databases until a payout is made.
Hacking / Unauthorized Access: Bypassing security protocols to breach networks or system backends.
Distributed Denial-of-Service (DDoS): Flooding servers with artificial traffic to crash online services or infrastructure.
2. Cyber-Enabled Crimes (Technology-Facilitated Crimes)
Definition: Traditional crimes that exist independent of computers, but are scaled up, accelerated, or expanded in reach using digital tools and the internet.
Role of Technology: Computer networks serve as an enabler or force multiplier, allowing perpetrators to target thousands of victims simultaneously across global jurisdictions.
Core Objectives: Financial theft, interpersonal harm, exploitation, or illegal trade using digital platforms for anonymity and scale.
Key Examples:
Financial Fraud & Phishing: Tricking victims into revealing bank credentials via fake websites or emails (modernized advance-fee fraud).
Financial Fraud & Phishing: Tricking victims into revealing bank credentials via fake websites or emails (modernized advance-fee fraud).
Child Sexual Abuse Material (CSAM) & Trafficking: Utilizing dark web marketplaces or encrypted channels to trade illegal illicit content or illegal contraband.
Cyber Security
The cyber threat environment is intensifying dramatically. Over the years, cyber security has often been intruded and has posed severe threats to sensitive personal data and business srelated information. Cyber Security is mainly aimed to protect the cyber space from attacking, damaging and misusing from industrial spying. The Cyberspace is susceptible of intrinsic attacks, which becomes even hard to be avoide daltogether. Some of them are, innumerable entry points through the internet, Computer Network Defence techniques, tactics and practices largely protectin dividual systems and networks rather than critical operations(missions) and major attacks are aimed at technology outpacing defence. India figures among the topmost internet users, 3rd in number after the USA and China The rate has increased 6 times between 2012-2017 with 44% growth rate. Indiais highly vulnerable to cybercrime along with the USA and is amongst top five states in cyber vulnerability. The NITI Ayog has come up with white paper on cyber security which prescribes the following five causes of cyber disruptions. (Dr VK Saraswat, Cyber security – 2019).
CYBERSPACE: AN ANALYSIS
The preamble of the National Cyber Security policy 2013, defines Cyberspace as a complex environment consisting of interaction s between people, software and services, supported by worldwide distribution of information and communication technology (ICT) devices and networks National Cyber Security Policy-2013) During1990’s modern definition of cyberspace evolved. From internet perspective cyberspace is defined as an interactive tool of online communication. In modern day world cyberspace is depicted as environmental space where in activities like chat room, online games, and websites exist and to which individuals gain access through the Internet. Nowadays the cyber network provides important platform for intellectual discourse, political and other group interactive sessions. The online world comprises networks of linked computers. The Merriam Webster dictionary defines cyberspace as, “the online world of computer networks and especially the interne”. The cyberspace like the physical space comprises (at least), the four sub concepts namely: place, distance, size and route. With the growth in electronic communications, the word “cyberspace” has entered into everyday parlance. Althoug the cyberspace has many things in common with the physical space, such as the concepts of place, distance, size and route, but the cyberspace exibits many novel properties than the 2013physical space. After the land, the Sea the Air and space, the cyberspace has been now officially designated as the fifth dimension of warfare. The USA has already done it and NATO countriE and others have already done it. Cyberspace has got no boundaries. So, if one is in a military space or any other space, things can come from anywhere and go anywhere.
· DATA (PRIVACY AND PROTECTION) Law
In August 2023, the Indian Parliament passed the Digital Personal Data Protection (DPDP) Act, 2023, marking a significant step toward addressing the growing concerns over personal data security. This law, which comes after over six years of deliberation, represent India's first cross-sectoral legislation on data protection. The DPDP Act, 2023 is the culmination of a series of drafts and revisions. The first version of the bill was created by a committee of experts in 2018, followed by the introduction of the Personal Data Protection Bill, 2019. This version underwent significant scrutiny and revisions by a parliamentary committee and was withdrawn by the government in late 2021. A new draft, the Digital Personal Data Protection Bill, 2022, was published in November of that year, which formed the basis of the 2023 Act. Notably, the Act introduces several new provisions and modifies others, particularly in terms of the regulatory framework, the scope of data processing, and the protections afforded to consumers. of the 2019 bill, incorporating a simpler regulatory structure that confers significant discretionary powers to the central government. This paper explores the implications of these changes, considering both their potential benefits and drawbacks. The DPDP Act, 2023, marks India’s first comprehensive data privacy legislation, requiring consent for processing personal data with clearly defined exceptions, and granting consumers rights to access, correct, update, and erase their data, along with provisions for children's data protection. The law imposes obligations on businesses to inform consumers about data collection, adhere to purpose limitations, and implement security safeguards. It also mandates grievance redress mechanisms and empowers the Data Protection Board (DPB) to handle.
complaints and issue penalties for noncompliance. While the law establishes a statutory framework, its success hinges on effectiv implementation and enforcement, particularly whether it targets data-heavy industries or applies across the economy. However, there are concerns about certain provisions that could .
undermine privacy protections. For example, state exemptions for consent in cases like emergencies or wheh a government beneficiary has previously consented to state services could lead to broad data aggregation, undermining privacy. Similarly, the law grants the government sweeping powers to exemp agencies from compliance in the interest of national security, public order, and investigations, potentially creating acategory of state actions beyond privacy constraints. The law also gives the government significant discretion, such as the power to exempt businesses from provisions on children’s data processing without clear guidelines, which could lead to misuse. Furthermore, the DPB, while independent, has a limited mandate and lacks clear mechanisms for impartial decision-making, raising concerns about the separation of powers within the board. While the law mars a significant step forwara in data privacy, its potential to protect privacy depends on careful and transparent implementation by the government. The DPDP Act has evolved significantly from earlier drafts, with reduced rights and obligations compared to the 2018 and 2019 bills, focusing more on data privacy and eliminating criminal penalties in favor of monetary fines. The law also shifts from a regulatory framework with an independent Data Protection Authority (DPA) to a more limited mandate for the DPB. This change reflects a more pragmatic approach, considering issues like data sovereignty, national security, and the lessons learned from the implementation of global data protection frameworks like the GDPR. Despite these shifts, the law retains controversial state exemptions for surveillance agencies, reflecting a long-standing tension between privacy protections and national security concerns. The law’s future success will depend on balancing these competing interests, particularly as the government retains significant discretionary powers that could impact the law’s effectiveness.
CONCLUSION
s India strides into a future dominated by digital innovation, the twin challenges of combating cybercrime and safeguarding privacy have never been more urgent, demanding a transformative approach to both regulation and protection. As India accelerates its digital transformation, the rapid rise of cybercrimes presents significant challenges to both data security and privacy. With nearly every aspect of life—ranging from personal data to commercial transactions—moving online, therisks of cyberattacks, data breaches, and the misuse of sensitive information have grown
exponentially. While the Information Technology Act, 2000, provides some legal provisions, it remains insufficient in addressing the evolving nature of cybercrimes and privacy violations. Current laws fail to cover emerging threats such as phishing, sextortion, and cyberstalking, and penalties for offenses like hacking are often too lenient to act as a deterrent. Many of these offenses are bailable, undermining the law's effectiveness, while the reporting of cybercrimes, particularly crimes against children, remains low. The absence of a dedicated bug reporting mechanism and the lack of specific legal frameworks to tackle certain types of cybercrime leave individuals and organizations exposed to ongoing risks. The need for stronger regulation, coupled with robusprivacy protections, is evident. As India continues to embrace digitalization, prioritizing privacy is crucial. Citizens' personal data must be safeguarded against misuse, and individuals should have the right to control their own information. This calls for comprehensive and stricter legislation that not only addresses the full spectrum of cybercrimes but also ensures that privacy remains a fundamental right. Strengthening penalties for cybercrimes, improving enforcement mechanisms, and expanding legal provisions to cover emerging online threats will be essential steps in protecting both individuals and businesses. Moreover, India must reassess its position on international cooperation, particularly by joining the Budapest Convention on Cybercrime, to align its efforts with global standards and facilitate cross-border collaboration in addressing cyber threats. Finally, privacy protections must be at the heart of India's cybersecurity strategy, with a focus on data minimization, transparency, and accountability in how personal data is collected, processed, and stored. By integrating robust privacy measures into its digital regulatory framework, India can create a secure, resilient, and trustworthy online environment for all its citizens, balancing the need for innovation with the protection of fundamental rights.
