The adoption by consensus of the UN Convention against Cybercrime at the General Assembly in October 2025, and its subsequent signing in Hanoi by 75 member states, was a significant milestone that was by no means inevitable. The convention’s development phase was characterized by a lack of common understanding or shared vision. Even before the more recent geopolitical division emerged, there was a clear and deep divide between those who were pushing for the convention – mainly Russia and China – and those in the West who opposed it. These divisions were clear throughout all the negotiations on the convention but were eventually overcome. Indeed, the convention already has its first parties: Qatar, which acceded in February 2026, and Azerbaijan and Vietnam, which adopted it in April.

The need for a universally accepted global framework for combating cybercrime was urgent. Cyber-related crimes continue to expand in scale, complexity and geographic distribution, affecting both source and target countries. However, the current legal frameworks are not being implemented effectively enough to reduce cybercriminal activity, and capacity is weak in many jurisdictions. INTERPOL estimates that the total value lost to cybercrime yearly rivals the GDPs of major economies.

The term ‘cybercrime’ encompasses activities that range from financially motivated scams and ransomware attacks to cyber-enabled trafficking and illicit online marketplaces. These activities are often interconnected, with proceeds from one form of criminal activity being reinvested into others. The resulting ecosystem is not only transnational but also highly adaptive, making it increasingly difficult for states to respond through isolated or purely domestic measures.

The cybercrime convention represents an international effort, under the auspices of the UN, to establish a global baseline for the criminalization of cybercrime and the facilitation of cross-border cooperation. It is designed to complement existing regional instruments, such as the Budapest Convention on Cybercrime, which was created by the Council of Europe in 2001 (and has been in force since 2004). The Budapest convention is aimed at addressing internet and computer-related crime and has served as a foundational framework for international cooperation among its signatories. However, its reach remains limited because of uneven adoption and varying levels of engagement by states.

The Hanoi convention faces similar challenges. Since its initiation by Russia, it has been the subject of intense negotiations due to disagreements over many issues, including even its title, and has followed an unpredictable and fraught trajectory. In effect, the convention represents a compromise between the varied positions held by different states during the negotiations and has been both criticized and supported by non-governmental players.

This policy brief explores the opportunities and challenges of this convention. It examines the polarized views that characterized the negotiations and the various perspectives of the stakeholders involved in the convention’s development and eventual implementation. It also outlines issues that need to be addressed if the convention is to work effectively, including how to translate its provisions into practice, and how to include diverse stakeholders in its implementation. It concludes by highlighting the importance of trust building on various levels – among practitioners, between sectors, and between different regional and political groupings. The complex range of issues and sensitivities will not be solved through narrow or closed engagement; a broad range of stakeholders are recognized in the convention itself and must be part of the solution as it moves towards implementation.