Every time someone’s private photos are shared without consent, a stalker tracks an ex-partner’s location through spyware, or a hacker steals financial data from thousands of accounts, cybercrime is at work. But what exactly is cybercrime – and why does the answer matter more than it might seem? Defining it is not just a legal formality. Without a clear, shared definition, laws fail, perpetrators go unprosecuted, and victims – disproportionately women – are left without recourse. This post breaks down what cybercrime means, who defines it, and how its categories shape our understanding of digital harm.
Table of Contents
- What is cybercrime?
- Key definitions and perspectives
- Academic perspectives: Gordon, Ford, and the “type” framework
- The UNODC definition
- The Council of Europe: Budapest Convention
- Categories of cybercrime
- Crimes against individuals
- Crimes against property
- Crimes against governments
- Why definitions matter for gender justice
What is cybercrime?
At its most basic, cybercrime refers to any criminal activity that involves a computer, network, or networked device. This covers a staggering range of behaviors – from ransomware attacks and bank fraud to cyberstalking, child exploitation, and state-sponsored espionage. As TechTarget notes, while most cybercriminals are driven by financial gain, some cybercrimes are carried out to damage or disable systems directly, while others use digital tools to spread harmful content or facilitate other crimes entirely.
What makes cybercrime distinct from ordinary crime is not just the presence of technology – it is the way technology transforms the scale, speed, and reach of harmful acts. A stalker who once had to physically follow a victim can now monitor her location, messages, and social connections in real time through spyware. A fraudster no longer needs to be in the same country as their target. The digital dimension removes traditional barriers, making harm easier to commit, harder to trace, and more difficult to prosecute.
Key definitions and perspectives
One of the central challenges in studying and combating cybercrime is that no single, universally accepted definition exists. Different scholars, governments, and international bodies have approached the term in different ways, each emphasizing different aspects of the phenomenon.
Academic perspectives: Gordon, Ford, and the “type” framework
Among the most widely cited academic frameworks is that of Gordon and Ford, who divided cybercrime into two categories. Type I cybercrime is primarily technological in nature – think malware, hacking, and network intrusions. Type II cybercrime involves a stronger human element, encompassing crimes like cyberstalking, online fraud, and grooming. This distinction is useful because it highlights that not all cybercrimes look the same: some exploit software vulnerabilities, while others exploit trust, relationships, and psychological manipulation.
Thomas and Loader, another frequently cited pair of scholars, defined cybercrime broadly as computer-mediated activities that are either illegal or considered illicit by certain parties. Their framing deliberately casts a wider net, acknowledging that legal definitions vary across jurisdictions and that some harmful digital behaviors may not yet be formally criminalized everywhere.
The UNODC definition
The United Nations Office on Drugs and Crime (UNODC) offers a definition that bridges legal and social concerns: cybercrime is an act that violates the law, perpetrated using information and communication technology (ICT) to either target networks, systems, data, websites, and technology – or to facilitate a crime. This “facilitation” clause is crucial. It means that using a smartphone to send threatening messages, or using social media to distribute non-consensual intimate images, qualifies as cybercrime even if the primary harm is interpersonal rather than technical.
The Council of Europe: Budapest Convention
Perhaps the most influential international legal framework on cybercrime is the Council of Europe’s Budapest Convention on Cybercrime, opened for signature in 2001. It was the first international treaty to specifically address crimes committed via the internet and computer networks, covering everything from illegal access and data interference to computer-related fraud, child pornography, and hate crimes. As of 2025, 81 states have ratified the convention, making it the closest thing the world has to a shared global standard on cybercrime law.
The Budapest Convention also introduced a critical conceptual distinction that now shapes cybercrime research and policy worldwide: the difference between cyber-dependent crimes (crimes that can only exist because of digital technology, such as hacking or deploying malware) and cyber-enabled crimes (traditional crimes amplified or facilitated by technology, such as fraud, stalking, or trafficking). This two-pronged model acknowledges that cybercrime is not a single thing – it is a spectrum.
Importantly, even with the Budapest Convention in place, significant gaps remain. As Phillips et al. (2022) note in a structured review of cybercrime definitions, no complete classification framework has yet been developed that satisfies both academic and law enforcement needs. Each existing taxonomy has identifiable gaps, and the scope of cybercrimes continues to outpace the frameworks designed to contain them.
Categories of cybercrime
Although definitions vary, most frameworks agree that cybercrimes can be grouped by who or what they target. This categorical approach – used by both the U.S. Department of Justice and international legal scholars – helps clarify the breadth of digital crime and the very different harms it produces.
Crimes against individuals
This category includes phishing, cyberstalking, identity theft, cyberbullying, online harassment, and the non-consensual sharing of intimate images. These crimes target people directly, often exploiting personal relationships, emotional vulnerabilities, or personal data. UNODC research confirms that cyberstalking and cyberharassment are distinctly gendered crimes – women and girls are significantly more likely to experience them than men and boys.
This is where cybercrime intersects most sharply with gender-based violence. UN Women reports that between 16 and 58 percent of women globally have experienced some form of technology-facilitated violence. In Arab states, that figure rises to 60 percent of women internet users. These are not edge cases – they represent a structural pattern in how digital tools are weaponized against women. UNDP data further shows that 38 percent of women worldwide have directly experienced online abuse, with women aged 18 to 24 facing the highest risk across all forms of cyberviolence.
The Violence Against Women Act Reauthorization Act of 2022 in the United States formally defined “cybercrime against individuals” for the first time in U.S. federal law, as a criminal offense involving a computer used to harass, threaten, stalk, extort, or intimidate an individual – including the non-consensual distribution of intimate images. The inclusion of image-based abuse in this definition was a significant legal milestone, reflecting growing recognition that such acts cause serious psychological harm comparable to physical assault. Research cited by the Centre for International Governance Innovation found that women who had intimate images shared without their consent experienced psychological distress similar to survivors of sexual assault.
Crimes against property
Property-based cybercrime targets financial assets, intellectual property, and digital systems for economic gain. This includes bank fraud, credit card theft, ransomware attacks, phishing scams designed to extract payment credentials, and the theft of proprietary business data. These crimes affect both individuals and organizations. The financial toll is enormous – in 2022 alone, e-commerce globally lost an estimated $41 billion to online payment fraud.
Property crimes also intersect with crimes against individuals in significant ways. Identity theft, for instance, is simultaneously an economic crime and a personal violation. Women, as OCCRP reporting highlights, are more likely than men to have their stolen identities used in non-consensual deepfake pornography – meaning a crime categorized as “property-based” can have deeply personal and gendered consequences.
Crimes against governments
The most serious category involves cyberattacks targeting government institutions, national infrastructure, and public systems. This encompasses cyber espionage, cyberterrorism, attacks on power grids or healthcare networks, and interference in electoral systems. Wikipedia’s overview of cybercrime notes that as early as 2000, the UN Congress on the Prevention of Crime classified government-targeted cybercrimes into five sub-types: unauthorized access, damage to computer data, system sabotage, unauthorized interception of data, and computer espionage.
The World Economic Forum’s 2023 Global Risks Report ranked cybercrime among the top ten risks facing the world both now and over the next decade. When cybercriminals or state actors target governments, the impact ripples outward – disrupting public services, eroding democratic institutions, and undermining the trust that entire societies place in digital systems.
Why definitions matter for gender justice
The debate over how to define cybercrime is not merely academic. How a crime is defined determines whether it can be prosecuted. When cyberstalking is not explicitly included in a country’s cybercrime laws, perpetrators walk free. When image-based abuse is treated as a minor civil matter rather than a criminal offense, survivors are denied justice. When harassment is framed as a “property crime” because it involves data, the personal harm to the individual – often a woman – becomes invisible in the legal framework.
The European Institute for Gender Equality (EIGE) recognized this gap explicitly: the EU’s 2024 Directive on combating violence against women placed a legal obligation on member states to collect statistics on all forms of cyberviolence, including non-consensual sharing of intimate material, cyberstalking, and cyber harassment. This is a structural acknowledgment that definitions shape data, data shapes law, and law shapes lives.
Despite international frameworks like the Budapest Convention, coverage remains uneven. World Bank research found that laws on cyber harassment protect fewer than half of the world’s women population, and only 12 percent are protected by legislation that specifically addresses cyber-sexual harassment. The definition problem, in other words, has real human costs – particularly for those most vulnerable to online violence.
What do you think? Given how differently countries define cybercrime, should there be a binding global legal standard that specifically addresses gender-based digital violence – and what would that take to achieve? And with technology evolving faster than legislation, which emerging forms of cybercrime do you think are most urgently in need of a clear legal definition?
References
- https://www.techtarget.com/searchsecurity/definition/cybercrime
- https://link.springer.com/article/10.1007/s11416-006-0015-z
- https://www.unodc.org/e4j/zh/cybercrime/module-12/key-issues/gender-based-interpersonal-cybercrime.html
- https://www.coe.int/en/web/cybercrime/key-facts
- https://en.wikipedia.org/wiki/Budapest_Convention_on_Cybercrime
- https://www.mdpi.com/2673-6756/2/2/28
- https://www.unwomen.org/en/articles/faqs/digital-abuse-trolling-stalking-and-other-forms-of-technology-facilitated-violence-against-women
- https://www.undp.org/eurasia/blog/cyberviolence-disempowers-women-and-girls-and-threatens-their-fundamental-rights
- https://www.cigionline.org/static/documents/OGBV_AnnotatedBibliography_FINAL.pdf
- https://www.eccu.edu/blog/what-is-cybercrime-types-examples-and-prevention/
- https://www.occrp.org/en/news/report-minorities-and-women-are-more-likely-victims-of-cyber-crime
- https://en.wikipedia.org/wiki/Cybercrime
- https://eige.europa.eu/gender-based-violence/cyber-violence-against-women?language_content_entity=en
- https://blogs.worldbank.org/en/developmenttalk/protecting-women-and-girls-cyber-harassment-global-assessment
Leave a Reply