The United Nations Convention against Cybercrime has drawn broad international signatures but remains far from taking effect, with more than 70 states signing the treaty while only Qatar, Azerbaijan, and Vietnam had ratified it by mid-2026. Adopted by the UN General Assembly in late 2024 and opened for signature in Hanoi in 2025, the convention requires 40 ratifications to enter into force. Debate has shifted from adoption to implementation, with governments and civil society focusing on the treaty’s human rights safeguards, its broad application to "serious" offenses, and unresolved rules for participation in the future Conference of States Parties.
Canada’s unexpected decision to sign has intensified criticism from rights advocates, who warn the convention could operate as a cross-border surveillance and electronic evidence-sharing framework with significant extraterritorial reach. Critics say the treaty could expose journalists, whistleblowers, security researchers, and platform accountability researchers to greater risk, while potentially legitimizing the sharing of spyware-derived data through opaque cooperation channels. The United States has not signed and has indicated it is unlikely to do so until there is evidence that participating states are implementing the convention’s legal and human rights protections.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
The Canadian government announced earlier in July 2026 that it had signed the United Nations Convention against Cybercrime. The announcement prompted criticism from Citizen Lab senior research associate Kate Robertson.
A special treaty event in Abu Dhabi created another opportunity for states to sign or ratify the Convention. The event produced no reported surge in ratifications.
From January 26 to 30, 2026, the Ad Hoc Committee met to draft Rules of Procedure for the future Conference of States Parties. It failed to reach consensus on participation roles for civil society, the private sector, academia, and technical experts.
As of mid-2026, only Qatar, Azerbaijan, and Vietnam had ratified the Convention, far short of the 40 ratifications required for entry into force.
The Convention opened for signature at a ceremony in Hanoi, where 71 states and the European Union signed. Russia, China, Iran, and the European Union were among the signatories, while the United States did not sign.
The United Nations Convention against Cybercrime was adopted by consensus by the UN General Assembly. The United States joined the consensus for adoption but did not commit to signing afterward.
The Convention originated from a 2019 Russian push to create a UN-negotiated alternative to the Council of Europe’s Budapest Convention on Cybercrime.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcecybercenter.space
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.