Cybercrime Conviction Rates Across Jurisdictions
Most cybercrime complaints never reach prosecution, even in well-resourced jurisdictions.

There is a version of this story that flatters everyone involved. Governments pass cybercrime laws. Agencies make arrests. Courts record convictions. Numbers go up. Everyone nods.
Here is the version that is actually true: the volume of cybercrime has outrun enforcement capacity in every jurisdiction on earth, and the gap between what gets reported and what results in a conviction is, in most places, enormous. The FBI's IC3 crossed one million complaints in a single year for the first time ever, with reported losses reaching $20.87 billion. The year before that, it logged 859,532 complaints and $16.6 billion in losses. Global cybercrime costs are projected to hit $10.29 trillion in 2025, climbing toward $16 trillion by 2029.
High volume produces complaints, not convictions. Enforcement machinery has failed to scale with crime volume anywhere in the world. And here is the part worth sitting with: the same offence, committed the same way, produces radically different legal outcomes depending entirely on where it is investigated. That divergence is structural. And the rest of this piece explains exactly why.
Why Legal Architecture Alone Does Not Determine Whether Prosecutions Succeed
Where cybercrime is concerned, the existence of a law almost never guarantees enforcement follows.
Four structural variables interact in every jurisdiction:
Legislation. Does the law actually cover the offence as it is currently being committed?
Cross-border cooperation mechanisms. Can investigators share evidence across national lines fast enough to matter?
Investigative capacity. Does the agency doing the investigating have the tools, training, and staffing to build a prosecutable case?
Prosecutorial resource. Does the office bringing charges have the bandwidth and expertise to see it through court?
All four have to work together. When one fails, the others cannot fully compensate.
The Budapest Convention is the clearest benchmark for international cooperation. Which countries have ratified it shapes what cross-border evidence sharing looks like in practice. For countries outside that framework, the standard fallback is a Mutual Legal Assistance Treaty (MLAT). MLATs work. They are also slow. Digital evidence is volatile. The math on that combination is not encouraging.
Then there is the extradition problem. The United States, the United Kingdom, and most of Europe have no extradition treaties with Russia, China, and a number of other states where major threat actors operate freely. This is a permanent structural feature of the international system. Indictments without arrests are a design outcome.
Keep these four variables in mind. Every country section below is really just a different version of the same question: which of these four failed, by how much, and what did that produce?
The United States: An Enormous Prosecution Gap Despite Substantial Federal Machinery
The United States has the FBI, the DOJ, the Secret Service, and a federal court system with genuine expertise in complex cybercrime cases. It has dedicated units, established doctrine, and a track record of building sophisticated prosecutions. It also has a prosecution gap that is, frankly, staggering.
Between 2014 and 2021, roughly 2,590 individuals were federally sentenced for offences involving hacking, cryptocurrency, or dark-web activity. That works out to about 323 federal sentences per year, per the US Sentencing Commission's September 2024 report.
Now set that against what the FBI was receiving during the same period. Between 2020 and 2024 alone, the IC3 took in nearly 4.2 million complaints, with losses totalling more than $50 billion. In 2024, cryptocurrency complaints alone accounted for nearly 150,000 complaints and more than $9.3 billion in losses. A category that has more than doubled in three years, and federal courts are still building doctrine to handle it.
When prosecution does work, it looks like this:
Deniss Zolotarjovs, tied to Conti, Karakurt, and Royal ransomware groups, sentenced to 8.5 years after extradition from Georgia.
Noah Urban of Scattered Spider, sentenced to 10 years and ordered to repay $13 million.
Two cybersecurity professionals sentenced to four years each for deploying ALPHV/BlackCat ransomware.
These convictions represent genuine investigative and prosecutorial effort, yet they remain a very small number relative to the complaint volume.
Then there is Maksim Yakubets of Evil Corp. Indicted in 2019. A $5 million reward attached to his name. Believed to remain in Moscow. The group continued operations after the indictment. The indictment itself is, practically speaking, symbolic.
That is the US pattern in two sentences: credible prosecution machinery, a persistent indictment-without-arrest problem for the highest-value targets. The tools exist, but geography limits their reach.
The United Kingdom: High Conviction Rates Where Cases Reach Court, But a Counting Problem Underneath
The UK's conviction numbers look excellent on the surface. The Crown Prosecution Service recorded an overall conviction rate of 83.1% in 2024/25. For fraud and forgery, which is where most cybercrime-adjacent cases land in the statistics, the CPS prosecuted more than 25,000 defendants between April 2021 and December 2024 and secured more than 21,700 convictions. The fraud conviction rate rose to 85.3% in FY 2023/24 and held at 85.4% through the first three quarters of FY 2024/25.
Operation Venetic is the proof-of-concept case. More than 2,400 convictions between 2021 and 2025, produced through coordinated work between the CPS and the National Crime Agency. Over £450 million recovered through confiscation orders in the five years to 2024, with £88 million returned directly to victims.
All of that is real, and a significant limitation sits beneath it.
"Cybercrime" is absent as a discrete category from official UK statistics. The ONS does not produce conviction data specific to cybercrime offences. What this means, methodologically, is that the UK's strong conviction figures reflect only the cases the CPS chose to charge, a subset of reported cybercrime.
The attrition between report and charge is largely invisible in public data. Cases that never made it to charge, evidence that never made it to admissibility, complaints that were closed without prosecution. That part of the story is absent from the numbers. Serious and organised crime costs the UK at least £47 billion annually. That scale of problem dwarfs what published prosecution figures can capture, however strong those figures look.
The UK pattern: what reaches court gets prosecuted very well. Public data on what never reaches court is sparse.
Nigeria: Record Conviction Output That Still Outpaces Its Own Investigative Infrastructure
Nigeria's Economic and Financial Crimes Commission recorded 4,111 convictions in 2024. That followed 12,928 investigated cases, of which more than 5,000 were filed in courts. It is a record figure. It followed a previous record of 3,455 convictions in 2022.
A December 2024 Lagos operation produced 792 arrests of suspected cryptocurrency and romance fraud operators in a single raid. Two Chinese national directors received cumulative 46-year sentences. A separate Abuja operation led to convictions for 21 foreign nationals linked to a cybercrime syndicate.
These are real numbers. No one is disputing the output.
Here is the context that matters. The 2024 World Cybercrime Index, produced by Oxford and the University of New South Wales, ranked Nigeria fifth globally as a source of cybercrime activity, behind Russia, Ukraine, China, and the United States. The conviction record sits alongside a continued ranking as a significant threat source. Those two things are happening at the same time.
Despite legislative reforms, investigators still face gaps in technical expertise and fragmented coordination between agencies. The gap between conviction volume and investigative depth is real. Nigeria can produce high conviction counts through enforcement focus without yet resolving the upstream structural gaps that allow cybercrime to remain a viable industry.
That is the Nigeria pattern: enforcement volume as institutional effort. High output numbers. The conditions that make cybercrime attractive remain in place.
India: The Largest Volume of Reported Incidents and Among the Lowest Conviction Rates
India's National Cybercrime Reporting Portal received more than 6.5 million incident reports between 2021 and mid-2025. Reported cases in 2024 alone were roughly five times the 2021 figure. Indians lost over ₹22,845 crore to cyber fraud in 2024, a 206% increase from 2023 levels.
Against that scale, by 2021 only 490 convictions had been recorded nationally. Cybercrimes carry one of the lowest conviction rates in the Indian legal system.
Four structural failure modes, all present simultaneously:
Outdated legislation. The IT Act was passed in 2000. It predates deepfakes, AI-enabled fraud, and modern detection tools for child sexual abuse material. The law is structurally mismatched with the offences it nominally covers.
No multilateral cooperation framework. India has not joined the Budapest Convention, citing national sovereignty and data localisation concerns. This forces reliance on slower MLATs and bilateral agreements for cross-border cases. Cross-border cases dominate the complaint register.
Limited investigative capacity. The volume of incidents vastly exceeds the investigative infrastructure available to handle them.
Prosecutorial attrition. Cases that do reach the system face significant drop-off before conviction.
India is the clearest single-country argument for why these four variables compound rather than average out. When all four fail together, the outcome is: millions of victims, minimal accountability.
The Asia-Pacific Region: Uneven Enforcement Across a Threat Landscape That Is Growing Faster Than Capacity
INTERPOL's 2025/2026 Asia and South Pacific Cyberthreat Assessment, covering January 2024 through March 2025, found that more than half the countries surveyed reported cybercrime now accounting for 30% of all crimes recorded nationally.
The regional enforcement gaps INTERPOL identified:
Gaps in specialised forensic tools
Limited access to cybercrime training
Insufficient technical capacity
This is the same triad that appears in the India analysis. It appears because these are the consistent failure points across developing enforcement environments.
Smaller island states and developing economies represent a specific problem. Limited resources, limited expertise, limited detection capability. This makes them both high-risk targets for cybercrime and low-risk operating bases for threat actors. Near-certain impunity is a predictable outcome of under-resourced enforcement.
The Asia-Pacific picture reinforces the central argument directly: enforcement outcomes are a function of the structural variables each jurisdiction has or has not built.
What the Cross-Jurisdictional Evidence Actually Shows About Where Prosecution Fails
By this point, the patterns should be readable on their own. But it is worth naming them explicitly, because they each represent a different failure configuration.
The India pattern. Legislation without enforcement infrastructure. High complaint volume. Near-zero conviction rate. The law exists. The capacity to use it does not.
The US pattern. Enforcement infrastructure without extradition reach. Credible prosecution machinery for cases where arrests can be made. A persistent indictment-without-arrest problem for the highest-value targets, who operate from jurisdictions beyond reach.
The UK pattern. Strong prosecutorial conviction rates coexisting with invisible attrition upstream. What reaches court is prosecuted well. Public statistics leave the attrition before charge largely unrecorded.
The Nigeria pattern. High conviction output coexisting with a high threat-source ranking. Enforcement volume reflects institutional effort while leaving intact the conditions that make cybercrime viable.
The common thread across all four:
Every jurisdiction carries at least one of the four gaps. Legislation, cross-border cooperation, investigative capacity, and prosecutorial resource. The gaps interact. Weakness in one amplifies weakness in another.
For security practitioners, vendors, and anyone building threat programs: where an attacker operates is as significant a variable as how they operate. Jurisdictional impunity is a structural feature threat actors actively select for.
The enforcement map is part of the threat model. It always has been.



