Cybercrime DB

Egypt Cybercrime Law and Enforcement Activity

Egypt's 2018 cybercrime law targets hackers while granting the state sweeping surveillance power.

Correspondent · · 11 min read
Cover illustration for “Egypt Cybercrime Law and Enforcement Activity”
cybercrime takedowns and seizures · September 15, 2026 · 11 min read · 2,405 words

Egypt's Law No. 175 of 2018 is the country's first real attempt to put internet crime into a legal box with defined edges. President Abdel Fattah al-Sisi signed it in August 2018, and it does two things at once: it goes after actual hackers and fraudsters, and it hands the state broad power to watch, retain, and block online activity. Both of those things are true at the same time, and that tension runs through every provision below.

Some context before the breakdown. Egypt told the UN's Ad Hoc Committee on Cybercrime that cybercrime in the country jumped roughly 190% between 2012 and 2017. The five-year trend line points straight up, showing the law wasn't dreamed up in a vacuum. It also landed during a presidential election cycle, right when authorities were already blocking websites through a process nobody could quite point to in writing. So the law is part crime-fighting tool, part paperwork for something the government was already doing.

How the law is structured and who it applies to

The statute, officially the "Anti-Cyber and Information Technology Crimes" law, runs 45 articles and sorts the internet into several categories of people, including regular users, service providers, web administrators, and others with defined roles. "Web administrator" is defined wide enough to catch both the person who keeps the servers running and the person who decides what content goes up (Article 1(14) does not split those two jobs apart).

The offenses themselves sit across eight chapters, covering everything from data confidentiality and system integrity to computer fraud, privacy, banned content, and national security threats. Service providers carry the heaviest day-to-day load: retaining data, protecting user info, cooperating with investigators, and executing blocking orders when told to. The law also claims reach beyond Egypt's borders, covering offenses committed abroad if they touch Egyptian interests or users, though how that plays out in an actual cross-border case is still murky.

An Executive Regulation followed in August 2020 and added teeth: cybersecurity standards including encryption and secure protocols, plus a registration requirement for anyone running critical infrastructure (energy, electricity, telecom) that includes keeping records of hardware, software, and network configurations.

The core offenses practitioners need to know and their penalties

Article 14 covers unauthorized access, meaning breaking into a system or overstaying your welcome once you're in by accident. Penalty: at least a year in prison and/or a fine between EGP 50,000 and 100,000. If that access causes damage, like erasing, altering, copying, or leaking data, the floor jumps to two years.

Article 15 handles the lighter version, exceeding access you already have, say using the wrong privileges or logging in at the wrong time. That's at least six months and a fine of EGP 30,000 to 50,000.

Hacking a state information system (Article 20) draws a fine of EGP 50,000 to 200,000. Using a wireless network or broadcast channel without a permit (Article 13) is at least three months plus EGP 10,000 to 50,000.

Fake accounts and impersonation (Article 24) get at least three months and EGP 10,000 to 30,000, but impersonating a public figure to insult them jumps to a fine of EGP 100,000 to 300,000. That's a much steeper price tag for mocking someone with a title.

Article 25 is the one worth sitting with. Posting someone's private content without permission draws at least six months and EGP 50,000 to 100,000, and posting anything that "violates family principles and values upheld by Egyptian society" carries that exact same penalty. Nobody has ever defined what those values actually are in the statute, and no higher court has stepped in to pin it down. So the meaning gets built one ruling at a time, which is a strange way to run a criminal law.

Article 30 also holds that a service provider that doesn't comply with a blocking order faces at least a year in prison and a fine anywhere from EGP 50,000 to 1 million. Compare that ceiling to the individual offenses above. Ignoring a government order costs more than most of the hacking itself.

The data retention and website blocking powers and what they demand of service providers

Telecom companies have to hold onto user data, including identifying info and IP addresses, for 180 days under Article 2, so investigators can pull records when they need them.

Article 7 lets investigative authorities block any website they decide is pushing extremist ideas, threatening national security, or hurting the economy. No court order needed up front. The order does have to go to a court within 24 hours for a rubber stamp, but the actual grounds for blocking are written loosely enough to cover a lot of ground. Article 8 gives the site owner or the internet provider a week to appeal to a criminal court, which is something, even if it comes after the site's already dark.

Article 4 pushes Egypt's foreign affairs ministry to sign cybercrime agreements with other governments, partly to extend cooperation on cross-border offenses. And in 2024, the Cloud First Policy added another layer: cloud providers now have to keep anything classified "top secret" or "secret" physically stored inside Egypt. That's a narrow rule, it only touches classified data, but it's the first real data-localization requirement on the books.

The penalty for a provider who won't execute a blocking order is heavier than the penalty for most user-side crimes in this law. Compliance risk, in other words, outweighs a lot of the technical risk.

How the Personal Data Protection Law of 2020 layers onto the cybercrime framework

Law No. 151 of 2020 took effect in October 2020, and gave Egypt its first real data protection statute. It requires clear consent before anyone processes personal data, and it gives people the right to see their data, fix it, pull their consent, or object to how it's used. Companies handling personal data need a Data Protection Officer, and any breach has to be reported to the Personal Data Protection Centre within 72 hours.

Penalties run up to EGP 5 million in administrative fines, on top of criminal exposure: criminal penalties including imprisonment for violations that cause harm, with steeper exposure for anything touching sensitive data or cross-border transfers.

Here's the catch. Executive regulations for this law didn't show up until Decree No. 816 of 2025, five years after the statute passed. And the Personal Data Protection Centre, the body that's actually supposed to license, monitor, and enforce all of this, hasn't been stood up yet based on available records. So the law is live, the penalties are real on paper, but the referee hasn't walked onto the field.

That creates a genuine puzzle for anyone running a service in Egypt: the Cybercrime Law tells providers to retain and hand over data, while the PDPL tells them not to process data without consent. Both apply at once. Nobody's fully sorted out how they talk to each other. The NTRA handles telecom-sector privacy oversight under separate telecom law, while the Public Prosecution and the economic courts handle the criminal side of cybercrime enforcement.

The ONNX Store / Caffeine phishing-as-a-service prosecution (what the case shows about Egyptian enforcement)

Egypt's Public Prosecution referred five defendants to trial over two phishing operations, ONNX Store and Caffeine, aimed at financial institutions and Microsoft accounts worldwide. The Mansoura Economic Court convicted them on related charges, handing down two to three years in prison and fines topping EGP 1.5 million combined.

ONNX sold phishing kits mostly through Telegram, with a basic plan at $150 a month and a professional tier at $550. Microsoft's Digital Defense Report placed ONNX among the top five phishing kit providers by email volume in the first half of 2024, which is not a small operation, that's assembly-line phishing. The person behind it, known online as "MRxC0DER," had reportedly been selling kits since 2017 under names like Caffeine and FUHRER, and Microsoft had been tracking the operation.

The tradecraft was genuinely sophisticated: encrypted JavaScript that only decrypts once the page loads, plus basic anti-debugging tricks meant to dodge phishing scanners and slow down analysts. But the kits didn't put themselves in prison. Threat intel firm EclecticIQ connected ONNX Store to Caffeine by analyzing overlapping infrastructure and activity patterns, and a group called Dark Atlas tracked the real identity behind the handle through plain old username searching, digging up a deleted Facebook profile, a phone number, and a LinkedIn page. Authorities moved to take down malicious domains used to hit Office 365 users globally.

The digital trail matched the real-world defendants because private analysts built that trail first. The law gave prosecutors the authority to act, but threat intelligence companies did the legwork that made acting possible.

Other enforcement actions that show the range of the law's application

The HoggPool case shows the fraud side. In March 2023, Egyptian authorities arrested 29 people, 13 of them foreign nationals, over a fake cryptocurrency investment platform that launched in August 2022 and quietly died in February 2023. Egypt's Social Media Monitoring Unit and Counter-Cyber Crime Department caught it after victims started posting complaints online, which is a fairly low-tech way to crack a crypto scam.

In 2024, the Administrative Control Authority arrested someone running platforms that built malware to steal banking data and fake websites that impersonated real financial institutions. Payment ran through cryptocurrency in US dollars, and the total take crossed into the hundreds of thousands. The ACA called it one of the largest operations of its kind globally that year.

Operation Ramz, running from October 2025 through February 28, 2026, was coordinated by INTERPOL across 13 countries including Egypt. It's the first cybercrime operation of this scale run by INTERPOL in the MENA region: 201 arrests, 382 suspects identified, 3,867 victims found, 53 servers seized, all targeting phishing, malware, and scam operations. Group-IB, Kaspersky, the Shadowserver Foundation, Team Cymru, and TrendAI fed intelligence into the operation, nearly 8,000 pieces of data shared across the participating countries.

Notice the pattern repeating across all three cases. Social media monitoring, tracing crypto transactions, and private threat intel firms keep showing up as the actual mechanism that turns a law into an arrest. The statute provides the authority. Someone still has to do the finding.

The civil liberties dimension that security professionals operating here cannot ignore

Article 25's "family values" language isn't just vague on paper, it's been applied that way in practice. A human rights organization documented a wave of arrests targeting online content creators starting in July 2025: at least 29 people, including at least 19 women and one child, arrested or prosecuted for online content between late July and late August 2025 alone. Independent media and rights groups tracked roughly eight more cases in that same window.

This isn't new behavior dressed up in new law. Before the statute even passed, more than 500 websites, including news outlets and NGOs, had already been blocked through a process with no clear legal footing. The 2018 law gave that blocking power an actual paper trail, but it never fully closed the procedural gaps that let it happen in the first place.

So the same legal framework that convicted the ONNX Store operators also gives authorities the tool to arrest a content creator or block a political site. Anyone doing security work that touches content moderation, threat intel sharing, or user data in Egypt needs to understand that clean technical compliance doesn't make the legal exposure disappear. The content provisions apply to any platform reaching Egyptian users, whether or not that platform is based there.

What the threat environment looks like for organizations operating in Egypt

The numbers are moving fast. PurpleGuard's 2026 threat landscape report found that recorded incidents in Egypt in just the first half of 2026 were almost double the total for all of 2025. That's not gradual growth, that's the threat curve outrunning the legal system meant to police it.

Six major ransomware attacks hit government entities in the first half of 2024 alone, and as Egypt's fintech sector keeps expanding and handling more sensitive data, it's turning into a more attractive ransomware target every year. Egypt belongs to the global Counter Ransomware Initiative and holds a firm no-negotiation, no-payment policy toward threat actors.

Meanwhile the country's ICT sector grew 14.4% in the 2023/2024 fiscal year, making it Egypt's fastest-growing industry, and internet penetration hit 81.9% in 2025 with 96.3 million users online. Egypt ranked third among African economies for tech investment in 2024, but only 95th on the E-Government Development Index. Put those two rankings side by side and the picture is clear: digital growth is sprinting ahead of the regulatory system meant to keep pace with it. Egypt's own National Cybersecurity Strategy, released in February 2024, admits as much, laying out plans to update legislation, tighten domestic cooperation, and build out cyber defense systems.

What security vendors and practitioners working near the Egyptian market actually need to account for

Three separate compliance layers apply at once, and they don't always agree with each other. There's the Cybercrime Law (data retention, blocking cooperation, avoiding the criminal offenses above), the PDPL (consent, a DPO on staff, 72-hour breach notification), and sector rules from the NTRA and the 2020 Executive Regulation. A single company can be on the hook for all three simultaneously.

The PDPL enforcement gap is real and worth tracking. With the Personal Data Protection Centre still not established, formal enforcement under that law isn't happening yet in practice, even though the criminal penalties and the 2025 executive regulations are technically in force. That's a strange in-between state: illegal on paper, unenforced in practice, at least for now.

Article 25's vague content standard and Article 7's loose blocking criteria create a kind of risk no firewall or encryption protocol can patch. Content reaching Egyptian users gets judged against a standard courts are still writing case by case, and no amount of technical hardening changes that.

And the enforcement record, ONNX Store, HoggPool, Operation Ramz, all point the same direction. Open-source digging, infrastructure correlation, Telegram channel tracking: that's what turns a law on paper into an actual conviction. Firms that produce that kind of intelligence aren't adjacent to this ecosystem, they're load-bearing parts of it. Anyone writing or advising on security in this market earns trust by engaging with what the law actually says and what enforcement has actually done, not by handing over a generic compliance checklist that could've been written about any country on earth.

Sources

  1. Egypt: President Ratifies Anti-Cybercrime Law | Library of Congress
  2. unodc.org
  3. DPA Digital Digest: Egypt [2025 Edition]
  4. The New Egyptian Anti-Cybercrime Law Regulates Legal Responsibility for Web Pages and Their Content - Lexology
  5. TIMEP Brief: Cybercrime Law
  6. english.ahram.org.eg
  7. blog.eclecticiq.com
  8. hrw.org

More in cybercrime takedowns and seizures