This guide is maintained as a current resource for September 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Understanding cybercrime in England and Wales: what constitutes cybercrime, key offences under the Computer Misuse Act 1990, examples like hacking, phishing and malware, how investigations and prosecutions work, potential penalties, and practical guidance for victims and organisations.

Cybercrime refers to criminal activity that involves computers, networks or digital technology. It can target individuals, businesses, public services and national infrastructure, and it increasingly forms a core part of modern criminal law in England and Wales. Cybercrime encompasses a broad range of conduct - from unauthorised hacking to online fraud, phishing, identity theft and malicious software attacks. This article explains what cybercrime is, how the law defines key offences, what statutory frameworks apply, how investigations and prosecutions work, and practical steps people can take if affected. The aim is to provide clear, accurate, and accessible information for solicitors, students and members of the public.
What Is Cybercrime?
Cybercrime is an umbrella term for offences that are committed using digital technology or the internet. It covers two main types of criminal activity:
- Cyber‑dependent crimes: offences that can only be committed through the use of computers or information and communications technology (ICT). Examples include hacking into systems or deploying malware.
- Cyber‑enabled crimes: traditional crimes that are significantly facilitated or amplified by digital technology, such as online fraud, identity theft or distribution of illegal material.
This classification reflects both how technology can be the tool and target of crime and how it can increase the scale and reach of more conventional offending.
Legal Framework in England and Wales
There is no single statute labelled “the cybercrime law” in the UK, but a number of legislative frameworks apply to different types of cyber offences. They outline what conduct is criminal and what penalties apply:
Computer Misuse Act 1990
The principal legislation for cyber‑specific offences is the Computer Misuse Act 1990. This Act makes it a criminal offence to:
- Unauthorised access to computer material (commonly referred to as “hacking”).
- Unauthorised access with intent to commit or facilitate further criminal offences (for example, hacking to steal data or commit fraud).
- Unauthorised acts with intent to impair the operation of a computer or knowing that such acts are unauthorised.
- Making, supplying or obtaining articles (such as malware) for use in committing other offences under the Act.
The law does not define “computer” narrowly; courts interpret it to encompass modern devices such as laptops, tablets and servers that store, process or retrieve information.
Other Relevant Legislation
Cybercrime often intersects with other criminal laws, including:
- Fraud offences under the Fraud Act 2006, such as where online scams or phishing lead to financial loss.
- Data protection offences under the Data Protection Act 2018 and related GDPR obligations, including failure to protect personal information.
- Offences under the Terrorism Act 2000 when digital technology is used to further terrorism.
- Traditional criminal law provisions applied to online contexts, such as harassment or child sexual offences.
Common Types of Cybercrime
Hacking and Unauthorised Access
Hacking involves gaining access to a computer network or system without authorisation. This can include bypassing security measures or exploiting vulnerabilities. Under the Computer Misuse Act 1990, even accessing a system without causing damage can be a criminal offence.
Malware and Ransomware
Malicious software like viruses, worms, spyware or ransomware is designed to damage, disrupt or control computer systems. Ransomware is used by criminals to block access to data and demand payment for its return.
Phishing and Identity Theft
Cybercriminals frequently use deceptive emails, messages or websites (phishing) to trick people into disclosing sensitive information. That data can be used to commit identity theft or financial fraud.
Distributed Denial‑of‑Service (DDoS) Attacks
DDoS attacks overwhelm a website or network with traffic to make services unavailable to legitimate users. These attacks can disrupt business operations and essential services.
Online Fraud and Scams
Traditional fraud - such as investment scams, auction fraud, or advance fee fraud - can be conducted online, often at scale. These cyber‑enabled crimes may attract prosecution under the Fraud Act 2006.
Cyber Harassment and Abuse
Online harassment, stalking, or non‑consensual sharing of intimate images can constitute criminal offences, particularly where there is coercion or abuse. Digital technology often facilitates these behaviours.
How Cybercrime Is Investigated and Prosecuted
Cybercrime investigations are complex and typically involve specialist units within law enforcement. In England and Wales, police forces often work alongside the National Crime Agency (NCA) and specialist cyber units to gather digital evidence from devices, networks and online accounts.
Once sufficient evidence is collected, cases may be referred to the Crown Prosecution Service (CPS), which assesses whether there is a realistic prospect of conviction and whether prosecution is in the public interest. Charges are brought under the relevant legislation, such as the Computer Misuse Act 1990 or the Fraud Act 2006.
Penalties and Sentencing
The penalties for cybercrime vary by offence and severity:
- Unauthorised access under the Computer Misuse Act can result in imprisonment and fines. Depending on the circumstances and seriousness, sentences can range from custodial sentences of months to years.
- More serious offences - such as causing significant damage or facilitating further criminal activity - attract heavier sentences, including long prison terms and potentially life sentences where national security is involved.
- Fraud‑related cybercrime under the Fraud Act 2006 can lead to up to 10 years' imprisonment and unlimited fines, depending on the type of offence.
Penalties often include ancillary orders, such as confiscation orders, compensation orders to repay victims, and restrictions on internet use to prevent re‑offending.
Rights and Practical Steps for Victims
If you believe you are a victim of cybercrime:
- Report the matter to the police by calling 101 for non‑emergencies or using Action Fraud (the national reporting centre for fraud and cybercrime).
- Preserve evidence, such as screenshots, emails or transaction records.
- Contact your bank or financial institution promptly if financial information or accounts have been compromised.
- Consider contacting a qualified solicitor experienced in cybercrime or digital fraud if you require legal representation or advice.
Key Takeaways
Cybercrime in England and Wales encompasses a wide range of offences involving computers, networks and online systems. It includes both cyber‑dependent crimes - such as hacking and malware attacks under the Computer Misuse Act 1990 - and cyber‑enabled crimes like online fraud, identity theft and abuse.
Cybercrime investigations often involve specialist law enforcement units and can result in serious criminal charges, significant penalties and long‑term legal consequences. Victims should report incidents to the police or Action Fraud, preserve evidence and seek legal guidance where appropriate. Understanding how the law applies to digital conduct is essential for navigating the modern criminal justice landscape.