Showing posts with label cyberlaw. Show all posts
Showing posts with label cyberlaw. Show all posts

Saturday, 15 August 2026

Section 24 of the Cybercrimes Act Has Changed: A Note on a Recent Commentary on Google Searches and Nigerian Cyber Law


A recent piece by 1st Attorneys, titled "The Legal Effects of Google Searches in Nigerian Law," is a genuinely useful survey of how the courts and legislation in Nigeria are catching up with the digital footprints we all leave behind. Its treatment of the right to be forgotten under the NDPA 2023, its comparison of the Hillary Ogom and Adunni Ade decisions against Google, and its discussion of electronic evidence under the amended Evidence Act are all well researched and worth reading. Where the article falters, however, is in its account of Section 24 of the Cybercrimes (Prohibition, Prevention, Etc.) Act, and the error is significant enough to warrant a correction, particularly because Section 24 is the provision most often invoked against ordinary Nigerians for things said or searched online.

What the article says

The article describes Section 24 as prohibiting the knowing transmission of communications that are "grossly offensive, pornographic, or constitute cyberstalking," and elsewhere describes the offence as covering material sent with intent to cause annoyance, inconvenience, danger or injury (see the original article, Part III, under "Section 24: Cyberstalking and Harassment" and "Scenario 5"). This is a faithful description of Section 24 as it stood between 2015 and mid-2024. It is not, however, an accurate description of the law today.

What actually changed

The Cybercrimes (Prohibition, Prevention, Etc.) (Amendment) Act 2024 rewrote Section 24(1) substantially. The old provision criminalised messages that were grossly offensive, pornographic, indecent, obscene or menacing, or that the sender knew to be false and sent for the purpose of causing annoyance, inconvenience, danger, obstruction, insult, injury, criminal intimidation, enmity, hatred, ill will or needless anxiety. That sprawling list of subjective harms was precisely what made the old Section 24 so controversial. It was the provision most frequently deployed against bloggers, journalists, activists and ordinary citizens for social media posts that offended a complainant, and its vagueness attracted sustained criticism from civil society and the legal profession for years.

The 2024 amendment discards that language entirely. The new Section 24(1) now criminalises only messages that are pornographic, or messages the sender knows to be false and sends for the purpose of causing a breakdown of law and order or posing a threat to life. Everything in between, the grossly offensive post, the insulting comment, the message calculated merely to annoy or embarrass, no longer falls within the section at all. The offence has moved from policing subjective feelings such as annoyance and insult to policing objective and considerably narrower harms tied to public order and safety.

Why this matters beyond pedantry

This is not a minor drafting tweak. It is a fundamental narrowing of criminal liability, and it changes the analysis in several places where the article relies on the old formulation. The suggestion that search history showing repeated searches for a victim's name and address could support a Section 24 cyberstalking charge needs revisiting, since cyberstalking premised on annoyance or harassment, without more, sits outside the current wording. Likewise, the article's discussion of online defamation notes that Section 24 makes it an offence to knowingly send false material intending to cause annoyance, inconvenience, danger or injury. That is no longer the test. A prosecutor relying on the amended section must now show that the false statement was sent for the purpose of causing a breakdown of law and order or a threat to life, a considerably higher and more specific threshold than the old catalogue of subjective harms.

For defence counsel, this matters immediately. Any charge sheet or ongoing prosecution still framed in the language of grossly offensive, indecent or menacing content, or annoyance and insult, is charging conduct against a provision that Parliament has already replaced. Counsel should scrutinise the date of the offence alleged and the version of Section 24 actually in force at that time, since the amendment is not retroactive and older conduct may still fall to be assessed under the repealed text.

A note for practitioners and commentators generally

The lesson here is a broader one for anyone writing on Nigerian cyber law at the moment. The 2024 amendment to the Cybercrimes Act made several targeted changes beyond Section 24, and commentary drafted before August 2024, or drafted afterward but relying on older secondary sources, can easily reproduce provisions that have since been repealed. Given how often Section 24 features in both civil advocacy and criminal defence work, it is worth every practitioner confirming they are working from the amended text before relying on it in a brief, an article, or advice to a client.

This note is offered in the spirit of collegial correction, and with appreciation for the broader contribution the original article makes to an underdeveloped area of Nigerian legal writing.


Tuesday, 17 February 2026

When the Law Gets It Wrong: A Critique of the Cybercrime Charges Against El-Rufai


The Department of State Services (DSS) recently filed a three-count cybercrime charge against former Kaduna State Governor Nasir Ahmad El-Rufai, sending political ripples across Nigeria and setting off a wave of commentary from legal observers. The charge, widely reported in the press, invokes provisions of the Cybercrimes (Prohibition, Prevention, etc.) AmendmentAct, 2024. And that is precisely where the legal problems begin.

This piece is not principally about whether El-Rufai is guilty or innocent of whatever conduct the DSS suspects him of. That is a matter for trial. What is worth examining carefully, and somewhat urgently, is whether the DSS and whoever supervised this prosecution got the law right. The short answer is: they did not. And the implications of that error go beyond procedural embarrassment.

What the DSS Actually Charged

According to media reports, the first two counts of the charge invoke Section 12(1) and Section 27(b) of the Cybercrimes (Prohibition, Prevention, etc.) Amendment Act, 2024. These references are presented as if they are straightforward provisions of the law under which El-Rufai must answer. They are not.

Here is why.

The 2024 Amendment Act Is Not a Standalone Penal Law

The Cybercrimes (Prohibition, Prevention, etc.) Amendment Act, 2024 is, as its very title makes clear, an amendment. It exists for one purpose: to amend specific provisions of the principal legislation, which is the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015. An amendment act does not create an independent, self-contained body of criminal law. It modifies, inserts, deletes, or replaces sections of the parent Act. Once it has done that work, the operative legal instrument remains the principal Act, now updated with whatever changes the amendment introduced.

This is not a technicality. This is elementary legislation. Anyone who has studied law in Nigeria, or indeed any common law jurisdiction, understands that you charge a suspect under the principal Act as amended, not under the amending statute itself.

Now, let us look at what Section 12(1) of the 2024 Amendment Act actually says. It reads, in its entirety: "Section 48 of the Principal Act is amended by deleting subsection (4)." That is it. Section 12 of the 2024 Amendment Act is a housekeeping provision. It performs a narrow editorial function. It deletes a subsection from Section 48 of the 2015 Act. It creates no offence, prescribes no penalty, and defines no criminal conduct whatsoever. Charging anyone under Section 12(1) of the 2024 Amendment Act as if it were a substantive criminal provision is legally incoherent.

Similarly, Section 27(b) of the 2024 Amendment Act simply does not exist. The entire Amendment Act has only 12 sections!

The Correct Provisions Are in the 2015 Act

The actual substantive offences that the DSS appears to have intended to charge El-Rufai with are clearly found in the Cybercrimes (Prohibition,Prevention, etc.) Act, 2015 as amended. Two provisions in particular stand out as the appropriate basis for the first two counts.

The first is Section 12(1) of the 2015 Act, which provides:

"A person, who intentionally and without authorization, intercepts by technical means, non-public transmissions of Computer Data, content, or traffic data, including electromagnetic emissions or signals from a Computer, Computer System or Network carrying or emitting signals, to or from a Computer, Computer System or connected system or network, commits an offence and is liable on conviction to a term of imprisonment of not more than 2 years or to a fine of not more than 5,000,000.00 or both."

That is the unlawful interception provision. It targets the deliberate, unauthorized interception of electronic communications. If the DSS believes that El-Rufai or persons connected to him engaged in unauthorized interception of digital communications, this is the provision they should have cited. It is clear, it creates a specific offence, it has a defined penalty, and it sits properly in the principal Act.

The second relevant provision is Section 27(1)(b) of the 2015 Act, which provides:

"A person who aids, abets, conspires, counsels or procures another person to commit any offence under this Act, commits an offence and is liable on conviction to the punishment provided for the principal offence under this Act."

This is the conspiracy and abetting provision under the Cybercrimes Act. It is the appropriate section to charge someone who did not personally carry out the alleged cyber conduct but who may have facilitated, assisted, or procured another person to do so. Again, it is in the 2015 Act, not the 2024 Amendment Act.

The charges should have read: "Count 1: Contrary to Section 12(1) of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 as amended" and "Count 2: Contrary to Section 27(1)(b) of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 as amended." The failure to frame it this way is not a minor drafting infelicity. It is a substantive legal error that, depending on how the trial court views it, could affect the validity of the charge or at the very least embarrass the prosecution.

Why This Matters: The Consequences of Charging Under the Wrong Law

Some might argue that this is a technicality and that the court will simply look through to the underlying facts. The courts do have some latitude in treating errors in charge drafting, and the prosecution may seek to amend the charge. But that argument misses the broader point. In criminal proceedings, precision matters. The defendant is entitled to know exactly what law they are said to have violated. A charge that cites a non-existent substantive provision denies the accused a fair opportunity to understand and challenge the case against them. It also exposes the prosecution to objections at every stage of proceedings, from arraignment to trial.

More practically, prosecutorial credibility matters. When the agency bringing the charge cannot correctly identify the statute it is relying on, it raises legitimate questions about the quality of the investigation and the legal supervision of the case. It makes it harder for courts, the public, and legal observers to take the prosecution seriously on its merits.

The Rules of Professional Conduct for Legal Practitioners, 2023 speak directly to this. Rule 37(4) states that "the primary duty of a lawyer engaged in public prosecution is not to convict but to see that justice is done." Rule 37(5) goes further and is even more pointed: "A public prosecutor shall not institute or cause to be instituted a criminal charge, if he knows or ought reasonably to know that the charge is not supported by the probable evidence." Read together, these provisions draw a clear boundary. A public prosecutor is not an instrument of political will. They carry an independent professional duty to ensure that charges are legally sound before they are filed. Filing a charge under provisions that either do not exist or carry no substantive criminal content is not a clerical slip. It is a departure from that duty, and the Rules make no allowance for institutional pressure as an excuse.

The Uncomfortable Question: Was This Prosecution Rushed?

There is an uncomfortable dimension to all of this that cannot be avoided. The DSS is the country's secret police. It operates under the direct supervision of the Presidency. El-Rufai, since leaving government, has become an increasingly vocal and uncomfortable presence in opposition circles. The timing of the charges, and now the elementary legal error embedded in them, raises a question that serious observers cannot simply dismiss: was this prosecution properly prepared, or was it rushed to court to satisfy political pressure from above?

Cybercrime investigations, when done properly, take time. They require forensic analysis of devices and networks, the establishment of chains of digital evidence, careful assessment of the relevant statutory provisions, and thorough legal review before charges are filed. None of that is quick work. When charges are filed that cite provisions of an amendment act as if they were substantive offences, when those provisions turn out to be mere housekeeping clauses or simply non-existent as criminal provisions, one is entitled to wonder whether any serious legal review happened at all.

It is hard not to reach for an explanation. And the most obvious one is that someone in the DSS, under pressure to produce a result quickly, drafted and filed these charges without adequate scrutiny. The error is the kind that a law student should catch. That it appeared in a charge filed by a national security agency suggests either that the legal review was cursory or that no meaningful legal review happened at all.

The Pressure Cooker: Government Lawyers and Their Political Bosses

This brings us to a pattern that is unfortunately familiar in public law practice. Lawyers who work for government agencies, security services, and state institutions operate in an environment that is structurally different from private practice. They have clients, yes, but their clients are institutions that are themselves answerable to political principals. The Attorney-General's office, the DSS legal directorate, the Nigeria Police Force legal directorate, the Nigeria Army legal directorate and similar bodies do not exist in a professional vacuum. They operate within a chain of authority that runs, ultimately, to political appointees and to elected or appointed officials with agendas and timelines.

The foundation of the profession, however, does not shift with that chain of command. Rule 1 of the Rules of Professional Conduct for Legal Practitioners, 2023 is unambiguous on this: "A lawyer shall uphold and observe the rule of law, promote, and foster the course of justice, maintain a high standard of professional conduct, and shall not engage in any conduct which is unbecoming of a legal practitioner." That obligation does not have a carve-out for government lawyers. It does not say "except when your boss is in a hurry" or "unless the agency director wants results by Friday." It is absolute. It applies to the lawyer in private practice and equally to the lawyer sitting in the legal directorate of a security service drafting charges at the instruction of a political superior.

The pressure to file quickly, to show results, to demonstrate that the agency is active and effective, is real and pervasive. A political boss who wants a charge filed will not always appreciate being told that the forensic work is incomplete or that the legal drafting needs another week of review. Junior lawyers and even senior ones know that pushing back on a political boss carries professional risk. The path of least resistance is to file what you have, fix it later, and hope the court is tolerant.

The problem, of course, is that this approach does a disservice to everyone. It harms the prosecution's case. It potentially harms the defendant, who must navigate proceedings built on faulty foundations. It undermines public confidence in the justice system. And it harms the lawyers themselves, who are identifiable in the public record as the authors of a flawed charge.

It appears that government lawyers everywhere navigate the tension between professional duty and institutional loyalty. But the tension is particularly acute in environments where security agencies operate with limited independent oversight, where political pressure on prosecutorial decisions is normalized, and where the consequences of being seen as obstructive to the boss's agenda are swift and severe.

A Word to In-House Counsel Under Political Pressure

If you are a lawyer working within a government agency or under the supervision of a politically appointed superior, this case should serve as a sobering reminder of something you already know but perhaps find difficult to act on.

Your professional obligation runs to the law first. Not to your boss, not to the agency, not to the political agenda of the moment. Rule 1 of the Rules of Professional Conduct has already stated this plainly, and Rule 37 has sharpened it in the specific context of criminal prosecution. A public prosecutor who files a legally defective charge is not just making a technical error. They are, on the plain reading of those rules, failing in their primary professional duty. When a superior directs you to file a charge that you know is legally defective, you are not merely being asked to take a professional risk. You are being asked to participate in a process that may ultimately embarrass the institution you serve and, more importantly, undermine justice.

The practical advice here is straightforward, even if it is not always easy to follow. Push back in writing. Document your legal concerns in a memorandum. If you believe the charges as drafted cite the wrong legislation, say so clearly and in a format that creates a record. You may be overruled, and that is a reality of institutional practice. But you will have discharged your professional duty, and you will have evidence that you raised the issue. That documentation matters, both professionally and ethically.

If you are overruled and the defective charge is filed anyway, at the very least ensure that the record reflects the correct statutory basis for any subsequent amendment. Do not compound the initial error by defending it as if it were correct. Courts, opposing counsel, and the public are watching. And in the age of legal commentary, public analysis, and digital archives, elementary legal errors in high-profile cases do not disappear quietly.

More broadly, think carefully about the long game. A prosecution that collapses because it was built on a wrong statutory foundation does not serve the political boss who ordered it. It does not serve the agency that filed it. It certainly does not serve justice. The lawyer who stood up early and said "we need to get the law right before we file" is ultimately serving everyone better, even if that is not how it feels in the moment of political pressure.

The El-Rufai case, whatever its ultimate outcome, is an object lesson in what happens when the rush to please the boss overrides the duty to get the law right. The charges may be amended. The prosecution may proceed. But the elementary error is now on the public record. And that, for any lawyer worth their call to bar, should be reason enough to slow down next time, check the statute carefully, and file correctly the first time.

 

This article is written for legal commentary purposes and does not constitute legal advice. The author examined the publicly reported charges and the relevant statutory provisions on the basis of publicly available legal texts.

 

Thursday, 15 May 2025

A Decade of the Cybercrimes Act: Assessing the Nation’s Legal Framework Against Digital Threats (2015–2025)


Introduction

On May 15, 2015, the nation made a decisive move in addressing the growing threat of cybercrime by enacting the Cybercrimes (Prohibition, Prevention, etc.) Act. Ten years later, the law remains central to the country’s cybersecurity framework, offering legal definitions, prosecutorial mechanisms, and institutional frameworks to combat digital threats. As we mark this decade-long journey, it is time to assess the Act's major impacts, its 2024 amendments, its misuses, and what must change in the future to safeguard security and civil liberties.

1.     The Country’s First Comprehensive Legal Framework on Cybercrime

Prior to 2015, the legal environment addressing cybercrime in the nation was fragmented. Offenses were prosecuted under laws like the Advanced Fee Fraud Act, which did not fully capture the nature of modern digital threats. The 2015 Act changed that by clearly defining crimes such as hacking, identity theft, cyberterrorism, online fraud, and child pornography. It introduced penalties that enabled structured prosecution. The result has been a series of high-profile convictions, including notorious syndicates involved in ATM cards, phishing scams, etc.

2.     Creation of the Cybercrime Advisory Council

The Act provided for the establishment of the Cybercrime Advisory Council under the leadership of the National Security Adviser (NSA). Comprising stakeholders from public and private sectors, the Council was tasked with coordinating national cybersecurity policy. Although the Council has faced criticism for slow bureaucratic response, it has enabled strategic partnerships with international agencies like INTERPOL and the UK National Crime Agency.

3.     Protection of Critical National Infrastructure (CNII)

A notable provision of the Act was the designation of key sectors such as banking, energy, and telecommunications as Critical National Information Infrastructure (CNII). These sectors were mandated to implement enhanced cybersecurity protocols. Although large institutions have complied, enforcement remains inconsistent, especially among smaller banks and regional service providers.

4.     Reforming Section 24: From Overreach to Targeted Protection

Originally, Section 24 criminalized messages deemed "grossly offensive" or causing "needless anxiety." This provision was vague and became a tool for silencing journalists and critics. The 2024 amendment narrowed its scope, now targeting child pornography and false information likely to incite violence. This change followed the ECOWAS Court's 2020 judgment, which found the original section unconstitutional. Still, enforcement remains uneven and politically influenced.

Notable Misuse Cases:

·       Omoyele Sowore (January 2025). Charged with 16 counts under the Cybercrime Act based on his social media posts referring to the Inspector General of Police as an “illegal IGP.”

·         Agba Jalingo (2022): Prosecuted over Facebook posts alleging corruption.

The Erisco Tomato Paste Review Case – A Cautionary Tale

In 2023, Chioma Okoli, a national consumer, posted a Facebook review stating that she found Nagiko Tomato Mix, a product of Erisco Foods Limited, to be sugary. Erisco Foods Limited refuted her claim as untrue and unfounded. Subsequently, Okoli was arrested by the police following a petition by the company's President and CEO, Eric Umeofia. The police obtained an arrest warrant and remand order from a magistrate court in Masaka, Nasarawa State, leading to her detention. She was later arraigned at the Federal High Court in Abuja, where she pleaded not guilty to two counts of conspiracy and cyberstalking. Amid the legal proceedings, Okoli suffered a miscarriage. Her arrest and detention sparked public outrage, with many citizens calling for her release.

Displeased with the remand order, Okoli's counsel, Inibehe Effiong, petitioned the Nasarawa State Judicial Commission. He argued that it was improper for the magistrate to issue arrest and remand warrants against his client, who neither resided in Nasarawa State nor had ever visited it. Effiong contended that the alleged offences were not committed in Nasarawa State and that cybercrime is a federal offence under the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, which grants exclusive jurisdiction to the Federal High Court for such matters.

Following the petition, the Nasarawa State Judicial Commission investigated the matter and, in a letter dated January 6, 2025, informed Effiong that Chief Magistrate Emmanuel A. Jatau had been demoted from Chief Magistrate II (Grade Level 15) to Senior Magistrate I (Grade Level 14) and stripped of his magisterial duties. The commission cited misconduct in the handling of Okoli's case as the reason for the disciplinary action.

This case underscores the importance of adhering to proper jurisdictional procedures and the potential consequences of misapplying legal authority, particularly in matters involving federal offences such as cybercrime. It further highlights how cybercrime laws can be misapplied to suppress consumer rights and free expression, exemplifying a growing trend of using criminal prosecution to settle what are fundamentally civil disputes.

5.     International Collaboration and Extradition Challenges

The country’s endorsement of the Budapest Convention significantly improved its ability to cooperate on international cybercrime investigations. Countries such as the UK, South Africa, and Japan have partnered with the nation to track and extradite suspects. However, the process remains hampered by slow bureaucratic procedures and lack of mutual legal assistance frameworks with some jurisdictions.

6.     Introduction of the Cybersecurity Levy

A major provision in the 2024 amendment was the introduction of a 0.5% cybersecurity levy on electronic transactions, administered by the NSA. While aimed at funding national cyber defense infrastructure, the policy attracted strong public opposition, prompting government reviews and clarifications. Critics argue the levy disproportionately affects small businesses and low-income earners.

7.     Law Enforcement and Free Speech: A Fragile Balance

Even after the amendment, Section 24 continues to be used against journalists and whistleblowers. In 2024, journalist Daniel Ojukwu was detained for publishing corruption-related stories. In 2023, lawyer Chike Ibezim was charged over tweets criticizing a politician. Legal advocacy groups like SERAP and the Nigerian Union of Journalists (NUJ) have consistently called for more robust protections for free speech.

8.     Sectoral CERTs and Faster Incident Reporting

The 2024 reforms also created Sectoral Computer Emergency Response Teams (CERTs) to improve the handling of cyber incidents. Financial institutions, for example, must now report security breaches within 72 hours, a significant improvement over the previous 7-day period. This has improved real-time threat analysis and response mechanisms.

9.     Mandatory NIN for Electronic Transactions

To combat identity fraud, the amendment now mandates the use of National Identity Numbers (NIN) for all electronic transactions. While this policy has had a positive impact in reducing the number of fraudulent accounts, implementation remains difficult due to infrastructure gaps in the National Identity Management Commission (NIMC).

10.    Strengthening Law Enforcement Capacity

The Act led to the establishment of cybercrime units within agencies like the EFCC, the Nigeria Police Force, and the Nigerian Financial Intelligence Unit (NFIU). These units have recorded success in cracking complex cyber fraudcases. However, underfunding, skill shortages and accessibility outside Abuja and Lagos still limit their effectiveness. 

Judicial Warning Against Misuse of Criminal Law for Civil Disputes

The Supreme Court of the country, in Aviomoh v. C.O.P & Anor (2021) LPELR-55203(SC), offered a stark warning. Justice Helen Moronkeji Ogunwumiju held:

"My Lords, the misuse of the criminal law machinery for getting reliefs in disputes that are civil in nature, by using the instruments of State has become dangerously rampant in recent times... Criminal Courts should ensure that proceedings before it are not used for settling scores or to pressurize parties to settle civil disputes."

This principle must guide the application of the Cybercrimes Act, particularly Section 24, to prevent the criminalization of civil disagreements or dissenting opinions.

The Way Forward

1. Judicial Training:

Introduce mandatory training on digital rights and cybercrime legislation for magistrates and judges. The mishandling of the Erisco case underscores the urgent need for judicial officers to understand jurisdictional limits and the civil liberties at stake in cybercrime prosecutions.

2. Expansion of Forensic Infrastructure:

Establish well-equipped cybercrime forensic laboratories in each of the six geopolitical zones to improve digital evidence collection and analysis.

Deploy Cybercrime Units of the Nigeria Police Force across all 36 state commands. These units should be equipped with modern tools, including digital forensic software and blockchain analysis systems. Replicating such capacity nationwide will help reduce investigative delays, particularly in underserved rural areas.

3. Capacity Building:

Invest in the continuous training of law enforcement personnel in areas such as ethical hacking, cryptocurrency tracking, and dark web surveillance. Partnerships with institutions like the UK's National Cyber Security Centre (NCSC)  will ensure officers remain adept at handling sophisticated cyber threats.

4. Whistleblower Protection:

Enact legal safeguards to protect journalists, whistleblowers, and concerned citizens from retaliatory prosecutions under the Act. Such protection is crucial to fostering accountability and trust in public institutions.

5. Transparency and Accountability:

Mandate the publication of annual reports on cybercrime-related arrests, charges, and convictions. These reports should include disaggregated data to help identify patterns of misuse and support evidence-based reform.

Conclusion

In its first decade, the Cybercrimes Act has become a vital component of the national security framework. Yet, high-profile cases like Erisco and the detention of journalist Daniel Ojukwu expose persistent vulnerabilities in its application. As Justice Helen Ogunwumiju cautioned in Aviomoh v. C.O.P, criminal law must not be wielded as a tool for settling civil grievances or suppressing legitimate dissent.

To uphold both security and civil liberties in the digital age, the next phase must focus on legislative precision, institutional accountability, and infrastructural development. Decentralizing cybercrime units, expanding forensic capabilities, and ensuring judicial understanding of digital rights will help realign the Act with its original purpose: to protect citizens from genuine digital threats—not to punish lawful expression.

Without equipping all regions of the country to detect and respond to cybercrime effectively, the nation risks falling behind in its fight against increasingly complex digital criminality. Reform is no longer optional—it is imperative.

Sunday, 15 December 2024

The Need to Narrow the Scope of Cybercrime Laws: Lessons from Dele Farotimi's Case


 

1.0    Introduction

Cybercrime laws have become essential tools for combating crimes in the digital age, addressing issues such as hacking, identity theft, and the spread of malicious software. However, when these laws are broadened to include offenses that merely involve ICTs (information and communication technologies) as a medium rather than a direct target, they risk becoming instruments of overreach, censorship, and abuse. The recent case of Nigerian activist and lawyer Dele Farotimi, charged under the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (As Amended) for alleged bullying and harassment and disseminating false information for the purpose of causing breakdown of law and order, through his online expressions, underscores why these laws should be restricted to core cybercrimes.

This article examines the distinction between core cybercrimes and cyber-enabled offenses, the risks posed by overbroad cybercrime laws, and the implications of Farotimi's case for the future of digital rights and governance.

2.0   Understanding Core Cybercrimes

Core cybercrimes are offenses that inherently require ICT systems as both targets and tools. Without these technologies, these crimes would not exist. Examples of such crimes include spreading computer viruses, hacking a bank's servers to steal funds, or launching denial-of-service (DoS) attacks to disable websites are quintessential core cybercrimes. These activities are explicitly technological and could not occur without ICT systems. Without these technologies, these crimes would not exist. The Budapest Convention on Cybercrime, an international treaty regarded as the gold standard for defining cybercrimes, identifies five primary categories:

i. i.   Illegal Access: Gaining unauthorized access to computer systems or networks.

ii.  Illegal Interception: Eavesdropping on communications without permission.

iii. Data Interference: Altering, deleting, or damaging data without authorization.

iv.   System Interference: Disrupting the functionality of computer systems or networks.

v. Misuse of Devices: Creating or distributing tools (like malware) intended for committing cybercrimes.

3.0   Cyber-Enabled Offenses: A Different Domain

In contrast, cyber-enabled offenses are traditional crimes carried out using ICTs as a medium. Crimes like fraud, harassment, defamation, and even terrorism can occur both online and offline. For example, using social media to harass someone is a digital extension of harassment that does not require specialized cybercrime laws to address. Similarly, spreading misinformation online is akin to traditional defamation.

By conflating these offenses with core cybercrimes, many nations have crafted overly broad cybercrime laws, making it easier for authorities to exploit them for political or oppressive purposes. For example, in Turkey, provisions of its cybercrime legislation have been used to suppress online dissent and silence critics of the government under the guise of combating cyber-related threats.

4.0   Dele Farotimi: A Case in Point

Dele Farotimi faces multiple counts charge under the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (As Amended), for statements made during YouTube interviews and press conferences about his book "Nigeria and its Criminal Justice System." The charges stem from his criticisms of alleged corruption in the judiciary and his commentary on specific legal cases. Notably, these charges primarily invoke Section 24(a) and 24(1)(b) of the Cybercrimes Act, which deal with cyberstalking and false information dissemination. The charges appear to target his online statements rather than any activity that constitutes a core cybercrime.

Farotimi's case demonstrates the dangers of conflating core cybercrimes with cyber enabled crimes and the problematic expansion of cybercrime laws beyond their legitimate scope:

i.       Nature of the Activity: Farotimi's actions - expressing opinions about the judiciary and sharing his experiences - are traditional forms of speech that happen to use digital platforms. They don't constitute inherently technological offenses.

ii.         Platform vs. Crime: The only "cyber" element in these charges is the use of YouTube as a communication medium. The underlying activities (criticism, commentary, allegations of corruption) are traditional forms of expression that predate the internet.

5.0    Legal Discrepancy in Dele Farotimi's Cybercrime Charges

5.1.   The Charges as Filed

5.1.1 Section 24(a) - Bullying and Harassing

Several charges allege that Farotimi's statements were made "with the intention of bullying and harassing" named persons. These statements include: (i) comments about legal proceedings, (ii) observations about judicial conduct in specific cases, (iii) criticisms of alleged corruption in the justice system and (iv) expressions of opinion about systemic issues in the legal or justice system.

5.1.2 Section 24(1)(b) - False Information

Other charges claim his statements "contained false information for the purpose of causing breakdown of law and order." The contested statements include: (i) claims about corruption in the judiciary, (ii) discussions of specific court cases and their handling, (iii) commentary on his personal experiences within the legal system and (iv) analysis presented in his book "Nigeria and its Criminal Justice System".

5.2. The Actual Law

Section 24(1): A person who knowingly or intentionally sends a message or other matter by means of Computer Systems or Network that-

(a) is pornographic; or

(b) he knows to be false, for the purpose of causing breakdown of law and order, posing a threat to life or causing such message to be sent: commits an offence under this Act and is liable on conviction to a fine of not more than N7,000,000.00 or imprisonment for a term of not more than 3 years or both.

(2) A Person who knowingly or Intentionally Transmits or causes the Transmission of any communication through a Computer System or Network-

(a) to bully, threaten or harass another person, where such communication places another person in fear of death, violence or bodily harm to another person;

(b) containing any threat to kidnap any person or any threat to harm the person of another, any demand or request for a ransom for the release of any kidnapped person, to extort from any person, firm, association or corporation, any money or other thing of value, or

(c) containing any threat to harm the property or reputation of the addressee or of another or the reputation of a deceased person or any threat to accuse the addressee or any other person of a crime, to extort from any person, firm, association, or corporation, any money or other thing of value, commits an offence under this Act and is liable on conviction-

(i) in the case of paragraphs (a) and (6) of this sub-section, to imprisonment for a term of 10 years or a minimum fine of N25.000,000.00 and

(ii) in the case of paragraph (c) of this subsection, to imprisonment for a term of 5 years or a minimum fine of N15,000,000.00.

5.3. Misapplication of Section 24(2)(a)

The charges cite "Section 24(a)" for harassment whereas under the Act, there is no Section 24(a). The actual Section 24(1)(a) deals with pornography. The relevant harassment provision is in Section 24(2)(a).

While there was indeed a technical error in citing "Section 24(a)" instead of the correct Section 24(2)(a) for harassment, this error does not invalidate the charge or warrant setting aside the conviction if Dele is convicted. This is because established case law holds that when an offense known to law is properly disclosed, the penalty is prescribed in existing law, and neither the accused nor counsel were misled by the incorrect citation, the conviction should stand absent any miscarriage of justice. See the case of ADONIKE v. STATE(2015) LPELR-24281(SC) Per John Inyang Okoro, JSC at Pp 20 - 21 Paras B – E.

Furthermore, Section 220 of the Administration of Criminal Justice Act, 2015 explicitly provides that such errors in stating particulars are not material unless the defendant was actually misled by the error.

Therefore, unless it can be demonstrated that the Dele Farotimi was materially misled by the incorrect section citation or suffered prejudice as a result, the technical error in citing the wrong section number should not affect the validity of the proceedings or the ultimate conviction.

6. The Risks of Overbroad Cybercrime Laws

Farotimi's case raises serious concerns about the intent and application of cybercrime laws. By prosecuting Farotimi for his expressions, the Nigeria Police Force has blurred the lines between protecting against cyber threats and stifling dissent. This misuse of cybercrime laws sets a dangerous precedent, suggesting that such laws can be weaponized against political opponents, activists, and ordinary citizens.

The overreach of cybercrime laws has far-reaching consequences, both for individuals and for society at large.

6.1. Suppression of Free Speech

Cybercrime laws with vague language can easily be used to target individuals exercising their right to free expression. Farotimi's case is just one example of how online speech can be criminalized under the guise of combating cybercrime. This trend threatens to silence dissenting voices and erode democratic principles.

6.2. Overburdening Legal Systems

Overly broad cybercrime laws place significant pressure on already strained legal and enforcement systems. When cybercrime laws expand to include offenses that are not inherently technological—such as online defamation, harassment, or even activism—it can lead to several systemic challenges: 

6.2.1. Diverted Focus from Genuine Threats

Expanding the scope of cybercrime laws forces law enforcement agencies to handle a wide range of cases, many of which do not require specialized cyber expertise. For example, prosecuting an online comment as cyber harassment requires investigative resources that could have been better directed toward identifying and mitigating core cybercrimes like hacking, unauthorized debits from customer bank accounts or ransomware attacks. This misallocation weakens the overall effectiveness of cybersecurity measures. 

6.2.2. Complexity of Digital Investigations

Investigating cyber-related offenses requires significant expertise, advanced tools, and collaboration with international entities. When law enforcement is forced to deal with a high volume of cases, many of which may involve non-criminal online behaviour, they risk becoming bogged down in cases that do not contribute to cybersecurity. This inefficiency not only overburdens legal systems but also reduces public trust in their ability to address critical digital threats. 

6.2.3. Erosion of Trust Between Law Enforcement and the Public

When the Nigeria Police Force uses the Cybercrime Act to prosecute individuals for online speech or activism, it creates an impression of the Police being complicit in political suppression or subjugation. This perceived misuse of resources can undermine public trust in the justice system and foster resentment against the Police. 

Here are some recent examples of cybercrime incidents in Nigeria that underscore the importance of focusing cybercrime laws on core offenses:

Nigerian banks reported a series of fraud-related cybercrimes over the years, with billions lost to hacking and phishing schemes. For instance, a 2022 report detailed how N523 million was stolen from a single account through a coordinated cyber-attack that funnelled money across hundreds of bank accounts.

In 2024, Hope Payment Service Bank reported a massive cyberattack resulting in a loss of over 10 billion. The funds were transferred across multiple accounts, prompting an investigation and court orders to freeze over 800 implicated accounts. This highlights the need for law enforcement to prioritize complex cyber fraud cases over less critical cyber-enabled offenses.

Similarly, Guaranty Trust Bank (GTBank) faced a significant security breach in August 2024, where its website was compromised by hackers. This incident raised fears of customer data theft and caused major disruptions in online banking operations.

In another case, a syndicate hacked into a bank's server to create fictitious credits worth N1.87 billion. This demonstrates the advanced techniques used by cybercriminals and the necessity of robust cybersecurity measures.

These examples show the increasing sophistication of core cybercrimes in Nigeria, and why the Nigeria Police Force should focus its resources and expertise towards preventing, detecting, investigating and prosecuting such crimes using the Cybercrimes Act instead of prosecuting online criticism or defamation using the Cybercrimes Act.

6.3. Chilling Effect on Digital Activity 

The "chilling effect" refers to the discouragement of legitimate online behaviour due to fear of legal repercussions. When cybercrime laws are overly broad or ambiguously defined, they create uncertainty about what constitutes criminal behaviour, leading to self-censorship and reduced participation in digital spaces. 

6.3.1. Impact on Free Expression

People may refrain from posting opinions, criticisms, or controversial content online, fearing that their statements might be interpreted as cyber harassment, defamation, or other offenses. In environments where authorities use cybercrime laws to target dissent, individuals are less likely to engage in public debates, reducing the vibrancy and diversity of digital discourse. 

6.3.2. Stifling Activism and Advocacy

Activists and advocates who rely on digital platforms to organize campaigns, raise awareness, or criticize policies are particularly vulnerable to chilling effects. If they perceive a risk of prosecution under cybercrime laws, they may avoid using these platforms, weakening their impact and ability to mobilize support. 

6.3.3. Hindering Journalism

Journalists such as Fisayo Soyombo, often use digital tools to investigate and publish stories on issues of public interest. However, the threat of cybercrime charges for reporting on sensitive topics can lead to self-censorship. For example, journalists may avoid exposing corruption or misconduct if they fear being accused of spreading false information or defaming individuals under Cybercrimes Act. 

6.3.4. Economic Consequences

The chilling effect can also impact businesses and entrepreneurs. Startups and companies that depend on open digital communication may face challenges if their employees or users are hesitant to engage freely online. This hesitation can stifle growth, collaboration, and the sharing of ideas, ultimately hindering economic progress in the digital space. 

The combined effect of overburdening legal systems and creating a chilling effect on digital activity is a weakened digital ecosystem. Legal systems are less effective in addressing real cyber threats, while individuals and organizations become less willing to engage in online activities that drive progress, innovation, and civic engagement. 

Therefore, restricting cybercrime laws to core offenses ensures that law enforcement can focus on genuine cyber threats, while the public can participate freely in digital spaces without fear of unwarranted prosecution. By refining these laws, governments can strike a balance between maintaining cybersecurity and protecting fundamental rights, preserving the integrity of the legal system and the vibrancy of the digital age.

7. International Perspectives on Cybercrime Laws

The global debate over cybercrime laws highlights the importance of specificity and restraint. The draft UN Cybercrime Convention has been criticized for its overly broad scope. Advocacy groups like the Electronic Frontier Foundation (EFF) and CIVICUS, a global alliance dedicated to strengthening civil society, argue that the convention risks criminalizing acts that are not inherently harmful, such as security research or whistleblowing.

In their critique, the organizations emphasize that cybercrime laws should focus exclusively on core cybercrimes. Core cybercrimes comprise offenses in which ICTs are the direct objects as well as instruments of the crimes; these crimes could not exist at all without the ICT systems. A useful reference for the types of crimes that are inherently ICT crimes can be found in Articles 2-6 of the Budapest Convention: illegal access to computing systems, illegal interception of communications, data interference, system interference, and misuse of devices. For example, spreading a computer virus in the wild; using a password logger to steal someone else's password and access their email or photos; breaking into the computer system of a bank to steal money; using malicious software to delete all the data of a former employer's systems.

8. Lessons for Nigeria and Beyond

Farotimi's case offers a crucial lesson for policymakers in Nigeria and other nations: the need to align cybercrime laws with international best practices and democratic values. This includes:

8.1. Restricting Cybercrime Laws to Core Offenses

Cybercrime laws should address crimes that directly target ICT systems, such as hacking, malware distribution, and data breaches. Cyber-enabled offenses should be handled under existing laws for fraud, harassment, or defamation.

8.2. Safeguarding Free Expression

Cybercrime laws should explicitly protect freedom of expression. Activists, journalists, and ordinary citizens should not face legal repercussions for sharing opinions or engaging in peaceful dissent online.

8.3. Building Capacity to Address Genuine Threats

Law enforcement agencies should focus on developing expertise to combat core cybercrimes effectively. This includes training, resources, and partnerships with international organizations.

9. Conclusion

The case against Dele Farotimi is a stark reminder of the dangers posed by overly broad cybercrime laws. It highlights the need for policymakers to draw a clear line between core cybercrimes and cyber-enabled offenses, focusing on crimes that inherently involve ICT systems.

By refining cybercrime laws to be specific, narrow, and proportional, nations can uphold justice, protect freedoms, and create a safer digital environment. Farotimi's case should serve as a wake-up call, prompting governments worldwide to reconsider the scope and application of their cybercrime frameworks. In doing so, they can strike a balance between security and liberty, ensuring that the digital age remains a space for innovation, expression, and democratic engagement and  cybercrime laws serve their intended purpose, i.e. enhancing cybersecurity, without compromising fundamental rights..