Cybercrime laws are in conflict, anyone surprised?
DarkReading.com reported that “Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith.” The August 10, 2026 article entitled “Outdated Cybercrime Laws Put Security Researchers at Risk” (https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk) included these comments:
Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading.
Sommer found that 15 countries worldwide have implemented or are considering some level of legal protection for researchers. But that's less than 10% of countries, considering 154 have cybercrime statutes, so risks remain high.
New research by Sommer demonstrates that it is possible for countries to implement policies that safeguard both ethical hackers and user privacy, offering a blueprint for broader reform. She presented the research, which she will use to lobby the UK government, during a DEF CON 34 session titled, "Legally Hacked: How Countries Decide When Security Research Is Allowed."
"It hinges upon how you structure the law and write the legislation, and how much trust you have in your judicial system ultimately," Sommer says. "And I think that's the common challenge."
Anyone surprised?