The UN Treaty That Can Launder Spyware Evidence

Canada signed the UN Cybercrime Convention. A cross-border evidence-sharing channel that, once ratified, can launder data stolen by spyware.

The fact


On 16 July 2026, Canada signed the United Nations Convention against Cybercrime. No small thing: Canada had fought the very launch of these negotiations, and it was absent from the opening ceremony in Hanoi in October 2025. The reversal is total, and it went almost unnoticed.


A quick calendar reminder, because it changes everything. The Convention was adopted by the UN General Assembly in December 2024, opened for signature in October 2025, and Canada has just added its name. But signing is not ratifying. The text currently has more than 70 signatories, but only a handful of ratifications, and it enters into force only 90 days after the 40th instrument of ratification is deposited. In other words, nothing is operational yet. What is at stake is the trajectory.


And it is worth pausing on. Behind the reassuring name “convention against cybercrime” hides a cross-border evidence-sharing agreement whose scope reaches far beyond hacking.


Why it matters to you


Let’s start with what is written in black and white. The treaty’s investigative powers do not target only “cyber” offences: they cover the electronic evidence of any crime whatsoever. International cooperation, for its part, extends to any “serious crime”, defined as an offence punishable under domestic law by at least four years in prison.

Translation: a repressive state that has criminalised journalism, activism or homosexuality could turn its own laws into triggers for evidence collection on the other side of the world, once the treaty is in force.


Then comes the angle that hurts. According to Kate Robertson’s analysis, at the Citizen Lab, of the draft text, articles 46 to 48 set up sharing channels she calls “secretive”, with no restriction on the territorial origin of the data and, above all, no prohibition whatsoever on sharing data obtained through spyware.

Article 40 mandates mutual assistance to the “widest measure possible”, and articles 47 and 48 authorise direct police cooperation and joint investigations that invite forum shopping, that bargain-hunting across jurisdictions, toward the ones most accommodating to spyware.


The point to hold onto: nothing in the text requires evidence to have been obtained lawfully in order to circulate. That is an established fact, not a guess. The risk, for its part, is projected but argued: once ratified, this treaty can serve to bring in through the front door data that spyware stole through the window. Robertson puts it bluntly, this text is “poised to become a vehicle for complicity in the global mercenary spy trade”. Laundering is not a dirty word here, it is the mechanism.


This is exactly the logic of Chat Control / CSAR, whose final trilogue we followed closely, seen from another angle. The EU wants to force the scanning of your messages client-side, before encryption. The UN, for its part, doesn’t touch your crypto: it legalises the circulation of evidence once it exists, whatever its provenance. Two ends of the same pipe. And this treaty is not an isolated case, it is the 20th piece of the convergence of global texts we have been tracking for months, after the 19 already logged.


The real trap is not the jurisdiction of the courts, it is the extraterritorial reach of the cooperation. Robertson warns that “the treaty’s overbreadth and extraterritorial jurisdiction will further increase the risks for security researchers”. Michael Geist, for his part, calls it a surveillance treaty in disguise and cites a letter from twenty Canadian organisations warning of “a standing channel for transnational repression” aimed at diasporas. And more than 120 security experts fear seeing good-faith research criminalised.


Let’s be fair: the treaty has its defenders, INTERPOL welcomed its adoption, and the idea of cooperating against real cybercrime is not illegitimate. The problem is the near-total absence of safeguards. No mandatory independent judicial oversight, authorisation left to domestic law, gag orders allowed (silence orders that forbid revealing a request even took place), no political-offence exception, no mechanism to suspend a state that tramples human rights. The protections remain largely optional.


What you do now


Nothing to install, nothing to patch: the treaty is not in force, and this is not a product flaw. It is a regulatory trajectory, and a trajectory is something you watch. If you are a journalist, security researcher, whistleblower or member of an exposed diaspora, you are the one the extraterritorial reach targets first.


1. Watch ratification, not signature. The counter that counts is the one tracking the 40 ratifications: until it is reached, the text has no effect.


2. Demand from your representatives an explicit reservation on the origin of evidence. A treaty is ratified with national guarantees: that is where, in the implementing laws, the real fight is won or lost.


3. Encrypt by default and compartmentalise. What Signal, Proton and good data hygiene never produce, no one will ever be able to share. The best rampart against an evidence channel is still not generating the evidence.


The good news is that a text not yet ratified is still a text you can rein in. The bad news is that almost no one is watching. Be one of the few who watch.


Sources