According to a report by law firm RPC, hacking prosecutions in the UK fell by 12% in 2019, compared to the previous year. This means that just 0.33% of the 17,600 hacking crimes reported in the UK in 2019 resulted in prosecutions under the Computer Misuse Act.
RPC said the main reason for the decline in hacking prosecutions was a lack of police resources to investigate such crimes. The company added that the UK government typically focuses its resources on targeting cybercriminals involved in attempts to breach national security .

Furthermore, it is often very difficult to track down and prosecute hackers, as the majority of crimes reported in the UK may be committed in another country. In particular, the RPC pointed out that hackers are more likely to carry out attacks through countries that do not cooperate with UK authorities.
The sharp increase in phishing attacks and scams that have occurred this year is worrying, with hackers using the COVID-19 pandemic as "bait" to deceive and "infect" unsuspecting victims.
For example, in April, Google revealed that it was blocking more than 240 million COVID-19-related spam emails every day, as well as 18 million malware and phishing emails. Many of the emails Google blocked contained malware designed to allow attackers to gain access to the recipient’s system. In many phishing attacks, hackers sent targets emails that purported to come from government agencies or charities asking for donations or attempting to defraud small businesses.

Richard Breavington, a partner at RPC, said: “Tracking cybercriminals is a resource-intensive task. Hackers know how to cover their tracks, and that’s relatively simple. Cybercriminals see hacking as a low-risk activity, with almost no risk of prosecution.
Additionally, Ollie Whitehouse, CTO of NCC Group, highlighted the need for reform of the current legislation, noting the following: “As the global threat landscape evolves and expands and technology becomes increasingly sophisticated, the fact that fewer hackers are being successfully prosecuted in the UK demonstrates the urgent need for new legislation. The Computer Misuse Act – which has been in place for 30 years – was originally introduced to prevent unauthorised access to computer data and systems, but is no longer fit for the 21st century digital world. We want modern legislation to recognise the important role that cybersecurity professionals play in keeping people and businesses safe and protected. We want to transform what constitutes unauthorized access in practice and introduce legal defenses so that cybersecurity professionals can identify and investigate threats without fear of legal action, ensure that cybercriminals are appropriately punished, and ultimately prevent cyberattacks in the future.
