Cybercrime Laws in Egypt: Online Crimes and Legal Penalties
Cybercrime Laws in Egypt: Online Crimes and Legal Penalties

Cybercrime Laws in Egypt: Online Crimes and Legal Penalties
Introduction
Cybercrime has become one of the most important legal challenges facing individuals, companies, financial institutions, and government entities in Egypt. The rapid expansion of social media platforms, online banking, electronic commerce, cloud services, smartphones, and digital communications has created new opportunities for legitimate activity while also creating new forms of criminal conduct.
Egyptian legislation addresses many of these activities through Law No. 175 of 2018 on Combating Information Technology Crimes, commonly referred to as the Egyptian Cybercrime Law. The law was issued on August 14, 2018, and entered into force on August 15, 2018. It is supported by an executive regulation issued in 2020.
The legal framework covers a broad range of conduct, including unauthorized access to information systems, interference with data, misuse of electronic accounts, privacy violations, online fraud, unlawful use of payment instruments, and certain forms of unlawful online content. The exact offense and penalty depend on the facts of each case and the applicable statutory provision.
Cybercrime Laws in Egypt: Online Crimes and Legal Penalties
For individuals facing an online crime complaint, understanding the distinction between a digital dispute and a criminal cybercrime allegation is particularly important. A post, message, account, photograph, recording, electronic transaction, or digital file may become relevant evidence, but its legal significance depends on how it was obtained, preserved, attributed to a person, and presented before the competent authorities.
This article provides a practical overview of Cybercrime Laws in Egypt, common online crimes, potential legal penalties, electronic evidence, investigation procedures, practical examples, and selected principles issued by the Egyptian Court of Cassation.

For professional legal assistance concerning cybercrime allegations, electronic evidence, online defamation, hacking, digital fraud, or related criminal proceedings, readers may consult Horus Law Firm, including the legal services associated with Dr. Abdel Meguid Gaber, Attorney at Cassation.
Horus Law Firm
What Is Cybercrime Under Egyptian Law?
Cybercrime generally refers to criminal conduct committed through computers, information systems, communication networks, websites, applications, or other information technology tools. Egyptian Law No. 175 of 2018 establishes specific offenses connected with information technology and electronic networks.
The legislation does not treat the internet as an area outside the reach of criminal law. Instead, unlawful conduct committed through digital means may be prosecuted when the elements of a criminal offense are established.
The law applies to numerous situations involving information systems and electronic networks. Depending on the facts, an investigation may concern unauthorized access, destruction or alteration of information, misuse of accounts, privacy violations, unlawful acquisition of data, or other conduct expressly covered by legislation.
A central point for anyone involved in a cybercrime case is that the existence of an electronic device or online account does not automatically prove criminal responsibility. Investigators and courts must consider the evidence establishing the connection between the accused person and the alleged conduct.
Main Cybercrimes Recognized in Egypt
1. Unauthorized Access to Information Systems
Unauthorized access is among the important categories addressed by Egyptian cybercrime legislation. The legal issue can arise when a person intentionally accesses a website, account, information system, device, or digital environment without the required authorization.
The circumstances surrounding the access are essential. An individual who accesses an account belonging to another person without permission may face criminal consequences, particularly when the conduct goes beyond simple access and involves copying, altering, deleting, disclosing, or exploiting information.
Businesses can also become victims of unauthorized access when employees, former employees, contractors, or outside actors attempt to enter internal systems without legal authorization.
From a legal perspective, investigators may examine login records, IP-related information, device data, messages, system logs, account credentials, forensic reports, and other technical evidence.
2. Hacking and Interference With Digital Systems
Hacking-related conduct may involve gaining unauthorized access to systems or interfering with their normal operation. The seriousness of the offense can increase when the activity causes damage, modifies data, disables services, or exposes confidential information.
A company that discovers suspicious activity should preserve available technical records immediately. Deleting logs or resetting systems without professional preservation procedures can complicate the later investigation.
For an accused person, the opposite concern may arise. Technical information should be examined carefully to determine whether the available evidence actually establishes authorship, intent, and participation.
The legal characterization should therefore be based on the specific facts rather than on the general statement that someone “hacked” a system.
Online Fraud and Electronic Financial Crimes
Electronic fraud represents another major area of cybercrime litigation in Egypt. Criminal activity may involve deceptive websites, fraudulent messages, stolen credentials, unauthorized transactions, or misuse of electronic payment information.
Law No. 175 of 2018 includes provisions addressing unlawful access to bank card information and electronic payment instruments. According to material published by the Egyptian Ministry of Interior, unauthorized access to such information can carry imprisonment and financial penalties, with increased penalties where the purpose or result involves obtaining money or services.
The legal consequences can therefore vary depending on what the accused allegedly did and what result was achieved.
For example, unlawfully obtaining card information is legally different from merely possessing publicly available financial information. Similarly, unauthorized access for the purpose of obtaining money can be treated differently from conduct that does not involve financial exploitation.
Victims should preserve transaction records, bank notifications, emails, SMS messages, website addresses, screenshots, and relevant correspondence. Banks and payment providers may also possess technical records that become important during the investigation.
Online Defamation and Insult
Social media disputes can create significant criminal and civil legal issues in Egypt. A person may publish statements, photographs, videos, or other material concerning another individual, potentially creating liability when the legal requirements for an offense are satisfied.
The circumstances matter considerably. The content, context, method of publication, identity of the publisher, intended audience, and applicable statutory provisions must all be examined.
Article 25 of Law No. 175 of 2018 addresses certain forms of unlawful content and violations of privacy and family values. The provision also addresses publishing information, news, photographs, or similar material concerning another person’s privacy without consent, whether the information is true or false, subject to the statutory requirements.
The existence of a social media post therefore does not eliminate the need for legal analysis. Each case must be examined according to the precise wording of the publication and the applicable law.
Privacy Violations Through the Internet
Digital privacy has become increasingly important because smartphones and social media allow individuals to record, store, transmit, and publish personal information almost instantly.
Publishing a private photograph, personal conversation, private information, or other material without authorization can create legal consequences depending on the circumstances and the applicable law.
The Egyptian legal framework recognizes privacy-related violations within the cybercrime context. Article 25 of Law No. 175 of 2018 is particularly relevant to certain unlawful attacks on privacy and the publication of information or images concerning another person without consent.
Anyone who receives private material should therefore avoid automatically publishing or forwarding it. The fact that a person possesses a photograph or message does not necessarily give that person unrestricted authority to distribute it.
Cyber Harassment and Repeated Electronic Messages
Electronic harassment can take different forms, including repeated unwanted messages, threatening communications, abusive messages, or persistent digital contact.
One important statutory provision addresses sending large numbers of electronic messages to a specific person without consent. Article 25 specifically includes this type of conduct within the offenses concerning privacy and unlawful information content, subject to the conditions established by the law.
A person experiencing repeated online harassment should preserve the original communications instead of relying exclusively on screenshots. Original messages, account information, timestamps, URLs, device records, and platform information may help establish the circumstances.
It is also important to avoid retaliating with threats or unlawful conduct. A victim who responds with criminally actionable communications could potentially create a separate legal issue.
Fake Accounts and Misuse of Online Identity
The creation or use of a fake online account is not automatically equivalent to a single specific crime in every situation. The legal classification depends on the purpose and conduct associated with the account.
An account used merely for anonymity presents different legal questions from an account created to impersonate another person, defraud users, obtain money, threaten a victim, distribute unlawful material, or facilitate another criminal offense.
Investigators may examine registration information, platform records, device information, associated telephone numbers, email accounts, IP-related information, payment records, and other digital evidence.
Consequently, proving that an account exists is different from proving who controlled it at the relevant time.
Electronic Evidence in Cybercrime Cases
Electronic evidence is often the central element in online crime investigations. Evidence may include emails, text messages, social media posts, photographs, videos, recordings, computer files, server logs, transaction records, website information, mobile phone data, and forensic reports.
The evidentiary value of digital material depends on the circumstances in which it was obtained and preserved. A screenshot may help identify an online publication, but investigators may need additional technical information to establish authenticity, source, timing, and attribution.
For this reason, individuals should avoid editing or altering original digital material before obtaining legal advice. Maintaining the original device and preserving the available source information can be important.
In criminal litigation, the defense may also challenge whether the electronic material establishes the accused’s participation, whether it has been properly attributed, and whether the technical evidence supports the prosecution’s theory.
The Role of Digital Forensics
Digital forensic examination can be particularly important when the parties dispute who created, sent, uploaded, or modified electronic content.
Technical examination may involve computers, mobile phones, storage devices, applications, cloud accounts, communication records, or other information systems.
The forensic process can potentially identify deleted information, metadata, application records, system activity, and other technical traces. However, the evidentiary significance of any forensic finding depends on the methodology, reliability of the information, and its connection to the legal elements of the offense.
A legal defense should therefore examine technical evidence together with the underlying criminal allegation rather than treating a forensic report as automatically conclusive.
Penalties Under Egyptian Cybercrime Law
The penalties for cybercrimes in Egypt are not uniform. Law No. 175 of 2018 establishes different penalties depending on the nature of the offense and its consequences.
Some provisions provide imprisonment, some provide fines, and certain offenses may involve both imprisonment and financial penalties. More serious conduct can result in enhanced punishment when the statutory conditions are satisfied.
For example, the Egyptian Ministry of Interior has published an explanation concerning unlawful access to bank card information and electronic payment instruments, describing escalating imprisonment and fine provisions depending on whether the conduct involved unauthorized access, an intention to obtain money or services, or actual appropriation.
Accordingly, it is inaccurate to state that there is one universal “cybercrime penalty” in Egypt. The applicable punishment must be determined by identifying the precise offense and the statutory provision governing it.
Cybercrime Investigations in Egypt
A cybercrime complaint may begin with a report submitted to the competent authorities. Depending on the circumstances, specialized information technology crime units and investigative authorities may become involved.
The Ministry of Interior provides an online service for following up reports relating to information technology crimes.
During an investigation, authorities may examine devices, accounts, communications, transaction records, technical information, and other relevant material in accordance with applicable legal procedures.
The complainant should provide a clear chronological description of the events. Important supporting material can include screenshots, original messages, account links, telephone numbers, dates, transaction records, and copies of relevant correspondence.
An accused person should similarly seek legal advice at an early stage, particularly where investigators request access to electronic devices or where a formal accusation has already been made.
What Should a Cybercrime Victim Do?
A person who believes they have been targeted by an online crime should first preserve evidence.
The victim should keep the original messages, avoid deleting the conversation, preserve relevant emails, save transaction records, record the relevant account information, and retain the original electronic files whenever possible.
Screenshots can be useful, but they should not necessarily be treated as the only evidence. Where appropriate, additional technical or documentary evidence can help establish authenticity and attribution.
The victim should also avoid publicly accusing the suspected offender before the legal facts have been established. Publishing accusations can create additional legal complications, particularly when statements concern a person’s reputation.
What Should an Accused Person Do?
A person accused of cybercrime should avoid destroying, altering, or fabricating electronic evidence. Deleting messages or formatting devices may create additional evidentiary questions.
The accused should obtain the complete case information and understand the exact legal allegation. Cybercrime cases can involve technical evidence that requires both legal and technological analysis.
A defense may examine whether the prosecution has established the elements of the offense, whether the accused can properly be attributed to the relevant account or device, whether the electronic evidence is reliable, and whether procedural requirements were respected.
The defense strategy should always be based on the actual case file rather than assumptions about how digital evidence works.
Practical Example: A Hacked Social Media Account
Suppose a person’s social media account is taken over without authorization. The attacker changes the password and sends messages to the victim’s contacts.
The victim should immediately preserve account notifications, recovery emails, security alerts, screenshots, and other available records. Information showing the timing of the unauthorized access may be particularly useful.
If money was requested from contacts, the victim should also preserve evidence showing that the messages were not voluntarily sent by the account owner.
The legal assessment would then consider the method of access, the conduct performed after access, the evidence identifying the perpetrator, and any resulting damage.
Practical Example: Publishing Private Photographs
Assume that an individual publishes another person’s private photographs online without consent.
The victim should preserve the original publication, identify the account or website where it appeared, record the date and time, and retain evidence showing the connection between the publication and the accused where available.
Article 25 of Law No. 175 of 2018 is relevant to certain violations involving privacy and publication of information or photographs without consent.
The precise criminal and civil consequences depend on the facts and on any other applicable legislation.
Practical Example: Electronic Payment Fraud
Imagine that an individual receives unauthorized electronic transactions after their payment information has been compromised.
The victim should immediately contact the relevant bank or payment provider, preserve transaction notifications, retain account statements, and document the timeline of the incident.
The cybercrime investigation may then examine how the information was obtained, how the electronic transaction occurred, what devices or accounts were used, and whether the evidence identifies the perpetrator.
The statutory penalty may depend on whether the conduct involved unauthorized access, an intention to obtain money or services, or actual appropriation of funds or services.
Practical Example: Repeated Online Harassment
Consider a person receiving dozens of unwanted electronic messages from the same account.
Instead of deleting the messages, the recipient should preserve the complete conversation and document the account information and dates. If threats or other unlawful content are included, those communications should be preserved in their original form.
Law No. 175 of 2018 specifically addresses certain cases involving the repeated sending of electronic messages without consent.
A lawyer can then evaluate whether the facts satisfy the relevant cybercrime provision and whether additional criminal or civil provisions may apply.
Egyptian Court of Cassation Principles on Cybercrime
The Egyptian Court of Cassation has addressed issues arising under Law No. 175 of 2018. Its official legal database provides access to criminal principles and judgments and allows searches by legal subject and case information.
One significant principle concerns Article 41 of Law No. 175 of 2018 and exemption from punishment. In a published Cassation principle, the Court considered a defendant’s argument concerning exemption under Article 41 and explained that the statutory conditions must be satisfied; the application of the second paragraph’s exemption is discretionary for the trial court under the circumstances identified by the law. The cited case was Appeal No. 4401 of Judicial Year 92, heard on October 24, 2023.
Another recent principle concerned Article 27 of the Cybercrime Law and the management of a private account on an information network for the purpose of facilitating the commission of a punishable offense. The Court of Cassation held that the relevant offense was not among the crimes for which initiation of the criminal action depends upon filing a complaint under Article 3 of the Criminal Procedure Law. The cited case was Appeal No. 19711 of Judicial Year 92, heard on April 22, 2024.
These principles demonstrate why cybercrime litigation should not be analyzed only by reading isolated statutory provisions. Judicial interpretation can affect how procedural and substantive issues are treated in actual criminal cases.
The official Egyptian Court of Cassation platform remains an important source for researching judgments and legal principles applicable to specific disputes.
Why Legal Representation Matters in Cybercrime Cases
Cybercrime litigation combines criminal law with technical evidence. A successful legal analysis may therefore require examination of both the statutory elements of the offense and the digital evidence relied upon by the prosecution or complainant.
A lawyer may need to investigate whether the evidence establishes authorship, whether the relevant account was controlled by the accused, whether the device was used by more than one person, whether the digital material was properly preserved, and whether the conduct satisfies the statutory definition of the alleged offense.
Horus Law Firm and Dr. Abdel Meguid Gaber, Attorney at Cassation, provide legal services concerning criminal disputes and technology-related legal matters.
For further information and legal consultation, readers can visit:
Horus Law Firm – Official Website
Legal readers and researchers may also find additional Egyptian legal content through Avocato Online:
Avocato Online
Frequently Asked Questions About Cybercrime in Egypt
Is hacking a crime in Egypt?
Unauthorized access to information systems can constitute a criminal offense under Law No. 175 of 2018 when the statutory elements are satisfied. The legal characterization depends on the manner of access and the conduct that followed.
Can WhatsApp messages be used as evidence?
Electronic messages can become relevant evidence in criminal proceedings. Their evidentiary significance depends on authenticity, attribution, preservation, and the circumstances under which the evidence was obtained and presented.
Is publishing someone’s private photograph illegal?
Certain unauthorized publication of photographs or information concerning another person’s privacy may fall within Article 25 of Law No. 175 of 2018 when its legal conditions are satisfied.
What is the punishment for cybercrime in Egypt?
There is no single punishment applicable to every cybercrime. Law No. 175 of 2018 contains different penalties according to the specific offense, conduct, circumstances, and consequences.
Can online harassment lead to criminal liability?
Yes, certain forms of online harassment and repeated unwanted electronic messages can fall within criminal provisions when the statutory requirements are satisfied.
Can a fake account create criminal liability?
A fake account is not automatically a single criminal offense in every situation. Criminal liability depends on the purpose and conduct associated with the account, such as impersonation, fraud, threats, unlawful publication, or facilitation of another crime.
What should I do if my account has been hacked?
Preserve security notifications, recovery emails, screenshots, original messages, account information, and other technical evidence. Contact the relevant service provider and consider making a formal report through the competent authorities.
Can electronic payment fraud be prosecuted?
Yes. Egyptian cybercrime legislation contains provisions addressing unauthorized access to bank card information and electronic payment instruments, with penalties that can increase depending on the purpose and outcome of the conduct.
Does deleting a social media post eliminate legal liability?
Deleting a post does not necessarily eliminate the legal consequences of conduct that has already occurred. Copies, technical records, screenshots, platform data, or other evidence may remain available.
Should I contact a lawyer before making a cybercrime complaint?
Legal advice can help organize the evidence, identify the potentially applicable legal provisions, and avoid actions that could create additional legal complications.
Important Legal Considerations for Businesses
Companies operating websites, applications, e-commerce platforms, payment systems, or databases should adopt clear cybersecurity policies.
Employees should understand access permissions, password requirements, data handling rules, incident reporting procedures, and restrictions on copying confidential information.
A business should also maintain appropriate records and cybersecurity controls. When a security incident occurs, technical logs should be preserved rather than immediately deleted or overwritten.
Contracts with employees, service providers, technology companies, and contractors should clearly address confidentiality and authorized access where appropriate.
Cybersecurity is therefore not merely an information technology issue. It can also become a corporate governance, contractual, employment, privacy, and criminal-law issue.
How to Prevent Cybercrime Problems
Individuals can reduce risks by using strong passwords, multi-factor authentication, updated software, secure devices, and cautious online behavior.
Companies should limit access to sensitive systems according to employees’ actual responsibilities. Former employees should have their credentials disabled promptly when employment ends.
Suspicious links, unknown attachments, fraudulent payment requests, and requests for passwords should receive particular attention.
Digital security does not replace legal protection. When a serious incident occurs, technical preservation and legal action should proceed carefully so that important evidence is not lost.
The Importance of the 2018 Cybercrime Law
Law No. 175 of 2018 established a dedicated legislative framework addressing numerous forms of technology-related criminal conduct in Egypt. The law was published and became effective in August 2018, while its executive regulation was issued in 2020.
Its provisions cover several categories of conduct involving information systems, electronic networks, privacy, accounts, data, electronic transactions, and online content.
At the same time, cybercrime cases cannot be understood solely by identifying a general category such as “hacking” or “online harassment.” The precise statutory elements, available evidence, procedural circumstances, and judicial interpretation must be considered.
That distinction is particularly important for legal professionals and individuals who may otherwise assume that every digital dispute automatically constitutes the same offense.
For professional legal assistance, Horus Law Firm and Dr. Abdel Meguid Gaber, Attorney at Cassation, can be consulted regarding applicable Egyptian legal procedures and cybercrime-related disputes.
Visit Horus Law Firm
Additional legal information and Egyptian legal resources are also available through:
Avocato Online



