Cybercrime in Kuwaiti Law: Extortion, Defamation and Online Fraud (2026)
25 July 2026

A comprehensive legal guide to cybercrime in Kuwait under Law No. 63 of 2015, covering unlawful access, electronic extortion, impersonation, online defamation, financial fraud, digital evidence and reporting procedure.

Introduction

Cybercrime in the State of Kuwait is no longer a technical matter confined to specialists; it has become a daily legal reality affecting individuals, companies, and government bodies alike. With the vast expansion in the use of smartphones, social media applications, and digital payment services, traditional patterns of wrongdoing — theft, fraud, defamation, and threats — have migrated into the digital space and acquired new characteristics: rapid dissemination, ease of concealing identity, and indifference to geographical borders.

The Kuwaiti legislator recognised this transformation at an early stage and enacted the Law on Combating Information Technology Crimes No. 63 of 2015 as the specific framework governing this category of offences, alongside the Electronic Transactions Law No. 20 of 2014, which established the evidential authority of the electronic record and signature, while the Penal Code No. 16 of 1960 remains the general reference supplementing these provisions wherever no special text applies. Together these instruments form an integrated legislative system criminalising attacks on data and systems, protecting persons from extortion, defamation, and impersonation, and pursuing the various forms of digital financial fraud.

This article provides a comprehensive and precise legal explanation of the rules governing cybercrime under Kuwaiti law: the scope of criminalisation, the constituent elements of each offence, the settled principles of the Court of Cassation concerning digital evidence, and the practical procedures for lodging a complaint and preserving evidence, together with an analysis of commonly encountered hypothetical scenarios.

Quick Answer

  • Primary legislation: Law on Combating Information Technology Crimes No. 63 of 2015, the special statute governing offences committed by means of a computer, an information network, or any information technology device.
  • Complementary legislation: Electronic Transactions Law No. 20 of 2014 (evidential authority of electronic records and signatures), the Penal Code No. 16 of 1960 (general rules of criminal liability and punishment), and the Code of Criminal Procedure as the reference for investigation and evidence gathering.
  • Governing criterion: The use of an information technology means in the commission of the act, whether that means is the object of the offence (such as hacking a system) or its instrument (such as defamation through a messaging application).
  • Principal forms of criminalisation: Unlawful access to systems and data, electronic extortion, impersonation of identity, defamation and insult through social media, electronic financial fraud, and interference with personal and banking data.
  • Jurisdiction: The Public Prosecution conducts the investigation and prefers charges; the criminal courts hear the case. A specialised department within the Ministry of Interior handles cybercrime and receives complaints.
  • Digital evidence: Legally admissible where the integrity of its source and chain of preservation is established; its probative weight lies within the discretionary authority of the trial court.
  • Timing: Prompt reporting is decisive in practice, since connection data and digital logs are retained by service providers only for limited periods, and delay results in the loss of evidence.

I. The Legislative Framework for Combating Cybercrime in Kuwait

1. Law on Combating Information Technology Crimes No. 63 of 2015

This statute is the cornerstone of the Kuwaiti system for combating digital crime. It responded to the inability of traditional provisions to accommodate acts committed in an electronic environment: the general provisions of the Penal Code presuppose a tangible object of attack, whereas data, software, and digital accounts are intangible in nature and do not readily fall within classical descriptions of theft or destruction.

The statute widened the scope of criminalisation to embrace two principal categories:

  • First category — offences in which technology is the object of the attack: unlawful access to an information system, disabling systems, destroying, altering, or copying data without right, and the unlawful interception of data in transmission.
  • Second category — offences in which technology is the instrument of the attack: extortion, threats, defamation, insult, impersonation, and fraud, where committed through an information technology means.

An important feature of the statute is that it did not repeal the Penal Code but operates in conjunction with it. The rule is that the special provision prevails over the general within its field, while recourse is had to the general rules of the Penal Code on matters not specially regulated — attempt, complicity, excuses, mitigating and aggravating circumstances, and the concurrence of offences.

2. Electronic Transactions Law No. 20 of 2014

This statute addresses the civil and commercial dimension of the digital environment, establishing the evidential authority of the electronic record and electronic signature and placing them — where conditions of reliability are met — on a footing close to paper documents for the purposes of proof. It is not devoid of a penal dimension, since it punishes forms of interference with electronic signatures and certification credentials and the impersonation of their holders.

Its significance in the cybercrime context is twofold:

  • Evidential dimension: It provides a legal basis for relying upon electronic documents, messages, and records, assisting the victim in proving the digital attack.
  • Substantive dimension: It criminalises forgery and impersonation connected with electronic signatures and authentication tools, acts that frequently overlap with electronic financial fraud.

3. Penal Code No. 16 of 1960

The Penal Code remains the general reference from which the overarching rules of criminal responsibility are drawn: the material and mental elements, general and specific criminal intent, attempt, complicity by incitement, agreement, or assistance, and the grounds excluding unlawfulness or responsibility. It also remains the reference for traditional offences committed in digital form but not covered by the special statute, such as certain forms of threat, coercion, and invasion of privacy.

Accordingly, the correct legal characterisation of a digital incident calls for a twofold examination: do the provisions of Law No. 63 of 2015 apply as the special statute? And if not, do the provisions of the Penal Code apply, treating the matter as a traditional offence committed by a modern means?

4. Related Legislation of Indirect Relevance

  • Consumer Protection Law No. 39 of 2014: Provides additional protection in disputes concerning online shopping and misleading advertising on digital platforms.
  • Copyright and Neighbouring Rights Law No. 22 of 2016: Governs digital infringement of works, software, and protected content.
  • Civil and Commercial Procedure Law No. 38 of 1980: The reference for civil claims seeking compensation for harm arising from a cyber offence.

II. Offences Against Systems and Data

1. Unlawful Access to an Information System

This is the parent offence under Law No. 63 of 2015. It is committed where the perpetrator accesses an information system, website, or electronic account without authorisation from the person entitled to grant it, or exceeds the limits of the authorisation granted. It is immaterial whether access is achieved by technical intrusion or by the use of a password unlawfully obtained.

The material element comprises three components:

  • The act of access: Completed upon entry into the system or account, even absent any subsequent dealing with the data. The legislator criminalised access itself in order to protect the inviolability of the system.
  • Absence of authorisation: The essence of unlawfulness, inferred from the existence of technical protection or from the nature of the relationship between the parties. Importantly, past authorisation does not mean continuing authorisation: an employee who retains a password after the end of service and uses it accesses the system without authority.
  • The object of the offence: An information system, network, website, email account, or social media account. In practice the concept has expanded to encompass application accounts and cloud services.

The mental element is general criminal intent: the perpetrator's knowledge that he is entering a system he has no right to enter, and the direction of his will towards that act. No specific intent — such as an intention to harm or to profit — is required, although the occurrence of an additional result (viewing, copying, or deleting data) constitutes an aggravating circumstance increasing the penalty.

2. Aggravated Forms of Unlawful Access

  • Access coupled with viewing data: Where the perpetrator views private correspondence, financial data, or medical records.
  • Access coupled with copying or transfer: Including screen capture, downloading files, or transferring data to another medium.
  • Access coupled with alteration, deletion, or destruction: The gravest form, given the destruction of the value of the data.
  • Access to government systems or financial institutions: An aggravating circumstance given the severity of the impact on the public interest and on confidence in the financial system.
  • Commission by an employee in connection with his employment: Exploitation of office is treated as aggravating because it breaches the duty of trust.

3. Disabling Systems and Destroying Data

The law criminalises every act resulting in halting an information system, disabling it, slowing its performance, or blocking access to it, as well as destroying, distorting, deleting, or concealing data. This encompasses conduct involving the dissemination of malicious software and ransomware, which encrypts the victim's data and demands payment for its release — a form combining the offences of destruction and extortion simultaneously.

4. Interception of Data and Digital Eavesdropping

Criminalisation extends to the unlawful interception of data in the course of transmission across a network, and the capture of messages, calls, or data without the consent of the person concerned and without legal basis. This form intersects with the constitutional and statutory protection of the inviolability of correspondence and private life — a protection that is not forfeited merely because the communication is digital.

5. Misuse of Hacking Tools and Programs

The legislator did not confine itself to criminalising the act of intrusion but extended to criminalising the production, possession, provision, or trading in programs and tools designed for the commission of these offences, where the intention is to use them for an unlawful purpose. The rationale is early preventive intervention before actual harm materialises.

III. Offences Against Persons Committed by Electronic Means

1. Electronic Extortion

Electronic extortion consists in threatening the victim with the publication of images, recordings, information, or conversations affecting honour, reputation, or private life, in order to compel the victim to act, to refrain from acting, or to pay a sum of money. It ranks among the most damaging digital offences given the immense psychological pressure it inflicts, and because it frequently targets those most vulnerable to social exposure.

Its constituent elements are as follows:

  • The act of threatening: Realised by any digital means — text message, chat, comment, email — and need not be express; an implied or veiled threat suffices where its menacing sense is understood.
  • The subject of the threat: Publication of material affecting honour, reputation, or private life, whether the content is genuine or fabricated, since the truth of what is threatened to be published is not a condition of the offence.
  • The intended purpose: Compelling the victim to act or refrain, or obtaining a financial or non-financial benefit.
  • Criminal intent: The perpetrator's knowledge of the nature of his act and the direction of his will towards intimidating the victim to achieve his purpose.

A practically vital point is that the offence is complete upon the threat, even if the victim does not comply and nothing is in fact published. Equally, the victim's compliance does not extinguish the offence; it serves rather as evidence of the pressure exerted. Victims are consistently advised not to pay, since payment rarely ends the extortion and usually invites renewed demands.

2. Impersonation and Digital Identity Theft

Electronic impersonation means assuming the identity or capacity of another, or using their data, images, or name in an account, website, or application, so as to lead others to believe that the impersonator is the genuine holder. It has become widespread in two principal forms:

  • Fake accounts: Creating an account in a real person's name and image to publish content falsely attributed to them, or to communicate with their circle for purposes of harm or fraud.
  • Impersonation of an official body or institution: Sending messages in the name of a bank, government entity, or telecommunications company to elicit data — known as phishing — in which the offences of impersonation and fraud coincide.

The penalty is aggravated where impersonation is coupled with harm to others or the obtaining of an unlawful benefit. Impersonating a public official or an official body is regarded as particularly grave given its impact on confidence in public services.

3. Defamation and Insult Through Social Media

Electronic defamation means attributing to a person a fact which, if true, would expose them to punishment or to contempt among their compatriots, or which affects their honour and reputation, by means of an information technology device. Doctrine and case law distinguish three graduated forms:

  • Slander (qadhf): Attributing a specific fact affecting honour or reputation.
  • Insult (sabb): Injuring honour or standing without attributing any specific fact, as through abusive language or demeaning epithets.
  • Disclosure of private life: Publishing matters relating to private life even where true, since the defence of truth is not admitted here.

The most significant legal features of these offences in the digital environment are:

  • Publicity is inherently satisfied: Publication on a social platform or in an open group chat fulfils the element of publicity which aggravates the penalty, and no particular number of viewers is required.
  • Re-publication is an independent liability: A person who re-publishes defamatory content, shares it, or comments in a manner endorsing it may be liable as principal or accomplice — among the matters users most commonly overlook.
  • Deletion does not erase the offence: The offence was completed upon publication; subsequent deletion may be considered in mitigation of sentence, not as a ground of extinction.
  • A pseudonym confers no immunity: The true identity may be reached through subscription data and connection addresses.

A distinction must be drawn between permissible criticism and criminal defamation. Objective criticism directed at an idea, a performance, or a service, resting on accurate facts and expressed without descending into personal disparagement, remains within the sphere of freedom of opinion. Once an opinion crosses into an attack on the person and their honour, or rests upon false assertions of fact, it enters the sphere of criminality.

4. Invasion of Privacy and Personal Data

Criminalisation extends to capturing images or recording conversations in a private place without the consent of the person concerned, and to publishing what has been captured or recorded, even absent insult or slander. It further extends to disclosing personal data obtained by virtue of employment or by unlawful means. The gravity increases where the data is medical, financial, or familial in nature.

IV. Electronic Financial Fraud

1. Concept and Distinction from Traditional Fraud

Electronic financial fraud is the appropriation of another's money or financial data through fraudulent devices relying on an information technology means. It shares the essence of traditional fraud — obtaining property by deception — but is distinguished by the capacity of digital means to reach large numbers simultaneously, the ease of concealing the perpetrator's identity, and the speed with which proceeds are moved across multiple accounts.

2. Principal Practical Forms

  • Phishing: Sending messages or links imitating bank or government websites to induce the user to enter confidential data, which is then used to transfer funds.
  • Capture of the verification code: Persuading the victim to disclose the one-time code sent to their phone under the pretext of updating data or claiming a prize — the most prevalent pattern and the swiftest in causing loss.
  • Fictitious shops and advertisements: Offering goods or services on social platforms and collecting payment without delivery, or delivering a materially different product.
  • Fictitious investments and digital currencies: Promoting investment opportunities with unrealistic returns, or unlicensed wallets and platforms, building initial trust with small payments before appropriating larger sums.
  • Impersonation of an official body to demand fees: Fake notifications of fines, taxes, or customs duties accompanied by a fraudulent payment link.
  • Business email compromise: Hacking or imitating a company's email and directing the client to settle sums into a different bank account — a pattern targeting companies and causing severe losses.

3. Constituent Elements

  • Use of fraudulent devices: A bare lie does not always suffice; the deception must be supported by external manifestations creating an appearance of genuineness, such as a fake website, a fabricated document, or an assumed identity.
  • Delivery of property induced by the deception: A causal link is required between the fraudulent device and the delivery of money or data; where delivery occurred for another reason, the element is absent.
  • Specific criminal intent: The intention to appropriate the delivered property without right.

4. Concurrent Civil Liability

The consequences do not stop at criminal punishment. The victim is entitled to claim compensation for both material and moral harm, either by joining a civil claim to the criminal proceedings or by bringing an independent action before the civil court. Compensation covers loss sustained and profit foregone, as well as moral harm consisting in injury to reputation and standing and in psychological distress.

V. Settled Principles of the Kuwait Court of Cassation

Through its consistent rulings, the Kuwait Court of Cassation has established principles that operate today as governing practical rules in cybercrime disputes and matters of digital evidence. The most prominent are:

  • Conditional authority of digital evidence: It is settled that evidence derived from electronic means is admissible in criminal proof, provided it was lawfully obtained and the court is satisfied as to its integrity and freedom from tampering. Where a serious doubt arises as to its source or preservation, it loses its probative force.
  • Discretion of the trial court: Judicial practice holds that the assessment of evidence — including technical reports and digital examination records — falls within the exclusive province of the trial court, beyond review by the Court of Cassation where the ruling rests on sound reasoning grounded in the record.
  • Apparent ownership of an account is insufficient: It is settled that the mere attribution of an account or device to a person does not alone justify conviction; the court must be satisfied that the accused personally committed the act, given the possibility that the account was used by another or compromised. Technical evidence must therefore be reinforced by other indicia.
  • Publicity satisfied by digital publication: Judicial practice holds that publication over the information network or messaging applications satisfies the element of publicity where the content is accessible to an indeterminate number of persons, without requiring a specific number of viewers.
  • Independent liability of the re-publisher: It is settled that a person who re-publishes or adopts content injurious to another may incur criminal liability independently of the original publisher, since re-publication is a fresh material act widening the circle of harm.
  • Subsequent consent does not erase the offence: Judicial practice holds that offences affecting the public interest are not extinguished by the victim's waiver save where the law so provides, and that a waiver may be considered in assessing the penalty without of itself terminating the action.
  • Adequacy of reasoning in technical offences: The judgment must disclose the content of the technical evidence and the reasons that led the court to accept it, failing which it is vitiated by nullifying deficiency — particularly in offences proved by specialised technical reports.

Methodological note: The principles set out above are settled principles applied in judicial practice. Reference should always be made to the specific judgment relevant to the facts of each dispute, since the application of a principle varies with the facts, the documents, and the findings of the technical investigation in the particular case.

VI. Digital Evidence and Practical Reporting Procedure

1. The Nature and Characteristics of Digital Evidence

  • Fragility: It is readily and rapidly altered or erased, and may vanish upon the deletion of a message or the closure of an account.
  • Copying without visible trace: Copying leaves no perceptible physical trace, necessitating precise technical documentation.
  • Dependence on the service provider: Much decisive data — access logs and connection addresses — is held by providers for defined periods and is lost upon their expiry.
  • Need for technical expertise: Its extraction and analysis require specialised tools and personnel, and an expert is frequently appointed.

2. Preserving Your Evidence Before Reporting

  • Delete nothing: Retain the conversation, post, or message as it stands; do not delete a compromised account or reset the device before the incident is documented.
  • Capture complete screenshots: The capture must show the account name and handle, the date and time, and the full, uncropped content of the message.
  • Preserve links and identifiers: Copy the URL of the post or account and the user handle; these are essential keys to tracing the perpetrator.
  • Retain financial documents: In fraud cases, preserve transfer notifications, transaction references, account statements, and beneficiary account details.
  • Notify the bank immediately: In financial fraud, contact within the first minutes may enable the transfer to be stopped or the beneficiary account frozen.
  • Do not negotiate and do not pay: In extortion, payment invites repetition and guarantees nothing; it is better to cease contact while preserving the evidence.
  • Do not play investigator: Attempting to hack or entrap the perpetrator may expose you to criminal liability in turn.

3. The Procedural Path Step by Step

  • Step one — Lodging the complaint: The complaint is submitted to the competent cybercrime department of the Ministry of Interior, to the relevant police station, or directly to the Public Prosecution, accompanied by documented evidence.
  • Step two — Record and evidence gathering: The complainant's statements are recorded and relevant devices or accounts are seized; the phone or computer may be requested for technical examination.
  • Step three — Technical examination: The device or data is referred to the technical authority to extract digital evidence and prepare a report identifying the source and timing of the content and the associated connection addresses.
  • Step four — Investigation by the Public Prosecution: The Prosecution conducts the investigation, interrogates the accused, and hears witnesses. It may order arrest or pre-trial detention according to the gravity of the incident.
  • Step five — Referral to court: Where the Prosecution considers the evidence sufficient, it refers the case to the competent criminal court by a referral order setting out the charge and the provisions relied upon.
  • Step six — Trial and judgment: The court hears the case and the defence, may appoint an expert, and then issues a reasoned judgment.
  • Step seven — Civil claim and compensation: The victim may join a civil claim to the criminal proceedings or bring an independent compensation action before the civil court.

4. Documents Required in Practice

  • The complainant's civil identification, and a power of attorney where the complaint is lodged through counsel.
  • Complete screenshots of the conversations or posts in question.
  • Links to accounts and posts, and user identifiers.
  • Bank statements, transfer notifications, and transaction references in fraud cases.
  • The device used (phone or computer) where technical examination is required.
  • Evidence of harm: medical or psychological reports, documentation of financial loss, material showing injury to professional reputation.
  • Subscription data for the communications or internet service linked to the affected account.

VII. Practical Analysis and Hypothetical Scenarios

Scenario One: Extortion Using Private Images

Hypothetical facts: A young woman meets a person through an application, exchanges conversations and private images with him, and is then confronted with messages threatening to publish the images to her relatives' accounts unless she transfers a sum of money. She transfers an initial sum, whereupon the demand is repeated.

Legal characterisation: This is a completed offence of electronic extortion, constituted by the threat itself. It is immaterial that the victim sent the images voluntarily at the outset, since consent to sending does not extend to consent to publication or to threats. The transfer of the first sum does not extinguish the offence; it evidences the pressure exerted and the realisation of the intended result, while the renewed demand is a fresh incident capable of characterisation as a separate offence. The correct course is to cease contact immediately, preserve the entire conversation and the transfer notifications, and lodge an urgent complaint, bearing in mind that delay may forfeit the opportunity to obtain connection data from the service provider.

Scenario Two: The Former Employee and Access to Company Systems

Hypothetical facts: An employee's service ends but he retains login credentials to the client system. Two months later he accesses it, copies the client database for use in his new employment, and deletes certain records to conceal his trace.

Legal characterisation: A single incident here attracts multiple characterisations: unlawful access to an information system, since the prior authorisation lapsed with the employment relationship; copying data without right; and destruction and deletion of data — with the possibility of parallel liability for disclosure of professional secrets and unfair competition under the general rules. Liability is aggravated because the perpetrator exploited knowledge derived from his former post. In practical terms, the affected company should promptly freeze accounts and extract and technically document the system access logs before any modification, since system logs are the strongest evidence in such incidents.

Scenario Three: Re-publishing a Defamatory Post

Hypothetical facts: A person publishes a post accusing a merchant of deceit and fraud without foundation. Another person re-publishes it in a public group, adding the words "this is true and we are witnesses", then deletes the post two days later upon receiving a formal notice.

Legal characterisation: The original publisher answers for public slander by means of an information technology device. The re-publisher's liability is independent and subsists, because he did not merely transmit but adopted the content and added an endorsement of its truth, so he answers as a principal rather than a mere conduit. Subsequent deletion does not erase the offence, which was completed upon publication, although the court may take it into account in assessing the penalty. A defence of "freedom of opinion" fails here, since that freedom protects objective criticism resting on accurate facts and does not extend to the assertion of specific facts injurious to honour without proof.

VIII. Comparative Table — Extortion, Defamation, and Electronic Fraud

  • Electronic extortion: Essence — a threat of publication to compel an act or a payment. Protected interest — freedom of will and the integrity of private life. Moment of completion — the threat coming to the victim's knowledge, even without compliance. Key evidence — conversations, transfer notifications, connection logs. Civil consequence — compensation predominantly for moral harm, sometimes with material loss.
  • Defamation and insult by electronic means: Essence — publicly attributing a fact injurious to honour, or injuring standing. Protected interest — honour, standing, and reputation. Moment of completion — publication and the making available of the content to an indeterminate number of persons. Key evidence — complete screenshots, links, account identifiers, and the testimony of those who viewed it. Civil consequence — moral damages, extending to material damages where professional or commercial loss is proved.
  • Electronic financial fraud: Essence — appropriating money or financial data through digital fraudulent devices. Protected interest — the patrimony and confidence in digital dealings. Moment of completion — delivery of money or data induced by the deception. Key evidence — account statements, transaction references, fraudulent links, phishing messages. Civil consequence — recovery of the sum and compensation for loss sustained and profit foregone.

Confusing these three characterisations is among the most frequent causes of poorly framed complaints: many complainants describe extortion as a mere "threat", or fraud as "theft", which may delay correct characterisation. The practical rule is that extortion is pressure on the will, defamation is an attack on reputation, and fraud is an attack on property. All three may coincide in a single incident, generating multiple characterisations governed by the rules on concurrence in the Penal Code.

Frequently Asked Questions

1. Are conversations and screenshots admissible evidence before the court?

Yes, digital evidence is admissible in criminal proof, but its weight depends on the lawfulness of its acquisition and its freedom from tampering. It is always preferable to submit the original device for technical examination rather than rely on screenshots alone, which may attract an allegation of manipulation. The court's satisfaction with the evidence remains within its discretion.

2. I was extorted and paid a sum. Does this forfeit my right to complain?

No. Payment neither extinguishes the offence nor bars a complaint; it evidences the pressure exerted and the effect of the threat. It is better not to pay at all, since compliance usually encourages the perpetrator to renew his demands.

3. Can a person using a fake account or pseudonym be traced?

In many cases yes, through subscription data, connection addresses, and access logs held by service providers, upon authorisation from the competent authority. The prospect of successful tracing diminishes as reporting is delayed, since such data is retained only for defined periods before deletion.

4. I re-published a post containing an accusation. Am I criminally liable?

You may be. Re-publication is a fresh material act widening the circle of harm, and liability is clearer still where accompanied by a comment adopting or affirming the content. The practical rule is: do not re-publish what you cannot prove.

5. Does deleting the post end my liability?

No. The offence was completed upon publication and deletion comes afterwards. However, prompt deletion and an apology may be treated as mitigating circumstances guiding the court in sentencing, and may reduce the civil harm.

6. Someone hacked my account and sent offensive messages in my name. What is my position?

You are the victim of unlawful access and impersonation. You should promptly recover the account, document the access logs and security notifications, and lodge an immediate complaint. It is settled that the mere attribution of an account to a person does not suffice for conviction, which protects the holder of a compromised account once the intrusion is established.

7. I paid an online shop and received nothing. Is this a crime or a civil dispute?

The characterisation depends on whether an intention to appropriate existed from the outset and whether fraudulent devices were employed. If the shop was wholly fictitious or used forged particulars, this is criminal fraud. If the shop was genuine and failed to deliver for a commercial reason, the matter is in principle a contractual breach founding a civil action, with the possibility of relying on consumer protection.

8. Is harsh criticism of a service or company defamation?

Not necessarily. Objective criticism based on a genuine experience and directed at the service rather than at persons remains within freedom of opinion. If it asserts specific false facts or employs language injurious to honour and standing, it crosses into criminality.

9. How long does a cybercrime complaint take in practice?

This varies with the nature of the incident and the need for technical examination and correspondence with external entities. Incidents where the perpetrator is known and the evidence complete proceed far more quickly than those requiring the tracing of anonymous accounts. Prompt reporting and complete preservation of evidence are the single most important factors in shortening the process.

10. Is a company liable for a breach of its customers' data?

It may incur civil liability where its failure to adopt reasonable technical and organisational safeguards is established, on the basis of tortious liability or breach of a contractual duty of confidentiality. Criminal liability attaches principally to the intruder, and may extend to an insider who disclosed the data.

11. May I record a call or conversation to use as evidence?

Recording without the other party's knowledge is a delicate matter, since the law protects the inviolability of private life and correspondence, and the recording may itself constitute a violation. The safer course is to request that the competent authority undertake seizure and search in accordance with proper legal procedure, since evidence obtained unlawfully may be excluded.

12. Can cyber offences be settled or withdrawn?

This depends on the nature of the offence. In offences affecting the public interest, the public right is not extinguished by the victim's waiver save where the law so provides, although a waiver is taken into account in practice when assessing the penalty. The civil right to compensation, by contrast, may be waived or settled by the injured party.

13. What is the difference between reporting to the police and to the Public Prosecution?

A report to the competent police authority is the stage of gathering evidence and drawing up the record, which is then referred to the Public Prosecution as the investigating and charging authority. A complaint may also be lodged directly with the Prosecution. What matters in practice is the completeness of the accompanying evidence, whichever channel is used.

Conclusion

A study of the rules governing cybercrime under Kuwaiti law reveals a clear legislative policy of extending the umbrella of criminal protection over the digital environment in all its components: systems and data on the one hand, and persons, their reputation, and their patrimony on the other. Law No. 63 of 2015, in conjunction with the Electronic Transactions Law No. 20 of 2014 and the Penal Code No. 16 of 1960, has produced a framework capable of accommodating most emergent forms of digital wrongdoing.

Yet the effectiveness of that protection depends on two indispensable practical elements: promptness in reporting and integrity in preserving digital evidence. A delay of days may mean the loss of decisive records held by service providers, while interfering with a device or deleting conversations — even in good faith — may hollow out the complaint entirely. The first practical advice to any victim is therefore: do not delete, do not negotiate, document immediately, and then seek specialised assistance.

One governing principle should never be lost from view: the digital space is not a zone beyond the law. What is criminal in the physical world remains criminal when committed behind a screen or under a pseudonym, and the penalty may be aggravated by the breadth and speed of its dissemination. Grasping this reality protects the user from becoming a victim and, equally, from becoming — through ignorance or a hasty share — an accused in a case never intended.

Legal Disclaimer

The information contained in this article is provided for legal awareness purposes only and does not constitute legal advice or a binding legal opinion, as each case differs according to its own circumstances and facts.

If you require specialised legal advice or representation before the judicial authorities, we welcome you to book an appointment with our legal team.

📞 Book an appointment with our firm for specialised legal consultation.
📩 Contact us now to discuss your legal matter in complete confidence.

Need Legal Advice?

The Yumnaak Law Firm team is ready to help with trusted expertise.

Book Appointment Contact Us

All rights reserved to Yumnaak Law Firm 2026 YUMNAAK LAW FIRM