|
|
CHAPTER III. Policy and legislative frameworks
their activities or publish information on how to make explosives or other substances
for use in terrorist attacks.80
82. In 2008, the Government of Saudi Arabia implemented new technology-related
laws, including one that established as a criminal offence, punishable by fines and up
to
10 years of imprisonment, owning a website that advocates or supports
terrorism.81
83. Also in 2008, the Government of Pakistan enacted the Prevention of Electronic
Crimes Ordinance, 2008, which made specific provision for offences connected to cyber-
terrorism. The law is no longer in force, however.82
84. Finally, the same year saw the Government of India amend the Information
Technology Act, 2000, to provide for the offence of “cyber terrorism” (section 66F)
and other Internet-related issues.
85. Nevertheless, internationally, with some exceptions, in the absence of any universal
instrument imposing an express obligation to enact legislation specifically targeting
ŧerrorist activity over the Internet, most Governments have elected to deal with such
threats by using a mixed approach, utilizing a combination of general criminal laws, as
well as cybercrime and counter-terrorism legislation. In some States, for example,
criminal laws focus on substantive criminal acts without differentiating among the
specific means by which they are committed. Under this approach, the Internet is
regarded as merely a tool by which terrorists commit a substantive crime, often contained
within the provisions of the national penal code.
86. This is the approach in China, where the Criminal Law of the People’s Republic
of China contains an article dealing with the criminalization of all illegal activities
involving the use of the Internet. Article 287 of the Criminal Law makes it an offence
to use a computer in the commission of an offence, which will be prosecuted and
sentenced in accordance with the relevant criminalization and sentencing provisions in
that law. In this way, under Chinese criminal law, the use of Internet is regarded as a
medium or tool through which a criminal act may be committed, rather than an inde-
pendent constituent element of the crime, and is therefore criminalized within the
substantive provisions of the criminal law.
87. In the terrorism context, in China there are provisions criminalizing different forms
of terrorist activities, including article
120 of the Criminal Law, which criminalizes
activities related to organizing, leading and participating in terrorist organizations. This
broad criminalization provision covers a wide range of terrorism-related activities,
including those carried out over the Internet.
80 Federal Law No. (2) of 2006 on the Prevention of Information Technology Crimes, Official Gazette of the United
Arab Emirates, vol.
442, 36th year, Muharam 1427 H/January 2006 (unofficial English translation available from
81 David Westley, “Saudi tightens grip on Internet use”, Arabian Business, 26 January 2008.
82“Pakistan lacks laws to combat cyber terrorism”, The New New Internet, available from www.thenewnewInternet.
com/2010/09/01/pakistan-lacks-laws-to-combat-cyber-terrorism.
29
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
88. In the Republic of Korea, two types of criminal law can be applied to terrorist
acts involving some use of the Internet. One is the general criminal code and the other
is a special criminal code, established in 1986, relating to criminal acts involving infor-
mation/communication. Article 90 of the Criminal Code deals with the preparation of
such acts, as well as conspiracy, incitement or propaganda and provides that any person
who prepares or plots for the purpose of committing crimes under article 87 of the
Criminal Code (public riots, revolts or disturbances) or article 88 (homicides commit-
ted for the purpose of acts under article 87) is liable to imprisonment of three years
or more. Under article 101 of the Criminal Code, any person who prepares or conspires
to commit offences under articles 92 to 99 of the Criminal Code is guilty of a crime
and liable to two years or more imprisonment. Article 114 of the Criminal Code relates
to organizing a criminal group. Also under the special criminal code, the Government
established a range of criminal offences specifically criminalizing unlawful acts targeting
information-communication networks and personal information.
89. In practice, regardless of the policy approach taken, experience shows that most
States adopt a multifaceted approach when dealing with the investigation and prosecu-
tion of terrorist acts, including those involving some use of the Internet. Law enforce-
ment and prosecution agencies use whatever legislative provisions best suit the particular
circumstances of the case.
90. The powers required by law enforcement agencies to effectively investigate terror-
ism cases are broadly similar regardless of the particular jurisdiction involved, with
differences in national policies and legislation reflecting the diversity in legal systems,
constitutional arrangements and other factors (e.g. cultures).
91. The area of Internet regulation and content control leaves considerable room for
variations in national approaches. While the Universal Declaration of Human Rights
and the International Covenant on Civil and Political Rights provide international stand-
ards pertaining to the regulation of the expression and communication of ideas, there
is no comprehensive internationally binding instrument setting definitive, binding norms
on what is considered appropriate Internet content or how each State should regulate
Internet-related activity within its own territory. Currently, child pornography is the
one area where, even in the absence of a universally binding instrument or definition,
States invariably prohibit such activities.83 In the terrorism context, however, the absence
of a universally agreed definition of terrorism presents an ongoing obstacle to any
internationally agreed approach to the appropriate regulation of terrorism-related activ-
ity and content over the Internet.
92. In terms of specialized judicial or evidential procedures in the terrorism field,
some States have adopted specific judicial and case management procedures for terror-
ism cases that might apply to cases involving the use of the Internet by terrorists. When
this approach is adopted, it is important that any specialized mechanisms conform fully
with relevant international human rights obligations, including those related to the right
to liberty and a fair trial.
30
83 Maura Conway, “Terrorism and Internet governance: core issues”, Disarmament Forum, vol. 3 (2007), p. 27.
CHAPTER III. Policy and legislative frameworks
C. Legislation
1. Criminalization
93. As stated above, none of the universal instruments against terrorism impose an
obligation on States to enact legislation specifically targeting the use of the Internet by
terrorists. Accordingly, while it is therefore highly likely that most terrorism cases will
involve some use of the Internet by perpetrators, it is likely that in many States, in
addition to using offence provisions related to unlawful conduct specified in universal
instruments, authorities will also be reliant on other criminal offence provisions under
their penal codes, including inchoate offences such as conspiracy, solicitation and crimi-
nal association, in order to prosecute offenders.
94. In the present section, examples of different legislative provisions from some
States are considered, with a view to identifying approaches that might provide the
basis for effective criminal justice responses to different types of conduct.
(a) Internet-based acts or statements supporting terrorism
95. In addition to acts associated with the commission of substantive terrorist acts
(e.g. terrorist bombings), there is clear evidence that the Internet is increasingly being
used by terrorists to carry out support actions such as recruiting and training members,
sharing useful information, disseminating propaganda and inciting the commission of
acts of terrorism. Owing to the configuration and global reach of the Internet, it is
increasingly likely that these types of activities may involve different actors being physi-
cally present in different legal jurisdictions.
96. In the United Kingdom, part VI of the Terrorism Act 2000 contains several
offences that can provide the basis for charging individuals who have used the Internet
to support terrorist activities.
97. Section 54 of the Act makes it an offence to provide, receive or invite others to
receive instruction or training in the making or use of firearms, radioactive material or
related weapons, explosives or chemical, biological or nuclear weapons.
98. Section 57 makes it an offence to possess articles in circumstances that give rise
to a reasonable suspicion that a person has such articles in connection with the prepa-
ration, instigation or commission of an act of terrorism. In recent years, this offence
has been used to successfully prosecute several individuals who have been found in
possession of items as diverse as hard drives, DVDs and instructional documents on
how to make or operate items such as mortars, suicide vests and napalm.84 For there
to have been a commission of this offence, the prosecution must prove a connection
between the article in question and a specific act of terrorism. There have been several
84 Susan Hemming, “The practical application of counter-terrorism legislation in England and Wales: a prosecutor’s
perspective”, International Affairs, vol. 86, No. 4 (July 2010), p. 963.
31
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
successful prosecutions for offences under section 57; however, the Courts have adopted
a more restrictive approach in interpreting the scope of application of the section, as
demonstrated by the case of R. v. Zafar, Butt, Iqbal, Raja and Malik [2008] EWCA
Crim 184.
R. v. Zafar, Butt, Iqbal, Raja and Malik
This 2007 case from the United Kingdom involved successful appeals by the defendants
Zafar, Butt, Iqbal, Raja and Malik against convictions imposed for possession of articles for
a purpose connected with the commission, preparation or instigation of an act of terrorism,
contrary to section 57 of the Terrorism Act 2000.
Four of the five defendants in the case were students at Bradford University. The fifth, Raja,
was a schoolboy in Ilford and established contact with Iqbal through the Internet messaging
service MSN.
Raja visited Bradford for a few days, staying at the house in which Iqbal and Zafar lived,
and brought with him three CDs he had made that contained selected material from the
computer and were labelled as “philosophy discs”. Raja was arrested by police upon his
return home after the visit.
Subsequent police enquiries led them to arrest and search the places of residence of the
other accused, which revealed that they too were in possession of radical jihadist material
and other material such as a United States military manual downloaded from the Internet.
Evidence of communications via online messenger were found, including a discussion
between all four of the Bradford appellants and a cousin of Malik—Imran—who lived in
Pakistan.
The defendants originally faced charges under section 58 of the 2000 Act; however, at the
committal stage, the prosecution added counts under section 57 reflecting the same par-
ticulars as those under section 58. Following various pretrial rulings on the issue of whether
electronically stored information could be considered an article for the purposes of section
57, the prosecution elected to proceed to trial on the basis of the section 57 charges only.
At trial, Zafar and Iqbal were acquitted on one count, which charged them with possession
of three “philosophy discs” containing material emanating from Raja; however, they, together
with the other defendants, were found guilty in respect of all other charges. Malik was
sentenced to three years of imprisonment, Zafar and Iqbal to three years of detention in a
young offenders’ institution, Butt to 27 months of detention and Raja to two years of
detention.
The defendants appealed these convictions. At the appeal, the Court considered the critical
issue to be whether, based on the facts of the case, there existed between the articles and
the acts of terrorism a connection that satisfied the requirements of section 57.
The articles that the Crown alleged that the appellants possessed in breach of section 57
were, for the most part, CDs and hard drives containing electronically stored material. This
material included ideological propaganda and communications between the defendants,
which the prosecution alleged showed a settled plan involving the defendants travelling to
Pakistan to receive training and participate in fighting in Afghanistan, which the Crown
alleged amounted to acts of terrorism. The Court of Appeal held that it was necessary for
the prosecution to prove first the purpose for which each appellant held the stored material
and then to prove that this purpose was “connected with the commission, preparation or
instigation” of the prospective acts of terrorism relied on by the prosecution, namely fight-
32
ing against the Government in Afghanistan.
CHAPTER III. Policy and legislative frameworks
On the facts of the case, noting that it raised difficult questions of interpretation about the
scope of application of section 57, the Court held that the necessary connection was not
present, and therefore the resulting convictions were unsound, and allowed the appeals.
99. Section 58 of the Act has proven particularly useful in several cases in which
authorities have needed to intervene when there was no evidence that the individual
was engaged in activity associated with terrorism. The section makes it an offence to
collect, make or have in one’s possession, without a reasonable excuse, any record of
information of a kind likely to be useful to a person committing or preparing an act
of terrorism or to have possession of any document or record containing such
information.
100. In R v. K [2008] 3 All E.R. 526, the Court held that a document falls within
the scope of section 58 only if it is of a kind that is likely to provide practical assistance
to a person committing or preparing to commit an act of terrorism. This approach was
reaffirmed in R v. G and J [2009] UKHL 13, in which the Court reaffirmed this
“practical use test”, under which possession of a document or record is a crime only
if it is of practical use and was possessed by a person without a reasonable excuse.85
There is no restriction on what might constitute a reasonable excuse for this purpose,
provided that it is capable in law of amounting to a defence.
101. Under section 58, the prosecution is not required to prove that the accused is
a terrorist or that any items are possessed for a terrorist purpose; however, the prosecu-
tion may only in very limited circumstances call extrinsic evidence to prove the practical
utility of any item. For example, evidence of cipher may be called in order to decipher
a document written in code, but no evidence may be called to explain the significance
of locations circled on a map. The information must “speak for itself ” and not be of
a type in general circulation.
102. In R v. Sultan Mohammed
[2010] EWCA Crim 227, the court held that
“[p]rovided that the document containing the information is not one in every day use
by ordinary members of the public (e.g. published timetables and maps) and provided
that a reasonable jury could properly conclude that the document contains information
of a kind likely to be useful to a person committing or preparing an act of terrorism,
then it will be a matter for the jury whether they are sure that it contains such
information. If so, and provided the defendant has the necessary mens rea, then the
only issue will be whether the defendant has a reasonable excuse.”86 The jury must
accordingly decide whether the explanation given for possessing the document is in fact
reasonable given the particular facts and circumstances of the case.87
85 Ibid., p. 962.
86 Quotation from “R. v. Muhammed [2010] EWCA Crim 227: terrorism—preparing an act of terrorism”, Criminal
Law and Justice Weekly (20 March 2010).
87 Hemming, “The practical application of counter-terrorism legislation in England and Wales”, p. 963.
33
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
103. The Terrorism Act 2006 established (in its section 5) the offence of “committing
acts in preparation for terrorism”. This section was designed to deal with cases in which
individuals actively planning acts of terrorism were stopped before they completed or
attempted a substantive terrorist act.88
104. Section 5 has been particularly useful in “lone wolf ” cases, in which an offender
is acting alone, there is insufficient evidence to establish the basis of a conspiracy charge
because it cannot be proven that more than one person was involved, or authorities do
not know in detail the offence that was being planned. The offence does not require
proof of an identifiable final act or acts of terrorism, but the prosecution must prove
a specific intent to commit a terrorist act or to assist another to do so. Several indi-
viduals have been convicted of the offence in the United Kingdom and sentenced to
varying terms of imprisonment, including life imprisonment.89
105. The case of R v. Terence Roy Brown [2011] EWCA Crim 2751, is an example of
the utility of provisions such as section 58.
R v. Terence Roy Brown
Terence Roy Brown, a citizen of the United Kingdom, ran an online business, in which he
advertised and sold an annual edition of a CD-ROM that he called the “Anarchist’s Cook-
book” (the title is nearly identical to that of a well-known book called The Anarchist Cook-
book). Rather than a single publication, however, these discs contained 10,322 files, some
of which were complete publications in their own right. These included terrorist manuals
such as the Al-Qaida Manual and instructions for the manufacture of different forms of
explosives and the construction of bombs. Other files consisted of instructions for making
poisons, how to avoid attracting the attention of authorities when travelling and weapons-
handling techniques. In an apparent effort to circumvent the law, Mr. Brown posted dis-
claimers on the website advertising the publication, stating that the instructions they con-
tained might be illegal or dangerous to perform and were intended for “reading pleasure
and historical value only”. It was clear on investigation that Mr. Brown was motivated purely
by commercial incentives. It was also apparent that he deliberately had expanded his col-
lection in the immediate aftermath of the July 2005 London bombs and had significantly
increased his profit as a result.
In March 2011, Mr. Brown was convicted of seven counts under the Terrorism Act 2000
(section 58) relating to the collection of information that could have been used to prepare
or commit acts of terrorism, two counts under the Terrorism Act 2006 (section 2) relating
to the dissemination of terrorist publications and an offence under the Proceeds of Crime
Act 2002 relating to the transfer of criminal property
(his use of the profits from his
business).a
88 Ibid., p. 964.
34
89 Ibid.
CHAPTER III. Policy and legislative frameworks
The excuse raised by Mr. Brown at trial was that his activities amounted to no more than
the lawful exercise of his right to freedom of expression in relation to material that was
freely available on the Internet and that was similar in type, if not volume, to that sold by
other online booksellers. The same points were raised during an unsuccessful application to
appeal conviction, during which the court ruled that the restriction of Brown’s article 10
rights in relation to material that was likely to assist terrorists was justified and proportion-
ate. The court also affirmed the discretion of the prosecuting authorities not to charge every
individual who might have committed an offence, but to consider instead each case on its
own merits.
a “Businessman who published bomb-makers’ handbook ‘facing lengthy spell in jail’”, Daily Mail, 9 March
2011. Available from www.dailymail.co.uk/news/article-1364621/Businessman-published-bomb-makers-handbook-
facing-lengthy-spell-jail.html#ixzz1j4gXbMLu.
106. The case is one of several, including R v. K [2008] QB 827 and R v. G [2010]
1 AC 43, in which the courts in the United Kingdom have clarified the jurisprudence
surrounding the scope and application of section 58 of the Act, in the light of relevant
human rights safeguards.
107. In addition to criminal offences under anti-terrorism legislation, authorities in
the United Kingdom have, when circumstances require, used the offence of solicitation
to successfully prosecute persons carrying out activities linked to terrorism. An example
of this approach is the case of R v. Bilal Zaheer Ahmad,90 in which the defendant was
convicted of solicitation of murder.
R v. Bilal Zaheer Ahmad
This United Kingdom case is linked to, and followed, the 2010 case involving Roshanara
Choudhry, who was sentenced to life imprisonment on 2 November 2010 for the attempted
murder of Stephen Timms, a Member of Parliament.
In a statement, Choudhry said she had decided to commit the offence approximately four
weeks prior to the assault in May 2010 and had purchased two knives in preparation, one
as a spare in case the first broke while she stabbed the victim. She told police that she had
been watching Anwar al-Awalaki videos and Abdullah Azzam videos and had visited the
website www.revolutionmuslim.com during her period of radicalization. This well-known site,
which was hosted in the United States, contained material promoting violent jihad, including
videos and speeches encouraging terrorism and weblinks to terrorist publications.
On 1 November 2010, the defendant posted a link on his Facebook page to a news article
about the Timms/Choudhry case, to which he added the following comment:
90 Nottingham Crown Court, 13 May 2011.
35
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
This sister has put us men to shame. WE SHOULD BE DOING THIS.
On 4 November 2010, the defendant posted an article entitled “MPs that voted for War
on Iraq” on the Revolution Muslim website under the name of “BILAL”. The article was
headed with the symbol of the Islamic State of Iraq (an Al-Qaida affiliate). The opening text
was a quotation from the Koran stating that those who died without participating in jihad
were hypocrites.
The article advised readers that they could “track” British Members of Parliament through
a link it provided to an official parliamentary website. This would enable them to find out
details regarding the location of surgeries to be performed on Members of Parliament, where
they could be “encountered in person”.
This was followed by 29 religious quotations, all translated into English and all relating to
the obligation for Muslims to participate in jihad or to “martyrdom”. Immediately under
the quotations was a link to a web page advertising a knife for sale. A copy of this article
was captured evidentially by British counter-terrorism officers. A further copy of the web
page was obtained from Google Inc. in response to a letter of request.
On 10 November 2010, the defendant was arrested by the Counter Terrorism Unit of the
West Midlands Police near his home in Wolverhampton. He was found in possession of a
laptop, which he told the arresting officers he had used to post the article on members of
parliament on the Revolution Muslim website. Forensic examination of the laptop revealed
that he appeared to have attempted to delete traces of his online activities prior to his
arrest.
On 16 November, the defendant was charged with soliciting murder in relation to the article
and with three offences of possession of material likely to be of use to a terrorist under
section 58 of the Terrorism Act 2000. He later pleaded guilty to these charges, as well as
to an offence of inciting religious hatred, arising from comments posted on an Internet
forum, and was sentenced to 12 years of imprisonment, with an additional five years
extended period on licence.
108. In the United States, Title 18 of the United States Code, section 842 (p), entitled
“Distribution of information relating to explosives, destructive devices, and weapons of
mass destruction” makes it illegal for a person to distribute by any means information
regarding the manufacture or use of explosives, destructive devices or weapons of mass
destruction with the intent that the information be used in furtherance of a crime of
violence or with the knowledge that the person to whom the information is distributed
intends to use the information in furtherance of a crime of violence. This statute has
been used in the United States to prosecute individuals who have distributed such
information over the Internet.
(b) Incitement
109. The crime of inciting terrorist acts is the subject of Security Council resolution
1624 (2005). In that resolution, the Council called upon all States to, inter alia, adopt
such measures as may be necessary and appropriate and in accordance with their obli-
gations under international law to prohibit by law incitement to commit a terrorist act
36
or acts, and to prevent such conduct.
CHAPTER III. Policy and legislative frameworks
110. The development and enforcement of laws criminalizing the incitement of acts
of terrorism while fully protecting human rights such as the rights to freedom of expres-
sion and association presents an ongoing challenge for policymakers, legislators, law
enforcement agencies and prosecutors. Cases involving statements by persons made
over the Internet, especially when the alleged offender, the Internet services they use
and their intended audience are located in different jurisdictions, are regulated by dif-
ferent national laws and constitutional safeguards and therefore present additional chal-
lenges for investigators and prosecutors from an international cooperation
perspective.
111. International experience relating to the enforcement of criminal offences dealing
with incitement to commit terrorist acts highlights two issues: first, how important (and
sometimes difficult) it is in practice to differentiate between terrorist propaganda (state-
ments advocating particular ideological, religious or political views) from material or
statements that amount to incitement to commit violent terrorist acts; and second, how
the enforcement of laws dealing with alleged acts of incitement requires a careful case-
by-case assessment of the circumstances and context to determine whether the institu-
tion of a prosecution for an incitement offence is appropriate in a particular case.
112. Those experts at the expert group meeting who had been involved in cases related
to the investigation and prosecution of crimes of inciting terrorist acts agreed and
highlighted the importance, in practice, of fully assessing the context in which alleged
statements of incitement were made, including not only the words but also the forum
in which they were made, and that the characteristics of likely recipients might be highly
relevant factors in determining whether criminal proceedings for the crime of incitement
were instituted or likely to be successful in a particular case.
113. In the United Kingdom, section 59 of the Terrorism Act 2000 makes it an offence
to incite another person to commit an act of terrorism wholly or partly outside the
United Kingdom, when the act would, if committed in England and Wales, constitute
an offence specified in the section (e.g. murder, wounding with intent, explosions or
endangering life by damaging property).
114. In the well-known case of R v. Tsouli and others,91 Younes Tsouli, Waseem Mughal
and Tariq al-Daour pleaded guilty to charges under the Terrorism Act 2000 of inciting
murder for terrorist purposes by establishing and maintaining large numbers of websites
and chat forums used to publish materials inciting acts of terrorist murder, primarily
in Iraq.
91 R v. Tsouli [2007] EWCA (Crim) 3300.
37
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
R v. Tsouli and others
This well-known case from the United Kingdom involved three defendants—Younes Tsouli,
Waseem Mughal and Tariq al-Daour—who were initially indicted on 15 counts. Prior to trial,
Tsouli and Mughal pleaded guilty to a charge of conspiracy to defraud. During the trial,
having heard the prosecution evidence, all three pleaded guilty to a charge of inciting ter-
rorism overseas, and Al-Daour pleaded guilty to a charge of conspiracy to defraud.
Between June 2005 and their arrest in October 2005, the defendants were involved in the
purchase, construction and maintenance of a large number of websites and Internet chat
forums on which material was published that incited acts of terrorist murder, primarily in
Iraq. The cost of purchasing and maintaining the websites was met from the proceeds of
credit card fraud. The material on the websites included statements that it was the duty of
Muslims to wage armed jihad against Jews, crusaders, apostates and their supporters in all
Muslim countries and that it was the duty of every Muslim to fight and kill them wherever
they were, civilian or military.
In the Internet chat forums, individuals disposed to join the insurgency were provided with
routes by which to travel into Iraq and manuals on weapons and explosives recipes. Extreme
ideological material demonstrating adherence to the espoused justification for the acts of
murder that the websites and chat forums incited was recovered from the home of each
defendant.
Al-Daour organized the obtaining of stolen credit cards, both for his own purposes and for
providing Mughal with funds for the setting up and running of the websites. Al-Daour had
also been involved in further credit card fraud; the proceeds of which were not applied to
the support of the websites. The loss to the credit card companies from this aspect of the
defendants’ fraudulent activity was £1.8 million.
Among the evidence was a list made by Tsouli in his handwriting and found in his desk on
which he had written the details of a number of websites and of stolen credit cards. This
revealed 32 separate websites provided by a number of different web-hosting companies
that Tsouli had set up or attempted to set up, mostly in the last week of June 2005 but
continuing into July and into August. The creation and administration of these websites
were funded by the fraudulent use of credit card details that had been stolen from account
holders, either by direct theft of computer records, by hacking or by some fraudulent diver-
sion within the financial institutions. These credit card details had been passed on to Tsouli
by the other two defendants.
The websites created by Tsouli were used as a vehicle for uploading jihadist materials, which
incited acts of violence outside the United Kingdom in Iraq. Access to the sites was restricted
to those who had been issued with usernames and passwords. This was done, the trial
judge found, to make it more difficult for the web-hosting companies and the law enforce-
ment agencies to know what was being posted on the sites.
On 5 July 2007, Tsouli was sentenced to 10 years of imprisonment and 3½ years (concur-
rently) on two counts. Mughal to 7½ years of imprisonment and 3½ years (concurrently)
on two counts and al-Daour, to 6½ years of imprisonment and 3½ years (concurrently).
115. Part 1 of the Terrorism Act 2006 established a number of new offences aimed
at enhancing the ability of authorities to take action in cases involving statements by
persons inciting or glorifying acts of terrorism or otherwise intended to support the
38
commission of such acts.
CHAPTER III. Policy and legislative frameworks
116. Part 1 of the Act makes it an offence for a person to publish a statement intended
to directly or indirectly encourage members of the public to prepare, instigate or com-
mit acts of terrorism, including (but not limited to) encouragement that “glorifies”
terrorist acts, or for a person to be reckless as whether such conduct has such an effect.
In practice, how a statement is likely to be understood is determined by reference to
the content as a whole and the context in which it is made available.
117. Section 2 of the Act makes it an offence to (intentionally or recklessly) dissemi-
nate terrorist publications. These are defined as publications that are likely to encourage
acts of terrorism or are likely to be useful to someone planning or committing such an
act. This second category covers the same types of documents or publications to which
section 58 of the Terrorism Act 2000 applies. As with section 1 of the Terrorism Act
2006, the question of whether the material in question comes within the definition of
a “terrorist publication” must be determined by reference to its content as a whole and
the context in which it is made available.92
118. In the United Kingdom, when making decisions as to whether to initiate prosecu-
tions for incitement, prosecutors exercise wide discretion, taking into account the right
to freedom of speech and the overall context in which the statements or publications
are made or distributed, including how they are likely to be understood, both by the
general public and the intended recipients.
119. In the United States, a different legal approach has been taken to the criminali-
zation and prosecution of acts of incitement of terrorism owing to constitutional safe-
guards attaching to the right to freedom of speech under the First Amendment to the
Constitution. Under the principles set out in the landmark case of Brandenburg v. Ohio,
395 US. 444 (1969), in order to successfully prosecute an individual for incitement of
criminal acts (including terrorism), the prosecution is required to prove both an intent
to incite or produce unlawful action and the likelihood that the speech will actually
incite imminent unlawful action.93
120. In prosecuting statements inciting acts of terrorism, authorities in the United
States are reliant upon inchoate offences such as solicitation and conspiracy, together
with the “material support” provisions of the United States Criminal Code, which in
certain circumstances permit the prosecution of conduct that supports violent acts of
terrorism.94
121. The material support provisions of the United States Criminal Code, Title 18,
section 2339A and 2339B, prohibit persons from knowingly or intentionally providing,
attempting to provide or conspiring to provide material support or resources to a ter-
rorist organization. The Uniting and Strengthening America by Providing Appropriate
92 Hemming, “The practical application of counter-terrorism legislation in England and Wales”, p. 963.
93 Elizabeth M. Renieris, “Combating incitement to terrorism on the Internet: comparative approaches in the United
States and the United Kingdom and the need for an international solution”, Vanderbilt Journal of Entertainment and
Technology Law, vol. 11, No. 3 (2009), pp. 681-682.
94 United States Criminal Code, title 18, sections 2339A and 2339B.
39
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
Tools Required to Intercept and Obstruct Terrorism (PATRIOT) Act of 2001 broadened
the definition of material support to include “any property, tangible or intangible, or
service, including
… training, expert advice or assistance
… or communications
equipment”.95
122. The criminal offences of solicitation or conspiracy, found in United States Crimi-
nal Code, title
18, section
373 (a) provides that any person can be charged with
solicitation who
“solicits, commands, induces or otherwise endeavours to persuade
another person to engage in a felonious conduct with intent that another person engage
in the conduct”.
123. In the United States, there have been several cases in which this approach has
been used to successfully prosecute the words or actions of terrorists communicated
via the Internet. These include United States of America v. Emerson Winfield Begolly.
United States of America v. Emerson Winfield Begolly
A 22-year-old student (a United States national), Emerson Winfield Begolly was indicted for
his involvement in the distribution over the Internet of information relating to bomb-making
and solicitation to commit violence on American soil. Additional charges against him included
assaulting and threatening Federal Bureau of Investigation
(FBI) agents with a loaded
firearm.
Formally known under the alias of “Asadullah Alshishani”, Begolly took an active part in
an internationally known jihadist forum called the Ansar al-Mujahideen English Forum and
eventually became an active moderator. The forum provided an opportunity for Begolly to
express his affinity for radical views while concurrently encouraging other members of his
faith to engage in terrorist acts within the United States. His propaganda also included dis-
semination of videos with instructions for making explosive devices to perform acts of ter-
rorism. The intended targets included synagogues, military facilities, train lines, police sta-
tions, bridges, cell phone towers and water plants.
Over a period of nine months, Begolly posted several lengthy messages in which he exten-
sively discussed the need for violence. An indictment issued on 14 July 2011, by the U.S.
District Court of the Eastern District of Virginia, included as a key evidence part of the
propaganda that Begolly had posted on an Internet forum:
Peaceful protests do not work. The Kuffara see war as solution to their problems, so
we must see war as the solution to ours. No peace. But bullets, bombs and martyrdom
operations.
He also posted links to an online document entitled “The explosives course”, made available
for download. The 101-page document authored by “The Martyred Sheik Professor Abu
Khabbab al Misri” (as referred to by Begolly) contains detailed instructions on setting up a
laboratory with basic chemistry components for the manufacture of explosives. A note was
added that those downloading the content should be careful to use anonymity software
for their own protection.
40
95 Renieris, “Combating incitement to terrorism on the Internet”, pp. 682-683.
CHAPTER III. Policy and legislative frameworks
During this time, Begolly had been under the constant surveillance of federal authorities.
An FBI agent downloaded the document from one of the uploaded links, which eventually
led to Begolly being arrested. On 14 April 2011, he was charged with unlawful and pur-
poseful distribution of information over the Internet related to the manufacture and distri-
bution of explosive materials, use of weapons of mass destruction and solicitation to commit
bombings of places for public use, government buildings and public transportation systems.
On 9 August 2011, Begolly pleaded guilty to solicitation to commit terrorist acts. He is cur-
rently awaiting sentencing.
a A term extensively used by Begolly during his online forum discussions in reference to the “non-believers”
or infidels.
(c) Review of legal approach to incitement
124. In Europe, article 3 of the Council of the European Union framework decision
2008/919/JHA of 28 November 2008 amending framework decision 2002/475/JHA on
combating terrorism, and article 5 of the Council of Europe Convention on the Pre-
vention of Terrorism oblige the respective member States of each instrument to crimi-
nalize acts or statements constituting incitement to commit acts of terrorism. The Coun-
cil of Europe Convention on the Prevention of Terrorism imposes an obligation on
member States to criminalize ‘“public provocation to commit a terrorist offence”, as
well as both recruitment and training for terrorism.
125. The implementation of the Convention, which is partly based on article 3 of the
Additional Protocol to the Council of Europe Convention on Cybercrime, concerning
the Criminalisation of Acts of a Racist and Xenophobic Nature Committed through
Computer Systems, obliges States to strike a sensible balance between the requirements
of law enforcement and the protection of human rights and liberties. It has therefore
given rise to fundamental concerns and debates. Nevertheless, article 5 (like articles 6
and 7 on recruitment and training for terrorist purposes) must be applied in conjunc-
tion with the basic provision of article 12, which provides that implementation of that
criminalization must be carried out in a manner that respects human rights, in particular
the rights to freedom of expression, freedom of association and freedom of religion, as
set out in human rights instruments, including article 10, paragraph 1, of the European
Convention for the Protection of Human Rights and Fundamental Freedoms.
126. The European Court of Human Rights, in assessing the protections afforded by
article
10, paragraph 1, of the European Convention for the Protection of Human
Rights and Fundamental Freedoms, has already dealt with article 5 of the Council of
Europe Convention on the Prevention of Terrorism. In the well-known case of Leroy v.
France,96 a French Court did not find a violation of article 10 in the case of a journalist
who had been convicted and fined for having published a certain cartoon in a Basque
weekly newspaper. On 11 September 2001, the cartoonist submitted to the magazine’s
96 Judgement by the European Court of Human Rights (Fifth Section), case of Leroy v. France, Application no.
36109/03 of 2 October 2008.
41
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
editorial team a drawing representing the attack on the twin towers of the World Trade
Centre, with a caption which parodied the advertising slogan of a famous brand: “We
have all dreamt of it ... Hamas did it” (cf. “Sony did it”). The drawing was then pub-
lished in the magazine on 13 September 2001.
127. In its reasoning, the European Court of Human Rights, inter alia, referred to
article 5 of the Council of Europe Convention on the Prevention of Terrorism, the first
time that the Court took that Convention into consideration in a judgement. It held
that the drawing went further than merely criticizing the United States but rather sup-
ported and glorified its violent destruction. The Court noted the caption that accom-
panied the drawing, indicating the applicants’ moral support for the suspected perpetra-
tors of the attacks of 11 September 2001. Other factors taken into account by the
Court were the applicant’s choice of language, the date of publication of the drawings
(which the Court considered increased the cartoonist’s responsibility) and the politically
sensitive region in which it was distributed (the Basque region). According to the Court,
the cartoon had provoked a certain public reaction, capable of stirring up violence and
demonstrating a plausible impact on public order in the region. The principles developed
in this landmark case will apply equally to cases in which the alleged incitement to
terrorism has occurred via the Internet.
128. There have been successful prosecutions for acts of incitement in Europe. For
example, in Germany in 2008, Ibrahim Rashid, an Iraqi Kurdish immigrant was con-
victed of incitement after being charged with waging a “virtual jihad” on the Internet.
Prosecutors claimed that, by posting Al-Qaida propaganda on Internet chat rooms,
Rashid was trying to recruit individuals to join Al-Qaida and participate in jihad.
129. The UNODC Digest of Terrorist Cases97 contains a useful summary of approaches
taken to the criminalization of acts of incitement in Algeria, Egypt, Japan and Spain.
In Algeria, article 87 bis 1 of the Penal Code makes acts of violent terrorism punish-
able by death, life imprisonment or other lengthy sentences. Article 87 bis 4 provides
that whoever justifies, encourages or finances the listed terrorist acts is subject to impris-
onment for from 5 to 10 years, as well as a fine.98
130. In Egypt, in article 86 bis of the Penal Code establishes as offences acts amount-
ing to executive and support responsibility, the planning and preparation of terrorist
acts, membership in or support of an illegal organization, providing financing and
material support of terrorist organizations, and incitement offences. Moreover, the article
provides aggravated penalties for, inter alia, intentionally promoting (by any means) the
purposes of terrorist organizations or for obtaining or producing (directly or indirectly)
articles, publications or recordings of any kind intended to promote or encourage such
purposes.99
97 United Nations Office on Drugs and Crime, Digest of Terrorist Cases (2010).
98 Ibid., para. 100.
42
99 Ibid., para. 111.
CHAPTER III. Policy and legislative frameworks
131. In Japan any person who induces a crime, directly or through an intermediary,
is subject to sentencing as though the inducer had been one of the material executors
of the offence (article 61 of the Penal Code).100 Other statutory provisions in Japan,
such as articles 38 to 40 of the Subversive Activities Prevention Act, criminalize incite-
ment of insurrection or arson, with the intent to promote, support or oppose any
political doctrine or policy.
132. In Spain, articles 18 and 579 of the Spanish Penal Code make public incitement
to commit a crime of terrorism a preparatory act of the crime of provocation. Article
578 punishes the crime of praising terrorism, an offence that was incorporated in the
Penal Code by Organic Law 7/2000 of 22 December 2000. As informally translated,
this article provides that “The praising or the justification by any means of public
expression or dissemination of the offences included in articles 571 to 577 of this Code
(Crimes of Terrorism) or of anyone who has participated in their execution, or com-
mission of acts that involve discredit, contempt or humiliation of the victims of a ter-
rorist offence or of their family will be punished with imprisonment from one to two
years.” The Organic Law also provided a penalty of a period of civil disability upon
conviction.101
133. In Indonesia there is no regulation specifically addressing activities undertaken
by terrorists via the Internet, including incitement to commit acts of terrorism. Article
14 of Law No. 15/2003 on the elimination of acts of terrorism deals with incitement
to conduct terrorist acts without reference to the particular mode of communication
used by the perpetrator, as does the Indonesian Penal Code, which addresses incitement
to commit other criminal acts. Indonesian authorities have successfully prosecuted per-
sons for terrorism-related activity over the Internet. In
2007,
24-year-old Agung
Prabowo, also known as Max Fiderman, was sentenced to three years of imprisonment
(pursuant to section 13 (c) of Government Regulation in Lieu of Law No. 1/2002 and
Law No. 15/2003 on the elimination of acts of terrorism) for registering and hosting
a website, www.anshar.net, at the request of Noordin M. Top, leader of the Jemaah
Islamiyah terrorist group, through an intermediary, Abdul Aziz. Aziz is reported to have
designed www.anshar.net in mid-2005 at Top’s request, with the aim of spreading jihad-
ist propaganda. While it contained general information about Islam and jihad, it also
contained specific “tips and advice” on how and where to carry out terrorist attacks,
suggesting roads leading into shopping centres and offices, traffic jams and specific
named locations where members of the public could be found.102 In another case,
Muhammad Jibril Abdul Rahman, also known as Muhammad Ricky Ardan (the “Prince
of Jihad”), was sentenced to five years of imprisonment for having been an accomplice
in an act of terrorism.
134. In Singapore, in the Internet context, section 4 2 (g) of Singapore’s Internet
Code of Practice prohibits material that “glorifies, incites or endorses ethnic, racial or
religious hatred, strife or intolerance”.
100 Ibid., para. 100.
101 Ibid., para. 115.
43
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
2. Rule-of-law considerations related to criminalization of incitement
135. When calling upon States to criminalize the incitement of terrorist acts, Security
Council resolution 1624 (2005) expressly provides that States must ensure that any
measures adopted to implement their obligations comply with all their obligations under
international law, in particular human rights law, refugee law and humanitarian law.
136. This principle, which is also reflected in the universal counter-terrorism instru-
ments, has been reaffirmed many times at the international level (including within the
framework of the United Nations), is a fundamental element of the UNODC “rule of
law” approach to strengthening criminal justice responses to terrorism under the uni-
versal legal regime against terrorism and is supported by many regional counter-ŧerrorism
and human rights instruments, most notably those elaborated by the Council of Europe,
which have been referred to earlier (see section II.D above).103
137. It is not possible within the confines of the present publication to fully analyse,
in the context of respect for guaranteed human rights to freedom of expression, all the
commentaries and judicial authority available on the proper scope and application of
offence provisions enacted by countries to criminalize the incitement of terrorist acts.
138. Nevertheless, while the available jurisprudence on the precise scope of interna-
tional human rights instruments such as article
10, paragraph 1, of the European
Convention for the Protection of Human Rights and Fundamental Freedoms and article
19 of the International Covenant on Civil and Political Rights leaves room for ongoing
debate, what is clear is that, in practice, striking the right balance between preserving
the right to freedom of expression and enforcing criminal legislation targeting the incite-
ment of terrorist acts continues to be a challenge for Governments.
3. Law enforcement powers
139. The investigation of terrorism cases involving the use of the Internet or other
related services by suspected terrorists will often necessitate some type of intrusive or
coercive search, surveillance or monitoring activity by intelligence or law enforcement
agencies. It is therefore important, for the success of any prosecution, that these inves-
tigative techniques be properly authorized under national laws and, as always, that
supporting legislation uphold fundamental human rights protected under international
human rights law.
103 See the reports of the Special Rapporteur on the promotion and protection of human rights and fundamental
freedoms while countering terrorism to the Human Rights Council and the General Assembly, in which the Special
Rapporteur expressed concerns about the possible effect that legislation targeting incitement might have on freedom of
speech and expression by promoting the criminalization of free speech falling short of incitement of terrorism. These
views and concerns were highlighted in a written submission made to the expert group meeting by the Office of the
United Nations High Commissioner for Human Rights; see also the joint Declaration on Freedom of Expression and
the Internet, issued on 1 June 2011 by the Special Rapporteur on the promotion and protection of the right to freedom
of opinion and expression, the Representative on Freedom of the Media of the Organization for Security and Co-
operation in Europe, the Special Rapporteur for Freedom of Expression of the Organization of American States and
the Special Rapporteur on Freedom of Expression and Access to Information in Africa of the African Commission on
44
Human and Peoples’ Rights, in which they reaffirmed fundamental importance of the right to freedom of expression.
CHAPTER III. Policy and legislative frameworks
(a) Search, surveillance and interception powers
140. In Israel investigative powers for the collection of digital evidence on the Inter-
net, in both general criminal and terrorism-related cases, are dealt with under the
Computers Act of 1995, which defines a few specific powers for gathering digital
evidence. The Computers Act amended the Wiretap Act, deeming the acquisition of
communications between computers to be a “wiretap”, and therefore, making it pos-
sible for investigative authorities to obtain judicial permission, or administrative per-
mission in urgent and exceptional cases, to acquire data transferred on communication
between computers.
141. In 2007, the Communication Data Act was enacted. The purpose of that statute
was to arrange, in a more structured and progressive manner, the accepted practice
regarding obtaining non-content data from landline and cellular phone companies, as
well as from Internet-access providers. The Act does not apply to Internet-service pro-
viders that provide other services, such as information storage, information-sharing,
e-mail, social services and so forth. Currently, in cases in which authorities wish to
obtain information from Internet-service providers, an old section of the law applies
that enables them, in general, to issue a subpoena and obtain information from anyone
who has information that might advance the investigation.
142. In 2010, the Government of Israel promoted a bill aimed at codifying investi-
gative powers relating to both physical and digital data. The bill is designed to arrange,
in an advanced manner, the gathering of digital evidence. It contains an orderly
arrangement of powers that are not currently set forth in Israeli legislation, such as
secret searches of computers
(in the case of especially serious crimes), obtaining
information that is to be stored (in the future) on a certain computer, the manner
in which stored e-mails in the possession of the service provider are to be obtained,
a search of computer material by administrative authorization under certain circum-
stances. If passed, these measures would apply to terrorism cases involving use of the
Internet.
143. In 2006, the Government of France passed new counter-terrorism legislation
facilitating, for the purpose of terrorism-related investigations, the surveillance of com-
munications and police access to communication data from telephone operators,
Internet-service providers and Internet cafes.
144. The Law of Combating Terrorism and on Various Provisions Concerning Security
and Borders Controls (2006-64 of 23 January 2006) provided that Internet-service
providers, Internet cafes, hosting providers and operators must communicate traffic
data, called numbers and IP addresses to specialist government agencies in cases related
to the investigation of suspected terrorist activities.
145. Under article 6, mobile phone operators and Internet cafes are required to keep
records of client connections for 12 months and make these available to police. The
law also authorizes the use of surveillance cameras in public spaces such as train sta-
45
tions, churches and mosques, shops, factories and nuclear plants. Article 8 allows police
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
to automatically monitor vehicles and occupants on French roads and highways (includ-
ing by taking pictures of vehicle licence plates and occupants) and to monitor people
at large public gatherings.104
146. More recently, on 14 March 2011, the French Code of Criminal Procedure was
amended to provide authorities with additional powers in terrorism investigations. These
amendments include the power to requisition documents relevant to an investigation
(including the conversion and transfer of computer data), the decryption of protected
computer data, numeric infiltration, the capture of computer data (including images),
wiretapping and the interception of other communications. Moreover, the law establishes
the legal basis for the activities of law enforcement officers engaged in, inter alia, online
chat room discussions as part of investigations into crimes related to the incitement of
terrorism. This is an important legal issue to which Governments might wish to give
consideration. These articles provide French law enforcement authorities with, inter alia,
the ability to obtain evidence related to the connection data of e-mails, telephone activ-
ity and IP addresses.
147. The expert from China referred to regulations in that country under which the
police, when undertaking a criminal investigation involving the use of the Internet, may
order the submission by the Internet-service provider and Internet-communication
provider of relevant records and data, which they are required to retain by law for 60
days.
148. In the United Kingdom, the Regulation of Investigatory Powers Act 2000 sets
out a legal framework regulating the following five types of surveillance activities under-
taken by Government agencies:
••
Interception of communications (e.g. intercepting telephone calls or accessing
the contents of e-mails)
••
Intrusive surveillance (e.g. covert surveillance in private premises or vehicles)
••
Directed surveillance (e.g. covert surveillance against an identified target in a
public place)
••
Covert human intelligence sources (e.g. undercover agents)
••
Communications data (e.g. records related to communications but not the
content of such communications).105
149. In addition to setting out the purposes for and procedures by which such activi-
ties must be authorized, the Act obliges surveillance authorities to consider whether
the exercise of these powers and the interference with the rights of the individuals under
surveillance are proportionate and to take steps to avoid what is known as “collateral
intrusion”, whereby the rights of parties other than those being targeted are affected.
105“Summary of surveillance powers under the Regulation of Investigatory Powers Act”, National Council for Civil
46
Liberties.
CHAPTER III. Policy and legislative frameworks
The Act also makes it an offence for parties holding encryption keys for targeted com-
munications to withhold such keys from authorized agencies.106
150. In 2000, the Government of India passed the Information Technology Act 2000,
which it amended in 2008, to provide for the offence of “cyber-terrorism” (section
66F) and other Internet-related issues. Section 67C (1) of the Act deals with the issue
of data retention, stipulating that regulated providers “shall preserve and retain such
information as may be specified for such duration and in such manner and format as
the Central Government may prescribe” and making it an offence (punishable by up
to three years of imprisonment and fines) to knowingly contravene this obligation.
151. Section 69 (1) of the Act provides Government authorities with the power to
issue directions for the “interception, monitoring, and decryption of any information
generated, transmitted, received or stored in any computer resource” and sets out the
legal obligations and safeguards attaching to such State actions, while Section 69A (1)
provides State agencies with the power to issue directions for blocking public access to
any information through computer resources if they consider it necessary or expedient
to do so, in the interests of India’s sovereignty, integrity, security and international
relations, or to prevent the incitement of related “cognizable” offences, including ter-
rorism. Finally, Section 69B provides designated State agencies with the power to moni-
tor, collect and store data traffic or information generated, transmitted or received via
any computer resource.
152. In New Zealand, the Search and Surveillance Act 2012 updates, consolidates
and harmonizes the powers of law enforcement agencies relating to search, surveillance
and interception of communications to address new forms of technology. The Act cre-
ates a new definition of the term “computer system searches”, extending it to include
the search of computers that are not internally connected to, but are able to access, a
network remotely.
153. In order to strengthen legal safeguards, the Act makes it clear that remote-access
searching of computers is permitted in only two situations: when a computer had the
capability to lawfully access a computer system which is the subject of the search and
is therefore considered part of that system; and when there was no physical location to
search (e.g. in the case of web-based e-mail that the user accesses from various locations,
such as Internet cafes). The Act also provides that, when police undertake authorized
remote access searches of Internet data facilities, they must provide electronic notifica-
tion of the search via e-mail, sent to the e-mail address of the facility being searched.
(b) Issues associated with the provision of interception capability
154. When undertaking electronic monitoring, surveillance or interception activities,
authorities will require the cooperation of operators that provide public telecommuni
cations or related services. While in many cases private sector operators are willing to
106 Ian Walden, Computer Crimes and Digital Investigations (Oxford University Press, 2007), p. 216.
47
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
provide assistance to law enforcement agencies undertaking their lawful functions, clearly
there are limits to the time and resources they are willing to expend on an entirely gratis
basis. It is therefore desirable that Governments provide a clear legal basis for the
obligations placed on private sector parties, including the technical specifications required
of their networks and how the cost of providing such capabilities is to be met.
155. In Israel, section 13 of the Communication Law, 1982, states that the Prime
Minister may direct Internet-access providers, within Israel, to carry out technological
modifications as required by security forces (defined as including police, security and
other special services) for the purpose of counter-terrorism activities. The law applies
only to Internet-access providers, who under Israeli law receive their licences from the
Ministry of Communications. It does not apply to data storage service providers or
content management providers operating within Israel, as these operators do not require
a licence from the Ministry.
156. In New Zealand, the Telecommunications (Interception Capability) Act 2004
clarifies the obligations of network operators to assist authorized government agencies
in undertaking interception operations or providing authorized call-associated data. The
Act obliges network operators to ensure that every public telecommunications network
or service that it owns, controls or operates has interception capability. Networks or
services are deemed to have this capability when authorized government agencies are
able to intercept telecommunications or services in a manner that identifies and inter-
cepts only targeted telecommunications, provides call-associated data and content (in
a usable form) and enables unobtrusive, timely and efficient interception in a manner
that protects the privacy of, and avoids undue interference with, other telecommunica-
tions users. The Act also obliges network operators to provide the means of decrypting
any telecommunication carried over their network if the content is encrypted and the
network operator has provided that encryption facility.
157. Recognizing the time and expense involved for some network operators to comply
with these requirements, the Act provided affected operators with periods of 18 months
to five years (depending on the status of the network) within which to incorporate this
capability. Moreover, the Government agreed to meet the costs of incorporating inter-
ception capability into those networks already in operation at the date of commencement
that lacked the necessary interception capability.
158. In Brazil, Federal Law No. 9.296 of 1996, together with article 5 (XII) of the
Federal Constitution of 1988, regulates official wiretapping undertaken by authorized
government agencies. While recognizing the inviolable nature of telecommunications,
the laws provide, subject to judicial authorization, specific derogations for the purpose
of criminal investigations or penal processes. The law sets out the procedures to be
followed in wiretap cases, which take place under supervision of a judge. Once executed,
the results of the wiretap are transcribed and provided to the judge, along with a sum-
mary of all actions taken pursuant to the authority (article 6).
159. In order to meet their legal obligations, telecommunications companies have been
required to establish and train specialized units and invest in necessary technology. With
48
regard to the costs of providing interception capability, it falls to the
CHAPTER III. Policy and legislative frameworks
telecommunications companies to provide the necessary technical resources and staff
to support authorized interception activities. This approach reflects the fact that under
Brazil’s Constitution telecommunications companies operate under a government con-
cession and provision of telecommunications services is considered a public service.
160. In Indonesia, following the Bali bombings in 2002, the Government passed anti-
terrorism legislation which permits law enforcement and security agencies, for the pur-
pose of terrorism-related investigations, to intercept and examine information that is
expressed, sent, received or stored electronically or with an optical device. In relation
to the retention period of Internet or log files, this subject is regulated under Law No.
11 of 2008 on Electronic Information and Transactions, specifically article 6, paragraph
1, subparagraph a, which obliges every system operated by an electronic system provider
to reproduce in complete form any electronic information and/or electronic document
for the duration of the retention period stipulated under the law.
161. In Algeria, in 2006, the Government adopted a law permitting microphone and
video surveillance and the interception of correspondence, if authorized and executed
under the direct control of the prosecutor. The same law authorizes the technique of
infiltration for the purpose of investigating terrorism or organized crime and permits
the agent to commit specified minor infractions in the course of the infiltration. The
secrecy of the agent’s identity is carefully protected by law, but the infiltration must be
conducted under the authority of the prosecutor or investigating magistrate.107
162. In Malaysia, the Communications and Multimedia Act 1998 contains several
provisions pertaining to the regulation of the Internet and related criminal investiga-
tions. For example, section 249 of the Act dealing with the issue of access to computer
data during searches provides that access includes obtaining “passwords, encryption or
decryption codes, software or hardware and any other means required to enable com-
prehension of computerized data”.
163. In addition, chapter 4 of the Act, relating to national interest matters, imposes
a general obligation on Internet service operators to use “best endeavours” to ensure
that the network facilities they provide are not used for the commission of any offence
under the law of Malaysia (Section 263) and provides that the responsible minister may
determine, specifying related technical requirements, that a licensee or class of licensees
shall implement the capability to allow authorized interception of communications (Sec-
tion 265).
164. Chapter 2 of the Act relates to the issue of offensive content, and prohibits
content application service providers and any persons using such services from provid-
ing content that is “indecent, obscene, false, menacing, or offensive in character with
intent to annoy, abuse, threaten or harass any person” (Section 211). Persons contra-
vening these obligations commit an offence and are liable to a fine not exceeding 50,000
ringgit (approximately US $16,200) or to imprisonment for a term not exceeding one
year, or both, and shall also be liable to an ongoing fine of 1,000 ringgit (approximately
107 United Nations Office on Drugs and Crime, Digest of Terrorist Cases, para. 215.
49
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
US $325) for every day or part of a day during which the offence is continued after
conviction. Section 212 of the Act provides for the designation of an industry body to
be a forum for the development of an industry code relating to content.
165. In the United States, telecommunications operators are currently obliged, under
the Communications Assistance to Law Enforcement Act 1994, to provide interception
capability for telephone and broadband networks.
(c) Regulation of Internet cafes
166. There is evidence that terrorists have in some cases used Internet cafes to carry
out actions associated with terrorism; however, there is no data available on the propor-
tion this type of activity in relation to legitimate Internet activity conducted through
these services.
167. The issue of the extent to which Governments should, for counter-terrorism
purposes, regulate Internet or cybercafes is a complex issue, closely linked to human
rights issues. Internationally, there is a divergence of approaches. In some States, includ-
ing Egypt, India, Jordan and Pakistan, Governments apply specific legislative or regula-
tory measures, which oblige operators of Internet cafes to obtain, retain and, upon
request, produce photo identification, addresses and usage/connection data of customers
to law enforcement agencies.
168. While Governments can impose obligations on operators of Internet cafes aimed
at restricting misuse of those services by terrorists, the utility of such measures is open
to debate, especially when facilities such as other publicly available Internet services
(e.g. computers at public libraries or public wireless fidelity (Wi-Fi) zones) that offer
similar opportunities for the anonymous use of the Internet by terrorists. It is noted
that in 2005, the Government of Italy imposed regulatory obligations on operators of
Internet cafes relating to the identification of customers; however, these regulations were
abolished in late 2010, owing in part to concerns about the effect that this form of
regulation might have on the development of Internet services and their uptake by
legitimate users.
(d) Content control
169. The issue of the extent to which Governments should regulate terrorism-related
content on the Internet is highly contentious. Approaches vary considerably, with some
States applying strict regulatory controls on Internet and other related service providers,
including in some cases the use of technology to filter or block access to some content.
Others adopt a lighter regulatory approach, relying to a greater extent on self-regulation
by the information sector.
170. In the article “Terrorism and the Internet: should web sites that promote terror-
ism be shut down?”,108 Barbara Mantel notes that “most Internet service providers, web
108 Barbara Mantel, “Terrorism and the Internet: should web sites that promote terrorism be shut down?”, CQ
50
Global Researcher, vol. 3, No. 11 (November 2009).
CHAPTER III. Policy and legislative frameworks
hosting companies, file-sharing sites and social networking sites have terms-of-service
agreements that prohibit certain content”. For example, she notes, Yahoo’s Small Busi-
ness Web hosting service specifically forbids users from utilizing the service to provide
material support or resources to any organization(s) designated by the United States
Government as a foreign terrorist organization. To that extent, there is an element of
self-regulation within the information society.
171. When assessing the approach and level of intervention in this area, Governments
need to take a number of factors into account, including the location where content is
hosted, constitutional or other safeguards relating to the right to freedom of expression,
the content itself and the strategic implications from an intelligence or law enforcement
perspective of monitoring or infiltrating certain sites or rendering them
inaccessible.109
172. In the United Kingdom, an innovative tool, available to authorities in dealing
with cases involving potential acts of incitement over the Internet, is contained in sec-
tion 3 of the Terrorism Act 2006, which provides police with the power to issue a “take
down” notice to persons associated with operating websites or other Internet content.
173. Section 3 of the Act applies to cases involving offences under sections 1 or 2 of
that Act in which “(a) a statement is published or caused to be published in the course
of, or in connection with, the provision or use of a service provided electronically; or
(b) conduct falling within section 2(2) [dissemination of a terrorist publication] was in
the course of, or in connection with, the provision or use of such a service”.
174. Section 3(2) provides that, if the person upon whom the notice has been served
fails to remove the terrorism-related content, and if he or she is subsequently charged
with offences under sections 1 or 2 of the Terrorism Act 2006 in relation to it, then a
rebuttable assumption may be made at trial that the content in question had his or her
endorsement.
175. Despite the availability of these “take down” notices as a preventive measure, in
practice this power has not yet been used. In most cases, especially when the offending
content was hosted on the websites of third parties, it tended to breach the terms and
conditions of the service provider, and authorities were able to successfully negotiate
the removal of the offending content. In fact, in the United Kingdom the specialized
Counter Terrorism Internet Referral Unit coordinates national responses to referrals
from the public, as well as from Government and industry, on terrorism-related Internet
content and acts as a central, dedicated source of advice for the police service.
109 Catherine A. Theohary and John Rollins, “Terrorist use of the Internet: information operations in cyberspace”,
Congressional Research Service report (8 March 2011), p. 8.
51
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
4. International cooperation
176. States are obliged, under many different international, regional, multilateral and
bilateral instruments related to terrorism and transnational organized crime, to establish
policies and legislative frameworks to facilitate effective international cooperation in the
investigation and prosecution of these types of cases.
177. In addition to having policies and legislation that establish criminal offences
necessary to satisfy dual criminality requirements, States should enact comprehensive
legislation that provides their authorities with a legal basis for international cooperation
with foreign counterparts in transnational terrorism-related investigations. In cases
involving the use of Internet, it is highly likely that effective international cooperation,
including the ability to share information, including Internet-related data, will be a key
factor in the success of any criminal prosecution.
178. Issues related to international cooperation in terrorism cases are dealt with in
closer detail in chapter V below.
52
IV. Investigations and intelligence-gatheringIV.
A. Tools in the commission of terrorist offences involving the Internet
179. Technological advancements have provided many sophisticated means by which
terrorists may misuse the Internet for illicit purposes. Effective investigations relating
to Internet activity rely on a combination of traditional investigative methods, knowledge
of the tools available to conduct illicit activity via the Internet and the development of
practices targeted to identify, apprehend and prosecute the perpetrators of such acts.
180. A case from France illustrates how different types of investigative techniques,
both traditional and specifically relating to digital evidence, are employed in unison to
compile the necessary evidence to successfully prosecute terrorist use of the Internet.
Public Prosecutor v. Arnaud, Badache, Guihal and others
This French case involves several defendants: Rany Arnaud, Nadir Zahir Badache, Adrien
Luciano Guihal and Youssef Laabar, who were convicted on 26 January 2012 by the Tribunal
Correctionnel de Paris and sentenced to terms of imprisonment ranging from 18 months
to 6 years for, inter alia, disseminating terrorist-related material.
Arnaud, Badache and Guihal were arrested in France in December 2008 after Arnaud, who
operated under the username of “Abdallah”, posted messages calling for jihad against
France on a propaganda website, minbar-sos.com:
“Do not forget that France keeps on fighting our brothers in Afghanistan and that you
are in a land of war, rush up to martyr as soon as you can, boycott their economy,
squander their wealth, do not support their economy and do not participate in the
financing of their armies.”
As a result of the posting, authorities had intercepted Arnaud’s Internet account, put him
under physical surveillance and tapped his phone line. After arresting Mr. Arnaud, investiga-
tors forensically examined the content of the computers used by him and found that he
had conducted research on matters relating to the commission of terrorist acts, for example
products capable of being used to make explosives and incendiary devices, identifying pos-
sible targets and tracking the activities of a company which used ammonium nitrate. The
enquiries revealed that Arnaud had recruited Guihal and Badache, taken part in meetings
and discussions to prepare an attack, made contact with people involved in jihadist move-
ments to seek help in carrying it out and received remittances to fund it. These acts con-
stituted crimes pursuant to articles 421-2-1, 421-1, 421-5, 422-3, 422-6 and 422-7 of the
French Criminal Code, and articles
203 and 706-16 et. seq. of the Code of Criminal
Procedure.
53
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
The Court found that the plan in which Mr. Arnaud had allegedly taken part, in association
with the other offenders, which consisted of placing explosives on a truck that would explode
upon reaching the target, posed a particularly high threat to public policy. He was thus
sentenced to six months imprisonment on charges relating to participating in a group com-
mitting criminal acts for the purpose of preparing a terrorist attack, possession of several
fraudulent documents and fraudulent use of administrative documents evidencing a right,
identity or quality or granting an authorization. On the same charge, Mr. Badache was
sentenced to two years of imprisonment, with six months suspended, while Mr. Guihal was
sentenced to four years, with one year suspended. Mr. Laabar, who faced trial for other
related acts, was sentenced to 18 months incarceration.
181. The investigation and prosecution of cases involving digital evidence requires
specialist criminal investigation skills, as well as the expertise, knowledge and experience
to apply those skills in a virtual environment. While the admissibility of evidence is
ultimately a question of law, and therefore within the remit of the prosecutors, inves-
tigators should be familiar with the legal and procedural requirements to establish
admissibility for the purposes of both domestic and international investigations. A sound
working knowledge of the requirements of applicable rules of evidence, and in particular
with respect to digital evidence, promotes the collection of sufficient admissible evidence
by investigators to support the successful prosecution of a case. For example, the pro-
cedures used in gathering, preserving and analysing digital evidence must ensure that
a clear “chain of custody” has been maintained from the time it was first secured, so
that it could not have been tampered with from the moment of its seizure until its final
production in court.110
1. Internet-based communication
(a) Voice-over-Internet protocol
182. Over the past decade, applications that allow users to communicate in real time
using voice-over-Internet protocol (VoIP), video chat or text chat have grown in popu-
larity and sophistication. Some of these applications offer advanced information-sharing
functions, for example allowing users to share files or giving them the ability to remotely
view another user’s onscreen activity in real time. VoIP in particular has become increas-
ingly used as an effective means to communicate via the Internet. Well-known VoIP
service providers include Skype and Vonage, which operate by converting analogue
sound into a compressed, digital format, enabling transfer of the digital packets of
information via the Internet, using relatively low bandwidth connections.
183. As VoIP telephony involves the transmission of digital data packets, rather than
analogue signals, and service providers typically generate subscriber invoices related to
Internet usage based on aggregate data volume, computer-to-computer VoIP calls are
not invoiced on a per-call basis, as is the practice with traditional mobile and fixed-line
110 See, for example, Association of Chief Police Officers (United Kingdom), Good Practice Guide for Computer-Based
54
Electronic Evidence. Available from www.7safe.com/electronic_evidence/ACPO_guidelines_computer_evidence.pdf.
CHAPTER IV. Investigations and intelligence-gathering
telephone calls. This difference in billing practices may have a significant impact on
investigations involving VoIP communications, as it makes it more difficult for law
enforcement authorities to corroborate such communications with markers relating, for
example, to the time of the call and the location of the participants. Other indicators,
however, such as the timing and volume of Internet data traffic, may also provide a
means to identity perpetrators of illicit Internet activity (see para. 205 below). Addi
tionally, while the origin and destination of conventional telephone calls may be routed
via fixed-line switches or cellular communication towers, which leave geolocational
traces, wholly Internet-based VoIP communications, conducted for example via wireless
networks, may pose challenges in the context of an investigation. Further complicating
factors arising out of the use of VoIP technology may involve, inter alia, the routing of
calls via peer-to-peer networks and the encryption of call data (discussed in greater
detail in section IV.A.2 below).111
184. Duly submitted information requests to VoIP service providers may, however, still
provide valuable identifying information such as a user’s IP address, e-mail address or
payment details.
(b) Electronic mail
185. Web-based e-mail services also provide terrorists with a covert means of com-
munication, which can be misused for illicit purposes. E-mail messages sent between
parties typically contain a number of elements which may be of investigative value. A
typical e-mail may be comprised of the envelope header, the message header, the mes-
sage body and any related attachments. While only an abbreviated version of the enve-
lope header may be displayed, in accordance with the settings of the applicable software,
the complete envelope header generally contains a record of each mail server through
which the message transited on the way to the final recipient, as well as information
regarding the IP address of the sender.112 The information contained in the envelope
header is less susceptible to tampering (although not impermeable) than that in the
message header, which generally consists of user-provided information in fields such as
“To”, “From”, “Return-Path”, “Date” and “Time”, as displayed on the device from
which the message is being sent.113
186. One commonly used technique to reduce electronic traces between parties, and
therefore the likelihood of detection, is communication through the use of saved, unsent
messages in the draft folder of the e-mail account. This information is then available
to multiple parties using a shared password to access the account. Additional steps may
also be taken to avoid detection, for example use of a remote public access terminal,
such as in an Internet cafe, to access the draft message. This method was used in con-
nection with the Madrid terrorist bombings in 2004.
111Written submission of expert from the Raggruppamento Operativo Speciale of the Carabinieri of Italy.
112 United States, Department of Justice, Office of Justice Programs, National Institute of Justice, Investigations
Involving the Internet and Computer Networks (2007), p. 18 ff.
113 Ibid., p. 20.
55
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
187. It is also possible to employ anonymizing techniques (discussed in greater detail
in section IV.A.2 below) in connection with e-mail communications, for example by
disguising the IP address associated with the sender of an e-mail. Anonymizing mail
servers may also be used, which remove identifying information from the envelope
header prior to forwarding it to the subsequent mail server.
The importance of international cooperation in
investigating terrorism-related Internet activities
The expert from the Italian Raggruppamento Operativo Speciale (Special Operations Group)
of the Carabinieri of Italy outlined the key role of international cooperation and specialized
investigative techniques in the investigation of the use of the Internet for terrorist purposes
by the Turkish-based extremist organization, The Revolutionary People’s Liberation Party-Front
(DHKP-C). Close collaboration between law enforcement officials in Turkey and Italy enabled
the Italian investigators to identify the encryption techniques and other data security meas-
ures used by DHKP-C members to exchange information in furtherance of terrorist purposes,
including via online mail services. In particular, DHKP-C members used the stenography
software Camouflage to hide data within images in JPEG and GIF files, and WinZip software
to encrypt files, which were included as attachments to e-mail communications (see section
IV.A.2 below). Italian investigators intercepted or otherwise obtained encryption passwords
and identified relevant programs to assist in deciphering communications. Additional infor-
mation was obtained through forensic computer analysis, using EnCase software (See section
IV.C below) and traditional investigative techniques, to enable investigators to obtain digital
evidence from the computers of a suspect under investigation. The results of this investiga-
tion, together with extensive cross-border cooperation, led to the arrest, in April 2004, of
82 suspects in Turkey and an additional 59 suspects in Belgium, Germany, Greece, Italy and
the Netherlands.
(c) Online messenger services and chat rooms
188. Online messenger services and chat rooms provide additional means of real-time
communication, with varying degrees of potential anonymity. Online messenger services
typically involve bilateral communications, while chat rooms offer open communication
among a group of individuals. Registration for online messenger services is typically
based on unverified, user-provided information; however, some Internet services also
log the IP address in use at the time of registration, which may be requested by law
enforcement authorities, subject to applicable legal safeguards. Communications are
usually identified by a unique screen name, which may be assigned permanently upon
registration or limited to a particular online session. Information shared during an
online messenger session is not generally recorded by the service provider and therefore
may not be available for retrieval after the online session is terminated, subject to
recovery facilitated by forensic analysis of a participant’s hard drive.
189. Password-protected online chat rooms may be used by terrorist organizations and
sympathizers to promote a sense of community within a global environment. Chat room
messages may be subject to more monitoring and recordkeeping by the service provider
56
than bilateral messaging are, increasing the likelihood of potentially obtaining
CHAPTER IV. Investigations and intelligence-gathering
documentary evidence in connection with investigations.114 In some jurisdictions, law
enforcement personnel may, subject to certain conditions, covertly register for, and
participate in, chat room discussions under a pseudonym in connection with an
investigation.
190. For example, in France, article 706 of the Code of Criminal Procedure provides
for the authorization by the prosecutor or investigative judge of such infiltration opera-
tions in connection with offences committed through electronic communications (see
discussion in section III.C.3(a)). The aim of such operations may be, inter alia, to
gather intelligence or otherwise take proactive action in connection with a perceived
terrorist threat. Due care should be taken, however, at the inception of the operation
to ensure that any infiltration of online chat room or other Internet-based discussions
is conducted in a manner that would not support a defence of entrapment, based on
the assertion that a government authority induced a suspect to commit a crime that
he or she was not predisposed to commit.
(d) File-sharing networks and cloud technology
191. File-sharing websites, such as Rapidshare, Dropbox or Fileshare, provide parties
with the ability to easily upload, share, locate and access multimedia files via the Inter-
net. Encryption and anonymizing techniques employed in connection with other forms
of Internet communication are similarly applicable to files shared via, inter alia, peer-
to-peer (P2P) and File Transfer Protocol (FTP) technology. For example, in the Hicheur
case (see para. 20 above), evidence was presented that digital files in support of terrorist
activities were shared via Rapidshare, after being encrypted and compressed for security.
Some file-sharing networks may maintain transfer logs or payment information, which
may be relevant in the context of an investigation.
192. Cloud computing is a service which provides users with remote access to pro-
grams and data stored or run on third-party data servers. As with file-sharing, cloud
computing provides a convenient means to securely store, share and distribute material
online. The use of cloud technology to access remotely stored information reduces the
amount of data stored locally on individual devices, along with the corresponding ability
to recover potential evidence in connection with an investigation of terrorist use of the
Internet.
193. The data servers used to provide these services may also be physically located
in a different jurisdiction from that of the registered user, with varying levels of regula-
tion and enforcement capabilities. Close coordination with local law enforcement
authorities may therefore be required to obtain key evidence for legal proceedings.
2. Data encryption and anonymizing techniques
194. Data encryption refers to the protection of digital information from disclosure
by converting it into ciphertext, using a mathematical algorithm and an encryption key,
114 Ibid., pp. 34 ff.
57
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
so that it is intelligible only to the intended recipient. Encryption tools may be hard-
ware- or software-based, or a combination of both. Once encrypted, a password, a
passphrase, a “software key” or a physical access device, or some combination thereof,
may be required to access the information. Encryption may be employed in respect of
both “at-rest” data, contained in storage devices such as computer hard drives, flash
media and smart phones, and “in transit” data, transmitted over the Internet, for exam-
ple by means of VoIP and e-mail communications. Some examples of common software-
based encryption tools include those integrated into computer operating systems or
applications, as well as stand-alone software such as Pretty Good Privacy and WinZip.115
In a case in Brazil, an investigation was launched on the basis of international coopera-
tion and information-sharing against a suspect alleged to be participating in, moderating
and controlling the operations of a jihadist website affiliated with recognized terrorist
organizations, notably Al-Qaida. This website hosted videos, text and messages from
leadership-level extremist militants, which had been translated into English to reach a
broader audience, and was also used to conduct fundraising activities and racially moti-
vated propaganda campaigns. The police operation that led to the detention of the
suspect was targeted to take the suspect by surprise, while he was connected to the
Internet and actively engaged in activities relating to the website. By apprehending the
suspect while his computer was on and the relevant files were open, investigators were
able to bypass the cryptographic symmetric keys and other encryption and security
features used by the suspect and his associates. Investigators were therefore able to
access digital content that might have been otherwise unavailable or more difficult to
obtain if the computer had been secured while it was shut off.
195. Internet activity, or the identity of the associated users, can also be disguised
through advanced techniques, including masking the source IP address, impersonating
another system’s IP address or redirecting Internet traffic to an obscured IP address.116
A proxy server enables users to make indirect network connections to other network
services. Some proxy servers allow the configuration of a user’s browser to automatically
route browser traffic through a proxy server. The proxy server requests network services
on behalf of the user and then routes the delivery of the results again through a proxy.
Varying levels of anonymity may be facilitated by the use of proxy servers. A proxy may
obscure the identity of a user by fulfilling requests for network services without reveal-
ing the IP address from which the request originates, or by intentionally providing a
distorted source IP address. For example, applications such as The Onion Router may
be used to protect the anonymity of users by automatically rerouting Internet activity
via a network of proxy servers in order to mask its original source. Rerouting network
traffic via multiple proxy servers, potentially located in different jurisdictions, increases
the degree of difficulty of accurately identifying the originator of a transmission.
196. Alternatively, a suspect may hack into a legitimate organization’s IP address and
browse the Internet using the hacked address. Any traces of such activity would be
115 United States, Department of Justice, Office of Justice Programs, National Institute of Justice, Investigative Uses
of Technology: Devices, Tools and Techniques (2007), p. 50.
58
116 National Institute of Justice, Investigations Involving the Internet and Computer Networks, p. 9.
CHAPTER IV. Investigations and intelligence-gathering
linked to the IP address of the compromised organization. A suspect may also access
a website through a compromised computer or store malware (used, for example, to
obtain credit card or other personal financial information) on compromised websites
in an effort to avoid being identified.
197. There is a variety of software programs that are available to disguise or encrypt
data transmitted over the Internet for illicit purposes. These programs may include the
use of software such as Camouflage to mask information through steganography or the
encryption and password protection of files using software such as WinZip. Multiple
layers of data protection may also be employed. For example, Camouflage allows one
to hide files by scrambling them and then attaching them to the end of a cover file of
one’s choice. The cover file retains its original properties but is used as a carrier to
store or transmit the hidden file. This software may be applied to a broad range of file
types. The hidden file may, however, be detected by an examination of raw file data,
which would show the existence of the appended hidden file.117
198. In the United Kingdom, it is a criminal offence under the Regulation of Inves-
tigatory Powers Act 2000 to refuse to hand over an encryption key when required. Care
must be taken, however, to ensure that suspects do not seek to evade the provision by
utilizing several layers of encryption and multiple keys to protect different data sets.
For example, a setting of TruCrypt, a common free encryption tool, allows a suspect
to encrypt a hard drive and create two passwords: one for the “clean” drive and the
other containing the incriminating material. This can be circumvented by ensuring that
the forensic examination of the hard drive takes into consideration whether there is any
“missing volume” of data. Additionally, offences of this nature are usually summary
offences, which carry maximum penalties of six months imprisonment. In the United
Kingdom, however, when the case involves national security issues, the maximum pen-
alty increases to two years of imprisonment.
3. Wireless technology
199. Wireless networking technology allows computers and other devices to access the
Internet over a radio signal rather than via a hard-wired connection, such as a cable.
To access a Wi-Fi network, a degree of proximity to the network resources must be
maintained, which is dependent upon the strength of the wireless signal. Wireless net-
works may be configured to allow open access to the Internet, without registration, or
may be secured with the use of a passphrase or varying levels of encryption. Wireless
networks, registered to individuals, businesses or public entities, can often be accessed
from public locations. Anonymous access to secured or unsecured Wi-Fi networks may
allow perpetrators to mask links between Internet activity and identifying
information.
200. In addition, service providers such as Fon have emerged in recent years, which
enable registered users to share a portion of their residential Wi-Fi bandwidth with
117Written submission of expert from the Raggruppamento Operativo Speciale of the Carabinieri of Italy.
59
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
other subscribers, in exchange for reciprocal access to Wi-Fi networks of subscribers
worldwide. Activity conducted over a shared Wi-Fi network significantly complicates
the process of attribution of an act to a single, identifiable perpetrator in the course of
an investigation.118
201. A novel technique relates to the use of software-defined high performance High-
frequency (HF) radio receivers routed through a computer. In this way, no data is
exchanged through a server and no logs are created. It is more difficult for law enforce-
ment and intelligence agencies to intercept communications sent using this method,
both in relation to finding the location of the transmitters and with respect to predicting
in real time the frequency at which the communications are transmitted.
B. Investigations of terrorist cases involving the Internet
1. Systematic approach to investigations involving the Internet
202. There is a vast range of data and services available via the Internet which may
be employed in an investigation to counter terrorist use of the Internet. A proactive
approach to investigative strategies and supporting specialist tools, which capitalizes on
evolving Internet resources, promotes the efficient identification of data and services
likely to yield the maximum benefit to an investigation. In recognition of the need for
a systematic approach to using technological developments relating to the Internet for
investigative purposes, the Raggruppamento Operativo Speciale of the Carabinieri of
Italy developed the following guidelines, which have been disseminated through the
University College Dublin, master’s programme in forensic computing and cybercrime
(see section IV.G below) and implemented by domestic enforcement authorities of many
member States of the International Criminal Police Organization (INTERPOL) and
the European Police Office (Europol):
Protocol of a systematic approach
""
Data collection: This phase involves the collection of data through traditional investiga-
tive methods, such as information relating to the suspect, any co-inhabitants, relevant
co-workers or other associates and information compiled through conventional moni-
toring activities of channels of communication, including in relation to fixed-line and
mobile telephone usage.
""
Research for additional information available via Internet-based services: This phase
involves requests to obtain information collected and stored in the databases of web-
based e-commerce, communications and networking services, such as eBay, PayPal,
Google and Facebook, as well as using dedicated search engines such as www.123people.
com. Data collected by these services through commonly used Internet “cookies” also
provide key information regarding multiple users of a single computer or mobile device.
60
118 Ibid.
CHAPTER IV. Investigations and intelligence-gathering
""
The activities in phases (a) and (b) above provide information that may be combined
and cross-referenced to build a profile of the individual or group under investigation
and made available for analysis during later stages of the investigation.
""
VoIP server requests: In this phase, law enforcement authorities request information
from VoIP service providers relating to the persons under investigation and any known
affiliates or users of the same networking devices. The information collected in this
phase may also be used as a form of “smart filter” for the purposes of verifying the
information obtained in the two prior phases.
""
Analysis: The large volume of data obtained from VoIP servers and the providers of
various Internet services are then analysed to identify information and trends useful
for investigative purposes. This analysis may be facilitated by computer programs, which
may filter information or provide graphic representations of the digital data collected
to highlight, inter alia, trends, chronology, the existence of an organized group or
hierarchy, the geolocation of members of such group, or factors common among
multiple users, such as a common source of financing.
""
Identification of subjects of interest: In this phase, following smart analysis of the data,
it is common to identify subjects of interest based, for example, on subscriber informa-
tion linked to a financial, VoIP or e-mail account.
""
Interception activity: In this phase, law enforcement authorities employ interception
tactics similar to those used for traditional communication channels, shifting them to
a different platform: digital communication channels. Interception activity may be
undertaken in connection with telecommunications services, such as fixed-line broad-
band, mobile broadband and wireless communications, as well as with regard to
services provided by ISPs, such as e-mail, chat and forum communication services. In
particular, in recent years experience has revealed vulnerabilities in new communications
technologies which may be exploited for investigative or intelligence-gathering pur-
poses. Due care should be taken with respect to ensuring the forensic integrity of the
data being gathered and the corroboration, to the extent possible, of any intelligence
gathered with objective identifiers such as GPS coordinates, time stamps or video
surveillance.
Where permitted by domestic law, some law enforcement authorities may also employ digital
monitoring techniques facilitated by the installation of computer hardware or applications
such as a virus, a “Trojan Horse” or a keystroke logger on the computer of the person
under investigation. This may be achieved through direct or remote access to the relevant
computer, taking into consideration the technical profile of the hardware to be compromised
(such as the presence of antivirus protections or firewalls) and the personal profile of all
users of the device, targeting the least sophisticated user profile.
203. The Korean National Police Agency has responded to the need to standardize
domestic law enforcement practices relating to digital forensics by developing and imple-
menting two manuals: the Standard Guidelines for Handling Digital Evidence and the
Digital Forensics Technical Manual. The Standard Guidelines detail seven steps in the
proper handling of digital evidence: preparation; collection; examination; evidence
request, receipt, and transport; analysis; reporting; and preservation and evidence man-
agement. The Digital Forensics Technical Manual outlines required procedures and the
appropriate approach to the collection of digital evidence, including with reference to
establishing the appropriate environment, forensic tools and equipment; preparatory
61
steps such as the set-up of hardware and software, network connections and
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
time-accuracy; measures to secure the maximum amount of digital evidence; independent
analysis of secured data; and the production of the final report.119
2. Tracing an IP address
204. The IP address associated with an Internet communication is an important iden-
tifier, and therefore key in investigations into terrorist use of the Internet. An IP address
identifies the specific network and device being used to access the Internet. The IP
addresses can be dynamic, temporarily assigned for the duration of an online session
from a pool of addresses available to an ISP, or static (assigned on a fixed basis, as in
the case of website addresses). Dynamic IP addresses are typically assigned to ISPs
within region-based blocks. Therefore, in the absence of the intervening use of anonymiz-
ing or other techniques, a dynamic IP address can often be used to identify the region
or State from which a computer is connecting to the Internet.
205. Further, in response to a duly made request, an ISP can often identify which of
its subscriber accounts was associated with an IP address at a specific time. Traditional
investigative methods may then be used to identify the person physically in control of
the subscriber account at that time. In the Hicheur case (see para. 20 above), the
defendant was identified by tracing a static IP address used to access an e-mail account
under surveillance. A request made to the relevant ISP enabled authorities to link the
IP address to a subscriber account used by multiple occupants of a household, includ-
ing the defendant. By intercepting the data traffic for this subscriber account, investiga-
tors were also able to establish links between the IP address and activity on a pro-jihadist
website which, inter alia, distributed materials for the purpose of physically and mentally
training extremist combatants. In particular, investigators were able to correlate the
times at which multiple connections were made to the website’s discussion forum with
concurrent increases in Internet data volume linked to the defendant’s personal e-mail
account.120
206. Given the time-sensitive nature of investigations involving the Internet and the
risk of alteration or deletion of digital data owing to, inter alia, potential server capacity
constraints of the relevant ISP or applicable data protection regulations, consideration
should also be given to the appropriateness of a request to the ISP to preserve data
relevant to the criminal investigation, pending fulfilment of the necessary steps to secure
the data for evidentiary purposes.
207. In the case of an investigation relating to a website, the relevant domain name
must first be resolved to an IP address. In order to identify the associated IP address,
which is in turn registered with the Internet Corporation for Assigned Names and
Numbers (ICANN), several dedicated utilities may be used. Common utilities, which
119Written submission of expert from the Republic of Korea.
120 Judgement of 4 May 2012, Case No. 0926639036 of the Tribunal de Grande Instance de Paris (14th Cham-
62
ber/2), p. 7 et. seq.
CHAPTER IV. Investigations and intelligence-gathering
are available via the Internet, include “whois” and “nslookup”.121 For example, a whois
query related to the domain name of the United Nations Office on Drugs and Crime
(www.unodc.org) produces the following result:
Domain ID: D91116542-LROR
Domain Name: UNODC.ORG
Created On: 11-Oct-2002 09:23:23 UTC
Last Updated On: 19-Oct-2004 00:49:30 UTC
Expiration Date: 11-Oct-2012 09:23:23 UTC
Sponsoring Registrar: Network Solutions LLC (R63-LROR)
Status: CLIENT TRANSFER PROHIBITED
Registrant ID: 15108436-NSI
Registrant Name: Wiessner Alexander
Registrant Organization: United Nations Vienna
Registrant Street1: Vienna International Centre, P.O. Box 500
Registrant City: A-1400 Wien Vienna AT 1400
Registrant Postal Code: 99999
Registrant Country: AT
Registrant Phone: +43.1260604409
Registrant FAX: +43.1213464409
Registrant E-mail: noc@unvienna.org
These details are provided by the registrant, however. As a result, further
steps
may
also be required to independently verify the accuracy of registrant details. Domains
may also be leased or otherwise under the control of a party other than the
registrant.
208. Persons investigating the use of the Internet for terrorist purposes should also
be aware that online activity related to an investigation may be monitored, recorded
and traced by third parties. Due care should therefore be taken to avoid making online
enquiries from devices which can be traced back to the investigating organization.122
3. Specialized investigative utilities and hardware
209. Investigators with the appropriate technical background have available to them a
range of specialized utilities and hardware. Some, such as “Ping”, and “Traceroute”,
121 National Institute of Justice, Investigations Involving the Internet and Computer Networks, p. 10.
122 Ibid.
63
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
may be integrated into the operating system of a device under investigation. Ping, for
example, may be used to send a signal to a computer connected to the Internet to
determine whether it is connected at a given time, subject to the interference of any
firewalls or other network configuration. Similarly, Traceroute may show the path between
two networked computers, which may assist in determining the physical location.
210. Other programs that may be used, subject to domestic laws and regulations
regarding, inter alia, access to the device and interception of communications, include
“trojan horses” or Remote Administration Trojans (RATs), which may be introduced
covertly into a computer system to collect information or to enable remote control over
the compromised machine. Keystroke monitoring tools may also be installed on a device
and used to monitor and record keyboard activity. Keystroke loggers, in the form of
hardware or software, assist in obtaining information relating to, inter alia, passwords,
communications and website or localized activity undertaken using the device being
monitored. In addition, data packet “sniffers” may be used to gather data relevant to
an investigation. Sniffers, which may be a device or software, gather information directly
from a network and may provide information relating to the source and content of
communications, as well as the content communicated.
C. Forensic data preservation and recovery
211. An important part of the acquisition of evidence in connection with cases involving
the use of the Internet for terrorist purposes concerns the recovery of stored digital data.
The two primary goals in this data recovery exercise are the retrieval of relevant evidence
for the purposes of effective investigation and prosecution and the preservation of the
integrity of the data source and the chain of custody to ensure its admissibility in court
proceedings. In order to identify the best method of evidence preservation, it is important
to distinguish between volatile data, which stored on devices, such as the random access
memory (RAM) of devices, and may be irretrievably lost if there is a disruption in the
power supply, and non-volatile data, which is maintained independently of the power
supply to the device. For example, the act of switching off a computer may alter the data
contained on the storage discs and RAM, which may contain important evidence of
computer programs used by the suspect or websites visited. Volatile data may provide
information relating to current processes on an active computer which may be useful in
an investigation, such as information relating to users, passwords, unencrypted data or
instant messages. Examples of storage devices for non-volatile data include internal/exter-
nal hard disks, portable disk drives, flash storage devices and zip disks.
212. The United States Department of Homeland Security has developed a valuable
overview of this process in a guide entitled “Best practices for seizing electronic evidence:
a pocket guide for first responders”.123 This guide outlines the following steps to preserve
evidence in connection with criminal investigations involving computing devices:
123 United States, Department of Homeland Security, “Best practices for seizing electronic evidence: a pocket guide
64
for first responders”, 3rd ed. (2007). Available from www.forwardedge2.com/pdf/bestPractices.pdf.
CHAPTER IV. Investigations and intelligence-gathering
Best practices for data preservation
""
Do not use the computer or attempt to search for evidence
""
If the computer is connected to a network, unplug the power source to the router or
modem
""
Prior to moving any evidence, photograph the computer as found, including the front
and back, as well as any cords or connected devices and the surrounding area
""
If the computer is “off”, do not turn it “on”
""
If the computer is “on” and something is displayed on the monitor, photograph the
screen
""
If the computer is “on” and the screen is blank, move the mouse or press the space
bar (this will display the active image on the screen); after the image appears, photo-
graph the screen
""
For desktop computers, unplug the power cord from back of the computer tower
""
For laptop computers, unplug the power cord; if the laptop does not shut down,
locate and remove the battery pack (the battery is commonly placed on the bottom,
and there is usually a button or switch that allows for its removal); once the battery
is removed, do not return it to or store it in the laptop (this will prevent the accidental
start-up of the laptop)
""
Diagram and label cords to later identify connected devices
""
Disconnect all cords and devices from the tower or laptop
""
Package and transport components (including the router and modem, if present) as
fragile cargo
""
Where permitted pursuant to the terms of any applicable search warrant, seize any
additional storage media
""
Keep all media, including the tower, away from magnets, radio transmitters and other
potentially damaging elements
""
Collect instruction manuals, documentation and notes, paying particular attention to
any items that may identify computer-related passwords or passphrases
""
Document all steps involved in the seizure of a computer and its components.
213. With regard to mobile devices such as smart phones and personal digital assis-
tants, similar principles apply, except that it is recommended not to power down the
device, as this may enable any password protection, thus preventing access to evidence.
The device should therefore be kept charged, to the extent possible, or undergo spe-
cialist analysis as soon as possible before the battery is discharged to avoid data loss.
214. The case below from India illustrates the importance of forensic analysis in the
identification and recovery of digital and other evidence of terrorist use of the
Internet.
65
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
The Zia Ul Haq case
The defendant, Zia Ul Haq, who was arrested on 3 May 2010 and is currently awaiting
trial, is allegedly a member of Lashker e Taiba, which is a Pakistan-based armed group
fighting against Indian control in Kashmir. The prosecution case against Zia Ul Haq alleges,
inter alia, that he was lured into jihad while working in Saudi Arabia between 1999 and
2001; received training outside India in the use of arms, ammunition and explosives and
communicating through e-mails; collected a consignment of arms, ammunition and explo-
sives in Delhi in 2005, after being requested to do so via e-mail; and subsequently used
the Internet to coordinate with other members of Lashker e Taiba and conspired to commit
terrorist acts using arms, ammunition and explosives.
The prosecution further alleges that, on 7 May 2006, Zia Ul Haq used hand grenades sup-
plied in the weapons consignment from Lashker e Taiba in an attack against the Odeon
cinema in Hyderabad.
E-mail communications between the defendant and his handler were obtained from the
Internet-service providers and their content was examined. The cybercafe computers that
were used by the offender were forensically analysed, the hotel where he stayed while he
was in Delhi to collect the grenades was traced and his signature in the guests’ register
forensically matched. While the defendant was in jail awaiting trial, a letter rogatory was
sent from India to the central authority in another country to initiate action against the
alleged handler.
Zia Ul Haq was charged in India for various offences, including under sections 15, 16, 17
and 18 of the Unlawful Activities (Prevention) Act of 1967, as amended in 2004 and 2008,
which provides for punishment for terrorist activities, training and recruitment for terrorist
purposes, raising funds for terrorist activities and conspiracy to commit terrorist activities.
215. Owing to the fragile nature of digital evidence, its assessment, acquisition and
examination is most effectively performed by specially trained forensic experts. In Israel,
domestic legislation acknowledges the importance of specialist training, requiring that
digital evidence be secured by trained computer investigators, who undergo a basic
professional course and advanced professional in-service training to become acquainted
with computer systems, diverse forensic software and the optimal way to use them.
When the need for an especially complex investigation arises, such as recovery of deleted,
defective or complexly coded or encrypted files, an external expert, who may later be
called as an expert witness on behalf of the prosecution, may be retained.124
216. It is advisable to perform any examinations on a copy of the original evidence,
in order to preserve the integrity of the original source data.125 A duplicate copy of
digital data may be created with the use of specific forensic tools, such as Guidance
Software’s EnCase or Forensic Tool Kit¸ or freeware alternatives. To the extent possible,
124Written submission of expert from Israel.
125 United States, Department of Justice, Office of Justice Programs, National Institute of Justice, Forensic Examina-
66
tion of Digital Evidence: A Guide for Law Enforcement (2004), p. 1. Available from www.ncjrs.gov/pdffiles1/nij/199408.pdf.
CHAPTER IV. Investigations and intelligence-gathering
at least two different forensic tools should be used to create duplicate copies, in the
event that one does not adequately collect all data.126
217. EnCase makes a duplicate image of the data on the device under examination,
analysing all sectors of the hard disk, including unallocated sectors, to ensure the cap-
ture of any hidden or deleted files. The software may also be used, inter alia, to analyse
the structure of the file system of digital media, organize the files under analysis and
generate a graphic representation or other report relating to certain characteristics of
the files. EnCase also generates and assigns a unique identifier, known as a “hash value”,
to the digital evidence.127
218. In order to support the authenticity of digital evidence in connection with legal
proceedings (see section IV.D below), a hash value assigned to digital files, or portions
thereof, is based on a mathematical algorithm applied to characteristics of the dataset.
Any alteration of the dataset would result in the generation of a different hash value.
Hash values are generated with respect to (a) the original hard drive prior to the creation
of a duplicate image, (b) the duplicated copy or copies prior to forensic examination and
(c) the duplicated copy or copies after examination. Matching hash values support a
finding that digital evidence has not been tampered with and that the copy that has
undergone forensic examination may be treated as the original source data for the purposes
of the legal proceedings. Commonly used algorithms include MD5 and SHA.128
D. Supporting the authentication of digital evidence
219. An effective prosecution of suspected use of the Internet for terrorist purposes
must be supported by evidence that has been properly collected and well documented
(see section VI.G.2). This is necessary to establish the integrity of the digital evidence,
for the purposes of both its admissibility in court and its persuasive value. The integrity
of digital evidence may be established by a combination of traditional and specialized
investigative techniques. Key issues include the chain of custody of both the physical
device used to store or transmit electronic data and the actual data, as well as the
procedures followed to secure such data and any deviations from established procedures.
With regard to traditional investigative methods, law enforcement officers may make
enquiries to establish, to the extent possible, who may have handled or had access to
the evidence prior to it being taken into custody and when, how and from where the
evidence was collected.
220. A prosecutor may also be required to show, inter alia, that the information
obtained is a true and accurate representation of the data originally contained on the
126 EC-Council Press, Computer Forensics: Investigating Data and Image Files (Clifton Park, New York, Course Tech-
nology Cengage Learning, 2010), p. 2-4.
127Written submission of expert from the Raggruppamento Operativo Speciale of the Carabinieri of Italy.
128 Barbara J. Rothstein, Ronald J. Hedges and Elizabeth C. Wiggins, “Managing discovery of electronic information:
a pocket guide for judges” (Federal Judicial Center, 2007). Available from www.fjc.gov/public/pdf.nsf/lookup/eldscpkt.
pdf/$file/eldscpkt.pdf.
67
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
media and that it may be attributed to the accused. Hash values generated with respect
to digital evidence provide strong support that such evidence remains uncompromised.
Additional corroborating evidence and testimony may also be introduced to establish
authenticity. An illustration of this practice can be found in the case of Adam Busby,
who was convicted in Ireland in 2010 of sending a bomb threat via e-mail to Heathrow
Airport in London. During the Busby trial, in addition to producing evidence that the
e-mail was sent from a specific computer to which the accused had access, hard-copy
computer logs and closed caption television footage were also introduced to establish
the time at which the e-mail was transmitted and the fact that the accused was the
person in control of the computer at that time.
E. Operational cybercrime units
1. National or regional cybercrime units
221. Increased dependency on computer technology has led to dramatic increases in
the demand for dedicated cybercrime units to respond to requests for forensic retrieval
of computer-based evidence, and not just in terrorist cases involving the use of the
Internet. Organized crime such as drug trafficking, trafficking in persons and interna-
tional paedophile groups offers examples of cases in which criminal use of the Internet
has been particularly prevalent, but in recent years there has been an increase in the
degree to which cases involve computer-based or electronic evidence in some form.
The establishment of national cybercrime units with specialized skills relating to the
investigation of cybercrime could significantly improve a State’s operational capability
to support such demands. Depending on geographical and resource requirements, such
a national unit may also be supported by smaller regional units to respond to local
needs. Additionally, it may be more efficient and cost-effective to have regional units
under the command of local regional management.
222. The responsibilities of national or regional cybercrime units may include the
following:
(a) Gathering open-source intelligence by using specialist online surveillance tech-
niques from social networking sites, chat rooms, websites and Internet bulletin
boards revealing the activities of terrorist groups (among many other criminal
elements). Insofar as terrorist groups are concerned, this function could be
placed within the remit of counter-terrorism units in which personnel have
sufficient training and experience to conduct this task, but specialist training
within a cybercrime environment is seen as essential training for this role.
The intelligence-gathering function also requires evaluation and analysis to
support the development of strategy in countering the threat posed by ter-
rorists’ use of the Internet. Conflicting responsibilities or objectives between
national intelligence agencies may, however, hinder harmonization and the
translation of intelligence leads into effective operational plans;
(b) Conducting specialist cybercrime investigations in national and international
68
technology-related crime cases, such as those involving Internet fraud or theft
CHAPTER IV. Investigations and intelligence-gathering
of data and other cases in which complex issues of technology, law and pro-
cedure arise and the management of the cybercrime unit assesses that the
specialist investigation resources of that unit are necessary;
(c) Serving as an industry and international liaison for the development of part-
nerships with the principal stakeholders in the fight against cybercrime, such
as the financial services industry, the telecommunications services industry,
the computer industry, relevant government departments, academic institu-
tions and intergovernmental or regional organizations;
(d) Maintaining an assessment unit to assess cybercrime cases nationally and
internationally for prioritized investigation by national or regional cybercrime
units. Such a unit may also be responsible for the maintenance of statistics
on the incidence of cybercrime cases;
(e) Providing training, research and development, as the complex and evolving
nature of cybercrime requires scientific support from specialist academic insti-
tutions to ensure that national and regional units are properly skilled and
resourced with all the technological tools, training and education that is
required to forensically examine computer media and investigate
cybercrime.
2. Computer forensic triage units
223. Computer forensic triage units may be established to support national and
regional cybercrime units. The personnel of such units would be trained to forensically
view computer items using specially developed software tools at search sites. A triage
team member can conduct an initial examination on site to either eliminate computers
or other peripheral computer equipment from the investigation as having no evidential
value or may seize the computer-based evidence in accordance with proper forensic
techniques and support local investigation teams in the questioning of suspects as
regards the computer-based evidence uncovered. When necessary, the items of computer
media seized by triage units may also be submitted for full forensic examination to the
relevant regional cybercrime unit or to the national cybercrime unit, as appropriate.
224. Researchers from University College Dublin are currently working on the devel-
opment of a range of forensic software tools to support preliminary analysis, which will
be available to law enforcement officials at no cost. The development of these tools is
part of a broader strategic solution being explored by the University College Dublin
Centre for Cybersecurity and Cybercrime Investigation and the Computer Crime Inves-
tigation Unit of An Garda Síochána (Ireland’s national police service), aimed at assisting
underresourced cybercrime units, with limited budgets and personnel, in the manage-
ment of their caseloads. The objective of this initiative will be to create an entirely
“open source” forensics lab. Participating investigators will receive instruction on build-
ing computer evidence storage and processing equipment, and will be trained on the
use of free forensic tools.
69
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
F. Intelligence-gathering
225. Intelligence-gathering is a key component of counter-terrorism activities, as infor-
mation obtained through such channels often triggers the investigations that lead to the
prosecution of suspects, or is used as evidence at trial, to the extent permitted by
domestic law and rules of procedure. The different purposes for which intelligence may
be gathered, and the different agencies which may acquire or use this information, may
require the careful balancing of competing interests, however. For example, the law
enforcement or intelligence services involved in acquiring intelligence information may
place significant emphasis on the protection of the confidentiality of the source of the
information, while officials of the court would need to consider, inter alia, a defendant’s
right to a fair trial and equal access to the evidence presented against him or her. Due
care should be taken to ensure that adequate checks and balances are in place with
respect to the fundamental human rights outlined in the applicable international
conventions.129
226. In some Member States, intelligence from anonymous sources is not admissible
as evidence in court; however, intelligence information that is corroborated by authori-
tative sources or additional evidence may be considered. For example, in Ireland, intel-
ligence gathered on terrorists can amount to prima facie evidence that a particular
individual is a member of an unlawful organization when that evidence is given under
oath by a police officer with a rank of at least chief superintendent. The Irish Supreme
Court upheld the use of such intelligence as evidence, in the presence of corroborating
evidence, when the fear of reprisals made direct evidence unavailable and given the
senior rank of the officer giving evidence.130
227. Several experts have also highlighted the tension between the need to encourage
the availability of information regarding potential terrorist activity conducted via the
Internet and the need to apprehend and prosecute the perpetrators of such activity.
For example, once potentially terrorism-related website activity is identified, national
security agencies may consider the long-term and short-term implications of the opera-
tional response. Such response may include passively monitoring website activity for
intelligence purposes, covertly engaging with other users to elicit further information
for counter-terrorism purposes or shutting down the website. The varying objectives
and strategies of different domestic and foreign agencies may guide the preferred coun-
ter-terrorism actions.131
228. The practical considerations when evaluating the intelligence value versus the
threat level of an online resource were highlighted in a recent report of the United
States Congressional Research Service:
129 See, for example, the Universal Declaration of Human Rights, art. 10; International Covenant on Civil and
Political Rights, art. 14; and European Convention for the Protection of Human Rights and Fundamental Freedoms,
art. 6.
130 People (DPP) v. Kelly, [2006] 3 I.R. 115.
131 Catherine Theohary and John Rollins, Congressional Research Service (United States), “Terrorist use of the
70
Internet: information operations in cyberspace” (8 March 2011), p. 8.
CHAPTER IV. Investigations and intelligence-gathering
For example, a “honey pot” jihadist website reportedly was designed by the [Central
Intelligence Agency] and Saudi Arabian Government to attract and monitor ter-
rorist activities. The information collected from the site was used by intelligence
analysts to track the operational plans of jihadists, leading to arrests before the
planned attacks could be executed. However, the website also was reportedly being
used to transmit operational plans for jihadists entering Iraq to conduct attacks on
U.S. troops. Debates between representatives of the [National Security Agency,
Central Intelligence Agency, Department of Defense, Office of the Director of
National Intelligence and National Security Council] led to a determination that
the threat to troops in theater was greater than the intelligence value gained from
monitoring the website, and a computer network team from the [Joint Task Force-
Global Network Operations] ultimately dismantled it.132
As illustrated in the above case, coordination between agencies is an important factor
in successfully responding to identified threats.
229. Other Member States, such as the United Kingdom, have indicated that signifi-
cant emphasis has been placed on developing working relationships and entering into
memorandums of understanding between the prosecution and law enforcement or intel-
ligence agencies, with positive results. Similarly, in Colombia, the Integrated Centre of
Intelligence and Investigation (Centro Integrado de Inteligencia e Investigación, or CI3)
is the domestic agency that coordinates investigations into suspected terrorist activities
using a strategy based on six pillars. This approach involves a high-ranking official from
the national police assuming overall command and control of different phases of the
investigation, which include the gathering, verification and analysis of evidence and a
judicial phase in which police collect information on parties and places associated with
the commission of any crimes.133
230. The expert from France outlined the domestic approach to coordinating inter-
agency responses to identified terrorist activity:
""
Phase 1: Surveillance and intelligence services identify a threat by monitoring
Internet activity
""
Phase 2: The surveillance services notify the public prosecution services of the
threat identified. The judge or prosecutor can then authorize law enforcement
authorities to place the Internet activity of an identified suspect under surveil-
lance. As of 2011, legislation permits the leading judge to authorize law enforce-
ment to record the monitored person’s computer data. Moreover, personal data
(e.g. name, phone number, credit card number) can be requested from the
relevant service providers
""
Phase 3: The investigation is conducted based on the evidence gathered from
the sources outlined under phases 1 and 2.
132 Ibid, p. 13.
133 United Nations Office on Drugs and Crime, Digest of Terrorist Cases, para. 191.
71
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
G. Training
231. Law enforcement officials involved in investigations of the use of the Internet for
terrorist purposes require specialist training in the technical aspects of how terrorists
and other criminals can use the Internet in furtherance of illicit purposes and how law
enforcement can effectively use the Internet as a resource to monitor the activities of
terrorist groups. Training may be provided through public or private sector initiatives,
or a combination of both.
232. Courses on information technology forensics and cybercrime investigations may
be provided at the regional or international level by organizations such as Europol and
INTERPOL. In addition, a number of countries have developed their own law enforce-
ment cybercrime training programmes, either alone or in conjunction with academic
institutes. Training may also be provided through ad hoc training courses, seminars,
conferences and hands-on training provided through the public sector or relevant indus-
try stakeholders.
233. Specialized training may also be available through academic institutions, such as
University College Dublin in Ireland, which in 2006 established the Centre for Cyber-
security and Cybercrime Investigation. Programmes offered by the university include
the law-enforcement-only master’s degree in forensic computing and cybercrime inves-
tigation. Further courses also provide first responders with training to support their
operational role in connection with cybercrime cases.
234. The Cybercrime Centres of Excellence Network for Training, Research and Edu-
cation (2CENTRE) is a project funded by the European Commission and launched in
2010, with the aim of creating a network of Cybercrime Centres of Excellence for
Training, Research and Education in Europe. Centres are currently being developed in
Belgium, Estonia, France and Ireland. Each national centre is founded on a partnership
among representatives of law enforcement, industry and academia, collaborating to
develop relevant training programmes and qualifications, as well as tools for use in the
fight against cybercrime. The University College Dublin Centre for Cybersecurity and
Cybercrime Investigation is the leader and coordinator of the project.134
235. Online counter-terrorism training is also available through the Counter-Terrorism
Learning Platform of UNODC, which was launched in 2011.135 The platform is an
interactive tool specifically designed to train criminal justice practitioners in the fight
against terrorism, while incorporating them into a single virtual community where they
can share their experiences and perspectives to fight terrorism. In addition to allowing
practitioners who have previously participated in training provided by UNODC to con-
nect and create networks with their counterparts, the platform allows them to be kept
abreast of legal developments in the field, to be informed about upcoming training
opportunities and to engage in continuous learning activities.
134 See www.2centre.eu.
72
V. International cooperationV.
A. Introduction
236. The speed, global reach and relative anonymity with which terrorists can use the
Internet to promote their causes or facilitate terrorist acts, together with complexities
related to the location, retention, seizure and production of Internet-related data, makes
timely and effective international cooperation between law enforcement and intelligence
agencies an increasingly critical factor in the successful investigation and prosecution
of many terrorism cases.
B. Instruments and arrangements relating to international cooperation
1. The universal instruments against terrorism
237. The universal instruments against terrorism, comprised of international conven-
tions and protocols and relevant resolutions of the Security Council, contain compre-
hensive mechanisms for international cooperation in criminal proceedings related to
terrorism. These instruments make provision for extradition, mutual legal assistance,
transfer of criminal proceedings and convicted persons, reciprocal enforcement of judge-
ments, freezing and seizure of assets and exchange of information between law enforce-
ment agencies.
238. Key elements of the instruments against terrorism relating to international coop-
eration include:
""
The obligation to bring perpetrators of acts of terrorism to justice
""
The obligation to extradite or prosecute (the aut dedere aut judicare principle)
""
The obligation to establish legal jurisdiction in defined circumstances
""
The obligation to exclude the political offence exception as a ground for refus-
ing a request for cooperation
""
Respect for the rule of law and human rights
""
Respect for the principle of dual criminality
""
Respect for the rule of speciality
""
Respect for the ne bis in idem rule: precluding a second prosecution for the same
offence.136
136 United Nations Office on Drugs and Crime, Manual on International Cooperation in Criminal Matters related to
Terrorism (2009), sect. 1.C.
73
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
239. The general principles applicable to extradition and mutual legal assistance in
cases involving terrorism or transnational organized crime are part of comprehensive
mechanisms set out in the universal counter-terrorism instruments and other instru-
ments dealing with transnational organized crime (e.g. the United Nations Convention
against Transnational Organized Crime).137 It is not the intention of the present pub-
lication to provide a detailed restatement or analysis of how these principles should be
implemented by States at the national level. Rather; its focus is on identifying, within
the broad international cooperation framework established through these instruments,
and with reference to established principles and mechanisms, issues specific to terrorism
cases involving the use of the Internet, in order to provide guidance to policymakers
and practitioners on approaches or strategies that reflect current good practice
(a) Absence of a universal instrument relating to cyberissues
240. While the international cooperation mechanisms in the universal instruments
against terrorism, when fully implemented, are likely to provide a legal basis for coop-
eration in many cases involving Internet-related acts by persons involved in the com-
mission of unlawful conduct specified in the instruments, none of them deals specifically
with Internet-related acts per se. In the absence of a counter-terrorism instrument
dealing specifically with Internet issues connected to terrorism, authorities, when inves-
tigating and prosecuting such cases, will continue to be reliant upon existing interna-
tional or regional treaties or arrangements, established to facilitate international coop-
eration in the investigation and prosecution of terrorism or transnational organized
crime offences generally.
241. It is clear that international cooperation in the investigation and prosecution of
terrorism cases involving use of the Internet by terrorists is hindered, to some extent,
by the absence of a universal instrument dealing specifically with cyberissues. It is not
the aim of the present document, however, to assess the relative merits of arguments
in favour or against the utility of the development of a comprehensive universal instru-
ment dealing with, inter alia, international cooperation in criminal cases (including
terrorism) involving cyberrelated issues. Rather, its focus is on identifying areas under
the current international framework that operate as obstacles to such cooperation and
how existing available instruments and arrangements might be used by national authori-
ties to facilitate or strengthen international cooperation in terrorism cases involving
some aspect of Internet use.
(b) Other instruments: the United Nations Convention against Transnational Organized Crime and
the Council of Europe Convention on Cybercrime
242. The United Nations Convention against Transnational Organized Crime is the
primary international instrument dealing with the international cooperation between
States on serious transnational organized crime. Articles 16 (extradition), 18 (mutual
legal assistance), 19 (joint investigations) and 27 (law enforcement cooperation) of the
74
137 United Nations, Treaty Series, vol. 2225, No. 39574.
CHAPTER V. International cooperation
Organized Crime Convention deal with international cooperation. Although the unlaw-
ful conduct referred to in the Organized Crime Convention deals with transnational
organized crime, not terrorism, the underlying principles and mechanisms in that Con-
vention related to international cooperation are very similar to those set out in the
universal counter-terrorism instruments. As such, those States parties which have imple-
mented their international cooperation obligations under these instruments should have
broadly compatible frameworks and mechanisms.
243. In addition to the Council of Europe Convention on Cybercrime, the Council
of Europe Convention on the Prevention of Terrorism; the European Convention on
Extradition,138 with its three Additional Protocols;139 the European Convention on
Mutual Assistance in Criminal Matters,140 with its two Additional Protocols;141 and the
Council of the European Union Act 2000/C 197/01 [of 29 May 2000] establishing, in
accordance with article 34 of the Treaty on European Union, the Convention on Mutual
Assistance in Criminal Matters between the Member States of the European Union
might afford a legal basis for international cooperation in terrorism cases involving some
element of Internet use.
244. The Council of Europe Convention on Cybercrime contains provisions aimed at
encouraging international cooperation via police and judicial cooperation mechanisms
and provisional measures in urgent cases, for example, the informal provision of spon-
taneous information upon request (art. 26) and the establishment of 24/7 points of
contact (art. 35). Such requests can be accompanied by a request for non-disclosure
and provide a legal mechanism enabling the use of informal means of communication
and information-sharing among the parties of the Convention, even if they do not have
such a provision in their national legislation.
245. It is noted that the Council of Europe Convention on Cybercrime is open not
only to members of the Council of Europe or non-member States that have participated
in its elaboration, but may also be acceded to by other non-member States, in the latter
case subject to unanimous agreement of the contracting States entitled to sit on the
Committee of Ministers.
2. Other regional or multilateral arrangements
246. In addition to the international and regional instruments mentioned above, States
may choose to enter into bilateral or multilateral treaties or arrangements that make
specific provision for cooperation on cyberrelated activity connected to terrorism or
transnational crime. Extradition and mutual legal assistance tend to be regulated either
by treaties or through “soft law” agreed upon by blocs of countries. Nevertheless,
regional and subregional organizations also play an important role in facilitating the
138 Council of Europe, European Treaty Series, No. 24.
139 Ibid., Nos. 86, 98 and 209.
140 Ibid., No. 30.
141 Ibid., Nos. 99 and 182.
75
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
exchange of information and the provision of cooperation under such mutually agreed
arrangements.
(a) European arrest warrant: Schengen framework
247. The European arrest warrant under the Schengen framework is a cooperation
tool applicable throughout all member States of the European Union; it has proven
extremely useful in strengthening legal cooperation in the investigation and prosecution
of criminal cases, including those related to terrorism in Europe. Once issued, it requires,
on the basis of reciprocity, that the authorities of another member State arrest and
transfer a criminal suspect or sentenced person to the issuing State so that the person
can be put on trial or complete a detention period. In this context, it is noted that the
European arrest warrant provides, inter alia, for the extradition of a member State’s
own nationals, a concept formerly alien to the legal (often constitutional) provisions of
many States adhering to the so-called European continental system.
(b) European evidence warrant
248. Since it came into force in 2009, the European evidence warrant has, in a similar
way to the European arrest warrant with respect to arrests, provided a streamlined
procedure for procuring and transferring evidence, including objects, documents and
data, between member States for use in criminal proceedings. For the purposes of the
European evidence warrant, evidence gathered may include Internet-related customer
data.142
249. Using these framework decisions and other international instruments, European
States have, as a bloc, established a highly developed, broadly collective approach to
the cross-border collection and transmission of evidence and extradition/surrender of
offenders for the purposes of criminal proceedings. Other Governments might consider,
at a political and operational level, the desirability of adopting and adapting a collective
approach at the regional or subregional level to harmonizing their efforts to cooperate
in the cross-border investigation and prosecution of terrorism-related offences.
(c) Commonwealth Schemes relating to extradition and mutual legal assistance
250. In a similar manner to the European arrest warrant under the Schengen frame-
work, the Commonwealth Scheme for the Transfer of Convicted Offenders (London
Scheme) provides a simplified mechanism for extradition between Commonwealth
countries, providing for the provisional arrest of offenders on the basis of arrest war-
rants issued by other member countries, without the need for an assessment of the
evidential sufficiency of the case against the suspect. The scheme defines offences as
extraditable if they constitute offences in both countries and carry imprisonment for
two years or more.
142Voislav Stojanovski,
“The European evidence warrant”, in Dny práva—2009—Days of Law: the Conference
76
Proceedings, 1st. ed., David Sehnálek and others, eds. (Brno, Czech Republic, Masaryk University, 2009).
CHAPTER V. International cooperation
251. Likewise, the Commonwealth Scheme for Mutual Assistance in Criminal Matters
(Harare Scheme) is aimed at increasing the level and scope of assistance rendered
between Commonwealth countries in criminal matters by facilitating the identification
and location of persons; the service of documents; the examination of witnesses; search
and seizure of evidence; the appearance of witnesses; the temporary transfer of persons
in custody for purpose of testimony; the production of judicial or official records; the
tracing, seizure and confiscation of the proceeds or instrumentalities of crime; and the
preservation of computer data.
252. While the Commonwealth Schemes are not treaties as such, they are examples
of non-binding arrangements, or “soft law”, under which certain countries have agreed
to incorporate compatible legislation into their domestic laws, consistent with agreed
principles, to simplify extradition and mutual legal assistance among themselves in
criminal cases, including terrorism-related investigations and prosecutions
(d) Council of Europe
253. In addition to the elaboration of instruments aimed at promoting international
cooperation in cyberrelated criminal cases, including terrorism, the Council of Europe
has also established (under article 35 of the Council of Europe Convention on Cyber-
crime) the Council of Europe 24/7 Network of contact points available 24 hours a day,
seven days a week, which is aimed at facilitating international cooperation in cybercrime
cases. The Council of Europe and European Union regional projects CyberCrime@IPA
and Cybercrime@EAP, among others, support the participation of 24/7 contact points
in training events, which provides an opportunity for them to link up with each other
as well as network with members of the Group of Eight (G-8) network.
254. Since 2006, the Council of Europe has, through its Global Project on Cybercrime,
been supporting countries worldwide in the strengthening of legislation; the training of
judges, prosecutors and law enforcement investigators in matters related to cybercrime
and electronic evidence; and in law enforcement/service provider cooperation and inter-
national cooperation.143 Since 2010, one focus area has been criminal money flows and
financial investigations on the Internet, including Internet-based terrorist financing.144
(e) European Union action plan: cybercrime centre
255. On 26 April 2010, recognizing the integral role that information and communi-
cations technology plays in modern society and the increasing number, scope, sophis-
tication and potential impact of threats for multiple jurisdictions reinforcing the need
for strengthened cooperation between Member States and the private sector, the Council
of the European Union adopted conclusions concerning a cybercrime action plan, to
be included in the Stockholm Programme for 2010-2014 and the associated future
Internal Security Strategy.
144 Council of Europe, Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the
77
Financing of Terrorism, Criminal Money Flows on the Internet: Methods, Trends and Multi-Stakeholder Counteraction (2012).
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
256. Under the plan, members agreed, inter alia, to mandate the European Commis-
sion, in cooperation with Europol, to analyse and report back on the utility and feasi-
bility of establishing a European cybercrime centre to strengthen knowledge, capacity
and cooperation on cybercrime issues. This work has been completed and a proposal
developed under which Europol would host a new facility for receiving and processing
analytical work files related to serious organized crime and terrorism.
3. Role of other regional organizations and cooperation agreements
257. As stated earlier, formal cooperation agreements, at the regional or subregional
level, between law enforcement or intelligence agencies play an integral role in efforts
by the international community to strengthen and coordinate measures targeting ter-
rorism and transnational organized crime. While cooperation under these arrangements
is usually not based on legally binding treaties or other instruments, it can nevertheless
provide highly effective mechanisms for cooperation between participating member
countries.
258. Internationally, there are many examples of such arrangements, but three, operat-
ing in Europe, Africa and the Pacific, illustrate how groups of countries with compatible
law enforcement and security interests and objectives can successfully work together to
develop and harmonize close cooperation on criminal investigations.
259. The French-German Centre for Police and Customs Cooperation, also known
as the Offenburg Centre, was established in 1998 to, inter alia, support the coordina-
tion of multi-agency operations (e.g. search and surveillance operations and exchanging
information collected) across those countries’ common border. It is staffed by police
and customs and border agencies from both federal and state level and handles many
thousands of requests each year, serving as a platform for mediating pragmatic solutions
to issues between partner agencies and developing inter-agency trust and
cooperation.
260. In Africa, members of the Southern African Regional Police Chiefs Cooperation
Organization and the Eastern African Police Chiefs Cooperation Organization have
agreed to specific areas in which police agencies will cooperate, including in the regular
exchange of crime-related information; the planning, coordination and execution of
joint operations, including undercover operations; border control and crime prevention
in border areas, as well as follow-up operations; the controlled delivery of illegal sub-
stances or any other objects; and technical assistance and expertise, where required.145
261. In the Pacific region, the Pacific Transnational Crime Coordination Centre pro-
vides a hub for the collection, coordination, analysis and sharing of criminal intelligence
data collected via a network of national transnational crime units located in member
countries across the region. The Centre, which is operated by officers seconded from
145 Charles Goredema, “Inter-State cooperation”, in African Commitments to Combating Organised Crime and Terrorism:
A review of eight NEPAD countries (African Human Security Initiative, 2004). Available from www.iss.co.za/pubs/Other/
78
ahsi/Goredema_Botha/pt1chap5.pdf.
CHAPTER V. International cooperation
different law enforcement and border agencies in Pacific island countries, provides
member countries with an access point to INTERPOL and other law enforcement
agencies around the world, via the international network of the Australian Federal Police,
which supports the initiative.
262. Similarly, countries that are not necessarily close geographically, but that have
common interests in thematic areas related to law enforcement and security, might
enter into collective arrangements that provide for information exchange and intelligence
sharing.
(a) Egmont Group of Financial Intelligence Units
263. An example of such an arrangement with implications for investigations related
to terrorist financing is the Egmont Group of Financial Intelligence Units. Investigations
into suspected terrorist financing will invariably involve the collection, sharing and
analysis of financial or banking records located in one or more jurisdictions. In these
cases, the ability of financial intelligence units to cooperate and share financial intelli-
gence is likely to be critical to a successful investigation and prosecution. The Egmont
Group, an international body established in 1995, works to promote and improve coop-
eration between financial intelligence units in efforts to counter money-laundering and
the financing of terrorism and to foster, among other things, the expansion and sys-
tematization of international cooperation in the reciprocal exchange of information. The
Egmont Group recommends that its members enter into memorandums of understand-
ing in which they agree to exchange financial intelligence relevant to the investigation
and prosecution of terrorist financing, money-laundering and related criminal activity.
264. In order to ensure that their national financial intelligence units are able to
cooperate effectively with foreign counterparts in such cases, authorities should consider
the desirability of entering into appropriate information-sharing agreements or arrange-
ments with foreign counterparts. The model memorandum of understanding suggested
by the Egmont Group provides useful guidance on the types of issues that might need
to be addressed.
(b) International Criminal Police Organization
265. Many international instruments, including the International Convention for the
Suppression of the Financing of Terrorism146 (art. 18, para. 4) and the United Nations
Convention against Transnational Organized Crime (art. 18, para. 13) and various
Security Council resolutions, including resolution 1617 (2005), specifically encourage
countries to work within the INTERPOL framework for cooperation on the exchange
of information.
266. One of the core functions of INTERPOL is to promote international cooperation
between international law enforcement agencies and the fast and secure exchange and
146 United Nations, Treaty Series, vol. 2178, No. 38349.
79
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
analysis of information related to criminal activities. It does this via its I-24/7 system,
which is available to law enforcement officials in all member countries.
267. Using the I-24/7 system, national central bureaus can search and cross-check a
wide range of data, including information on suspected terrorists and a variety of data-
bases. The aim of the system is to facilitate more effective criminal investigations by
providing a broader range of information for investigators.
268. In addition to the I-24/7 network, the cybercrime program of INTERPOL is
aimed at promoting the exchange of information among member countries through
regional working parties and conferences, delivering training courses to build and main-
tain professional standards, coordinating and assisting international operations, estab-
lishing a global list of contact officers for cybercrime investigations, assisting member
countries in the event of cyberattacks or cybercrime investigations through investigative
and database services, developing strategic partnerships with other international organi-
zations and private sector bodies, identifying emerging threats and sharing this intelli-
gence with member countries and providing a secure web portal for accessing opera-
tional information and documents.147
269. Since 2009, INTERPOL has worked closely with University College Dublin to
provide specialist training and academic exchanges to promote law enforcement e-crime
investigation expertise. In August 2011, cybercrime investigators and computer forensic
specialists from 21 countries took part in the first INTERPOL/University College Dub-
lin cybercrime summer school training course. The two-week programme, which was
developed by the University, included case-simulation exercises and was delivered by
professionals from law enforcement, University College Dublin and the private sector.
The event was aimed at developing theoretical and practical knowledge and skills across
a range of areas to assist investigators in conducting more effective cybercrime investi-
gations and provided participants with skills in such areas as disk imaging, live data
forensics, mobile phone forensics, money-laundering investigations, search and seizure
techniques, VoIP and wireless investigations and malware detection and analysis.148
270. Finally, the High-Tech Crime Unit of INTERPOL facilitates operational coop-
eration among member countries through global and regional cybercrime expert group
meetings and training workshops, as well as cooperation among law enforcement, indus-
try and academia. It also assists member countries in the event of cyberattack and in
cybercrime investigations, through investigative and database services.
(c) European Police Office
271. A major part of the mandate of Europol is to improve the effectiveness of and
cooperation among law enforcement authorities of European Union member States in
preventing and combating terrorism and other forms of transnational organized crime.
80
148 Ibid.
CHAPTER V. International cooperation
Europol plays a key role in the European Cybercrime Task Force, an expert group
made up of representatives from Europol, Eurojust and the European Commission,
working together with the heads of European Union cybercrime units to facilitate the
cross-border fight against cybercrime. Europol offers the following support to European
Union member States on cybercrime related issues:
""
Cybercrime database: Europol provides European Union member States with
investigative and analytical support on cybercrime and facilitates cross-border
cooperation and information exchange
""
The Threat Assessment on Internet Facilitated Organised Crime
(iOCTA)
assesses current and future trends in cybercrime, including terrorist activities,
and attacks on electronic networks, which informs both operational activity and
European Union policy
""
The Internet Crime Reporting Online System (ICROS) and the Internet and
Forensic Expert Forum (IFOREX) are currently in development. These will
provide centralized coordination of reports of cybercrime from the authorities
of European Union member States, and will host technical data and training
for law enforcement.149
272. In addition to this support, at an operational level and in conjunction with
Eurojust, Europol is heavily involved in the establishment and support of joint investi-
gation teams and provides support to member States with respect to investigations
through analytical work files and case-based coordination and tactical meetings. Under
the analytical work file platform for analysis, nominative data (e.g. information on wit-
nesses, victims, telephone numbers, locations, vehicles and events) is stored and sub-
jected to a dynamic analytical process linking objects, entities and data between national
inquiries and investigations. The data is tagged with a “handling code” that clearly
indicates the conditions of use attached to that particular data component.
(d) Eurojust
273. As part of its mandate, the work of Eurojust in the counter terrorism field
includes the facilitation of the exchange of information between the judicial authorities
of the different member States involved in terrorism-related investigations and
prosecutions;150 supporting the judicial authorities of member States in the issuance
and execution of European arrest warrants; and facilitating investigative and evidence-
gathering measures necessary for member States to prosecute suspected terrorism
offences (e.g. witness testimony, scientific evidence, searches and seizures, and the inter-
ception of communications). The 27 Eurojust national members (judges, prosecutors
or police authorities with equivalent competences in their respective member States)
149 See “Cybercrime presents a major challenge for law enforcement”, European Police Office press release, 3 January
2011. Available from www.europol.europa.eu/content/press/cybercrime-presents-major-challenge-law-enforcement-523.
150 Council of the European Union decision 2005/671/JHA of 20 September 2005 on the exchange of information
and cooperation concerning terrorist offences obliges all member States to designate national correspondents for ter-
rorism matters, who must inform Eurojust (the judicial cooperation unit of the European Union) of all terrorist activities
in their country, from the first stages of interviewing suspects to the indictment stage and from European arrest warrants
issued with regard to terrorism to mutual legal assistance requests and judgements.
81
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
are based in The Hague, the Netherlands, and are in permanent contact with the
national authorities of their respective member States, which may request the support
of Eurojust in the course of particular investigations or prosecutions against terrorism
(e.g. in resolving conflicts of jurisdiction or facilitating the gathering of evidence).
274. Eurojust also encourages and supports the establishment and work of joint inves-
tigation teams by providing information and advice to practitioners. Joint investigation
teams are increasingly recognized as an effective instrument in the judicial response to
cross-border crime and an adequate forum in which to exchange operational informa-
tion on particular terrorism cases. Eurojust national members can participate in joint
investigation teams, acting either on behalf of Eurojust or in their capacity as national
competent authorities for terrorism. For example, in a Danish case related to terrorist
activities, in which a request for the establishment of a joint investigation team was
forwarded to Belgian authorities, the Danish and Belgium desks at Eurojust were
involved in setting up the team between the two competent national authorities. Eurojust
also provides financial and logistical assistance to the operations of such teams and
hosts the permanent secretariat for joint investigation teams.
275. The Terrorism Convictions Monitor of Eurojust is also intended to provide
practitioners with examples of judgements in one country which might be useful in
another, in particular with respect to interpreting European Union legislation on
ŧerrorism. In its September 2010 edition, the Terrorism Convictions Monitor provided
in-depth analysis of two cases featuring common attributes, such as jihadist-related
terrorism, radicalization and use of the Internet.151 One of the cases, provided by Belgian
authorities, was Malika el Aroud and Others, referred to below (see para. 377). The
Counter-Terrorism Team of Eurojust regularly organizes tactical and strategic meetings
on terrorism trends, in which leading magistrates and experts on terrorism law from
European Union and non-European Union countries share their expertise on concrete
matters. Examples of such meetings include the 2010 strategic meeting relating to the
use of VoIP technology for terrorist purposes and the need for lawful interception, and
a tactical meeting held in April 2011 on violent single issue extremism/terrorism. At
these meetings, common issues are identified, and best practices and resulting knowledge
are disseminated to European Union decision makers, identifying possible ways to make
counter-terrorism coordination more effective.
C. National legislative frameworks
276. The existence, at the national level, of a legislative framework providing for
international cooperation is a fundamental element of an effective framework for the
facilitation of international cooperation in the investigation and prosecution of terrorism
cases. Such legislation should incorporate into a country’s domestic law the principles
related to international cooperation espoused in the universal instruments against
terrorism.
82
151The Terrorism Convictions Monitor is available upon request from the Eurojust Counter-Terrorism Team.
CHAPTER V. International cooperation
277. In addition to producing a number of publications aimed at assisting countries
with the legislative incorporation of international cooperation mechanisms, the Terror-
ism Prevention Branch of UNODC includes advisory support, training and capacity-
building on these issues as part of its menu of services available to countries on the
implementation of their international counter-terrorism obligations.
D. Non-legislative measures
278. While accession to multilateral and bilateral instruments and adopting related
legislation are fundamental components of any effective regime for international coop-
eration, they are not the entire answer. A key element in the successful provision of
effective international cooperation is the presence of a properly resourced and proactive
central authority which can, based on any available mechanisms (both formal and
informal), facilitate cooperation in a timely and efficient manner.
279. An important precondition for successful international cooperation is the pres-
ence of effective inter-agency coordination between law enforcement, specialist intelli-
gence agencies (e.g. financial intelligence units) and central authorities at the national
level, supported by necessary legislation and clear, streamlined procedures for handling
requests.
280. A good example of cooperation, at both the national and international level, is
illustrated in the following case, prosecuted in Colombia, with extensive formal and
informal cooperation between authorities.
Case involving the Revolutionary Armed Forces of Colombia (FARC)
On 1 March 2008, the Colombian armed forces carried out various operations against alleged
members of the Revolutionary Armed Forces of Colombia (FARC). During these operations,
an individual suspected of being one of the top leaders of FARC and several other members
of the organization were killed, and evidence was retrieved, which included electronic devices
such as computers, digital diaries and USB sticks. The objects containing digital evidence
were passed to the Colombian judicial police for use in possible criminal investigations and
prosecutions.
The data retrieved from the digital devices revealed information related to the organization’s
international network of support, including links to several countries in Central and South
America and in Europe. The network’s primary objective was fundraising for FARC activities,
the recruitment of new members and the promotion of the organization’s policies, including
the removal of the organization’s designation on various terrorism lists maintained by the
European Union and some countries. Based on the evidence retrieved, the Public Prosecutor
of Colombia initiated criminal investigations against the persons allegedly supporting and
financing FARC.
The evidence, which was shared by Colombian authorities with counterparts in Spain, led to
the identification of the leader of FARC in Spain, known by the alias “Leonardo”. “Leonardo”
entered Spain in 2000, and was granted political asylum.
83
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
The Public Prosecutor of Colombia obtained sufficient evidence to order the issuance of an
arrest warrant for the purposes of extradition against “Leonardo” and used diplomatic and
other legal international cooperation channels to request his extradition to Colombia for
trial.
“Leonardo” was arrested in Spain, and searches of his residence and workplace revealed
documents and electronic devices that contained evidence of his links to the crimes under
investigation. He was subsequently released on bail; his refugee status prevented his imme-
diate extradition.
Criminal proceedings were initiated in Colombia against “Leonardo” in absentia for his
alleged involvement in the financing of terrorism. In a decision by the Supreme Court of
Justice of Colombia, the information obtained during the 1 March 2008 operation and
located on the seized electronic devices was deemed inadmissible. The Prosecutor subse-
quently, in conjunction with counterparts in several other countries where members of the
FARC network of support were present, used all available channels of international coopera-
tion to identify members of the network in Spain and other European countries and collect
further evidence in support of the case.
Additionally, in responding to the letters rogatory issued by the Public Prosecutor of Colom-
bia, the Spanish judicial authorities transmitted to their Colombian counterparts all the
information collected during the raids and searches of “Leonardo’s” house. According to
the Spanish judicial police, this information established the culpability of “Leonardo” and
other persons with respect to forming a FARC terrorist cell in Spain. It also helped establish
“Leonardo’s” culpability for the financing of terrorism and strengthened the assumption of
possible links between “Leonardo” and persons being prosecuted for their links with the
terrorist group Euskadi Ta Askatasuna (ETA) (Basque Homeland and Liberty). The searches
conducted in Spain resulted in the seizure of further documentary and digital evidence,
which was substantively similar to the evidence that had been declared inadmissible. Using
this new evidence provided by Spanish authorities, the Colombian Prosecutor continued the
proceedings against “Leonardo”. Furthermore, the new evidence established efforts by FARC
to provide its members with access to universities, non-governmental organizations and
other State entities where funding opportunities could be sought and new members recruited.
The evidence also supported the existence of an “international commission” within FARC,
which operated a security programme for communications, particularly those transmitted
via the Internet or radio waves (permanent means of communications between the leaders
of the organization and members of the international network of support), by encrypting
the information transmitted, using steganography to conceal messages, sending spam e-mails
and deleting browsing histories to ensure that information could not be retrieved by inves-
tigative or judicial authorities. In this regard, Spanish and Colombian authorities cooperated
to “break” the keys and decipher the content of the messages that were transmitted from
the alleged leaders of FARC in Colombia and Spain.
Before initiating the proceedings against “Leonardo”, the Public Prosecutor of Colombia
submitted a request to a judge that the new evidence be deemed “evidence subsequently
received” and from an “independent source”. The effect of these requests, which were
granted, was to allow the inclusion of the evidence in the legal proceedings without trig-
gering the grounds on which similar evidence would otherwise have been excluded.
The Prosecution of the defendant “Leonardo” in absentia on charges of financing of ter-
rorism is currently ongoing in Colombia, pending the outcome of the extradition
proceedings.
84
CHAPTER V. International cooperation
281. In the above case, the authorities benefited from both formal mutual legal assis-
tance mechanisms and informal relationships. While there may be differences in the
extent to which authorities in different countries can provide mutual assistance in the
absence of a treaty or formal request, authorities in many countries do have some abil-
ity to provide assistance on the basis of informal requests from foreign counterparts in
investigations related to terrorism. The expert group meeting highlighted several cases
and circumstances in which such informal cooperation had been or could be used to
successfully investigate cases involving the use of the Internet by terrorists.
1. The importance of relationships
282. At an operational level, it is also highly important that national law enforcement
and prosecuting agencies promote, establish and maintain relationships of trust and
confidence with foreign counterparts with which they might need to cooperate in cross-
border criminal investigations.
283. Given the transnational nature of much terrorism and related criminal activity,
the highly complex and sensitive nature of intelligence-based investigations and the need
for urgency in rapidly-evolving events and investigations, trust between law enforcement
and prosecution agencies at both the national and international level is often a critical
factor in the successful investigation and prosecution of terrorism-related offences. This
is particularly important in the Internet context, where the preservation of, for example,
usage data and digital evidence held on computers and other portable devices, often
in one or more different jurisdictions, is often critical evidence in a prosecution, and
has to occur within tight time frames. Personal contacts with counterparts in other
jurisdictions, familiarity with their procedures and trust are all factors that contribute
to effective international cooperation.
284. While the means by which informal cooperation can be afforded by specific
countries might differ, it is possible to identify some elements of good practice in the
provision of informal assistance in terrorism-related investigations.
(a) Developing effective mechanisms for exchange of information: the use of liaison officers
285. Several experts at the expert group meeting noted that their national law enforce-
ment agencies operate a network of international liaison posts which assist greatly with
the facilitation of international cooperation requests. For example, the German Federal
Criminal Police Office, the Bundeskriminalamt has a liaison officer and direct contacts
in about 150 countries. Moreover, the European Expert Network on Terrorism Issues,
established in
2007, brings together experts from academia, police and intelligence
services and has proven to be a very effective channel for members to share informa-
tion and expertise on a multidisciplinary basis.
286. The case of R. v. Namouh is an example of highly successful international coop-
eration, undertaken entirely on an informal basis, between law enforcement/prosecution
authorities in Austria and Canada in the investigation and prosecution of persons located
85
in those jurisdictions and using the Internet to engage in terrorism-related activity.
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
R. v. Said Namouh
Mr. Said Namouh was a Moroccan national living in a small town in Canada.
On 10 March 2007, a video in the form of an “open” letter read by Sheik Ayman al-Zawahiri
was posted on an Internet website. In it, Al-Zawahiri warned the Governments of Austria
and Germany to withdraw their troops from peace-support missions in Afghanistan or face
consequences. At one point in the statement, Al-Zawahiri stated:
Peace is a reciprocal matter. If we are safe, you will be safe. If we are at peace, you
will be at peace and, if we are going to be killed, God willing, you will be beaten and
killed. This is the exact equation. Try, then, to understand it, if you understand.
The video, with the accompanying statements by Al-Zawahiri, was set against a mosaic of
images that included armoured cars with national flags and prominent Austrian and German
national politicians. In some parts of the video, there were photos of Al-Zawahiri and other
hooded figures.
Following the broadcast of the video, Austrian authorities initiated an investigation that
included wiretaps on various communications from Mohammed Mahmoud, an Austrian
national living in Vienna. These communications consisted of VoIP and Internet chat sessions,
conducted in Arabic, which revealed that Mr. Mahmoud was engaged in communication
about issues associated with jihad with a person in Canada, including plans for a terrorist
attack, most likely in Europe. The participants discussed using explosives and other arrange-
ments related to an attack.
As a result of interception activities, Said Namouh, living in Canada, was identified as one
of the participants in the above communications. In July 2007, the Royal Canadian Mounted
Police became involved in the investigation, which was coordinated between Austrian and
Canadian authorities through Canada’s law enforcement liaison officer based in Vienna.
While a formal mutual legal assistance treaty existed between Austria and Canada, no formal
mutual legal assistance request under the treaty was initiated; the cooperation took place
entirely on an informal basis.
Investigations revealed that between November 2006 and September 2007 someone using
Mr. Namouh’s Internet connection was spending a considerable amount of time on the
Internet and was in constant contact with jihadists around the world, including via the
Global Islamic Media Front (GIMF), one of the oldest and most prominent virtual jihadist
groups. Supported by Al-Fajr Center, GIMF acts as the media arm for the Army of Islam
[Jaish al-Islam]. Among other things, GIMF disseminates propaganda and provides jihadists
with the tools (e.g. bomb manuals, encryption software) needed to carry out jihad. Much
of Mr. Namouh’s Internet activity involved postings on various discussion forums frequented
by jihadists.
In May 2007, BBC journalist Alan Johnston was kidnapped in Gaza by the “Army of Islam”.
GIMF published several videos related to this event, but of particular note was the video
published on 9 May 2007, in which the Army of Islam claimed responsibility for the kidnap-
ping, as well as videos published on 20 and 25 June, in which threats to execute him were
made if certain demands were not met. Fortunately, Mr. Johnston was released unharmed
on 3 July 2007.
86
CHAPTER V. International cooperation
On 7 and 8 May, communications by Mr. Namouh via an Internet chat forum, intercepted
by authorities, revealed that Mr. Namouh was participating in discussions related to the Alan
Johnson kidnapping, and specifically in discussions about the preparation of the GIMF mes-
sage claiming responsibility, which was broadcast a short time later on 9 May. According
to a transcript of the Internet chat on 8 May, produced in evidence at trial (and translated
from Arabic to French), Mr. Namouh posted: “My beloved brother Abou Obayada, stay with
us on the line, may Allah fulfil you with riches so that you may see what needs to be done;
the statement will be made today, God willing.”
In total, between 3 June and 9 September 2007, 31 conversations took place between
Namouh and Mahmoud. These conversations revealed them to be planning to carry out a
bombing at an undisclosed location in Europe and discussing how to obtain or make suicide
explosive belts, financing issues and travel plans to meet other persons in the Maghreb and
Egypt for final preparations. These conversations suggested that Mr. Namouh was the
intended suicide bomber.
On 12 September 2007, fearing the plans were getting very close to fruition, authorities in
Austria and Canada carried out the simultaneous arrests of Namouh and Mahmoud.
In Canada, Mr. Namouh was charged with conspiracy to use explosives (unknown location
in Europe), participation in the activities of a terrorist group, facilitating terrorist activities
and extortion of a foreign Government (threat video against Austria and Germany).
At trial, Mr. Namouh’s defence challenged several aspects of the prosecution, including by
raising constitutional arguments based on the right to freedom of expression (related to the
issue of whether the GIMF was a terrorist organization). Objections were raised to the
objectivity of the primary expert witness called by the prosecution to give testimony on the
Al-Qaida movement, its offshoots, global jihadism (including virtual jihadism) and the meth-
ods and style of GIMF propaganda and the organization’s use of the Internet. The defence
also challenged whether activities undertaken by GIMF and associated groups amounted to
terrorism, as well as the reliability of evidence related to the interception of Internet-based
communications in Austria and Canada and the accuracy of translations of the records of
these communications from Arabic into French. The defence asked the court to find that
different messages circulated by Mr. Namouh on behalf of GIMF should be taken figuratively
and not as acts counselling or encouraging acts of terrorism.
In considering the defence arguments in relation to the nature of the material posted or
communicated on behalf of GIMF, the court concluded:
The Court has no doubt on this subject. The context of these messages clearly refers
to real actions encouraged by the GIMF. Death and destruction are everywhere. The
jihad promoted by the GIMF is a violent one. This promotion clearly constitutes coun-
selling (“encouragement”) and sometimes a threat of terrorist activity. Therefore, this
activity clearly falls within the definition of terrorist activity within the meaning of Sec-
tion 83.01 of the Criminal Code.
In finding that Mr. Namouh was guilty of counselling or encouraging acts of terrorism, the
court referred to intercepted communications containing statements which showed the zeal-
ous, active nature of his participation in the activities of GIMF. Also relevant in the court’s
view were several posts, including the one below from 12 December 2006, in which the
defendant expressed his wish to conceal his activities, and those of GIMF, by removing
incriminating computer data:
87
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
[TRANSLATION]
Urgent Urgent Urgent
May the peace, mercy, and benedictions of Allah be with you
I want to erase all the jihadist films and books that are on my computer without leav-
ing any traces, may Allah bless you, because I suspect that someone has inspected my
computer.
May the peace, mercy, and benedictions of Allah be with you.
In other communications, the defendant enquired about the use of anonymizing software
and similar tools that could be used to conceal his activities. Following trial in October 2009,
the defendant was found guilty of all charges; he was later sentenced to life
imprisonment.
(b) Joint investigations
287. While the concept of “joint investigations” is mentioned in some international
treaties (e.g. article 19 of the United Nations Convention against Transnational Organ-
ized Crime), there is no express reference to the strategy in the universal counter-
terrorism instruments. Nevertheless, such an approach to investigations is entirely
consistent with the underlying principles and spirit of the international cooperation
elements of these instruments. Some countries, particularly in Europe, have successfully
adopted this approach in a number of terrorism-related investigations, and the important
role of Europol in establishing and supporting joint investigation teams is noted. The
main purpose of these joint investigation teams, which comprise both national law
enforcement officers and Europol officers, is to carry out investigations for a specific
purpose and limited duration in one or more member States.152
288. Europol works with a system of national units, which are designated contact
points within national police forces. It facilitates and encourages information exchange
between member States through a secure digital network and provides a system of 17
analytical work files within the Europol legal framework, primarily aimed at enabling
participating authorities to ensure full coordination and cooperation.
289. While it is difficult to assess, at the international level, the extent to which coun-
tries have collaborated in this manner, discussions at the expert group meeting high-
lighted the increasing awareness within the international law enforcement and security
communities that the nature of modern terrorism and modi operandi of terrorists makes
close cooperation in the investigation of terrorism an increasingly important component
of successful efforts to disrupt, prevent and prosecute terrorist acts.
152 Eveline R. Hertzberger, Counter-Terrorism Intelligence Cooperation in the European Union
(Turin, Italy, United
88
Nations Interregional Crime and Justice Research Institute, July 2007).
CHAPTER V. International cooperation
E. Formal versus informal cooperation
290. International cooperation in terrorism cases involving a cross-border element can
take many forms, depending on the nature of the offence being investigated, the type
of assistance sought, the applicable national legislation and the existence and status of
any supporting treaty or arrangement.
291. Despite improvements in the overall level of their efficiency and effectiveness,
formal mutual legal assistance procedures in criminal cases can still be lengthy processes,
involving considerable amounts of bureaucracy for both requesting and requested coun-
tries. In many terrorism cases, particularly those involving Internet-related crimes, infor-
mal cooperation is increasingly proving to be as important as formal channels, avoiding
considerable delays in situations in which time-critical actions (e.g. the preservation of
Internet-usage data) are pivotal to a successful prosecution outcome. Participants at
the expert group meeting highlighted the importance of the proactive development and
utilization, wherever possible, by national intelligence, law enforcement authorities and
prosecutors of mechanisms available for facilitating both informal and formal channels
for international cooperation.
292. In many cases, for example when authorities in one country seek the preserva-
tion of Internet data held by an ISP in another country, it might be possible for
authorities to cooperate informally to preserve such data for the purpose of the inves-
tigation or prosecution of a criminal offence.
293. The legal issues associated with the conduct of Internet-related criminal inves-
tigations, particularly issues related to jurisdiction, can be extremely complex. In cases
in which investigators in one country need to access information held on computers
located in another country, complex questions can arise about the legal authority and
the basis for their actions. While it is possible for authorities in one country to deal
directly with parties holding the information they seek in another, the responses to this
approach may vary. As a general rule, it is desirable for authorities to work with their
foreign counterparts, if possible on an informal basis, to obtain such information.
294. The form and method of cooperation will depend largely on the nature and
intended purpose of the assistance requested. For example, while authorities in one
country might be able to afford informal assistance to foreign counterparts by seeking
the voluntary preservation of Internet-related data from ISPs, the search and seizure
of such data will usually require judicial authorization, which can only be obtained by
formal means.
295. Sometimes, the use of formal requests is the only method by which authorities
can provide the required mutual cooperation. In such cases, it is important that coun-
tries have in place legislation and procedures that provide for timely and effective
responses to requests, to maximize, to the extent possible, the likelihood of such assis-
tance being successful.
89
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
Informal cooperation
296. Given the potential importance and urgency of locating and securing Internet-
related data in terrorism investigations, and the probability that such data will be held
in another country, investigators need to consider both formal and informal means of
obtaining it. While formal mutual legal assistance channels might offer greater certainty
with respect to associated legal issues, they also take longer and involve more bureau-
cracy than informal channels.
297. At the expert group meeting, the expert from Canada emphasized the critical
role that the close informal cooperation between the Royal Canadian Mounted Police
and Austria’s Federal Agency for State Protection and Counter-Terrorism (Bundesamt
für Verfassungsschutz und Terrorismusbekämpfung), facilitated through Canada’s liaison
officer based in Vienna, played in the successful outcome of the prosecution. In addi-
tion to that case, other experts referred to other similar examples in which the use of
liaison officers to facilitate informal cooperation had been instrumental in successful
outcomes.
298. Internet-related data such as customer usage data held by ISPs is likely to be
crucial evidence in terrorism cases involving the use of computers and the Internet. If
investigators can secure physical possession of computers used by a suspect, as well as
associated usage data held by ISPs, they are more likely to establish the link between
the suspect and the commission of a crime.
299. With this is mind, it is important that investigators and prosecutors be fully
cognizant of the potential importance of Internet-related data and the need to take the
earliest possible steps to preserve it in a manner that ensures its admissibility as potential
evidence in any later proceedings. To the extent possible, national law enforcement
agencies should develop, either directly with ISPs or with counterpart agencies in other
countries, clear procedures, involving both formal and informal elements, aimed at
ensuring the earliest possible retention and production of Internet-usage data required
for a criminal investigation.
300. In the United States, where many major ISPs are hosted, a “dual” approach is
used by authorities to assist foreign counterparts with the retention and production of
Internet-related data held by ISPs based in the United States, for possible evidential
purposes. Under this approach, foreign requests for retention and production of user
account information of Internet service providers could be handled in two ways:
(a) Informal process. There are two ways by which investigating authorities can
secure the retention of Internet related data held in the United States by
informal means: (i) foreign authorities can develop a direct relationship with
ISPs and make a direct informal request that they retain and produce the
required data; or (ii) if no direct relationship exists, they can make an informal
request through the Federal Bureau of Investigation, which will make the
request to the ISP;
(b) Formal process. Under the formal process, foreign authorities can make a
90
formal mutual legal assistance request for data related to a specific user
CHAPTER V. International cooperation
account, which goes through the Office of International Affairs of the United
States Department of Justice. Upon receipt, the request will be reviewed by
the Department’s Counterterrorism Section to identify whether it is connected
to any investigation being led by the United States. If not, the request is
submitted to a federal court for the necessary warrant authorizing the collec-
tion and transmittal of the required information to authorities in the request-
ing country.
301. The above approach for production of ISP-related data has been used success-
fully in several terrorism investigations by authorities in the United Kingdom and the
United States. In one particular case, the procedures resulted in a United States-based
ISP providing a substantial cache of Internet data which was crucial evidence in a
prosecution in the United Kingdom.
F. Challenges and issues
302. By its very nature, the virtual geographical footprint, fragmented structure and
rapidly evolving technology associated with the Internet presents ongoing challenges
and issues for law enforcement and criminal justice authorities involved in the investi-
gation and prosecution of terrorism cases. The discussion at the expert group meeting
highlighted some areas that were currently problematic in relation to international coop-
eration. These included difficulties, in some cases, in satisfying the dual criminality
requirements in extradition and mutual legal assistance requests. A number of experts
had experienced cases in which mutual legal assistance or extradition requests had been
delayed or refused because of problems satisfying dual criminality requirements. In
some cases, that had been a result of the incompatibility of criminal offence provisions,
but in others it was the result of an unduly restrictive approach to judicial interpreta-
tion of corresponding criminalization provisions by the judiciary. Several experts con-
sidered that this situation highlighted the need for training for members of the judiciary
on international cooperation issues.
1. Protecting sensitive information
303. Experts from several countries at the expert group meeting referred to the ongo-
ing challenges associated with the sharing of sensitive intelligence information by national
law enforcement and intelligence agencies with foreign counterparts. Invariably, in ter-
rorism cases criminal investigations and prosecutions are intelligence-based, at least in
the early stages, and involve sensitive information that is closely held and protected.
The disclosure of such information carries considerable risks, often not only for its
originating source but also for the agency or agencies holding it, particularly if disclo-
sure is likely to or might compromise an ongoing or future investigation or
operation.
304. Assessments by national authorities on whether and in what circumstances to
share such information, or under what conditions, can be complex, requiring them to
91
balance a number of factors. Nevertheless, regardless of the specific criteria used for
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
assessing the possible sharing of information, in all cases, regardless of the circum-
stances, the agency making the disclosure will want to satisfy itself that the receiving
agency will provide the agreed safeguards and protection to the information once in
its possession.
2. Sovereignty
305. The concept of sovereignty, including the right of nations to determine their own
political status and exercise permanent sovereignty within the limits of their territorial
jurisdiction, is a widely recognized principle under international relations and law. Cases
requiring the investigation or prosecution of cross-border activities of terrorists or other
criminals might have sovereignty implications for those countries in which investigations
need to be undertaken.
306. In some instances, concerns, valid or otherwise, held by national authorities about
perceived intrusion into their State’s sovereignty can impede effective international coop-
eration in criminal cases. It is therefore important, when considering investigative actions
involving the collection of evidence related to computers or the Internet, for investigators
and prosecutors to be mindful of the potential implications such investigative actions
might have for the sovereignty of other States (e.g. authorities in one country remotely
searching the computer being operated by a suspect located in another country).
307. Generally speaking, whenever possible, national authorities considering investiga-
tive steps relating to persons or objects located in another jurisdiction should notify
and coordinate such actions with their foreign counterparts in relevant countries.
3. Retention and production of Internet-related data
308. As stated, in many terrorism cases an important part of the evidence against
suspected offenders will relate to some aspect of Internet-related activity by the suspect
(e.g. credit card billing information and customer usage data related to Internet-based
communication such as e-mail, VoIP, Skype or related to social networking or other
websites). In many cases, it will be necessary for investigating authorities to ensure that
the relevant Internet-data is retained and preserved for later evidential use in proceed-
ings. In this regard, it is important to note the distinction between “retention” of data
and “preservation” of data. In many countries, ISPs are obliged by law to retain certain
types of data for a specified time period. On the other hand, preservation refers to an
obligation imposed on an ISP, pursuant to a judicial order, warrant or direction, to
preserve data under specified terms and conditions for production as evidence in crimi-
nal proceedings.
309. One of the major problems confronting all law enforcement agencies is the lack
of an internationally agreed framework for retention of data held by ISPs. While Gov-
ernments in many countries have imposed legal obligations on locally based ISPs to
retain Internet-related data for law enforcement purposes, internationally there is no
single, universally agreed, standard time period for which every ISP is obliged to retain
92
this information.
CHAPTER V. International cooperation
310. As a result, while investigators in countries that have imposed data-retention
obligations on ISPs have some certainty, when engaged in purely domestic investiga-
tions, about the type of Internet data that will be retained by ISPs and for how long,
the same cannot be said in those investigations in which they are required to collect
data held by an ISP in another country.
311. In the United States, the current approach requires ISPs to retain usage data at
the specific request of law enforcement agencies, with providers applying widely varying
policies for storing data, ranging from days to months.
312. While there have been some efforts, most notably within the European Union,
to achieve some consistency on this issue, this has proven, even at the European Union
level, to be problematic. Under directive 2006/24/EC of the European Parliament and
of the Council of the European Union of 15 March 2006 on the retention of data
generated or processed in connection with the provision of publicly available electronic
communications services or of public communications networks and amending directive
2002/58/EC, in dealing with the retention of data held by providers of electronic com-
munications services and public communications networks, European Union member
States are obliged to ensure that regulated providers retain specified communications
data for a period of between six months and two years. Nevertheless, despite the Direc-
tive, there remains no single consistent data-retention period for all ISPs hosted within
the European Union, with periods ranging across the six-month to two-year time period
set by the directive. Consequently, while there is a greater measure of certainty on these
issues even within the European Union context, there are differences in the duration
for which data is held by ISPs based there.
313. Several participants at the expert group meeting were of the view that the devel-
opment of a universally accepted regulatory framework imposing consistent obligations
on all ISPs regarding the type and duration of customer usage data to be retained
would be of considerable benefit to law enforcement and intelligence agencies investi-
gating terrorism cases.
314. With no universally agreed standards or obligations on ISPs and other commu-
nication providers relating to the retention of Internet-related data, it is important in
criminal investigations that investigators and prosecutors identify at the earliest possible
stage whether such data exists and for what time frame, whether it is likely to be of
relevance to a prosecution and where it is located, along with the applicable time frame,
if any, for which it must be retained by the party holding it. If in doubt, it would be
prudent for authorities to contact their counterparts in the country in which the data
is located and initiate steps (either formal and informal) that might be necessary to
secure the preservation of the data for possible production. Depending on the circum-
stances, including their familiarity or relationship with the relevant ISP, authorities might
consider contacting the ISP directly and seeking its informal assistance. Given sensitivi-
ties over compliance with customer confidentiality and national privacy laws, however,
the level of responsiveness by ISPs to such direct, informal requests can be highly vari-
able. It would always be prudent for investigators and prosecutors to communicate and
coordinate their efforts with their foreign counterparts to secure the preservation and
production of such information.
93
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
4. Evidential requirements
315. In order for testimony, exhibits or other information to be admissible as evidence
in criminal proceedings, investigators and prosecutors need to exercise great care to
ensure that the methods used in its collection, preservation, production or transmission
are in full accordance with applicable laws, legal principles and rules of evidence. A
failure to observe the requirements relating to the admissibility of evidence can weaken
the prosecution case, to the point that authorities may even be obliged to discontinue
or withdraw the prosecution case. In the Namouh case, Canadian prosecutors were able,
through close collaboration with their Austrian counterparts, to ensure that vital evidence
relating to the defendants’ use of Internet chat rooms and websites was collected and
transmitted to Canada for use in an admissible form even though there were differences
between the two countries in the applicable rules of evidence.
316. In terrorism cases, there are a number of issues that can pose considerable chal-
lenges for authorities in ensuring the admissibility of certain types of information. Suc-
cessfully overcoming them remains an ongoing challenge for all practitioners involved
in the investigation and prosecution of terrorism-related cases, which often contain
characteristics that could impede the admissibility of information. The transnational
nature of terrorism cases, including the extensive use of intelligence (often provided by
foreign partners under strict conditions) or highly specialized, often covert and intrusive,
search, surveillance and interception methods as the basis for the collection of evidence,
can present significant obstacles to authorities seeking to present admissible evidence
to a court or tribunal.
317. In the terrorism context, with specific reference to evidential issues that might
arise in relation to the Internet or computer technology, the general approach taken by
investigators and prosecutors remains the same. Issues of particular importance are
likely to be the need to secure, at the earliest possible opportunity, physical possession
of computers or similar devices allegedly used by suspects; and the need to apply
appropriate measures, in accordance with recognized good practice, to protect the integ-
rity of these exhibits
(i.e. the chain of custody/evidence) and undertake any digital
forensics. A failure to follow these procedures could potentially affect the admissibility
of this type of evidence. Other forms of evidence that might require particular care
include material obtained as a result of search and/or surveillance activities, which must
be carried out only within the terms of the appropriate judicial authorization.
318. When managing evidential issues, at the investigative stage, it is important that
investigators have sufficient understanding of the legal rules/principles applicable to
investigative actions they are undertaking as part of an investigation and/or to com-
municate closely with prosecutors, by both updating them and seeking legal advice. In
cases in which evidence is being collected by authorities in one country for use in a
prosecution taking place in another, close communication and coordination with foreign
counterparts on the actions being taken to collect and preserve evidence is very impor-
tant. As part of this coordination, it is important that authorities undertaking investiga-
tive actions clearly understand the evidential requirements/implications associated with
94
their actions in the jurisdiction in which the evidence is ultimately to be used. Issues
CHAPTER V. International cooperation
associated with the admissibility of foreign evidence in terrorism-related cases are dealt
with more broadly in the UNODC Digest of Terrorist Cases.153
5. Dual criminality
319. A requirement, commonly found in the universal counter-terrorism instruments
and other international, regional and bilateral instruments relating to terrorism and
transnational organized crime, is that only unlawful conduct that constitutes a criminal
offence in both the requesting and requested States can form the basis for international
cooperation. This requirement, known as “dual criminality”, can present difficulties in
all criminal investigations and prosecutions, not merely those relating to terrorism,
involving some element of international cooperation. Several participants at the expert
group meeting identified the dual criminality issue as an ongoing fundamental problem,
which often led to mutual legal assistance or extradition requests being refused when
authorities in requested countries considered dual criminality requirements not to have
been satisfied.
320. In the terrorism context, in the absence of any universal obligation on States to
criminalize specific unlawful conduct carried out over the Internet, central authorities
are likely to be reliant, when making or receiving requests for international cooperation,
on criminal offences established under terrorism-related legislation or their national
penal codes. For example, in the case of alleged acts of incitement to terrorism that
occur over the Internet, owing to differences in the legal approach taken by States with
respect to such conduct, international cooperation requests might need to be based on
inchoate offences such as solicitation.
321. In addressing this issue, it is desirable that Governments, when criminalizing the
required unlawful conduct associated with terrorism, formulate offences in terms that
are as close as possible to those contained in relevant instruments. Moreover, to the
extent permitted under national legal systems, legislation should be drafted in a way
that is not unduly restrictive with respect to the issue of dual criminality, providing
central authorities and judges with sufficient scope to focus on and assess the substance
of the unlawful conduct that is the subject of requests rather than adopting an unduly
narrow approach. If this legislative approach is adopted uniformly by States, the full
benefits of legislative harmonization intended by the instruments will be achieved and
the potential for problems with respect to dual criminality reduced.
322. While issues related to dual criminality can create difficulties in criminal cases
involving international cooperation generally, they can be particularly problematic in
cases involving certain terrorism-related crimes committed by using the Internet (e.g.
incitement) in which the risk of incompatibility between the national legislative and
constitutional frameworks of corresponding States might be higher. An example, dis-
cussed at the expert group meeting, relates to the position regarding extradition from
the United States of persons accused of the crime of incitement. In that country, there
are strong constitutional safeguards relating to freedom of speech, enshrined in the First
153 See United Nations Office on Drugs and Crime, Digest of Terrorist Cases, paras. 292-295.
95
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
Amendment to the United States Constitution. Under United States law, statements
amounting to independent advocacy for any ideological, religious or political position
are not considered criminal acts per se, although they might constitute acts amounting
to the provision of information at the direction of or in order to control a terrorist
organization, or fall within the scope of the offence of solicitation. Given this position,
mutual legal assistance or extradition requests related to alleged acts of incitement
involving some constituent element within the United States might be problematic from
a dual criminality perspective, requiring authorities in both countries to take a flexible
and pragmatic approach.
323. In addition to having compatible legislation and a flexible approach to applying
such legislation, it is important that investigators, prosecutors and the judiciary be well
trained and that they understand the way international cooperation mechanisms fit into
the international community’s response to terrorism and transnational organized crime.
6. Differences in the application of constitutional and human rights safeguards
324. Matters related to human rights and constitutional safeguards touch on many
issues associated with the investigation and prosecution of terrorism, including those
related to international cooperation. Again, using acts relating to the incitement of ter-
rorism as an example, different national approaches to the application of constitutional
rights and/or human rights can be reflected in different legal approaches. This can lead
to difficulties in international cooperation cases in which States seek to request or
provide assistance. For example, when authorities in one country make a request to
their counterparts in another country for Internet-related data relating to statements
made over the Internet amounting to incitement to commit terrorism in their jurisdic-
tion, it will be of great relevance whether the alleged acts also constitute a crime in
the requested country. In the broader context of Internet content control, when authori-
ties in one country seek the removal of content that they consider incites terrorism,
and which is hosted on a server located in another jurisdiction, applicable laws and
constitutional safeguards for rights such as the freedom of expression may differ.
325. The situation involving some types of terrorist-related e-mail or Internet content
being routed through, or stored on, ISPs based in the United States is particularly
relevant. Depending on the nature and context of such content, these cases, which fall
under United States jurisdiction, can be problematic given the strong protections
afforded to freedom of speech by the First Amendment to the United States Constitu-
tion. In these cases, authorities in different countries need to communicate closely to
determine what, if any, preventive or prosecution measures can be taken that are con-
sistent with their respective national laws, legal and cultural norms and international
counter-terrorism obligations.
7. Concurrent jurisdiction
326. Terrorism cases in which constituent elements of crimes are carried out over the
Internet can raise complex jurisdictional issues, especially when a suspected offender
96
is located in one country and uses Internet sites or services hosted by ISPs in another
CHAPTER V. International cooperation
to carry out constituent acts of a crime. There have been cases in which persons resi-
dent in one country have set up, administered and maintained websites used for pro-
moting jihad and for other terrorism-related purposes in another.
327. The Belgian case of Malaki el Aroud and Others (see para. 377) is one such
example. The defendant, who was living in Belgium, administered a website, hosted in
Canada, which she used for promoting jihad and for other purposes aimed at support-
ing terrorist activities. The prosecution of terrorist-related activities in these situations
relies heavily on effective international cooperation.
328. There are no binding rules under international law dealing with the issue of how
States should deal with situations in which more than one State might assert jurisdic-
tion to prosecute a crime involving the same suspect. Despite the fact that States have
broad discretion with respect to the criteria applied, this typically involves balancing,
or weighing up, different factors. These might include the relative “connectivity” between
the alleged crime and particular States, including the suspect’s nationality, the location
where various constituent acts forming the crime took place, the location of relevant
witnesses and evidence and the relative potential difficulties in collecting, transmitting
or producing evidence in a particular jurisdiction. In some States, including Belgium,
Canada and Spain, certain forms of jurisdiction are considered to be subsidiary to
others. States with close connections to a crime (e.g. the crime is committed within
their territory or by one of their nationals) are considered to have primary jurisdiction,
with States holding jurisdiction on other bases acting only when the State with primary
jurisdiction is either unwilling or unable to prosecute.154
329. Some countries, including Canada, apply a “real and substantial connection” test
when determining whether criminal jurisdiction exists.155 In Israel, when international
cooperation requests are received from other countries, these are investigated domesti-
cally to determine if it can be proven that an offence under Israeli law was committed
which should be prosecuted in Israel. If no prosecution results from such an investiga-
tion, Israeli authorities will transmit all available evidence [and transfer the suspected
offender] via formal channels to the requesting country for the purpose of prosecution
there. In the United Kingdom, legislation and case law dealing with certain terrorism-
related crimes involving activity outside the United Kingdom (including via the Internet)
allow British authorities to assert jurisdiction if it can be shown that a “substantial
measure” of the activities constituting the crime took place in the United Kingdom,
and if it can reasonably be argued that these activities should not be dealt with by
another country.
330. In resolving issues related to concurrent jurisdiction or related international coop-
eration, central authorities (often prosecutors) need, at an early stage, to be cognizant
of the need for early and collaborative communication with their counterparts in other
154 International Bar Association, Legal Practice Division, Report of the Task Force on Extraterritorial Jurisdiction (2008),
pp. 172-173.
155 R. v. Hape [2007] 2 SCR.292, 2007 SCC 26, para. 62.
97
THE USE OF THE INTERNET FOR TERRORIST PURPOSES
jurisdictions that might have an interest in instituting proceedings against the same
suspected offender. The decision of when and how to initiate this communication should
be taken on a case-by-case basis, after full consideration of the various factors that
might be at play in the particular case. Useful guidance for prosecutors considering
such issues can be found in the 2007 Guidance for Handling Criminal Cases with
Concurrent Jurisdiction between the United Kingdom and the United States, issued
by the Attorneys General of the United Kingdom and the United States,156 which pro-
vides, in the context of “the most serious, sensitive or complex criminal cases” (to
which the report related) for improved information-sharing and communication between
prosecutors in the two countries. As the test for initiating such contact, the report
provides the following: “does it appear that there is a real possibility that a prosecutor
in the [other country] may have an interest in prosecuting the case? Such a case would
usually have significant links with the [other country].” While the timing and method
of communication on jurisdictional and international cooperation issues will vary accord-
ing to the circumstances of the particular case, prosecutors might consider this test a
useful guide to apply in the course of their work.
8. National privacy and data protection laws
331. National data protection or privacy legislation can often restrict the ability of law
enforcement and intelligence agencies to share information with both national and
foreign counterparts. Again, striking the appropriate balance between the human right
to privacy and the legitimate interest of the State to effectively investigate and prosecute
crime is and ongoing challenge for Governments and, in some cases (including responses
to terrorism), has been the subject of concern.157
332. In addition to legislation that provides clear guidance to investigators, prosecutors
and (in the case of Internet data) the ISPs holding data on the obligations pertaining
to the collection and use of personal data, it is equally important that countries establish
and operate effective mechanisms for the oversight of intelligence and law enforcement
agencies. Governments should ensure that appropriate mechanisms are included in their
national laws to enable authorities to share, subject to appropriate privacy safeguards,
information relevant to the investigation and prosecution of terrorism cases with both
national and foreign counterparts.
9. Treaty-based versus non-treaty-based requests
333. National approaches to the facilitation of non-treaty-based requests for coopera-
tion vary, with some countries having restrictions on their ability to provide formal
cooperation in the absence of a treaty. In recognition of this, the universal instruments
against terrorism and transnational organized crime make provision for the instruments
156Available from www.publications.parliament.uk/pa/ld200607/ldlwa/70125ws1.pdf.
157 See the 2009 report of the Special Rapporteur on the promotion and protection of human rights and funda-
mental freedoms while countering terrorism (A/HRC/10/3), in which the Special Rapporteur expressed concerns related
to the incursion of individual rights to privacy caused by heightened surveillance and intelligence sharing between State
98
agencies.
|
||
|
|
|