By Abdulrahman Abotaleb
If a user in Aden is targeted by online extortion, has an account hacked, or has personal data stolen, where should they report the incident? What messages, files or records should they preserve so they can later be used as evidence in an investigation?
For a large share of participants in a survey cited by a recent Yemeni study, the answer was far from clear.
The study reported that 70.3% of respondents in a survey conducted in Aden Governorate did not know how to report a cyber incident or which authority they should approach. The researchers linked this finding to weaknesses in reporting mechanisms and institutional guidance.
The figure, however, needs to be treated cautiously.
Published in 2025 under the title Legislative Reforms and Tactical Approaches to Combat Cybercrime in the Republic of Yemen, the study says its survey data involved 1,024 users and professionals. Yet its reference list identifies the underlying survey dataset as unpublished data compiled by one of the researchers at the University of Science and Technology in February 2025.
The published paper also provides insufficient detail about how participants were selected to justify treating the findings as representative of Yemen’s population — or even of all residents of Aden.
Still, the result raises a larger question: Can Yemen’s legal and institutional systems keep pace with the expansion of the digital services they are expected to protect?
A New Digital Layer
The question is no longer hypothetical.
In June 2025, the World Bank approved a $20 million grant for Yemen’s Financial Market Infrastructure and Inclusion Project, implemented by the United Nations Development Programme. The project is intended to strengthen payment infrastructure and expand access to financial services.
The grant was part of a broader $30 million package, with another $10 million allocated to an education project.
According to UNDP, the financial project is expected to support the digitization of government payments, social transfers and private-sector transactions, while improving the efficiency and security of financial services.
That does not mean Yemen has suddenly become an advanced digital economy. The project itself starts from a much more basic challenge: building a more connected and inclusive financial infrastructure.
But every expansion of digital payments and transactions also creates more accounts, more data and more points of access that need to be protected when fraud, hacking or data leaks occur.
That is the gap the Yemeni study attempts to describe.
The Problem Goes Beyond Passing a Law
The researchers argue that Yemen’s challenge is not simply the presence or absence of legal provisions criminalizing online offences.
The study describes weaknesses in handling digital evidence, reporting incidents and coordinating between institutions. It also points to a shortage of expertise in digital forensics and warns that inadequate investigative capacity can result in evidence being lost or becoming difficult to extract and use effectively.
Digital evidence is not simply a phone, a screenshot or a saved chat.
For electronic material to retain its value in an investigation or court proceeding, it must be collected, preserved and documented in a way that allows its integrity to be examined and reduces the risk of tampering or legal challenges.
That is why the study proposes a much broader system than a new cybercrime law alone. Its recommendations include a national cybersecurity authority, specialized cybercrime units, training for judges and prosecutors, standardized procedures for handling digital evidence, and a centralized incident-response mechanism.
The researchers suggest introducing these measures in stages: beginning with legislation, training and public awareness, followed by the establishment of specialized institutions and reporting systems, and eventually periodic legal review and stronger international cooperation.
The paper also acknowledges that limited resources and political obstacles would make gradual implementation necessary.
But those recommendations raise an even deeper Yemeni question: How can a “national” cybersecurity system be created in a country whose legal and institutional structures are themselves divided?
Legislation Moving on Parallel Tracks
Since the study was published, describing the situation simply as a “legal vacuum” has become less accurate.
In June 2026, the Ministry of Legal Affairs under Yemen’s internationally recognized government said that personal-data protection legislation and a cybercrime law were among the priority laws it was working on.
In Sana’a, meanwhile, another legislative process has been moving separately. In April 2026, the Ministry of Justice under the authorities there announced that a joint committee was reviewing a draft Information Technology Crimes Law, and later reported the completion of meetings to review the proposal.
This does not mean that two separate, fully enacted cybercrime laws are now in force.
It does, however, show that legislation is developing through separate institutional tracks. The issue therefore extends beyond whether “Yemen has a cybercrime law.” The more fundamental question is whether a unified national framework can exist while authority and decision-making remain divided.
The study itself acknowledges institutional fragmentation, political obstacles and financial constraints as challenges to implementing its proposed centralized national authority.
Who Receives the Complaint, and Who Preserves the Evidence?
Questions of institutional jurisdiction may sound abstract until a cyber incident actually happens.
If someone is being blackmailed on a social-media platform, which authority receives the complaint? If investigators need information from a telecom operator or a platform based outside Yemen, who makes the request? Who ensures that a phone, file or chat record has been collected in a way that preserves its legal value?
The study argues that weak information-sharing and fragmented institutional responsibilities can hinder efforts to trace cyber offences and suspects. It also uses the Aden survey result as an indication that many respondents did not know where to report an incident.
But it is important to separate the researchers’ diagnosis from what the available data can establish.
The paper does not provide a national database comparing the number of complaints, prosecutions or convictions across Yemen’s governorates. Nor does it offer a reliable time series that would allow journalists to conclude that cybercrime in Yemen is rising by a particular rate.
For that reason, claims such as “cybercrime is surging dramatically in Yemen” would go beyond the evidence currently available.
What can be said with greater confidence is that Yemeni authorities and researchers increasingly treat cyber extortion, online fraud and other digital offences as contemporary security challenges — while publicly available national statistics remain limited.
Proposed Solutions, Not Proven Outcomes
The study builds some of its recommendations through comparisons with Jordan, Kuwait and the United Arab Emirates, as well as international cybersecurity frameworks.
But not all of those comparisons rest on equally strong sourcing. Some legal details concerning Jordan and Kuwait, for example, are referenced through Wikipedia rather than original legal texts. Any precise journalistic comparison would therefore need to be verified against primary legislation.
More importantly, establishing a national authority, specialized units or an incident-response center is not a solution whose effectiveness the study has demonstrated in Yemen.
These are policy recommendations derived from the authors’ analysis and comparisons with other models.
The researchers themselves call for future longitudinal studies, after reforms are implemented, to measure indicators such as cybercrime rates, prosecution efficiency, financial losses and the resilience of critical infrastructure.
In other words, the effects of the proposed reforms remain something to be tested.
That distinction matters: there is a difference between what a study recommends and what it proves.
A Race Between Building and Protecting
In Yemen, cybersecurity is not only about preventing a hack.
Once a digital incident occurs, another chain of questions begins: Who receives the report? Who has jurisdiction? How is the evidence collected? Which law applies? And which institution can coordinate when data — or the offence itself — crosses regional or national boundaries?
The study places those questions at the center of its proposed reforms. Developments since its publication, however, show that building effective protection will not be merely a technical or legislative challenge.
In a country where digital-payment infrastructure is expanding while laws and institutions continue to move along parallel tracks, the hardest question is no longer simply how Yemen’s cyberspace can be protected.
It is also who can protect it within a single, coherent system.
Yemen Science يمن ساينس: الشبكة اليمنية للعلوم والبيئة، موقع يهتم بأخبار العلوم والتكنولوجيا والصحة والبيئة والسكان
