Hacking under Austrian criminal law: a lawyer explains when a cyber-attack becomes a criminal offence

Hacking is one of the best-known forms of computer crime. Whilst in common usage the term describes almost any form of unauthorised access to computer systems, Austrian criminal law does not recognise ‘hacking’ as a specific criminal offence in its own right. Rather, depending on the nature of the attack and the specific consequences, various computer-related offences under the Austrian Criminal Code (StGB) may apply. Even unauthorised intrusion into an IT system can have criminal consequences, even if it does not result in any loss of data or financial damage. In this article, you will learn which hacking activities may be relevant under criminal law, which offences may apply, what penalties may be imposed, and why both accused individuals and companies should seek legal assistance at an early stage in the event of cyber-attacks.

What is meant by “hacking”?

The term ‘hacking’ is not a legally defined term. Generally, it refers to the unauthorised intrusion into third-party computer systems or networks in order to access data or functions, circumvent security measures or manipulate IT systems. The motives can vary greatly. Some attacks are carried out solely to uncover security vulnerabilities. Others are driven by financial motives, including unlawful enrichment, or are intended to steal data, encrypt systems or cause targeted harm to companies. From a criminal law perspective, it is therefore always necessary to examine exactly what specific action was taken.

Which criminal offence may apply in the context of hacking?

Austrian criminal law contains several provisions for the protection of computer systems, data and IT infrastructure. In practice, these offences often overlap. Which offence has been committed depends on the specific attack and its objective.

Here, we shall focus separately on just a few of the most important computer-related offences:

  • Unlawful access to a computer system (Sec 118a StGB),
  • Improper interception of data (Sec 119a StGB),
  • Disrupting the operation of a computer system (Sec 126b StGB),
  • Misuse of computer programmes or login data (Sec 126c StGB).

Unlawful access to a computer system (Sec 118a StGB)

The key criminal offence in connection with hacking is unlawful access to a computer system under Sec 118a StGB. In principle, a person may be criminally liable under Sec 118a StGB if they gain unauthorised access to a computer system or part thereof by overcoming a specific security measure (e.g. password, two-factor authentication, firewall). An important requirement is ‘direct intent’: the offender must intend to obtain personal data subject to confidentiality (Sec 118a para 1 no 1 StGB) or to cause harm through data stored in the system that is not intended for them (Sec 118a para 1 no 2 StGB).

The confidentiality of information technology systems is thereby protected. It is therefore not decisive whether the perpetrator alters data or causes financial loss. Unauthorised intrusion alone may be a criminal offence if the required intent is present.

Typical examples include:

  • cracking a password,
  • bypassing two-factor authentication,
  • exploiting a security vulnerability,
  • gaining administrative access rights,
  • infiltrating corporate networks.

Improper interception of data (Sec 119a StGB)

Sec 119a StGB covers the improper interception of data transmitted via a computer system and not intended for the perpetrator. In particular, a person may be criminally liable under Sec 119a StGB if they use a technical device that has been attached to a computer system or otherwise made ready to receive data, or that intercepts the electromagnetic emissions of a computer system.

The perpetrator must act with the intention of obtaining knowledge of the data for themselves or for another unauthorised person. In addition, their conduct must be aimed at using the data themselves, making it accessible to another unauthorised person or publishing it, and thereby conferring a financial advantage on themselves or another person, or causing a disadvantage to another person. The intent is a heightened form of intent: the perpetrator must specifically aim to bring about the circumstances described above (Sec 5 para 2 StGB).

The provision therefore does not cover every instance of technical interception of data. Rather, what is required is a deliberate course of action accompanied by an additional intent to cause harm or to enrich oneself. Typical examples include the covert recording of third-party data transmissions, the interception of information transmitted wirelessly, or the use of specially prepared eavesdropping devices. Sec 119a StGB applies only on a subsidiary basis. If the conduct is already punishable under Sec 119 StGB (breach of telecommunications confidentiality), Sec 119a StGB is subsidiary to Sec 119 StGB.

Disrupting the operation of a computer system (Sec 126b StGB)

Whilst Sec 118a StGB already covers unauthorised access, Sec 126b StGB requires an impairment of the system’s functionality, whereby the disruption must be caused by the input or transmission of data. These include, in particular, denial-of-service (DoS) attacks, the deliberate overloading of servers, the sabotage or blocking of corporate networks and operational IT infrastructure, and ransomware. Such attacks often result in significant financial damage, particularly for businesses.

Misuse of computer programmes or login data (Sec 126c StGB)

Many cyber-attacks begin long before the actual intrusion into a computer system. Passwords are illicitly obtained, malware is developed, or specialised hacking programmes are deployed. Under certain conditions, Austrian criminal law already criminalises these preparatory acts. This covers, in particular, programmes or login data that are clearly intended for the commission of computer-related offences. The intent required for criminal liability is also based on this criterion.

Sec 126c StGB covers a wide range of acts: these include manufacturing, importing, distributing, selling, otherwise making available, procuring and possessing. The aim is to prevent attacks from being prepared or facilitated in the first place. Whether a specific case involves criminal preparation or merely a lawful IT security analysis depends on the circumstances of the individual case.

When is so-called “ethical hacking” permissible?

Not all hacking is unlawful. In the field of IT security, targeted security audits are carried out to identify vulnerabilities. Such tests are regularly conducted on behalf of the system operator. The key factor here is the consent of the authorised party. If there is valid authorisation and the testing remains within the agreed scope, the access is generally not considered unauthorised. However, problems arise when agreed limits are exceeded or third-party systems are tested without consent. Even well-intentioned security analyses can then lead to criminal consequences.

How are investigations into hacking conducted?

Investigations into computer-related offences differ in many respects from traditional criminal proceedings. Digital evidence must be secured and analysed swiftly. In doing so, the public prosecutor’s office and the criminal investigation department regularly collaborate with IT experts.

The most common investigative measures include:

For defendants, even the seizure of devices used for work can have significant consequences. This makes it all the more important to check at an early stage whether the coercive measures ordered were carried out lawfully, and to actively exercise the defendant’s rights right from the investigation proceedings. An experienced criminal defence lawyer ensures that legal protection during the investigation proceedings is effectively safeguarded by lodging objections on the grounds of a violation of rights and complaints against court orders.

What are the potential penalties for hacking?

The potential penalties depend on the specific offence committed and the actual consequences of the attack. Depending on the circumstances, sanctions range from fines to prison sentences of several years. If several computer-related offences or property offences are committed concurrently, the criminal liability increases significantly. The range of penalties is particularly severe in serious cases where significant financial losses are incurred, critical infrastructure (Sec 74 para 1 no 11 StGB) is affected, or the attack is carried out as part of a criminal association (Sec 278 para 2 StGB).

What defence options are available?

Not every allegation of hacking necessarily leads to a conviction. Computer crime proceedings, in particular, often raise complex technical and legal issues.

A criminal defence lawyer will examine, in particular,

  • whether unauthorised access actually took place,
  • whether there was valid consent from the authorised party,
  • whether any specific security measure was actually bypassed,
  • whether digital evidence was properly secured and analysed,
  • whether criminal intent can be proven, or
  • whether the accused can be held responsible for the specific act at all.

Cooperation between defence lawyers and IT experts is of particular importance in technically complex cases. Through this close collaboration, exculpatory evidence can be introduced into the criminal proceedings by way of motions to adduce evidence. This makes it possible to actively influence the course and outcome of the proceedings.

What should companies bear in mind following a cyber-attack?

A cyber-attack often affects more than just the IT department. Depending on the incident, criminal, data protection, civil and compliance issues may arise simultaneously. Companies should therefore act swiftly and document the incident comprehensively. This includes, in particular, securing digital evidence, checking statutory reporting obligations and assessing possible criminal proceedings against the perpetrators. Equally important is the internal review of the incident in the form of an internal investigation. At the same time, consideration should be given to filing a prompt report with the law enforcement authorities, accompanied by a statement of facts to the public prosecutor’s office. Within this framework, claims for damages may also be asserted by joining the proceedings as a private party.

It is often only after a detailed analysis that it becomes clear which security vulnerability enabled the attack and which organisational measures will be necessary in future. Early legal support helps to avoid mistakes in handling the incident and to comprehensively safeguard the company’s interests in the long term. Ultimately, effective and well-founded prevention of cyber-attacks is part of any efficient compliance management system.

Dr. Elias Schönborn

Dr. Elias Schönborn
Attorney at Law & Criminal Defense Lawyer

CONCLUSION

The criminal law assessment of hacking is significantly more complex than the term might initially suggest. Austrian criminal law does not recognise a single, uniform criminal offence for hacking. Rather, depending on the specific nature of the attack, various offences under IT criminal law and property offences may apply. Investigations into hacking are often technically complex. This makes an early legal assessment of the facts by a lawyer specialising in cybercrime all the more important. If you are under investigation for a computer-related offence or if your company has fallen victim to a cyber-attack, we would be happy to assist you. We have extensive experience in IT criminal law and regularly publish articles in specialist journals on this area of law. You are welcome to book an initial consultation. During this consultation, we will assess the legal situation, develop a strategy tailored to your specific case and support you throughout the entire criminal proceedings.
Picture of Dr. Elias Schönborn

Dr. Elias Schönborn

Dr. Elias Schönborn is an attorney at law and criminal defense lawyer based in Vienna. As an expert in criminal law, he represents clients at every stage of criminal proceedings. Dr. Schönborn has been recognized, among others, by Legal 500, Chambers Europe, the Austrian newspaper KURIER, and the daily Der STANDARD, and regularly serves as a lecturer and author of numerous professional publications.

CONSULTATION APPOINTMENT

Fast and competent legal advice

Do you need legal support?
We are here for you – book a consultation appointment directly or use the contact form to get in touch with us.

CONTACT FORM