What is meant by “hacking”?
The term ‘hacking’ is not a legally defined term. Generally, it refers to the unauthorised intrusion into third-party computer systems or networks in order to access data or functions, circumvent security measures or manipulate IT systems. The motives can vary greatly. Some attacks are carried out solely to uncover security vulnerabilities. Others are driven by financial motives, including unlawful enrichment, or are intended to steal data, encrypt systems or cause targeted harm to companies. From a criminal law perspective, it is therefore always necessary to examine exactly what specific action was taken.
Which criminal offence may apply in the context of hacking?
Austrian criminal law contains several provisions for the protection of computer systems, data and IT infrastructure. In practice, these offences often overlap. Which offence has been committed depends on the specific attack and its objective.
Here, we shall focus separately on just a few of the most important computer-related offences:
- Unlawful access to a computer system (Sec 118a StGB),
- Improper interception of data (Sec 119a StGB),
- Disrupting the operation of a computer system (Sec 126b StGB),
- Misuse of computer programmes or login data (Sec 126c StGB).
Unlawful access to a computer system (Sec 118a StGB)
The key criminal offence in connection with hacking is unlawful access to a computer system under Sec 118a StGB. In principle, a person may be criminally liable under Sec 118a StGB if they gain unauthorised access to a computer system or part thereof by overcoming a specific security measure (e.g. password, two-factor authentication, firewall). An important requirement is ‘direct intent’: the offender must intend to obtain personal data subject to confidentiality (Sec 118a para 1 no 1 StGB) or to cause harm through data stored in the system that is not intended for them (Sec 118a para 1 no 2 StGB).
The confidentiality of information technology systems is thereby protected. It is therefore not decisive whether the perpetrator alters data or causes financial loss. Unauthorised intrusion alone may be a criminal offence if the required intent is present.
Typical examples include:
- cracking a password,
- bypassing two-factor authentication,
- exploiting a security vulnerability,
- gaining administrative access rights,
- infiltrating corporate networks.
Improper interception of data (Sec 119a StGB)
Sec 119a StGB covers the improper interception of data transmitted via a computer system and not intended for the perpetrator. In particular, a person may be criminally liable under Sec 119a StGB if they use a technical device that has been attached to a computer system or otherwise made ready to receive data, or that intercepts the electromagnetic emissions of a computer system.
The perpetrator must act with the intention of obtaining knowledge of the data for themselves or for another unauthorised person. In addition, their conduct must be aimed at using the data themselves, making it accessible to another unauthorised person or publishing it, and thereby conferring a financial advantage on themselves or another person, or causing a disadvantage to another person. The intent is a heightened form of intent: the perpetrator must specifically aim to bring about the circumstances described above (Sec 5 para 2 StGB).
The provision therefore does not cover every instance of technical interception of data. Rather, what is required is a deliberate course of action accompanied by an additional intent to cause harm or to enrich oneself. Typical examples include the covert recording of third-party data transmissions, the interception of information transmitted wirelessly, or the use of specially prepared eavesdropping devices. Sec 119a StGB applies only on a subsidiary basis. If the conduct is already punishable under Sec 119 StGB (breach of telecommunications confidentiality), Sec 119a StGB is subsidiary to Sec 119 StGB.
Disrupting the operation of a computer system (Sec 126b StGB)
Whilst Sec 118a StGB already covers unauthorised access, Sec 126b StGB requires an impairment of the system’s functionality, whereby the disruption must be caused by the input or transmission of data. These include, in particular, denial-of-service (DoS) attacks, the deliberate overloading of servers, the sabotage or blocking of corporate networks and operational IT infrastructure, and ransomware. Such attacks often result in significant financial damage, particularly for businesses.
Misuse of computer programmes or login data (Sec 126c StGB)
Many cyber-attacks begin long before the actual intrusion into a computer system. Passwords are illicitly obtained, malware is developed, or specialised hacking programmes are deployed. Under certain conditions, Austrian criminal law already criminalises these preparatory acts. This covers, in particular, programmes or login data that are clearly intended for the commission of computer-related offences. The intent required for criminal liability is also based on this criterion.
Sec 126c StGB covers a wide range of acts: these include manufacturing, importing, distributing, selling, otherwise making available, procuring and possessing. The aim is to prevent attacks from being prepared or facilitated in the first place. Whether a specific case involves criminal preparation or merely a lawful IT security analysis depends on the circumstances of the individual case.
When is so-called “ethical hacking” permissible?
Not all hacking is unlawful. In the field of IT security, targeted security audits are carried out to identify vulnerabilities. Such tests are regularly conducted on behalf of the system operator. The key factor here is the consent of the authorised party. If there is valid authorisation and the testing remains within the agreed scope, the access is generally not considered unauthorised. However, problems arise when agreed limits are exceeded or third-party systems are tested without consent. Even well-intentioned security analyses can then lead to criminal consequences.
How are investigations into hacking conducted?
Investigations into computer-related offences differ in many respects from traditional criminal proceedings. Digital evidence must be secured and analysed swiftly. In doing so, the public prosecutor’s office and the criminal investigation department regularly collaborate with IT experts.
The most common investigative measures include:
- house searches,
- seizure of computers, smartphones and data storage devices,
- analysis of digital storage media,
- securing log files and server data,
- obtaining information from internet and cloud service providers,
- international mutual legal assistance in the case of cross-border cyber-attacks.
For defendants, even the seizure of devices used for work can have significant consequences. This makes it all the more important to check at an early stage whether the coercive measures ordered were carried out lawfully, and to actively exercise the defendant’s rights right from the investigation proceedings. An experienced criminal defence lawyer ensures that legal protection during the investigation proceedings is effectively safeguarded by lodging objections on the grounds of a violation of rights and complaints against court orders.
What are the potential penalties for hacking?
The potential penalties depend on the specific offence committed and the actual consequences of the attack. Depending on the circumstances, sanctions range from fines to prison sentences of several years. If several computer-related offences or property offences are committed concurrently, the criminal liability increases significantly. The range of penalties is particularly severe in serious cases where significant financial losses are incurred, critical infrastructure (Sec 74 para 1 no 11 StGB) is affected, or the attack is carried out as part of a criminal association (Sec 278 para 2 StGB).
What defence options are available?
Not every allegation of hacking necessarily leads to a conviction. Computer crime proceedings, in particular, often raise complex technical and legal issues.
A criminal defence lawyer will examine, in particular,
- whether unauthorised access actually took place,
- whether there was valid consent from the authorised party,
- whether any specific security measure was actually bypassed,
- whether digital evidence was properly secured and analysed,
- whether criminal intent can be proven, or
- whether the accused can be held responsible for the specific act at all.
Cooperation between defence lawyers and IT experts is of particular importance in technically complex cases. Through this close collaboration, exculpatory evidence can be introduced into the criminal proceedings by way of motions to adduce evidence. This makes it possible to actively influence the course and outcome of the proceedings.
What should companies bear in mind following a cyber-attack?
A cyber-attack often affects more than just the IT department. Depending on the incident, criminal, data protection, civil and compliance issues may arise simultaneously. Companies should therefore act swiftly and document the incident comprehensively. This includes, in particular, securing digital evidence, checking statutory reporting obligations and assessing possible criminal proceedings against the perpetrators. Equally important is the internal review of the incident in the form of an internal investigation. At the same time, consideration should be given to filing a prompt report with the law enforcement authorities, accompanied by a statement of facts to the public prosecutor’s office. Within this framework, claims for damages may also be asserted by joining the proceedings as a private party.
It is often only after a detailed analysis that it becomes clear which security vulnerability enabled the attack and which organisational measures will be necessary in future. Early legal support helps to avoid mistakes in handling the incident and to comprehensively safeguard the company’s interests in the long term. Ultimately, effective and well-founded prevention of cyber-attacks is part of any efficient compliance management system.