HomeCybercrime Law › Module 2 · Integrity offences

Module 2 · Computer integrity offences

What this module covers and why it matters. This module covers the crimes committed against computers, devices, data and networks. The reading list groups this conduct as illegal access, illegal interception, data and system interference and illegal devices. It is the first of the offence modules and so it sits at the front of the subject's arc from offences to jurisdiction to investigations to cooperation. The doctrinal load is heavy here because these offences supply the core of the 1500-word problem question and so the RULE cards and the comparison table carry most of the weight. The debate load matters too because the questions of whether mere access should be a crime and whether hacktivism deserves protection feed the research essay. The instruments are the Budapest Convention offences and their Australian counterparts in Part 10.7 of the Criminal Code and the Telecommunications (Interception and Access) Act 1979.

Instruments at a glance

Instrument Key provisions What it does
Budapest Convention on Cybercrime (ETS 185, 2001) Art 2 illegal access; art 3 illegal interception; art 4 data interference; art 5 system interference; art 6 misuse of devices Harmonises the core computer-integrity offences. Each offence requires the act to be done "without right" and in general intentionally
Budapest Convention, Explanatory Report Paras [44] to [50] and following on arts 2 to 6 Interprets the offences. It confines "access" and "interception", restricts art 3 to "non-public" transmissions "by technical means" and requires the art 5 hindering to be "serious"
Criminal Code Act 1995 (Cth), Part 10.7 s 476.1 definitions; s 476.2 meaning of "unauthorised"; s 476.3 geographical jurisdiction; ss 477.1 to 477.3 serious offences; ss 478.1 to 478.2 summary offences Australia's computer-integrity offences, inserted by the Cybercrime Act 2001 (Cth). Splits serious offences carrying long penalties from summary offences carrying two years
Telecommunications (Interception and Access) Act 1979 (Cth) s 7 telecommunications not to be intercepted, with the s 7(2) exceptions; s 108 stored communications not to be accessed, with the s 108(2) exceptions Prohibits interception of live communications and access to stored communications, subject to warrant and other lawful-authority exceptions

Cases at a glance

Case Point it settles
R v Tahiraj [2014] QCA 353 Applies s 477.1, unauthorised access with intent to commit a serious offence, in a child-exploitation prosecution built on forensic proof that the accused controlled the malware
R v Martin [2013] EWCA Crim 1420 A DDoS attack, including one on the University of Oxford website, causes real cost. The victim estimated almost two weeks of staff time to deal with it
R v Walker Bot code written and deployed by the accused produced a DDoS attack on the University of Pennsylvania system, illustrating impairment through distributed attack (Urbas ch 4)

Attack plan

Attack plan. Work a computer-integrity problem in this fixed order. First, characterise the conduct as access, modification, impairment or interception, because the offence chosen follows from the conduct. Second, identify the Commonwealth offence and set out its physical elements from Part 10.7. Third, ask whether the conduct was "unauthorised" within s 476.2, meaning the person was not entitled to cause it. Fourth, state the mental element the section requires, which is knowledge of the lack of authorisation plus intent or recklessness as the particular section specifies. Fifth, check any lawful-authority or warrant exception, including the s 476.2(4) warrant entitlement and the TIA Act exceptions in ss 7(2) and 108(2). Sixth, confirm the jurisdiction hook in s 476.3, which replicates the Category A extended geographical jurisdiction of s 15.1.

The Budapest offences

RULE. The Budapest offences each require the act to be done "without right". This covers the absence of permission from a person with authority over the system or data and the absence of any legal power to act, so a police officer acting under a warrant acts "by right" (Budapest art 2; Explanatory Report).
RULE. Illegal access is the intentional access to the whole or any part of a computer system without right. No damage is required and copying or merely looking at data suffices, so access is complete once the system is entered (Budapest art 2).
RULE. Illegal interception is the intentional interception without right, by technical means, of non-public transmissions of computer data to, from or within a computer system. It reaches data captured in transit rather than data read after arrival, which falls under access instead (Budapest art 3).
RULE. Data interference is the intentional damaging, deletion, deterioration, alteration or suppression of computer data without right. A party may reserve the right to require that the conduct result in serious harm (Budapest art 4).
RULE. System interference is the intentional serious hindering without right of the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data. The hindering must be serious, which is the paradigm of a denial-of-service attack (Budapest art 5).
RULE. Misuse of devices criminalises the production, sale, procurement, distribution or possession of a device, password or access code designed or adapted to commit an art 2 to 5 offence, done with intent that it be so used. Conduct for authorised testing or protection of a system is not caught (Budapest art 6).

The Australian offences

RULE. Part 10.7 defines "access to data" as the display or output of the data, its copying or moving, or the execution of a program. It limits access, modification and impairment to conduct caused by the execution of a function of a computer (Criminal Code s 476.1).
RULE. Access, modification or impairment is "unauthorised" if the person is not entitled to cause it. It is not unauthorised merely because the person has an ulterior purpose. A person causes it if their conduct substantially contributes to it (Criminal Code s 476.2).
RULE. twist A person acting under a warrant, or under an emergency authorisation or tracking-device authorisation of the Surveillance Devices Act 2004, is entitled to cause the access, modification or impairment, so it is not unauthorised. Lawful authority is what converts an apparent offence into permitted conduct (Criminal Code s 476.2(4)).
RULE. checklist A person commits the serious offence if they cause unauthorised access to data, unauthorised modification of data or unauthorised impairment of electronic communication to or from a computer, know it is unauthorised and intend by it to commit or facilitate a serious offence. The penalty equals that of the intended serious offence (Criminal Code s 477.1).
RULE. A "serious offence" for s 477.1 is one punishable by life or by five or more years. The prosecution need not prove the accused knew the offence was serious. Impossibility is no bar and there is no offence of attempting s 477.1 (Criminal Code s 477.1).
RULE. A person commits an offence if they cause unauthorised modification of data held in a computer, know the modification is unauthorised and are reckless as to whether it will impair access to, or the reliability, security or operation of, that data. The penalty is ten years (Criminal Code s 477.2).
RULE. A person commits an offence if they cause unauthorised impairment of electronic communication to or from a computer and know the impairment is unauthorised. The penalty is ten years (Criminal Code s 477.3).
RULE. A person commits the summary offence if they cause unauthorised access to, or modification of, restricted data, intend to cause it and know it is unauthorised. Restricted data is data protected by an access-control system. The penalty is two years (Criminal Code s 478.1).
RULE. A person commits an offence if they cause unauthorised impairment of the reliability, security or operation of data held on a computer disk, credit card or similar device, intend to cause the impairment and know it is unauthorised. The penalty is two years (Criminal Code s 478.2).
RULE. Part 10.7 offences carry extended geographical jurisdiction. Section 476.3 replicates the Category A jurisdiction of s 15.1, reaching conduct done or having an effect in Australia, with the Attorney-General's consent required where the conduct is wholly foreign and the accused is not an Australian citizen or Australian body corporate (Criminal Code s 476.3).
RULE. Live telecommunications may not be intercepted. Section 7 prohibits interception and the s 7(2) exceptions permit interception under a warrant and in other defined circumstances, which keeps interception under judicial or statutory control (TIA Act s 7).
RULE. twist Stored communications may not be accessed. Section 108 prohibits access and the s 108(2) exceptions permit access under a stored-communications warrant, an interception warrant or an ASIO computer-access warrant, so the warrant is the gateway to lawful access (TIA Act s 108).

Serious offences and summary offences compared

s 477.1 s 477.2 s 477.3 s 478.1
Conduct Unauthorised access, modification or impairment Unauthorised modification of data Unauthorised impairment of electronic communication Unauthorised access to or modification of restricted data
Mental element Knows it is unauthorised and intends by it to commit or facilitate a serious offence Knows the modification is unauthorised and is reckless as to whether it will impair data Knows the impairment is unauthorised Intends the access or modification and knows it is unauthorised
Penalty As for the intended serious offence 10 years 10 years 2 years

Common confusions

Confusion. Illegal access is complete without any further harm. Access under art 2 and s 477.1 needs no damage and no copying and no reading, because entering the system in whole or in part is the offence and later damage engages separate offences (Budapest art 2; Criminal Code s 477.1).
Confusion. Interception and access to stored communications are different acts under different provisions. Interception under the TIA Act s 7 catches data captured in transit, while access to a message already stored is dealt with under s 108, and the Budapest scheme draws the same line between art 3 interception and art 2 access (TIA Act ss 7 and 108; Budapest arts 2 and 3).
Confusion. An ulterior purpose does not make access unauthorised. Section 476.2(2) states that access is not unauthorised merely because the person has an ulterior purpose, so the question is entitlement to cause the access rather than the motive behind it (Criminal Code s 476.2).
Confusion. Exceeding authorisation can still be unauthorised access. A person given access for a limited purpose who goes beyond that limit may act without authority, because the issue is whether the particular access fell within the scope of the permission given (Urbas ch 2, citing Hayne J on computer trespass).
Confusion. The device offence does not ban dual-use tools outright. Article 6 and its Australian counterparts require intent that the device be used to commit an offence, so tools traded for authorised security testing or protection are not caught, which is the compromise that keeps legitimate penetration testing lawful (Budapest art 6(2)).
Confusion. The serious offences and the summary offences are not graded by the same trigger. Sections 477.2 and 477.3 turn on impairment and knowledge and carry ten years, while ss 478.1 and 478.2 are the lower two-year offences for access to restricted data and impairment of stored data, so match the conduct to the right tier before stating a penalty (Criminal Code ss 477.2, 477.3, 478.1, 478.2).

Debate

The Debate section carries the research-essay load, so each strand is set out as a contest with the leading voices named. Each closes with questions to test a position rather than settle it.

Should merely accessing a computer be a crime? The Budapest scheme and s 477.1 treat access as complete without damage, which criminalises conduct that causes no loss. Furnell rejects the argument that a hacker who only looks does no harm, because the intruder may still have seen private or commercially sensitive material, so harm is done even where the data is untouched (Gillespie ch 2, citing Furnell). Furnell presses the house analogy, that a person would not accept an uninvited look around their home on the ground that the door was open (Gillespie ch 2). Gillespie notes the contradiction that entering a computer system without permission is a crime while entering a house is criminal only with an ulterior intent, which sharpens the question of whether bare access deserves the criminal law (Gillespie ch 2).

Is a DoS or DDoS attack a form of protest that should be protected? Some hackers claim their attacks are protest, and Yar treats hacktivism as the cyberspace analogue of the civil-rights movement, involving virtual sit-ins, email bombs, website defacement and malware (Gillespie ch 2, citing Yar). The virtual sit-in draws a deliberate analogy to the peaceful occupation of a building, and some describe hacktivism as "electronic civil disobedience" (Gillespie ch 2). Against protection, a DDoS attack suppresses data and seriously hinders a system, which is the paradigm of art 5 and produces real cost, as R v Martin showed for the University of Oxford (Gillespie ch 2; Budapest art 5). In 2013 Anonymous petitioned the United States government to recognise DDoS attacks as legitimate protest akin to peaceful occupation of land, and the government rejected it (Gillespie ch 2). Hampson locates the difference between hacktivist and criminal in the pursuit of a political goal rather than self-interest, though he concedes the difficulty of deciding who defines a legitimate political goal (Gillespie ch 2, citing Hampson). Denning doubts the tactic even works, suggesting disruptive action strengthens cyber-defence policy rather than winning the concessions sought (Urbas ch 3, citing Denning).

Should defences be available for ethical hackers or security researchers? White-hat or "ethical" hackers argue the internet becomes safer through their work, so there is a public benefit in exposing security flaws (Gillespie ch 2). The counter-argument makes consent the dividing line. Testing invited by a company through a penetration-testing arrangement is legitimate, while unconsented testing is harder to defend. Furnell adds that researchers rarely report a flaw quietly, so public disclosure can invite attacks before the flaw is closed (Gillespie ch 2, citing Furnell and Wall). The law reflects this tension in the device offence, where art 6(2) and its Australian counterparts exempt tools used for authorised testing or protection of a system, which shields the security industry without opening a general loophole (Budapest art 6(2)). Whether a broader defence should protect an unconsented researcher acting in good faith remains contested, because motivation is hard to prove after the fact and can be asserted by any intruder once caught (Gillespie ch 2).

Discussion prompts

  1. Australian and Budapest law treat access to a computer as complete without any damage. Argue for and against criminalising bare access, drawing on Furnell's harm analysis and the contrast Gillespie draws with the law of trespass to a house.
  2. Set out the elements the prosecution must prove under s 477.1, and explain how the fault requirements differ for the conduct element and for the lack of authorisation.
  3. Explain the line between interception under the TIA Act s 7 and access to stored communications under s 108, and assess whether the distinction still makes sense given cloud storage.
  4. Evaluate the claim that a DDoS attack can be a legitimate form of protest, using the civil-disobedience analogy on one side and the art 5 system-interference framing on the other.
  5. Consider whether the law should recognise a defence for security researchers who access systems without consent, and explain how the device offence in art 6 already accommodates authorised testing.
  6. Compare the s 477 serious offences with the s 478 summary offences, and explain what work the concepts of impairment, recklessness and "restricted data" do in setting the penalty tier.

Check your understanding

Auto-marked drills. Answer, then read the authority in the feedback.