Home › Cybercrime Law › Module 2 · Integrity offences
Module 2 · Computer integrity offences
What this module covers and why it matters. This module covers the crimes committed against computers, devices, data and networks. The reading list groups this conduct as illegal access, illegal interception, data and system interference and illegal devices. It is the first of the offence modules and so it sits at the front of the subject's arc from offences to jurisdiction to investigations to cooperation. The doctrinal load is heavy here because these offences supply the core of the 1500-word problem question and so the RULE cards and the comparison table carry most of the weight. The debate load matters too because the questions of whether mere access should be a crime and whether hacktivism deserves protection feed the research essay. The instruments are the Budapest Convention offences and their Australian counterparts in Part 10.7 of the Criminal Code and the Telecommunications (Interception and Access) Act 1979.
Instruments at a glance
| Instrument | Key provisions | What it does |
|---|---|---|
| Budapest Convention on Cybercrime (ETS 185, 2001) | Art 2 illegal access; art 3 illegal interception; art 4 data interference; art 5 system interference; art 6 misuse of devices | Harmonises the core computer-integrity offences. Each offence requires the act to be done "without right" and in general intentionally |
| Budapest Convention, Explanatory Report | Paras [44] to [50] and following on arts 2 to 6 | Interprets the offences. It confines "access" and "interception", restricts art 3 to "non-public" transmissions "by technical means" and requires the art 5 hindering to be "serious" |
| Criminal Code Act 1995 (Cth), Part 10.7 | s 476.1 definitions; s 476.2 meaning of "unauthorised"; s 476.3 geographical jurisdiction; ss 477.1 to 477.3 serious offences; ss 478.1 to 478.2 summary offences | Australia's computer-integrity offences, inserted by the Cybercrime Act 2001 (Cth). Splits serious offences carrying long penalties from summary offences carrying two years |
| Telecommunications (Interception and Access) Act 1979 (Cth) | s 7 telecommunications not to be intercepted, with the s 7(2) exceptions; s 108 stored communications not to be accessed, with the s 108(2) exceptions | Prohibits interception of live communications and access to stored communications, subject to warrant and other lawful-authority exceptions |
Cases at a glance
| Case | Point it settles |
|---|---|
| R v Tahiraj [2014] QCA 353 | Applies s 477.1, unauthorised access with intent to commit a serious offence, in a child-exploitation prosecution built on forensic proof that the accused controlled the malware |
| R v Martin [2013] EWCA Crim 1420 | A DDoS attack, including one on the University of Oxford website, causes real cost. The victim estimated almost two weeks of staff time to deal with it |
| R v Walker | Bot code written and deployed by the accused produced a DDoS attack on the University of Pennsylvania system, illustrating impairment through distributed attack (Urbas ch 4) |
Attack plan
Attack plan. Work a computer-integrity problem in this fixed order. First, characterise the conduct as access, modification, impairment or interception, because the offence chosen follows from the conduct. Second, identify the Commonwealth offence and set out its physical elements from Part 10.7. Third, ask whether the conduct was "unauthorised" within s 476.2, meaning the person was not entitled to cause it. Fourth, state the mental element the section requires, which is knowledge of the lack of authorisation plus intent or recklessness as the particular section specifies. Fifth, check any lawful-authority or warrant exception, including the s 476.2(4) warrant entitlement and the TIA Act exceptions in ss 7(2) and 108(2). Sixth, confirm the jurisdiction hook in s 476.3, which replicates the Category A extended geographical jurisdiction of s 15.1.
The Budapest offences
The Australian offences
Serious offences and summary offences compared
| s 477.1 | s 477.2 | s 477.3 | s 478.1 | |
|---|---|---|---|---|
| Conduct | Unauthorised access, modification or impairment | Unauthorised modification of data | Unauthorised impairment of electronic communication | Unauthorised access to or modification of restricted data |
| Mental element | Knows it is unauthorised and intends by it to commit or facilitate a serious offence | Knows the modification is unauthorised and is reckless as to whether it will impair data | Knows the impairment is unauthorised | Intends the access or modification and knows it is unauthorised |
| Penalty | As for the intended serious offence | 10 years | 10 years | 2 years |
Common confusions
Debate
The Debate section carries the research-essay load, so each strand is set out as a contest with the leading voices named. Each closes with questions to test a position rather than settle it.
Should merely accessing a computer be a crime? The Budapest scheme and s 477.1 treat access as complete without damage, which criminalises conduct that causes no loss. Furnell rejects the argument that a hacker who only looks does no harm, because the intruder may still have seen private or commercially sensitive material, so harm is done even where the data is untouched (Gillespie ch 2, citing Furnell). Furnell presses the house analogy, that a person would not accept an uninvited look around their home on the ground that the door was open (Gillespie ch 2). Gillespie notes the contradiction that entering a computer system without permission is a crime while entering a house is criminal only with an ulterior intent, which sharpens the question of whether bare access deserves the criminal law (Gillespie ch 2).
- Does viewing private data without altering it cause a harm the criminal law should punish?
- Is the contrast with the law of trespass to a house a reason to require some ulterior intent for bare access?
Is a DoS or DDoS attack a form of protest that should be protected? Some hackers claim their attacks are protest, and Yar treats hacktivism as the cyberspace analogue of the civil-rights movement, involving virtual sit-ins, email bombs, website defacement and malware (Gillespie ch 2, citing Yar). The virtual sit-in draws a deliberate analogy to the peaceful occupation of a building, and some describe hacktivism as "electronic civil disobedience" (Gillespie ch 2). Against protection, a DDoS attack suppresses data and seriously hinders a system, which is the paradigm of art 5 and produces real cost, as R v Martin showed for the University of Oxford (Gillespie ch 2; Budapest art 5). In 2013 Anonymous petitioned the United States government to recognise DDoS attacks as legitimate protest akin to peaceful occupation of land, and the government rejected it (Gillespie ch 2). Hampson locates the difference between hacktivist and criminal in the pursuit of a political goal rather than self-interest, though he concedes the difficulty of deciding who defines a legitimate political goal (Gillespie ch 2, citing Hampson). Denning doubts the tactic even works, suggesting disruptive action strengthens cyber-defence policy rather than winning the concessions sought (Urbas ch 3, citing Denning).
- Does the sit-in analogy hold when a DDoS attack blocks other users rather than persuading them?
- If a political motive is what separates protest from crime, who should decide which goals qualify?
Should defences be available for ethical hackers or security researchers? White-hat or "ethical" hackers argue the internet becomes safer through their work, so there is a public benefit in exposing security flaws (Gillespie ch 2). The counter-argument makes consent the dividing line. Testing invited by a company through a penetration-testing arrangement is legitimate, while unconsented testing is harder to defend. Furnell adds that researchers rarely report a flaw quietly, so public disclosure can invite attacks before the flaw is closed (Gillespie ch 2, citing Furnell and Wall). The law reflects this tension in the device offence, where art 6(2) and its Australian counterparts exempt tools used for authorised testing or protection of a system, which shields the security industry without opening a general loophole (Budapest art 6(2)). Whether a broader defence should protect an unconsented researcher acting in good faith remains contested, because motivation is hard to prove after the fact and can be asserted by any intruder once caught (Gillespie ch 2).
- Should good faith protect a researcher who tests a system without the owner's consent?
- Can a motive-based defence be drawn narrowly enough to avoid shielding any intruder who claims good intentions?
Discussion prompts
- Australian and Budapest law treat access to a computer as complete without any damage. Argue for and against criminalising bare access, drawing on Furnell's harm analysis and the contrast Gillespie draws with the law of trespass to a house.
- Set out the elements the prosecution must prove under s 477.1, and explain how the fault requirements differ for the conduct element and for the lack of authorisation.
- Explain the line between interception under the TIA Act s 7 and access to stored communications under s 108, and assess whether the distinction still makes sense given cloud storage.
- Evaluate the claim that a DDoS attack can be a legitimate form of protest, using the civil-disobedience analogy on one side and the art 5 system-interference framing on the other.
- Consider whether the law should recognise a defence for security researchers who access systems without consent, and explain how the device offence in art 6 already accommodates authorised testing.
- Compare the s 477 serious offences with the s 478 summary offences, and explain what work the concepts of impairment, recklessness and "restricted data" do in setting the penalty tier.
Check your understanding
Auto-marked drills. Answer, then read the authority in the feedback.