HomeCybercrimeFraud and forgery

How Do the Computer Offences Differ From Ordinary Crime?

They punish purpose rather than result, they reach preparation and supply, they treat deceiving a machine as they treat deceiving a person, and they attach corporate fines of up to K1,000,000. Loss is rarely an element, and consequence is usually an aggravating factor rather than a requirement.

The cybercrime series, no. 30 · Computer related offences · 5 min read

Division 2 of the Cybercrime Code Act 2016electronic fraud, electronic forgery, gambling by a child, identity theft and illegal devices — covers ground the general criminal law already occupies. Five differences explain why it exists.

1. Purpose, not result

The offences are complete before harm occurs

Section 12 is committed by manipulating data for the purpose of deceiving or depriving another of property. Whether anything was obtained is irrelevant to liability.

Section 13 is committed by creating inauthentic data for the purpose of its being acted upon as authentic. Whether anyone relied on it is irrelevant.

Section 16 is committed by dealing in a tool for the purpose of committing a Part III offence. Whether the offence was ever committed is irrelevant.

The reason is practical. In computer crime the act and the loss are often separated by months and by continents, and the loss may never be traced to the act at all. Fixing liability on the purpose makes the offences provable.

2. Preparation and supply are offences in themselves

Preparatory offences in the Act
StageProvisionMaximum (individual)
Agreeing to commit frauds 12(2)15 years / K25,000
Agreeing to commit forgerys 13(2)15 years / K15,000
Making, selling or obtaining tools or credentialss 16(1)15 years / K25,000
Merely possessing another’s identification datas 1510 years / K15,000
Advertising or promoting an offences 3110 years / K20,000

Every one of these can be charged before a victim suffers anything. That is a deliberate shift of the criminal law upstream, and it is where most enforcement against organised cybercrime is directed.

3. Deceiving a machine counts

The traditional problem

Classical fraud is built on a false representation made to a person who is thereby deceived. Where the only thing misled is a computer, that analysis is strained.

Sections 12 and 13 avoid the problem entirely. Their conduct elements are inputting, altering, deleting or suppressing electronic data, or otherwise interfering with the functioning of an electronic system or device. No human recipient is required.

Section 13 goes further with its closing words — the offence applies regardless of whether the data is directly readable or intelligible. Forging machine-readable data that no person ever sees is expressly covered.

4. Corporate penalties are built in

Corporate fines in Division 2
OffenceIndividualBody corporate
s 12(1) electronic fraud25 years / K100,000K1,000,000
s 12(2) conspiracy or attempt15 years / K25,000K500,000
s 13(1) electronic forgery25 years / K100,000K1,000,000
s 13(2) conspiracy or attempt15 years / K15,000K500,000
s 14(2) gaming operator25 years / K100,000K1,000,000
s 15 identity theft10 years / K15,000K100,000
s 16 illegal devices15 years / K25,000K100,000

Recall that section 2 defines “body corporate” as a company whether incorporated or unincorporated, and includes government or public bodies, as well as terrorist groups or organisations. See corporate fines and corporate liability.

5. Insiders are expressly targeted

“In excess of a lawful excuse or justification”

Every offence in Division 2 opens with that phrase. It means that a person who has authority, and goes beyond it, is treated the same as one with no authority at all.

In the general law an employee with access who misuses it raises difficult questions about whether the access was authorised. The Act removes them: the relevant question is whether the particular act was within the excuse.

See the article on the mental element.

How the Act and the general law interact

Section 3

(1) The Criminal Code Act (Chapter 262) provisions on criminal practice and procedure, jurisdiction (including ss 12–14) and punishments (including ss 18 and 19) apply to this Act.

(2) This Act is in addition to and not in derogation of the Criminal Code or any other criminal law — and where there are inconsistencies, this Act applies.

What that means for a prosecutor

The same conduct may found charges under both statutes. The choice will usually turn on:

What can be proved. Where loss cannot be traced, the Act’s purpose-based offences are easier to establish.

The maximum available. Twenty-five years for electronic fraud and forgery, and thirty for data espionage, are substantial.

Whether a company is involved. The Act’s corporate fines are express.

Where the case will be heard. Section 48 and Schedule 2 allow twelve offences to be dealt with summarily — including section 15, but not sections 12, 13, 14(2) or 16.

Note finally that the Act is not confined to Division 2 for computer-enabled wrongdoing. Divisions 1, 3 and 4 add offences against data and systems, content, and attacks and intellectual property — and Part IV supplies the procedural machinery for gathering the electronic evidence all of them depend on.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.