Section 12(2) of the Cybercrime Code Act 2016 creates an inchoate offence alongside electronic fraud.
Section 12(2)
A person who, without lawful excuse or justification, or in excess of a lawful excuse or justification, conspires with another person to commit, or attempts to commit, an offence under this section, is guilty of a crime.
Penalty: (a) for a natural person, a fine not exceeding K25,000 or imprisonment not exceeding 15 years, or both; and (b) for a body corporate, a fine not exceeding K500,000.
| s 12(1) — the full offence | s 12(2) — conspiracy or attempt | |
|---|---|---|
| Imprisonment | Up to 25 years | Up to 15 years |
| Fine — individual | Up to K100,000 | Up to K25,000 |
| Fine — company | Up to K1,000,000 | Up to K500,000 |
| Opening words | “intentionally and without lawful excuse ...” | “without lawful excuse ...” — the word “intentionally” is absent |
Section 12(2) omits the word “intentionally” that opens subsection (1). The omission is unlikely to matter in practice: conspiracy and attempt are by their nature intentional. A person cannot conspire, or attempt, without intending the object of the agreement or the attempt.
Contrast the parallel provision for electronic forgery in section 13(2), which does retain the word “intentionally”.
Conspiring with another person
An agreement with at least one other person to commit an offence under section 12 — that is, to input, alter, delete or suppress electronic data, or otherwise interfere with a system, for the purpose of deceiving or depriving another of their property.
Electronic frauds are frequently collaborative and distributed. One person obtains credentials, another builds the fraudulent site or message, another moves the money, another launders it. Several may never meet.
Section 12(2) allows each participant to be charged on the basis of the agreement, without having to prove that a particular individual performed the acts in subsection (1).
It also allows intervention before loss occurs. Where police disrupt a scheme at the planning stage, subsection (2) is the charge available.
Note that the general provisions of the Criminal Code Act (Chapter 262) on criminal responsibility apply through section 3(1), so the Code’s rules on parties to offences operate alongside section 12(2).
Attempting to commit the offence
The full offence in section 12(1) is already committed when the conduct is done for the purpose of deceiving or depriving. It does not require the fraud to succeed.
So an attempt under subsection (2) is a step further back: conduct towards doing the acts in subsection (1), where those acts have not yet been done.
The practical dividing line:
- Section 12(1) — the false data was entered, or the system was interfered with, with the fraudulent purpose. Complete whether or not money moved.
- Section 12(2) — the person tried to enter the data or interfere with the system, and failed; or agreed with another to do so.
An unsuccessful attempt to compromise a payment system is subsection (2). A successful compromise with no payout is subsection (1).
The parallel provision for forgery
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, conspires with another person to commit, or attempts to commit, an offence under this section — that is, electronic forgery — is guilty of a crime.
Penalty: a fine not exceeding K15,000 or imprisonment not exceeding 15 years, or both; and for a body corporate, K500,000.
Sections 12(2) and 13(2) are the only places where the Cybercrime Code Act separately criminalises conspiracy and attempt. Every other offence relies on the general law through section 3(1).
The difference in fines is notable: K25,000 for conspiring at fraud, K15,000 for conspiring at forgery — mirroring the different maxima Parliament attached to the completed offences’ consequences, even though both completed offences carry 25 years.
Other offences that reach preparatory conduct
| Provision | Conduct caught before any loss |
|---|---|
| s 12(2), 13(2) | Conspiring or attempting fraud or forgery |
| s 16(1) | Designing, producing, selling, importing or distributing a device, password or access code for the purpose of committing a Part III offence |
| s 15 | Possessing or accessing another person’s means of identification — no use or loss required |
| s 31 | Advertising or promoting an act that would be an offence |
| s 24 | Threatening to upload, deploy or input restricting software, or to expose data |
The Act consistently criminalises conduct upstream of harm — agreements, attempts, tools, credentials, advertisements and threats. That reflects the reality of computer crime, where the loss may occur long after, and far from, the acts that made it possible.
For anyone advising, the practical consequence is that the absence of loss is rarely an answer. The relevant question is what was done, and with what purpose.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 12, 13, 15, 16, 24, 31
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.