Section 16 of the Cybercrime Code Act 2016 attacks the supply chain for cybercrime.
Section 16(1) — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, designs, produces, sells, procures for use, imports, exports, distributes or otherwise makes available —
(a) an electronic system or device, or thing that is designed or adapted; or
(b) a password, access code or similar data by which the whole or any part of an electronic system or device, or thing is capable of being accessed,
for the purpose of committing an offence defined by other provisions of Part III of this Act, is guilty of a crime.
Penalty: (a) for a natural person, a fine not exceeding K25,000 or imprisonment not exceeding 15 years, or both; and (b) for a body corporate, a fine not exceeding K100,000.
The eight prohibited dealings
| Verb | Typical conduct |
|---|---|
| Designs | Creating the specification for a tool or exploit |
| Produces | Building or writing it |
| Sells | Trading in it |
| Procures for use | Obtaining it for use — the acquirer, not only the supplier |
| Imports / exports | Bringing it into or sending it out of the country |
| Distributes | Circulating it, with or without payment |
| Otherwise makes available | The residual limb — posting a tool online, sharing a credential list |
Most of the verbs describe supply. “Procures for use” describes acquisition. A person who obtains a hacking tool or a stolen credential list, intending to use it to commit a Part III offence, commits section 16(1) at the moment of acquisition — before any access, interference or fraud occurs.
That is the point of the section: it reaches conduct upstream of harm.
Paragraph (b) — passwords and access codes
A password, access code or similar data by which the whole or any part of an electronic system or device, or thing is capable of being accessed.
Paragraph (b) puts credentials on the same footing as hardware and software tools. Selling, distributing or obtaining a password, PIN, access code, key or token for the purpose of committing a Part III offence is the offence.
“Or similar data” extends it to authentication tokens, session keys, API keys and equivalent material.
Note the overlap with section 15, which criminalises accessing, possessing, using or transferring a means of identification of another person without authorisation. Section 15 requires the credential to belong to a person; section 16(1)(b) does not — a system password with no personal owner is within it. But section 16 requires the purpose of committing a Part III offence, which section 15 does not.
The purpose element
This is what limits the section, and it does two things.
It requires a specific criminal purpose. The dealing must be for the purpose of committing one of the offences in sections 6 to 31 — hacking, interception, data or system interference, espionage, fraud, forgery, identity theft, a content offence, or cyber attack.
It excludes dual-use tools handled innocently. Network scanners, password recovery utilities, forensic software and penetration testing suites all have legitimate uses. Dealing in them is only an offence where the purpose is criminal.
Note that paragraph (a) also requires the device or thing to be “designed or adapted” — which, read with the purpose element, points to tools made or modified for the criminal use rather than ordinary equipment put to a bad use.
The defence in section 16(2) then puts the matter beyond doubt for authorised testing, protection of systems and law enforcement.
In practice
| Conduct | Within section 16(1)? |
|---|---|
| Writing malware and selling it | Yes — produces and sells, for the purpose of s 27 |
| Selling a list of stolen passwords | Yes — para (b); also s 15 |
| Buying a hacking tool intending to break into a system | Yes — procures for use |
| Importing card-skimming hardware | Yes — imports a device designed or adapted for s 12 |
| Posting an exploit publicly, knowing it will be used to attack systems | Likely — otherwise makes available, subject to the purpose element |
| A security firm supplying testing tools to a client under contract | No — and see the s 16(2) defence |
| Selling ordinary network administration software | No — no criminal purpose |
| A locksmith-style service recovering a forgotten password with the owner’s authority | No — authorised |
Why a supply-side offence matters
It reaches those who never touch a victim’s system. The person who writes the tool, or sells the credentials, may be in another country and may never access anything. Section 16 makes their conduct an offence in its own right.
It allows early intervention. Police need not wait for a system to be attacked.
It complements the inchoate offences. Sections 12(2) and 13(2) reach conspiracy and attempt at fraud and forgery; section 16 reaches the tooling for any Part III offence, without needing an agreement or an attempt.
Section 16 is not listed in Schedule 2, so it cannot be dealt with summarily. And note section 31, which makes it a separate crime to use an electronic system to advertise or promote conduct that would be an offence — so advertising an illegal device is an offence distinct from dealing in it.
Sources
- Cybercrime Code Act 2016 — ss 2, 6–16, 27, 31, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.