Section 6(2) of the Cybercrime Code Act 2016 is the aggravated form of unauthorised access.
Section 6(2)
Where the offence in subsection (1) results in damage or loss to the whole or any part of an electronic system or device, or data, the offender is guilty of a crime.
Penalty: imprisonment for a term not exceeding 15 years or a fine not exceeding K25,000.00, or both.
| s 6(1) | s 6(2) | |
|---|---|---|
| Classification | Misdemeanour | Crime |
| Imprisonment | Up to 5 years | Up to 15 years |
| Fine | Up to K7,000 | Up to K25,000 |
| Triable summarily? | Yes — Schedule 2 | No |
| Extra element | — | Results in damage or loss |
The additional element
Section 6(2) does not require the offender to have intended damage or loss. It requires the section 6(1) offence to have resulted in it.
The mental element is carried over from subsection (1): the access must have been intentional and without lawful excuse. The consequence need only be caused.
That is a significant exposure. A person who breaks into a system out of curiosity, and inadvertently corrupts a database or crashes a service in doing so, moves from a five-year misdemeanour to a fifteen-year crime.
Neither word is defined in section 2. Taking their ordinary meanings, and reading them alongside the defined term “interference” — which covers damaging, deletion, deterioration, alteration, suppression, modification and hindering — the subsection would cover:
- Damage to data — corruption, deletion, alteration, or rendering it unusable;
- Damage to a system or device — including making it inoperable;
- Loss — which is wider than physical damage and naturally includes financial loss: business interruption, the cost of restoring systems, lost revenue while a service is down.
Note also “the whole or any part”. Damage to one file or one component is enough.
Where section 6(2) overlaps with other offences
| Offence | Distinguishing feature | Maximum (natural person) |
|---|---|---|
| s 6(2) aggravated access | Requires unauthorised access, and damage or loss as a result | 15 years / K25,000 |
| s 8 data interference | Directed at data; committed intentionally or recklessly; no access requirement | 10 years / K20,000 |
| s 9(1) system interference | Hindering the functioning of a system, or a person’s lawful use of it | 10 years / K10,000 |
| s 10 data espionage | Obtaining protected data not meant for you | 30 years / K100,000 |
| s 27 cyber attack | Inputting or deploying malicious software to harm or disrupt | 15 years / K50,000, plus ICT prohibition |
| s 24(1) cyber extortion | Deploying restricting software to procure a benefit — ransomware | 25 years / K50,000 |
A single incident will often satisfy several of these at once. A person who breaks into a network, deploys ransomware, encrypts the data and demands payment has committed offences under sections 6(2), 8, 9, 24(1) and 27.
Under section 3(2) the Act is in addition to other criminal law, so Criminal Code offences may also be available.
Note one practical difference. Sections 8 and 9 can be committed recklessly; section 6 requires the access to be intentional. Where the accused says the access was accidental but the damage was real, section 8 or 9 may be the sounder charge.
A gap worth noting
Almost every other offence in the Act states two penalties — one for a natural person, one for a body corporate, typically several times higher. Section 6 states a single penalty for both subsections.
That does not mean a company cannot commit the offence. Section 2 defines “person” to mean a natural person or body corporate, and “body corporate” to include unincorporated companies and government or public bodies. A company convicted under section 6 faces the stated maximum fine of K7,000 or K25,000 — modest by the standards of the Act.
Where corporate conduct causes serious harm, the charge is therefore more likely to be brought under section 8 (K100,000 for a body corporate), section 9 (K100,000, or K1,000,000 for critical infrastructure), or section 27 (K500,000, or K1,000,000). See corporate fines.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6, 8–10, 24, 27, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.