HomeCybercrimeData and system offences

What if Hacking Causes Damage or Loss?

The offence changes from a misdemeanour to a crime, and the maximum rises from five years and K7,000 to fifteen years and K25,000. All that is required is that the unauthorised access results in damage or loss to the whole or any part of the system, device or data.

The cybercrime series, no. 10 · Attacks on data and systems · 5 min read

Section 6(2) of the Cybercrime Code Act 2016 is the aggravated form of unauthorised access.

Section 6(2)

Section 6(2)

Where the offence in subsection (1) results in damage or loss to the whole or any part of an electronic system or device, or data, the offender is guilty of a crime.

Penalty: imprisonment for a term not exceeding 15 years or a fine not exceeding K25,000.00, or both.

Section 6(1) compared with section 6(2)
s 6(1)s 6(2)
ClassificationMisdemeanourCrime
ImprisonmentUp to 5 yearsUp to 15 years
FineUp to K7,000Up to K25,000
Triable summarily?Yes — Schedule 2No
Extra elementResults in damage or loss

The additional element

“Results in” — a causal test, not an intentional one

Section 6(2) does not require the offender to have intended damage or loss. It requires the section 6(1) offence to have resulted in it.

The mental element is carried over from subsection (1): the access must have been intentional and without lawful excuse. The consequence need only be caused.

That is a significant exposure. A person who breaks into a system out of curiosity, and inadvertently corrupts a database or crashes a service in doing so, moves from a five-year misdemeanour to a fifteen-year crime.

What counts as damage or loss

Neither word is defined in section 2. Taking their ordinary meanings, and reading them alongside the defined term “interference” — which covers damaging, deletion, deterioration, alteration, suppression, modification and hindering — the subsection would cover:

  • Damage to data — corruption, deletion, alteration, or rendering it unusable;
  • Damage to a system or device — including making it inoperable;
  • Loss — which is wider than physical damage and naturally includes financial loss: business interruption, the cost of restoring systems, lost revenue while a service is down.

Note also “the whole or any part”. Damage to one file or one component is enough.

Where section 6(2) overlaps with other offences

Section 6(2) compared with related offences
OffenceDistinguishing featureMaximum (natural person)
s 6(2) aggravated accessRequires unauthorised access, and damage or loss as a result15 years / K25,000
s 8 data interferenceDirected at data; committed intentionally or recklessly; no access requirement10 years / K20,000
s 9(1) system interferenceHindering the functioning of a system, or a person’s lawful use of it10 years / K10,000
s 10 data espionageObtaining protected data not meant for you30 years / K100,000
s 27 cyber attackInputting or deploying malicious software to harm or disrupt15 years / K50,000, plus ICT prohibition
s 24(1) cyber extortionDeploying restricting software to procure a benefit — ransomware25 years / K50,000
Choosing the charge

A single incident will often satisfy several of these at once. A person who breaks into a network, deploys ransomware, encrypts the data and demands payment has committed offences under sections 6(2), 8, 9, 24(1) and 27.

Under section 3(2) the Act is in addition to other criminal law, so Criminal Code offences may also be available.

Note one practical difference. Sections 8 and 9 can be committed recklessly; section 6 requires the access to be intentional. Where the accused says the access was accidental but the damage was real, section 8 or 9 may be the sounder charge.

A gap worth noting

Section 6 has no separate corporate penalty

Almost every other offence in the Act states two penalties — one for a natural person, one for a body corporate, typically several times higher. Section 6 states a single penalty for both subsections.

That does not mean a company cannot commit the offence. Section 2 defines “person” to mean a natural person or body corporate, and “body corporate” to include unincorporated companies and government or public bodies. A company convicted under section 6 faces the stated maximum fine of K7,000 or K25,000 — modest by the standards of the Act.

Where corporate conduct causes serious harm, the charge is therefore more likely to be brought under section 8 (K100,000 for a body corporate), section 9 (K100,000, or K1,000,000 for critical infrastructure), or section 27 (K500,000, or K1,000,000). See corporate fines.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.