Section 27 of the Cybercrime Code Act 2016 opens Division 4 — Other Offences. It is the malware provision.
Section 27(1)
inputs or deploys malicious software into —
- an electronic system or device; or
- data; or
- infrastructure; or
- a program,
resident or transiting within an electronic system or device,
for the purpose of altering or causing harm to, or, disrupting, degrading, destroying an electronic system or device, data, infrastructure, or program, is guilty of a crime.
| Offender | Available penalties |
|---|---|
| Natural person | Imprisonment up to 15 years; or a fine up to K50,000; or an ICT prohibition for the term of imprisonment plus two years; or all or any of them |
| Body corporate | A fine up to K500,000 |
This formula — used throughout Division 4 — gives the court complete freedom to combine imprisonment, a fine and an ICT prohibition, or to impose any one alone.
For an offender whose skills make repetition likely, the ICT prohibition may matter more than the custodial term. See how cybercrime penalties are structured.
“Malicious software”
Section 2 does not define malicious software. The expression carries its ordinary technical meaning — software designed to cause an unwanted effect on a system, its data, or its users.
In practice the character of the software will be established by expert evidence, and the required purpose in the closing words will usually be the surer route to proof: software deployed for the purpose of altering, harming, disrupting, degrading or destroying is malicious by that fact.
The five purposes cover the field: altering, causing harm to, disrupting, degrading, destroying.
The phrase makes clear that the target need not be stored on the system. Data in transit — passing through a network, in a message queue, mid-transfer — is protected equally with data at rest.
The same idea appears in section 7, which deals with interception of transmissions.
How section 27 differs from sections 8, 9 and 24
| s 27(1) cyber attack | s 8 data interference | s 9 system interference | s 24(1) extortion | |
|---|---|---|---|---|
| Means | Malicious software | Any means | Any means | Restricting software |
| Purpose required | Yes — alter, harm, disrupt, degrade, destroy | No | No | Yes — procuring benefit |
| Result required | No | Yes — the data must be affected | Yes — functioning must be hindered | No |
| Recklessness | Not available | Available | Available | Not available |
Nothing in subsection (1) requires the attack to succeed. The offence is complete when malicious software is input or deployed with one of the five purposes.
Malware that is detected and quarantined before it executes, or that fails because of a patched vulnerability, is within the section. Compare section 8 and section 9, which require an actual effect on data or on the functioning of a system.
Note also the absence of “or recklessly”. Section 27(1) requires intention, and a purpose. A person cannot recklessly hold a purpose of destroying a system.
Where deployment is lawful
Software of this character is deployed lawfully every day — in penetration testing, in malware research, in red team exercises, and by police using remote forensic tools under section 41.
Three sources of lawful excuse arise:
- Consent of the system owner, in a properly scoped engagement. See the defence for security testing and section 16, which expressly protects authorised testing.
- Statutory authority — the Part IV powers, exercised under warrant.
- Contractual authority — a system administrator acting within their role.
The words “in excess of” matter to testers. Authority to test one system is not authority to move laterally into another. Scope should be recorded in writing before work begins.
If the target is critical infrastructure
Section 27(2) raises the maximum to 25 years, the individual fine to K100,000 and the corporate fine to K1,000,000. On what qualifies, see critical infrastructure.
Section 27 is not listed in Schedule 2, so it cannot be dealt with summarily.
Sources
- Cybercrime Code Act 2016 — ss 2, 8, 9, 10, 16, 24, 27, 41, 48; Schedule 2
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.