HomeCybercrimeAttacks and IP

What Is a Cyber Attack?

Inputting or deploying malicious software into an electronic system or device, data, infrastructure or program, for the purpose of altering, harming, disrupting, degrading or destroying it. A crime carrying 15 years, or K50,000, or an ICT prohibition — or all three.

The cybercrime series, no. 59 · Cyber attack and intellectual property · 5 min read

Section 27 of the Cybercrime Code Act 2016 opens Division 4 — Other Offences. It is the malware provision.

Section 27(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification

inputs or deploys malicious software into —

  • an electronic system or device; or
  • data; or
  • infrastructure; or
  • a program,

resident or transiting within an electronic system or device,

for the purpose of altering or causing harm to, or, disrupting, degrading, destroying an electronic system or device, data, infrastructure, or program, is guilty of a crime.

Penalties under section 27(1)
OffenderAvailable penalties
Natural personImprisonment up to 15 years; or a fine up to K50,000; or an ICT prohibition for the term of imprisonment plus two years; or all or any of them
Body corporateA fine up to K500,000
“All or any of Subparagraphs (i), (ii) or (iii)”

This formula — used throughout Division 4 — gives the court complete freedom to combine imprisonment, a fine and an ICT prohibition, or to impose any one alone.

For an offender whose skills make repetition likely, the ICT prohibition may matter more than the custodial term. See how cybercrime penalties are structured.

“Malicious software”

Not defined in section 2

Section 2 does not define malicious software. The expression carries its ordinary technical meaning — software designed to cause an unwanted effect on a system, its data, or its users.

In practice the character of the software will be established by expert evidence, and the required purpose in the closing words will usually be the surer route to proof: software deployed for the purpose of altering, harming, disrupting, degrading or destroying is malicious by that fact.

The five purposes cover the field: altering, causing harm to, disrupting, degrading, destroying.

“Resident or transiting within”

The phrase makes clear that the target need not be stored on the system. Data in transit — passing through a network, in a message queue, mid-transfer — is protected equally with data at rest.

The same idea appears in section 7, which deals with interception of transmissions.

How section 27 differs from sections 8, 9 and 24

Section 27 compared with sections 8, 9 and 24
s 27(1) cyber attacks 8 data interferences 9 system interferences 24(1) extortion
MeansMalicious softwareAny meansAny meansRestricting software
Purpose requiredYes — alter, harm, disrupt, degrade, destroyNoNoYes — procuring benefit
Result requiredNoYes — the data must be affectedYes — functioning must be hinderedNo
RecklessnessNot availableAvailableAvailableNot available
Section 27 is a purpose offence, not a result offence

Nothing in subsection (1) requires the attack to succeed. The offence is complete when malicious software is input or deployed with one of the five purposes.

Malware that is detected and quarantined before it executes, or that fails because of a patched vulnerability, is within the section. Compare section 8 and section 9, which require an actual effect on data or on the functioning of a system.

Note also the absence of “or recklessly”. Section 27(1) requires intention, and a purpose. A person cannot recklessly hold a purpose of destroying a system.

Where deployment is lawful

“Without lawful excuse or justification, or in excess of”

Software of this character is deployed lawfully every day — in penetration testing, in malware research, in red team exercises, and by police using remote forensic tools under section 41.

Three sources of lawful excuse arise:

  • Consent of the system owner, in a properly scoped engagement. See the defence for security testing and section 16, which expressly protects authorised testing.
  • Statutory authority — the Part IV powers, exercised under warrant.
  • Contractual authority — a system administrator acting within their role.

The words “in excess of” matter to testers. Authority to test one system is not authority to move laterally into another. Scope should be recorded in writing before work begins.

If the target is critical infrastructure

Section 27(2) raises the maximum to 25 years, the individual fine to K100,000 and the corporate fine to K1,000,000. On what qualifies, see critical infrastructure.

Section 27 is not listed in Schedule 2, so it cannot be dealt with summarily.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.