HomeCybercrimeContent offences

What Is Cyber Extortion?

Uploading, deploying or inputting — or threatening to — software designed to restrict, disrupt or hinder the operation of or access to an electronic system or device, for the purpose of procuring money or another benefit. This is the ransomware offence, and it carries 25 years.

The cybercrime series, no. 54 · Content related offences · 5 min read

Section 24(1) of the Cybercrime Code Act 2016 is Papua New Guinea’s ransomware provision, although it never uses the word.

Section 24(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, uses an electronic system or device to

(a) upload or threaten to upload; or

(b) deploy or threaten to deploy; or

(c) input or threaten to input,

into an electronic system or device, software designed to restrict, disrupt or in any way hinder the operation of or access to an electronic system or device, for the purpose of procuring monetary or other benefit for himself or another person, is guilty of a crime.

Penalty: natural person — a fine up to K50,000 or imprisonment up to 25 years, or both; body corporate — a fine up to K500,000.

Twenty-five years

That places cyber extortion in the Act’s most serious band, alongside electronic fraud, child pornography, aggravated cyber bullying and cyber attack on critical infrastructure.

How the section covers ransomware

Every element of a ransomware attack is described

Software designed to restrict … access to an electronic system or device. Encryption of a victim’s files is exactly that — access is restricted until a key is supplied.

Upload, deploy or input. However the payload reaches the system — a phishing attachment, a compromised update, an exposed remote access port — one of the three verbs will fit.

For the purpose of procuring monetary or other benefit. The ransom demand. Note that the benefit may be for the offender or another person, and need not be monetary.

No payment need be made and no demand need be met. The offence is complete when the software is deployed with the required purpose.

The threat alone is enough

Each of the three paragraphs has a “threaten to” limb

Threatening to upload, deploy or input the software, for the purpose of procuring a benefit, is the completed offence — carrying the same 25-year maximum.

Why that matters

A common pattern is a demand supported by a claim of access which may or may not be real. Because the threat limb does not require the software to exist, still less to be deployed, the offence is committed by the demand.

Note the contrast with section 24(2), where subsection (3) expressly makes it immaterial whether the person accused actually committed the act. Section 24(1) contains no equivalent provision about the reality of the capability — but the words “threaten to” do the same work.

The elements compared

Section 24(1) compared with related offences
s 24(1) extortions 27(1) cyber attacks 9 system interference
ConductUpload, deploy or input — or threaten toInputs or deploys malicious softwareHinders the functioning of a system
PurposeProcuring monetary or other benefitAltering, harming, disrupting, degrading, destroying
Recklessness enough?No — intention onlyNo — intention onlyYes
Natural person25 years or K50,000, or both15 years, or K50,000, or ICT prohibitionSee s 9
Body corporateK500,000K500,000See s 9
No recklessness limb

Unlike most offences in the Act, section 24(1) omits “or recklessly”. The conduct must be intentional, and done without lawful excuse or justification, or in excess of one.

That is a deliberate narrowing. An extortion offence requires a purpose of procuring a benefit; a person cannot recklessly hold such a purpose.

The practical consequence is that a security researcher or systems administrator who deploys disruptive software by mistake is not within section 24 — though the conduct may fall under section 9 or section 8, both of which include a recklessness limb. See the defence for security testing.

Companies and the K500,000 fine

Two ways a body corporate is affected

As offender: paragraph (b) provides a fine of up to K500,000. On corporate liability generally, see section 3 and the Criminal Code.

As victim: the more common position. A company facing a ransom demand should report it, preserve the affected systems, and avoid destroying evidence — police can seek preservation notices under section 36 and production orders under section 35, and international co-operation under Part VI may be needed where the offender is offshore.

Paying a ransom is not itself an offence under the Act. But it funds the conduct, gives no assurance of restoration, and destroys nothing of the underlying compromise.

Where the offender is overseas

Section 3 and Part VI matter here. Ransomware is characteristically cross-border, and sections 46 and 47 provide for international co-operation, including mutual assistance and extradition arrangements.

Section 24 is not listed in Schedule 2, so it cannot be dealt with summarily. See also section 24(2), the blackmail limb, and managing cybercrime risk.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.