Section 13 of the Cybercrime Code Act 2016 mirrors section 12 in its conduct and differs in its purpose.
Section 13(1) — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification —
(a) inputs, alters, deletes, or suppresses electronic data; or
(b) otherwise interferes with the functioning of an electronic system or device,
for the purpose of creating or generating inauthentic data that it may be considered or acted upon for lawful purposes as if it were authentic — regardless of whether the data is directly readable or intelligible — is guilty of a crime.
Penalty: (a) for a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) for a body corporate, a fine not exceeding K1,000,000.
The distinguishing purpose
| s 12 — electronic fraud | s 13 — electronic forgery | |
|---|---|---|
| Conduct | Identical — input, alter, delete or suppress data; or otherwise interfere with a system | |
| Purpose | Deceiving or depriving another of property, for own or another’s gain | Creating inauthentic data to be considered or acted upon as authentic |
| Property element | Required | None |
| Gain element | Required | None |
| Penalty | Identical — 25 years / K100,000; K1,000,000 for a company | |
| Conspiracy / attempt fine | K25,000 — s 12(2) | K15,000 — s 13(2) |
That is the key difference. Section 12 requires a purpose of depriving someone of property for a gain. Section 13 requires only a purpose of producing inauthentic data that will be acted upon as if it were authentic.
So creating a false qualification, a fabricated identity document, a forged approval, a doctored record or a fake certificate is complete under section 13 whether or not anyone loses anything.
“For lawful purposes” describes how the data is intended to be used — in the ordinary course of legal, commercial or administrative affairs. It does not mean the forger’s purpose is lawful.
“Regardless of whether the data is directly readable or intelligible”
Traditional forgery concerns documents a person can read. Electronic forgery frequently does not.
The phrase makes clear that the offence covers material no human ever reads directly:
- Machine-readable data — magnetic stripe or chip data on a card, barcodes, QR codes.
- Encoded or encrypted data — tokens, hashes, credentials, certificates.
- Metadata — timestamps, log entries, message headers.
- Digital signatures and seals — which section 42 requires the Court to take judicial notice of.
Recall that “data” in section 2 expressly includes machine readable code or instructions and a program.
Typical cases
| Conduct | Why it is forgery |
|---|---|
| Producing a fake electronic certificate, licence or transcript | Inauthentic data to be acted on as authentic |
| Cloning a payment card’s chip or stripe data | Machine-readable inauthentic data — readability irrelevant |
| Falsifying an audit log or system record | Inputting or altering data to be relied on as genuine |
| Creating a spoofed email header so a message appears to come from someone else | Inauthentic data; and see s 26(c) on falsifying header information |
| Building a website impersonating a bank | Generating inauthentic data to be acted on as authentic; and s 12 if property is targeted |
| Altering a digital photograph offered as evidence | Inauthentic data for use in proceedings |
| Forging a digital signature or security certificate | Squarely within the “not directly readable” language |
Where forgery and fraud overlap
A fraudulent payment instruction is inauthentic data created to be acted on as authentic — forgery under section 13 — and is created for the purpose of depriving another of property — fraud under section 12.
Because the conduct elements are identical and the penalties are the same, the choice between them turns on what can be proved:
Where a property purpose is clear — a diverted payment, a stolen balance — section 12 is natural.
Where the purpose was to be believed rather than to be paid — a false qualification, a fabricated record, a forged approval — section 13 is the fit, and avoids the difficulty of proving a property purpose.
Both may be charged. Under section 3(2) this Act is additional to the Criminal Code Act (Chapter 262), whose forgery offences remain available.
Section 15 — using a system to access, manipulate, possess, use or transfer another person’s means of identification.
Section 16 — making or supplying devices, passwords or access codes for the purpose of committing a Part III offence.
Section 8 — where the alteration also damages or alters data.
Section 13(2) — conspiring or attempting to commit forgery.
Section 13 is not in Schedule 2 and cannot be dealt with summarily.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 8, 12, 13, 15, 16, 26, 42, 48; Schedule 2
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.