Section 12 of the Cybercrime Code Act 2016 opens Division 2, the computer related offences.
Section 12(1) — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification —
(a) inputs, alters, deletes, or suppresses electronic data; or
(b) otherwise interferes with the functioning of an electronic system or device,
for the purpose of deceiving or depriving another person of their property for his own gain or that of another person, is guilty of a crime.
Penalty: (a) for a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) for a body corporate, a fine not exceeding K1,000,000.
Conduct plus purpose
| Component | What must be shown |
|---|---|
| The conduct | Inputting, altering, deleting or suppressing electronic data; or otherwise interfering with the functioning of a system or device |
| The purpose | Deceiving or depriving another person of their property, for his own gain or that of another person |
| The mental element | Intentionally, without lawful excuse or in excess of one. There is no recklessness limb |
Section 12(1) does not require the deception to succeed or the property to be obtained. The conduct must be done for the purpose of deceiving or depriving. Where the purpose is proved, the offence is made out even if nothing was gained.
“Property” takes its meaning from section 1 of the Criminal Code Act (Chapter 262) and, under section 2 of this Act, includes money.
“For his own gain or that of another person” closes the argument that a person who diverted funds to someone else, or to an employer, was outside the section.
The four verbs, and the residual limb
Input covers creating false entries — a fictitious invoice, a fabricated payment instruction, a false account.
Alter covers changing existing records — bank details on a supplier file, amounts on a payment run, entitlements on a payroll.
Delete covers removing records so that a transaction escapes notice.
Suppress covers preventing data from being processed or seen — holding back a reconciliation, blocking an alert.
“Data” is defined in section 2 to include programs, so altering software to produce a fraudulent result is within paragraph (a).
This catches conduct that manipulates the system rather than the data — exploiting a flaw in a payment process, forcing a machine to behave differently, disabling a control so a transaction passes.
The word “otherwise” shows it is residual: paragraph (a) deals with data, paragraph (b) with everything else about the system.
Typical cases
| Conduct | Which limb |
|---|---|
| Changing a supplier’s bank account details so payments are diverted | (a) — alters data |
| Creating false employees on a payroll system | (a) — inputs data |
| Deleting records of a payment so it is made twice | (a) — deletes data |
| Sending a payment instruction from a compromised email account | (a) — inputs data; also s 15 if identification is used |
| Manipulating an ATM or point-of-sale terminal to release funds | (b) — interferes with functioning |
| Building a fake website to collect banking credentials | (a) and (b); also s 13 for the inauthentic data |
| Altering a database to write off a debt owed by yourself | (a) — alters data |
Electronic fraud and Criminal Code fraud
Under section 3(2), this Act is in addition to and not in derogation of the Criminal Code and every other criminal law, and where there are inconsistencies, this Act applies.
Section 12 adds three things to the general law of fraud:
It focuses on the technique — manipulation of data or systems — rather than on a false representation to a person. Deceiving a machine is squarely within it.
It does not require a result. The purpose is enough.
It provides a corporate penalty of K1,000,000, and section 2 defines “body corporate” to include unincorporated companies and government or public bodies.
Related offences in the same transaction
- s 6 — the access used to reach the system, and s 6(2) if damage or loss resulted.
- s 13 — where inauthentic data was created to be acted on as authentic.
- s 15 — where another person’s means of identification was used.
- s 16 — where devices, passwords or access codes were made or supplied for the purpose.
- s 8 — where data was damaged, altered or deleted.
- s 26 — where multiple electronic messages were sent to deceive or mislead.
- s 31 — where the scheme was advertised or promoted online.
And section 12(2) creates a separate offence of conspiring or attempting to commit electronic fraud.
Section 12 is not in Schedule 2, so it cannot be dealt with summarily. It is tried on indictment.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6, 8, 12, 13, 15, 16, 26, 31, 48; Schedule 2
- Criminal Code Act (Chapter 262) — s 1
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.