HomeCybercrimeFraud and forgery

What Is Identity Theft?

Using an electronic system or device to access, manipulate, possess, use or transfer another person’s means of identification without their authorisation. Five verbs, no requirement of loss or gain, and a maximum of 10 years or K15,000 — K100,000 for a company.

The cybercrime series, no. 27 · Computer related offences · 5 min read

Section 15 of the Cybercrime Code Act 2016 protects a person’s identity as such.

Section 15 — the offence

Section 15

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, uses an electronic system or device

(a) to access; or (b) to manipulate; or (c) to possess; or (d) to use; or (e) to transfer,

a means of identification of another person without the authorisation of that other person, is guilty of a crime.

Penalty: (a) for a natural person, a fine not exceeding K15,000 or imprisonment not exceeding 10 years, or both; and (b) for a body corporate, a fine not exceeding K100,000.

The five prohibited acts

The five acts in section 15
VerbWhat it covers
(a) AccessReaching the identification data — opening a file of credentials, viewing a record
(b) ManipulateAltering it — changing details on an account, editing an identity record
(c) PossessHolding it. And note the extended definition of “possession” in section 2 — it includes having under control in or on any website, whether or not another person has actual custody and whether or not the thing is visible
(d) UseEmploying it — logging in as someone else, opening an account in their name
(e) TransferPassing it on — selling a credential list, sending details to another person
Possession alone is enough

Paragraph (c) is the widest limb. A person who holds another’s identification data without authorisation commits the offence — without using it, without gaining anything, and without anyone suffering loss.

Combined with the extended meaning of possession, that reaches a person who controls a file of credentials stored on a remote server, even if they cannot see it and someone else holds the machine.

The practical consequence is significant for anyone who comes into possession of leaked or stolen credential data: retaining it is capable of being the offence.

“A means of identification”

Not defined — and therefore wide

Section 2 does not define “means of identification”, so the phrase takes its ordinary meaning: anything by which a person is identified.

That naturally covers:

  • Names and personal particulars — date of birth, address, parents’ names;
  • Numbers — passport, licence, tax file, employee, student or account numbers;
  • Credentials — usernames, passwords, PINs, security answers, authentication tokens;
  • Payment identifiers — card numbers, expiry dates, security codes;
  • Biometric data — fingerprints, facial data, voice patterns;
  • Digital identity — email addresses, phone numbers, social media accounts, digital signatures.

Note that the identification must be of another person. Using a wholly fictitious identity is not section 15 — though it may be electronic forgery under section 13 if inauthentic data is created to be acted on as authentic.

No loss, gain or deception required

Compare the fraud and forgery offences

Section 12 requires a purpose of deceiving or depriving another of property. Section 13 requires a purpose of creating inauthentic data to be acted on as authentic.

Section 15 requires no purpose at all beyond doing the act intentionally and without authorisation. The offence is complete on access, manipulation, possession, use or transfer.

That makes section 15 the natural charge where identity data has been taken but its intended use cannot be proved — a very common position in the early stages of an investigation.

The trade-off is the penalty. At 10 years and K15,000, section 15 is one of the lower maxima in Division 2, reflecting that it punishes the handling of identity rather than the harm done with it.

Where identity theft sits in a scheme

Offences typically charged alongside identity theft
StageOffence
Breaking into the system holding the datas 6; s 6(2) if damage or loss resulted
Obtaining the protected datas 10 — up to 30 years
Intercepting credentials in transits 7
Holding or transferring the identification datas 15
Making or supplying the tools, passwords or access codess 16
Sending deceptive messages to collect credentialss 26; s 13 for spoofed content
Using the identity to take moneys 12 — up to 25 years
Publishing the datas 25; s 24(2)(b) if used to extort

Practical points

  1. Sharing credentials is capable of being an offence. Giving someone else your colleague’s login, or using a shared account belonging to a named individual without their authorisation, engages paragraphs (d) and (e). Organisations should issue individual credentials and prohibit sharing.
  2. Authorisation is the defence. The offence requires the act to be done without the authorisation of that other person. Consent from the person whose identity it is — not merely from an employer — is what takes conduct outside the section.
  3. “In excess of a lawful excuse” catches insiders. A staff member entitled to see customer identity data for one purpose who accesses it for another is within the section. See the article on the mental element.
  4. Delete what you should not hold. Because possession is enough, retaining old credential files, exported identity data or copies of documents beyond need creates exposure.
  5. Summary trial. Section 15 is listed in Schedule 2, so it may be dealt with summarily by a District Court constituted by a Principal Magistrate.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.