HomeCybercrimeContent offences

What Is the Spam Offence?

Section 26 makes it an offence to send multiple electronic messages with intent to deceive or mislead users, to relay them through a password-protected system to disguise their origin, or to falsify header information. The lightest penalty in the Act — 12 months or K5,000.

The cybercrime series, no. 58 · Content related offences · 5 min read

Section 26 of the Cybercrime Code Act 2016 carries the lowest maximum penalty in the entire Act. It is also the last offence in Division 3, before the Division 4 offences begin.

Section 26

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, or recklessly, uses an electronic system or device

(a) to initiate the transmission of multiple electronic messages with the intent to deceive or mislead users; or

(b) which is password protected to relay or retransmit multiple electronic messages, with the intent to deceive or mislead users, or any ICT Service Provider, as to the origin of such messages; or

(c) to materially falsify header information in multiple electronic messages with the intent of initiating the transmission of such messages,

is guilty of an offence.

Penalty: natural person — a fine up to K5,000 or imprisonment up to 12 months, or both; body corporate — a fine up to K100,000.

“An offence” — neither a crime nor a misdemeanour

Most provisions in the Act say “is guilty of a crime” or “is guilty of a misdemeanour”. Section 26 says simply “is guilty of an offence”.

Under the Criminal Code Act (Chapter 262), offences are divided into crimes, misdemeanours and simple offences. Section 26 supplies no classification of its own. See crimes and misdemeanours.

Whatever the classification, the position on trial is settled by Schedule 2, which lists section 26 — Spam among the indictable offences triable summarily. A District Court constituted by a Principal Magistrate may deal with it under section 48.

Deception, not volume, is the offence

Ordinary bulk email is not caught

Each of the three limbs requires deception:

  • (a) intent to deceive or mislead users;
  • (b) intent to deceive or mislead users or a provider as to the origin of the messages;
  • (c) materially falsifying header information.

A business that sends a marketing message to its customer list commits no offence under section 26, however large the list, provided the messages are what they appear to be and come from where they appear to come from.

What section 26 targets is the infrastructure of deceptive bulk messaging: forged sender addresses, relayed traffic that conceals its source, falsified headers.

Papua New Guinea has no general anti-spam statute requiring consent or an unsubscribe facility. Section 26 is not that kind of provision.

The three limbs

The three limbs of section 26
LimbConductTypical example
(a)Initiating transmission of multiple messages to deceive or misleadA phishing campaign impersonating a bank
(b)Using a password-protected system to relay or retransmit, disguising originRouting bulk mail through a compromised mail server
(c)Materially falsifying header informationForging the From, Reply-To or Received fields
Limb (b) — “which is password protected”

The phrase describes the electronic system or device used, not the messages. It points at a system with access controls — typically a mail relay, a compromised account, or a server the sender is not entitled to use.

Where the system was accessed without authorisation, section 6 will also be engaged, and it carries a much heavier penalty than section 26.

Limb (b) is the only one that names ICT service providers as possible objects of the deception, recognising that spam relaying is aimed at defeating a provider’s filtering.

Spam and phishing

Section 26 is rarely the whole picture

A phishing campaign will normally involve several offences:

  • Section 26 — the deceptive bulk messages themselves; 12 months.
  • Section 12 — electronic fraud, where the object is to obtain a benefit or cause loss; 25 years.
  • Section 13 — electronic forgery, where data is created or altered to be acted on as authentic.
  • Section 15 — identity theft, where another person’s identifying information is used.
  • Section 6 — where credentials obtained are then used to access an account.

The low penalty in section 26 is best understood on that footing: it addresses the sending, and the serious conduct is charged under the provisions that address the object.

The corporate fine is twenty times the individual fine

K5,000 against K100,000

The disparity is the largest ratio in the Act. It reflects that deceptive bulk messaging is characteristically an organised commercial activity, and that a K5,000 fine would be no deterrent to a business.

For a legitimate business the practical points are straightforward: send from your own systems, do not disguise the sender, keep header information accurate, and make sure marketing messages describe accurately what they are. See managing cybercrime risk.

See also when an ICT service provider is liable and unlawful advertising under section 31.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.