HomeCybercrimeData and system offences

What Is Unauthorised Access or Hacking?

Accessing or gaining entry, without authorisation, to the whole or any part of a protected or non-public electronic system, device or data — intentionally, and without lawful excuse or justification or in excess of one. A misdemeanour carrying up to five years or K7,000, or both.

The cybercrime series, no. 9 · Attacks on data and systems · 5 min read

Section 6 of the Cybercrime Code Act 2016 is the first offence in the Act and the foundation of the others.

Section 6(1) — the basic offence

Section 6(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, accesses or gains entry without authorisation, to the whole or any part of a protected or non-public electronic system or device, or data, is guilty of a misdemeanour.

Penalty: imprisonment for a term not exceeding five years or a fine not exceeding K7,000.00, or both.

The elements

Elements of section 6(1)
ElementWhat it requires
IntentionallyThe access must be deliberate. Accidental access — a mistyped address, a misdirected connection — is not within the section
Without lawful excuse or justification, or in excess of oneSee the article on this formula. Note the third limb: exceeding a permission you do have is as culpable as having none
Accesses or gains entryTwo verbs. Nothing need be taken, read, copied or damaged — entry alone completes the offence
Without authorisationA separate requirement from lawful excuse. The system’s owner or controller must not have permitted the access
To the whole or any partAccessing one folder, one account or one page of a system is enough
Of a protected or non-public electronic system or device, or dataThe target must be protected or non-public. A publicly accessible website is neither
“Protected or non-public” is the limiting element

The Act does not define either word here, but the pairing matters. Protected suggests a technical barrier — a password, an access code, encryption, a firewall. Non-public is wider: a system or data not made available to the public, whether or not it is technically secured.

So an unsecured internal server that was never intended for public access is non-public even without a password. But visiting a page that anyone can reach on the open internet is not accessing something protected or non-public, however unwelcome the visit.

Note that the object may be a system, a device, or data. Accessing a protected file counts, even if the machine holding it was open.

The defined meaning of “hacking”

Section 2

“Hacking” means the act of exploring programs or determining the limitations of a computer, electronic system or device or network, for the purposes of gaining unauthorised access to it.

Purpose is what makes probing hacking

The definition captures the reconnaissance phase — scanning, probing, testing what a system will allow — but only where done for the purposes of gaining unauthorised access.

The same technical activity done with authority, to find weaknesses so they can be fixed, is not hacking within the definition. And section 16(2) provides a defence in relation to illegal devices where the activity is for authorised testing or protection of an electronic system or device, or for law enforcement purposes — a defence expressed to apply to that section, but reflecting the same distinction.

Note that the heading of section 6 is “Unauthorised access or hacking”, while the body of subsection (1) speaks only of accessing or gaining entry. The definition of hacking colours the section, but the offence is committed by the access itself.

What falls inside and outside

Applying section 6(1)
ConductWithin section 6(1)?
Guessing or using someone else’s password to open their emailYes — intentional, unauthorised, protected
Logging into a work system you have no permission to useYes
An employee opening a colleague’s restricted files using their own valid loginYesin excess of a lawful excuse
Using a friend’s phone with their permissionNo — authorised
Browsing a public websiteNo — not protected or non-public
Scanning a network to find open ports, intending to break inHacking within s 2; the offence is complete once access is obtained
Penetration testing with the owner’s written authorityNo — authorised; and see s 16(2)
Continuing to use an account after your access was revokedConsider section 11 — illegally remaining

Why this offence is a misdemeanour

The only misdemeanours in Division 1

Section 6(1) and section 11 are misdemeanours; every other offence in Division 1 — and section 6(2) — is a crime. The distinction matters for classification and, through section 3, for the Criminal Code procedure that applies. See the article on the distinction.

The K7,000 maximum fine is also the lowest of any offence in the Act apart from spam. The reason is that section 6(1) punishes bare access. Where the access produces consequences, other provisions take over:

  • Section 6(2) — where the access results in damage or loss: a crime, 15 years or K25,000.
  • Section 10 — where protected data is obtained: a crime, up to 30 years.
  • Section 8 — where data is damaged, deleted or altered.
  • Section 9 — where the system’s functioning is hindered.

Section 6(1) is listed in Schedule 2, so it may be dealt with summarily by a District Court constituted by a Principal Magistrate. Section 6(2) is not.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.