Cybercrime: types, evidence, liability and defence
The Internet has long become an integral part of everyday life, and with this, the digital environment has also become a space in which criminal offences are committed. Stealing money through phishing websites, gaining unauthorized access to accounts and information systems, distributing malicious software, extortion, and attacks on computer networks are just some examples.
At the same time, the term “cybercrime” does not mean that any offence committed via the Internet is automatically classified under one of the cybercrime provisions. The legal classification depends on what exactly the offence was directed against, how it was committed, what consequences resulted, and which circumstances can be proven.
What is considered cybercrime?
The Criminal Code of Ukraine (hereinafter referred to as the “CC of Ukraine”) does not contain a single universal provision establishing liability for “cybercrime.” Criminal offences in this area are regulated, in particular, by Articles 361-363-1 of the CC of Ukraine.
For example, Article 361 of the CC of Ukraine establishes liability for unauthorized interference with the operation of information systems, electronic communications systems, and other relevant systems. Depending on the manner in which the offence was committed and its consequences, the applicable liability may vary significantly – from a fine to a lengthy term of imprisonment.
Separate criminal liability is also provided for the creation, distribution or sale of malicious software or technical means (Article 361-1 of the CC of Ukraine), unlawful actions involving restricted-access information (Article 361-2), unauthorized actions involving information by a person who has authorized access to it (Article 362), violations of the rules governing the operation and protection of information (Article 363), and the mass distribution of messages resulting in disruption of the operation of systems or networks (Article 363-1).
At the same time, online fraud does not necessarily constitute an offence under Article 361 of the CC of Ukraine. If a person obtains another person’s money through deception using a messenger, social network, phishing website or other digital tool, the conduct may, depending on the specific circumstances, constitute fraud under Article 190 of the CC of Ukraine.
Therefore, for the correct legal classification, it is not enough to establish merely that a computer or the Internet was used. It is necessary to establish the specific actions of the person and their legal consequences.
The most common types of cybercrime
In the digital environment, criminal offences can take many different forms. The most common include:
Phishing – the use of fake websites, emails or messages to trick a person into disclosing a password, bank card details, a verification code or other confidential information.
Account hacking and unauthorized access – gaining access to email accounts, social media profiles, messengers or information systems without the owner’s permission.
Malware – the use of software or technical tools to gain unauthorized access, steal information or disrupt the operation of systems. Such actions may fall under Article 361-1 of the CC of Ukraine.
Ransomware and cyber extortion – blocking access to information or systems and demanding payment for their restoration, as well as threatening to disclose stolen data.
DDoS attacks – generating a significant volume of traffic or other load on an information system or network with the aim of disrupting its normal operation.
Data theft – the unlawful obtaining, copying, use or distribution of personal or other restricted-access information.
Online fraud – obtaining money or property through deception or abuse of trust using websites, social networks, messengers, email or other digital tools.
At the same time, the same technology may be used to commit different criminal offences. For example, a phishing message may simply be a means of obtaining banking information, after which the conduct may be classified depending on what exactly the person did and what consequences resulted.
How are cybercrimes investigated?
The specific nature of these criminal proceedings is that the traces of an offence often do not exist in the physical world but rather in the form of digital information.
Sources of evidence may include:
- computers, phones and other devices
- email and messenger correspondence
- information from social media
- IP addresses and data provided by electronic communications operators
- system and server access logs
- information from banks and payment systems
- website and hosting provider data
- information from online platforms
- cryptocurrency transaction data.
For example, when investigating fraud, law enforcement may simultaneously establish the movement of funds, a telephone number, an IP address, a messenger account, the device used to access the account, and other digital traces.
However, it is important to understand that a single digital trace does not automatically establish the identity of the offender. An IP address, telephone number, account, or even a specific device must be assessed together with other evidence.
Can a screenshot or chat correspondence be used as evidence?
Yes, electronic information can be used as evidence in criminal proceedings. The Criminal Procedure Code of Ukraine recognizes, among other things, information carriers containing computer data as documents.
The Supreme Court emphasizes that electronic evidence must be assessed with regard to its origin, authenticity, integrity, and the method by which it was obtained.
Therefore, the statement “a screenshot proves nothing” is just as incorrect as saying that “a screenshot conclusively proves that a crime was committed.”
For example, a screenshot of a chat conversation may confirm a particular circumstance, but separate questions may arise: who owned the account, who actually used it, whether the conversation is complete, when the screenshot was taken, whether the data was altered, and how the screenshot was obtained.
In more complex cases, technical data, the results of an inspection or expert examination, information obtained from operators and service providers, and other evidence may also be relevant.
What should you do if you become a victim of cybercrime?
First of all, preserve the digital traces.
If you have been scammed online, your account has been hacked, or your money has been stolen, you should preserve chat correspondence, emails, links to websites and profiles, telephone numbers, payment details, transaction information, and any other information related to the incident.
If money is involved, you should notify your bank or the relevant payment institution as soon as possible. In the case of cryptocurrency, it is important to preserve the wallet address, the transaction TXID/hash, the date, time, amount, and any other available technical data.
After that, you should report the incident to law enforcement authorities by filing a criminal complaint. Depending on the circumstances, it may also be advisable to consult a lawyer at this stage, who can help properly document the incident, preserve important digital evidence, and determine the next steps.
What if you are accused of cybercrime?
Defence in such proceedings should not be limited to simply denying the fact that you used the Internet, a computer, or a particular account.
It is necessary to establish:
- which specific article and part of the CC of Ukraine you are charged under
- what specific conduct is alleged
- when and how the alleged offence was committed
- what consequences resulted
- what evidence links the particular person to the offence
- whether the digital evidence was obtained lawfully
- whether that evidence actually proves the circumstances relied upon by the prosecution.
The analysis of digital evidence is of particular importance. The presence of an IP address, telephone number, account, or device does not, in itself, establish who actually performed the specific actions.
It is also necessary to verify compliance with procedural requirements during searches, the seizure of equipment, and the obtaining of information from telecommunications operators, banks, and online services.
The Supreme Court has repeatedly emphasized in its case law that electronic evidence must be assessed in terms of its admissibility, reliability, and verifiability.
When does cybercrime cross borders?
Cybercrime often has a cross-border nature. The victim may be in Ukraine, the offender in another country, the server in a third country, and the banking or cryptocurrency service in yet another jurisdiction.
In such cases, investigators may not always be able to obtain the necessary information directly. For example, information about an account holder, IP addresses, access logs, or the movement of funds may be stored on servers or held by companies outside Ukraine. Obtaining such information requires the use of legal mechanisms of international cooperation.
Ukraine is a party to the Budapest Convention on Cybercrime, which provides a legal framework for international cooperation in cybercrime cases and the obtaining of electronic evidence. Ukraine has also signed the Second Additional Protocol to the Convention, aimed at strengthening such cooperation and access to electronic evidence.
Therefore, the cross-border nature of a cybercrime can significantly affect the speed of an investigation and the ability to obtain the necessary evidence. For victims, this is another reason not to delay documenting the incident, as some digital data may be held by foreign services and may become unavailable over time.
Conclusion
Cybercrime has a distinctive feature that sets it apart from many traditional criminal offences: digital traces may be distributed across different devices, services, and even countries.
At the same time, the mere use of the Internet does not automatically determine the criminal-law classification of an offence. A proper assessment requires establishing the specific conduct, its consequences, the person responsible, and the relevant and admissible evidence.
If you have become a victim of cybercrime or criminal proceedings have been initiated against you in connection with an offence committed in the digital environment, timely legal assistance can be crucial for preserving evidence, ensuring the correct legal classification of the incident, and developing an effective defence strategy.