Cybercrime

Defense in Cases of Computer Crime and Digital Allegations

Immediate Measures

  • What to Do Immediately in the Event of a Search or Subpoena· Exercise your right to remain silent—this also applies to questions about passwords, accounts, and devices.
    · Explicitly object to the seizure; this keeps the possibility of judicial review open.
    · Request a list of the devices and data storage media that were taken.
    · If you rely on these devices for work, apply early for their return or for a copy of the data.
  • Under no circumstances should you· Unlock devices or provide access credentials just to cut the process short.
    · Delete data, accounts, or chat histories—deleted information can usually be recovered, and the act of deleting it is interpreted as an attempt to cover something up.
    · Explain technical procedures at the scene in an attempt to dispel suspicion.
    · Disclose third-party access or shared accounts.

The Key Issues in the Proceedings

The investigation often begins with a search, the seizure of a smartphone or computer, or a subpoena. Other cases arise from suspicious money transfers, compromised user accounts, malware, or an IP address associated with a particular connection. The investigative file then contains large amounts of data—and individual files, log entries, or chat messages only acquire their legal significance when viewed in their technical and temporal context.

This covers crimes against data and IT systems as well as traditional offenses that are alleged to have been committed using digital means. Typical charges include spying on or intercepting data under Sections 202a and 202b of the German Criminal Code (StGB), computer fraud under Section 263a StGB, data tampering under Section 303a StGB, and computer sabotage under Section 303b StGB. Additional offenses may include handling stolen data, extortion, forgery of documents containing evidence-relevant data, or operating a criminal trading platform.

As a defendant, you have the right under Section 136(1) of the Code of Criminal Procedure (StPO) to remain silent regarding the matter and to consult with your defense attorney at any time—even when asked about passwords, user accounts, devices, and communication records. I will review the investigative file, search and seizure documents, digital copies of data storage devices, forensic analysis reports, communication data, payment transactions, and expert opinions.

Data Access and Malware — Spying, Interception, and Preparation

Section 202a of the German Criminal Code (StGB) covers unauthorized access to data that is not intended for the perpetrator and is specifically secured against unauthorized access. It is required that this security measure be circumvented—this requirement is often more decisive than the act of access itself. The penalty ranges up to three years’ imprisonment or a fine. Section 202b of the German Criminal Code (StGB) addresses the technical interception of non-public data transmissions and provides for a penalty of up to two years.

Even the act of preparation may be punishable under Section 202c of the German Criminal Code (StGB). The provision refers to passwords, security codes, and programs intended for the commission of an offense under Section 202a or Section 202b of the German Criminal Code (StGB). However, mere possession of a program is not sufficient in itself—it depends on the program’s intended purpose and the owner’s intent. Tools for system administration, security testing, and remote access, in particular, can be used both lawfully and unlawfully, and this ambiguity is regularly resolved to the detriment of the accused in preliminary investigations.

In cases involving stolen login credentials or data records not generally accessible to the public, the offense of handling stolen data under Section 202d of the German Criminal Code (StGB) may also apply. Among other things, this offense requires that the data was obtained through another person’s unlawful act and that the accused acts with the intent to enrich themselves or cause harm. Phishing, password theft, and the use of malware therefore cannot automatically be attributed to the same person or classified under the same offense.

Computer Fraud and Identity Theft — Digital Property Crimes

Section 263a of the German Criminal Code (StGB) covers acts of manipulation involving automated data processing that cause damage to another person’s property and are intended to secure an unlawful financial advantage: incorrect program design, incorrect or incomplete data, unauthorized use of data, and other unauthorized interference with the processing. The basic offense is punishable by imprisonment for up to five years or a fine; an attempt to commit the offense is also punishable.

This may include manipulated payment transactions, misuse of account information, automated orders, or interference with billing and accounting systems. “Phishing,” on the other hand, initially refers only to a method. Under criminal law, the process often breaks down into several offenses: obtaining access credentials, their subsequent use, data forgery under Section 269 of the German Criminal Code (StGB), and, where applicable, money laundering by other account holders. Therefore, someone who has merely provided an account is at a different point in the chain than the person who obtained the data.

“Identity theft” is also not a uniformly defined criminal offense. The decisive factor is how another person’s personal, account, or access data was used: If the deception is directed at a person, Section 263 of the German Criminal Code (StGB) may apply; if an automated system is directly affected, Section 263a of the StGB must be considered. In its decision of March 14, 2024, 5 StR 80/24, the Federal Court of Justice once again relied on this fraud-specific distinction in the context of ATM withdrawals.

Data Tampering and Computer Sabotage — Attacks on IT Systems

The deletion, suppression, rendering unusable, or alteration of data may be punishable under Section 303a of the German Criminal Code (StGB) by imprisonment for up to two years or a fine; attempted acts and preparation as defined by law are also punishable. Furthermore, computer sabotage under Section 303b(1) of the German Criminal Code (StGB) requires that data processing essential to another party be significantly disrupted. If the offense affects another person’s business, a company, or a government agency, the penalty under Section 303b(2) of the German Criminal Code (StGB) may be up to five years’ imprisonment.

DDoS attacks may constitute a criminal offense if massive numbers of requests significantly disrupt a service. In the case of ransomware, data is encrypted or systems are blocked; if money is demanded for restoration, extortion under Section 253 of the German Criminal Code (StGB) may also apply. This results in two separate offenses, the elements of which must be established independently—which does not always happen in indictments.

In its ruling of April 8, 2021, 1 StR 78/21, the Federal Court of Justice treated a large number of ransomware attacks, among other things, as possible acts of computer sabotage committed in conjunction with extortion offenses. The decision also demonstrates that each set of offenses and each degree of involvement must be determined separately—an overall assessment does not replace this.

Participation and Attempt — Attribution of Digital Contributions to a Crime

These schemes almost always involve a division of labor: one person writes code, another obtains login credentials, and others operate servers, send messages, or provide payment accounts. A distinction must be made between principal liability under § 25 of the German Criminal Code (StGB), incitement under § 26 StGB, and aiding and abetting under § 27 StGB. Aiding and abetting requires the intentional support of an intentionally committed principal offense, and the penalty for it must be mitigated by law.

Technical involvement does not determine the form of participation. Providing a server, a user account, or a cryptocurrency address can be neutral, negligent, or intentionally facilitating the crime. The decisive factors are the specific contribution, knowledge of the main offense, and, where applicable, a shared plan to commit the offense. A username, IP address, and device identification are initially circumstantial evidence—they must be reliably linked to a specific person, a specific time period, and a specific action.

With regard to an attempt, Section 22 of the German Criminal Code (StGB) requires an immediate act aimed at fulfilling the elements of the offense; in the case of misdemeanors, it is punishable only if the law expressly provides for it. This must be distinguished from specific preparatory offenses such as § 202c of the German Criminal Code (StGB) or § 263a(3) of the German Criminal Code (StGB). In the case of automated attacks, non-punishable preparation, punishable preparation, and an attempt can occur in rapid succession within a matter of seconds.

That is why I do not merely examine to whom an account or device was formally assigned. What matters are the actions taken, the level of knowledge, the ability to access the account, and the time at which a post is alleged to have referred to a specific principal offense.

Digital Evidence — Search, Seizure, and Analysis

If there is reasonable suspicion of a crime, § 102 of the Code of Criminal Procedure (StPO) authorizes the search of the suspect’s residence, person, and property belonging to the suspect if evidence is believed to be present there. Smartphones, computers, storage media, hardware wallets, and written-down access data may be seized or confiscated pursuant to Section 94 of the Code of Criminal Procedure (StPO); confiscation is generally ordered by the court, but in cases of imminent danger, it may also be ordered by the public prosecutor’s office or investigating officers.

Under Section 110 of the Code of Criminal Procedure (StPO), the search may extend to electronic storage media and, under certain legal conditions, also to geographically separate storage locations accessible from the device—in practice, therefore, to cloud content. In addition, inventory, traffic, and usage data are analyzed: Section 100k of the StPO governs the collection of usage data from digital services under graduated conditions, while the stricter Sections 100a and 100b of the StPO apply to telecommunications surveillance and online searches. The actual scope of an order is rarely as clear as the subsequent analysis suggests.

Furthermore, these legal foundations are in flux. On June 24, 2025, in Case No. 1 BvR 180/23, the Federal Constitutional Court declared parts of the criminal procedure provisions governing telecommunications surveillance and online searches to be incompatible with the Basic Law; the affected provisions remain in effect only to a limited extent until new legislation is enacted. For ongoing proceedings, it must therefore be determined on what basis and at what point in time data was collected.

I examine the arrangement, scope, technical safeguards, and evaluation separately. Key factors here include timestamps, hash values, logging, search parameters, and whether the data originates from a device, a cloud, or a provider.

“Certain provisions of the criminal procedure regulations governing telecommunications surveillance and online searches are inconsistent with the Basic Law; until new legislation is enacted, they remain in effect only to a limited extent.”

Federal Constitutional Court
Decision of June 24, 2025, 1 BvR 180/23

International Matters — Servers, Accounts, and Parties Located Abroad

Digital processes regularly cross national borders: The defendant is in Germany, while servers, platform operators, victims, or payment accounts are located elsewhere. Under Section 9 of the German Criminal Code (StGB), an offense may be committed at any location where the perpetrator acts or where the result constituting the offense occurs—or is intended to occur, according to the perpetrator’s understanding. German criminal law may therefore apply even if only part of the incident has a domestic connection.

Cross-border investigations primarily involve information from platforms, communication and account data, server images, and cryptocurrency transactions. Within the European Union, there are instruments for judicial cooperation and the mutual recognition of investigative measures. The defense must examine the legal basis on which the data was collected, transmitted, and used in the German proceedings—a question that can easily get lost in voluminous case files.

The presence of multiple international connection points does not necessarily mean that a visible IP address proves a person’s actual location. VPN connections, compromised devices, cloud infrastructures, and shared accounts alter the technical attribution. Conversely, provider information and recurring access patterns can form a chain of evidence—the reliability of which depends on the origin, completeness, and documentation of the data.

The first things I identify are the presumed location of the offense, the location where the offense was committed, the server location, and the origin of each piece of evidence. Next, I must determine which German or European investigative basis was applied and whether the data provided actually supports the allegations.

Legal Consequences — Penalty Ranges, Statute of Limitations, and New Regulations

The legal consequences depend on the specific facts of the case and any aggravating circumstances. While § 202a and § 303b(1) of the German Criminal Code (StGB) provide for maximum sentences of three years, the basic sentencing ranges for computer fraud and extortion extend up to five years. Section 303b(4) of the German Criminal Code (StGB) provides for a sentence of six months to ten years for particularly serious cases of computer sabotage directed against businesses, companies, or public authorities. Committing the offense on a commercial basis or as part of a criminal organization also significantly increases the range of penalties for computer fraud.

According to Section 78 of the German Criminal Code (StGB), the statute of limitations for prosecution is based on the maximum statutory penalty: generally five years for penalties of more than one year but not exceeding five years, and generally three years for penalties of up to one year. Circumstances that interrupt or suspend the statute of limitations affect the actual course of the period, which is why the time limit is rarely determined by the calendar alone.

As of October 1, 2021, Section 127 of the German Criminal Code (StGB) makes the operation of certain criminal trading platforms on the Internet a criminal offense in and of itself. The basic offense carries a sentence of up to five years; commercial or organized criminal activity is punishable by six months to ten years, and for platforms designed to facilitate crime, the penalty ranges from one year to ten years. For incidents occurring prior to that date, the previous legal provisions apply.

In addition to the penalty, the law provides for the forfeiture of proceeds of crime pursuant to Sections 73 et seq. of the German Criminal Code (StGB), as well as the forfeiture or destruction of equipment and software used in the commission of the offense. I therefore examine the range of penalties, competing offenses, calculation of damages, the statute of limitations, and each individual forfeiture item separately.

Rechtsanwalt Klaas F. Fernkorn

My Advice and Offer

In these cases, the technical details of what happened are rarely in question—rather, the issue is who is responsible. Whether account ownership, an IP address, or device location data supports this attribution can only be determined by analyzing the case file, including logs, hash values, and timestamps.

Please describe to me what has happened so far: a search, seizure, subpoena, or a request from your payment service provider. You will receive a prompt assessment of which charges may actually apply, how reliable the technical evidence is, and what options are available.

Frequently Asked Questions

Is the use of someone else’s login credentials always a criminal offense?

No. The decisive factors are the origin and use of the data, the authorization status, and intent. Depending on the circumstances, Sections 202a, 202c, 202d, 263a, or 269 of the German Criminal Code (StGB) may apply—mere technical access does not automatically satisfy the elements of each of these offenses.

Can the police examine smartphones and computers?

Devices may be seized or confiscated pursuant to Sections 94, 98, and 102 of the Code of Criminal Procedure (StPO), and Section 110 of the StPO permits the examination of electronic storage media under the conditions set forth therein. However, the scope and depth of the analysis must be covered by the warrant and the purpose of the investigation—this is one of the most common points of contention for the defense.

Do I need to provide passwords or PINs?

As a defendant, you are free under Section 136(1) of the Code of Criminal Procedure to make a statement regarding the matter or to remain silent. The right to remain silent generally also applies to any information that would contribute to the allegations against you. This is distinct from technical investigative measures conducted on a legal basis.

Is an IP address sufficient to prove guilt?

An IP address identifies a connection or a technical point of access. It does not, on its own, typically reveal which individual is operating the device or performed the specific action. The decisive factor is a comprehensive assessment of additional device, time, communication, and usage data.

Is the possession of malware a criminal offense?

Not every program is versatile. Section 202c of the German Criminal Code (StGB) requires a program whose purpose is directed toward committing specific data-related offenses, as well as the subjective elements of the provision. In the case of malware, a distinction must also be made between preparation, attempt, completed data alteration, and computer sabotage.

When does the statute of limitations expire for a cybercrime?

This depends on the maximum statutory penalty and Sections 78 et seq. of the German Criminal Code (StGB). For many basic offenses with a maximum penalty of more than one year but not more than five years, the statute of limitations is five years. Aggravating factors, the start of the statute of limitations, its suspension, and its interruption may result in a different calculation.

I just provided my account. Does this affect me?

That depends on what you knew. Anyone who provides an account for third-party payments may be considered an accomplice to computer fraud or money laundering—but they may also have been deceived themselves. The key factors are the specific role played, the level of knowledge, and the timing.

Will I get my devices back?

As a general rule, yes, but often only after several months. Those who rely on the data for work can request its release or a copy early on. The seizure itself can be challenged in court—expressly objecting to the seizure keeps this option open.

Go Straight to the Law

  • Phone: 030 23258357Mon–Fri, 2:00–4:00 p.m.
  • Email: anfrage@rakff.deResponse within 24 hours
  • Address: Gneisenaustr. 115, 10961 BerlinU-Bahn station: Mehringdamm (U6, U7), a one-minute walk
Hochbahn auf der Oberbaumbrücke in Berlin