A Hacking Charge — What It Means for the Accused
When prosecutors speak of hacking in Georgia, they rely on Article 284 of the Criminal Code, which criminalizes unauthorized access to a computer system. This is a serious accusation whose consequences can reach personal liberty, so the accused needs to understand immediately which elements the prosecution must prove and where the defense can dismantle those elements. On this page we explain how this offense is constructed, what penalties each part of the article provides, and which questions become decisive in courtroom disputes.
The Statutory Concepts — Where Every Such Case Begins
Article 284 sits in the chapter of the Code that governs crimes committed in computer systems, and that chapter carries its own definitions. The analysis of a case begins with them:
- a computer system — any device or mechanism, or a group of them connected to one another, which automatically processes data by means of a program; this can be a personal computer, any device with a microprocessor, and even a mobile telephone;
- computer data — information in any form convenient for processing in the system, including a program that keeps the system running;
- unauthorized — unlawful, and also the situation where the holder of the right has not transferred that right to the person committing the act, directly or indirectly.
In practice this means the prosecution must establish that the person had no right to enter the system — neither by law nor by the permission of the right holder. If such permission existed, whether given directly or indirectly, the offense loses this element, and this is one of the most frequent and effective lines of defense.
Every Penalty, Part by Part
The law escalates liability across three levels, and each level must be presented separately. Under the first part — the basic composition — the penalty is a fine, or corrective labor for a term of up to two years, or imprisonment for a term of up to two years. Under the second part — where the same act is committed by a group with prior conspiracy, through use of an official position, more than once, or causing significant damage — the penalty is a fine, or corrective labor for a term of up to two years, or imprisonment for a term of two to five years. Under the third part — where an act provided for by the first and, or, the second part is committed against a subject of a critical information system — the only penalty is imprisonment for a term of three to six years. These measures differ from one another, and merging them or presenting them in a reduced form is impermissible — that is exactly why the part indicated in the charging documents must always be verified with particular care.
Significant Damage and Repetition — How They Are Counted
Under this chapter, significant damage means damage exceeding 2000 GEL, except for a case provided for by another norm of the Code. The existence and the amount of the damage must be established and documented by the prosecution — engaging specialized knowledge for the assessment often becomes necessary. As for repetition: a crime provided for by this chapter is considered committed more than once if it was preceded by the commission of any crime under the same chapter. This definition determines precisely which prior conduct counts and which does not, and without it any legal assessment of the accused's history is unfounded.
Subjects of Critical Information Systems
Applying the third part requires that the victim organization actually be a subject of a critical information system in the sense established by the Georgian Law on Information Security. That status must be confirmed separately in the case file and cannot simply be presumed — otherwise the application of the third part becomes unsubstantiated, which provides grounds for a substantial reduction of the potential penalty.
The Legal Entity and Its Risks
The note to the article provides that for this conduct a legal entity is punished by a fine, by deprivation of the right to carry out activity, or by liquidation and a fine. For companies this means that a case connected with an employee's conduct can threaten the operations of the entire organization, and assessing that risk in advance, on the basis of qualified legal analysis, is possible and necessary.
Defense Strategy — Where It Starts
The first step is a precise analysis of the charging documents: under which part the conduct is qualified and which features the prosecution claims to prove. Then, separately, one examines lack of authorization, the ownership of the system and the existence of access rights, the methodology of damage calculation, the features of group commission or official position, and, where relevant, the status of a critical information system subject. A separate direction is the lawfulness of how evidence was obtained — what was obtained unlawfully cannot serve as a basis of proof. The procedural deadlines and the course of the case are governed by criminal procedure legislation, and therefore a consultation with a lawyer should not be postponed — contact us, and we will review your situation in confidence.
