Phishing and cyber fraud — Articles 180 and 284
Phishing cases fall within the scope of application of two norms of the Criminal Code of Georgia. The first is fraud: the acquisition of another person's thing or the receipt of a property right by deception, for the purpose of unlawful appropriation. The second is unauthorized access to a computer system. Phishing combines both elements: data obtained by deception and their use in a system without the will of the right holder.
The note to the law precisely explains the key concepts: a computer system is any device or group of interconnected devices that processes data automatically by means of a program; unauthorized means unlawful, and also the case where the right holder has not transferred the right, directly or indirectly, to the person committing the act. Significant damage under this chapter is damage in an amount of more than two thousand lari.
The punishment for fraud — Article 180
Under the first part, fraud is punishable by a fine, or by community service for one hundred and seventy to two hundred hours, or by corrective labour for up to two years, or by house arrest for one to two years, or by imprisonment for two to four years. The second part — by a group with prior agreement or with significant damage — by a fine or imprisonment for four to seven years. The third part — through the use of an official position, in a large amount or repeatedly — by a fine or imprisonment for six to nine years. The fourth part — by an organized group or by a person convicted two or more times — by imprisonment for seven to ten years.
The punishment for unauthorized access — Article 284
Under the first part, unauthorized access to a computer system is punishable by a fine or by corrective labour for up to two years or by imprisonment for the same term. The second part — by a group with prior agreement, through the use of an official position, repeatedly or with significant damage — by a fine or corrective labour for up to two years or imprisonment for two to five years. The third part — against a subject of a critical information system — by imprisonment for three to six years.
Directions of the defence
In such cases a lawyer verifies the fact and content of the deception, the element of the lack of authorization — whether the right was transferred directly or indirectly — and the amount of the damage in relation to the threshold of two thousand lari. Most of the evidence is electronic, and the legality of its gathering is verified separately. The rules of procedure and the time limits are established by other acts of procedural legislation. Our team offers consultations on cases of this category for both parties.
In phishing cases the element of deception usually takes the form of false messages, sites or other forms of communication by which a person induces the victim to share his or her own data. The task of the defence is to reconstruct precisely who, when and in what form created that communication and whether the accused was connected to it. The digital trace — IP addresses, devices, accounts — needs context, and its interpretation is always verifiable.
The amount of the damage in these cases directly determines the classification: the threshold of two thousand lari is the boundary of the element of significant damage. Our team is ready to assist you on cases of this category from both sides — contact us.
Cases of this category develop quickly: digital evidence changes, accounts are closed and communication histories disappear. Timely fixation — both from the side of the accused and from that of the victim — is therefore decisive. The early involvement of a lawyer creates the foundation on which the position is later built. The boundary of the classification between fraud and unauthorized access always requires separate analysis: which act fits which norm better, and whether the elements of both exist simultaneously. Contact us — we will assess your situation.
Frequently Asked Questions
Below we answer the questions most frequently asked about phishing and cyber fraud.
What punishment is provided for fraud?
For the basic composition — from a fine up to four years of imprisonment; for qualified compositions — up to seven, nine and ten years.
What is unauthorized access?
Access to a computer system without the will of the right holder — under the law's explanation, unauthorized means both unlawful and the case where the right was not transferred, directly or indirectly.
What is significant damage under this chapter?
Under the note to the law — damage in an amount of more than two thousand lari.
Where is the boundary between Articles 180 and 284?
Fraud is an act built on false information, while unauthorized access is the breach of the legal boundary of access to a system; both may be examined on the same set of facts.
How We Help on Legal.ge
A phishing case stands on the boundary between two qualifications, and that boundary is drawn by evidence. The advocates of Legal.ge assist in building the position and representing you in court. Submit a request on the site and receive qualified assistance.
