Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.ge+995 551 911 961

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Criminal Law
  3. White-Collar, Cyber & Economic Crimes
  4. Cybercrime & Digital Forensics
  5. Ransomware Defense

Loading...

Cybercrime & Digital Forensics

Ransomware Defense

Which norms underlie a ransomware case?

Two: extortion — Article 181, and unauthorized access to a computer system — Article 284. Each has its own elements and its own penalties.

What penalty applies to extortion?

For the basic composition — a fine or imprisonment from two to four years; committed by a group, more than once, or with the purpose of obtaining property in a large amount — from four to seven years; by an organized group or by a person convicted twice or more for unlawful appropriation or extortion — from six to nine years.

What penalty applies to unauthorized access to a computer system?

Basic composition — a fine, corrective labor up to two years, or imprisonment up to two years; with aggravating features — from two to five years; against a critical information system subject — from three to six years.

What is significant damage?

Under this chapter, damage exceeding 2000 GEL, except for a case provided for by another norm of the Code. The prosecution establishes and documents the amount.

Can a legal entity be held liable?

Under Article 284 — yes: it is punished by a fine, by deprivation of the right to carry out activity, or by liquidation and a fine.

4 min·...

Ransomware and Cyber Extortion — Two Norms in One Case

Ransomware — the encryption of data coupled with a demand for payment — is legally not one crime at all. It is a combination of two independent criminal norms whose joint application fits precisely such scenarios in the Criminal Code of Georgia: the demand of extortion is prohibited by Article 181, while unauthorized access to a computer system is prohibited by Article 284. That is why a case of this kind must be read through both norms separately: each has its own elements and its own penalties, and it is in exactly those details that the opportunities of the defense are hidden.

Article 181 — Extortion: Elements and Penalties

Extortion is the demand of the transfer of another's property or property right, or of property benefit, coupled with a threat of the use of violence against the victim or their close relative, of the destruction or damage of their property, of the dissemination of defamatory information about them, or of other information whose dissemination may substantially harm their rights. Under the first part this is punished by a fine or imprisonment for a term of two to four years. The second part aggravates liability when the same act is committed by a group, more than once, or with the purpose of obtaining property in a large amount — the penalty being imprisonment for a term of four to seven years. Under the third part the same act, committed by an organized group or by a person who was convicted twice or more for unlawful appropriation of another's property or for extortion, is punished by imprisonment for a term of six to nine years. In a digital environment the form of the threat is often precisely intimidation through the publication or destruction of encrypted data, which fits the classical elements of extortion.

Article 284 — Unauthorized Access to a Computer System

The technical side of ransomware — entering a system without a right — is qualified under Article 284. The first part provides a fine, or corrective labor for a term of up to two years, or imprisonment for a term of up to two years. The second part punishes the same act committed by a group with prior conspiracy, through use of an official position, more than once, or causing significant damage — a fine or corrective labor for a term of up to two years, or imprisonment for a term of two to five years. The third part addresses this conduct committed against a subject of a critical information system and provides imprisonment for a term of three to six years. Under this chapter significant damage means damage exceeding 2000 GEL, except for a case provided for by another norm of the Code; and the concept of a computer system is broad, covering a personal computer, any device with a microprocessor, and even a mobile telephone.

How the Two Norms Combine in One Case

The typical ransomware scenario unfolds in two stages: first comes unauthorized entry into the system, followed by the encryption of data or the restriction of access to it; then the victim faces a demand — payment or other property benefit for restoring the data or avoiding its dissemination. Legally these two acts are the object of different norms, and the prosecution must establish each separately: who entered the system, how, and without which right; and how, with which threat, and from whom the property was demanded. The separate establishment of every element is exactly where the defense gains a realistic possibility of changing the outcome of the case: the existence of access rights, the existence and content of the threat, the connection between the demand and the threat, the amount of damage, the feature of group commission.

Critical Information System Subjects and the Legal Entity

Where the access is committed against an organization that is a subject of a critical information system as defined by the Georgian Law on Information Security, the third part of Article 284 applies and the penalty rises sharply — that status must be confirmed separately by the case materials. In addition, under the note to Article 284, for conduct provided for by that article a legal entity is punished by a fine, by deprivation of the right to carry out activity, or by liquidation and a fine — an additional and entirely real source of risk for companies.

Defense Directions in Cyber Extortion Cases

The first direction is the qualification: the elements of both articles are checked separately, and gaps in the logic of the prosecution — the unproven nature of the threat, the demand, or the access — are grounds for an essential change of the case. The second direction is evidence: technical logs, communication trails and the analysis of cryptocurrency transfers require specialized knowledge, and the lawfulness of their obtaining and evaluation is a separate subject of review. The third direction is sentencing: the features of group commission, an organized group, repetition, or prior convictions must each be established separately, and their refutation substantially reduces the penalty. The rules for applying the forms of punishment and the procedural deadlines are defined by other norms of the Code and of procedural legislation. Contact us — we will review your situation in confidence.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • საქართველოს სისხლის სამართლის კოდექსი

Find a Specialist

Professionals working in this field

Criminal Law AttorneyCriminal Law Lawyer