strafsachen.at
Property crimes

Fraudulent data processing misuse under section 148a StGB

Section 148a StGB: fraudulent data processing misuse in online banking, phishing, booking systems and payment data.

Your personal attorney

Mag. Christopher Angerer, Rechtsanwalt

Your lawyer for criminal defence

Criminal proceedings are a matter of trust. One lawyer who walks with you from the first consultation through to the trial, everything from one hand.

24 August 2026 · Mag. Christopher Angerer, Rechtsanwalt

Section 148a StGB concerns situations in which data processing is misused to cause a financial shift. In practice, this involves online banking, booking systems, payment processes, access credentials or manipulated electronic workflows.

This article explains from a lawyer’s perspective when fraudulent data processing misuse must be distinguished from classic fraud, falsification of data and general cybercrime allegations.

Stay informed. New notes from the Brandauer network and current articles are available at brandauer-news.at.

Quick assessment

Which question should be clarified first?

The first reaction depends on whether there is already a summons, a seizure or only an initial suspicion.

Already know that you want to send an inquiry? Go directly to the inquiry form.

01 Question 1

Which situation fits best?

This assessment does not replace file access. It only helps to sort the first step.

All paths at a glance

Overview of all answers.

01

Accused person: clarify allegation and file first.

Do not give a spontaneous explanation before the allegation, file position and evidence are known. From a lawyer’s perspective, defence starts with file access and a reliable chronology.

Prepare file access →
02

Business role: do not accept responsibility too early.

In a business, technical access, management responsibility and actual decision making may be separate. Roles, approvals and documentation routes must be reviewed separately.

Review roles →
03

Evidence: preserve original state and records.

If data, devices or documents have already been secured, records, copies, timing and scope matter. Only then can a remedy or statement be assessed.

Organise evidence →
04

Urgent situation: take the appointment seriously and stay calm.

A summons or official deadline is not a reason for improvised explanations. First check status, addressee and legal consequence of the letter.

Check deadline →

When section 148a StGB becomes relevant in practice

Fraudulent data processing misuse is not triggered by the mere use of a computer or app. The key is that data processing is influenced in a legally relevant way and a financial loss results.

Typical questions concern access data, payment approvals, bookings, account movements and automated systems. It must be checked precisely which conduct is attributed to the accused person.

This article is deliberately narrower than the general cybercrime overview.

Distinction from fraud, data falsification and payment cards

Classic fraud focuses on deception of a person. Under section 148a StGB, data processing itself becomes the central reference point.

Falsification of data under section 225a StGB concerns data with evidentiary function. Section 148a StGB focuses on the financial process. Payment cards or payment data may add separate offences.

The technical chronology is therefore important: input, approval, system reaction, payment and loss.

Preserve digital traces and account movements correctly

Relevant evidence includes log files, IP data, device access, bank approvals, TAN history, e-mail headers, booking data and account records. Screenshots alone are usually not enough.

Accused persons should not wipe devices or reinstall apps before the evidence position is secured. Affected persons should coordinate bank, payment provider and law enforcement steps.

If data or devices have been seized, the article on seizure and confiscation is useful.

Defence in online banking, phishing and system access cases

Defence must clarify whether there was a technical act, third party access or misattribution. In phishing chains, several persons, devices and countries may be involved.

It is important not to replace technical evidence with moral explanation. Who had access, when approval occurred and how the system reacted must be provable.

From a lawyer’s perspective, file access, technical analysis and a sober chronology are the basis for any statement.

Overview

Review points under section 148a StGB

Quick assessment

Fraudulent data processing misuse: technical and financial trail
Point Meaning First question
System data processing involved Which system reacted?
Access user or device Who had access?
Approval payment or booking How was it triggered?
Loss financial disadvantage What actually left?

Important: Do not reset devices, delete data or change accounts without coordination. Preserve the evidence position first.

Frequently asked questions

Fraudulent data processing misuse: key questions.

Is section 148a StGB the same as cybercrime? +

No. Cybercrime is broader. Section 148a StGB concerns financially harmful misuse of data processing.

Is phishing always section 148a StGB? +

Not automatically. It depends on the conduct, data process and financial loss that can be proven.

Which evidence matters first? +

Log files, bank approvals, device access, e-mail data, payment records and the technical chronology.

Topics
section 148a StGBcomputer fraudphishingonline bankingpayment datacybercrime

Interview, house search, indictment?

In criminal matters every hour counts. Call us directly or send an email, callback within one business day, earlier in urgent cases.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg