strafsachen.at
Latest

Unauthorised access to a computer system under § 118a StGB

Unauthorised access to a computer system under § 118a StGB: security measures, authority, intent, penalties and authorisation by the injured party.

Your personal attorney

Mag. Christopher Angerer, Rechtsanwalt

Your lawyer for criminal defence

Criminal proceedings are a matter of trust. One lawyer who walks with you from the first consultation through to the trial, everything from one hand.

30 September 2026, Mag. Christopher Angerer, Rechtsanwalt

The offence of unlawful access to a computer system under § 118a StGB focuses on obtaining unauthorised access by overcoming a specific security measure. The legal assessment therefore has to examine the system, the authority to use it, the protective measure and the person’s purpose at the time of access.

This article explains when § 118a StGB may apply, which penalties the provision sets out and why authorisation by the injured party matters. It distinguishes unlawful access from later data manipulation, disruption of a system and computer fraud.

Quick assessment

Which review matters now.

Choose the situation closest to your case. You will receive the key review points and the next step.

Would you like to get in touch directly? Go to the enquiry form.

01 Question 1

Which situation applies?

The assessment depends on authority, the security measure and the role of the affected person.

All paths at a glance

Overview of all answers.

01

In an allegation under § 118a, the key question is whether a specific security measure was overcome.

Before making a statement, review the alleged security measure, the authority and the technical records. The alleged purpose and the injured party’s authorisation also require separate assessment.

02

An affected person should preserve access, system protection and authorisation in a traceable form.

Preserve logs, times, configurations and permission lists in a traceable form. Also clarify who can give the injured party’s authorisation under § 118a Abs. 3 StGB.

03

Former or shared use may change the question whether the person lacked authority over the system.

Map the actual authority at the time of access. An administrative assignment or test environment may be assessed differently from access outside the authorised purpose.

What § 118a StGB requires

The provision first requires a computer system that the person accessing it may not control, or may not control alone. It also covers part of such a system. The relevant question is therefore who had authority over the system and what use was permitted at the relevant time.

Access must be obtained by overcoming a specific security measure. The assessment may concern the technical or organisational barrier in place, the way it protected the system and how access was obtained despite that barrier. Merely using another person’s username or password does not answer this question by itself.

The provision also requires a particular purpose. The person must intend to obtain access for themselves or for another unauthorised person. That purpose must relate to the access and to one of the purposes described by the statute. Mere technical curiosity does not automatically satisfy the wording of the provision.

Which purposes can make the access criminal

The first statutory variant concerns personal data. The person must intend to obtain knowledge, for themselves or for another unauthorised person, of data whose disclosure infringes the affected person’s legally protected confidentiality interests. The content, attribution and sensitivity of the data are therefore relevant.

The second variant concerns causing a disadvantage. Access may fall within the provision where the person intends to cause another person a disadvantage by using stored data that was not intended for them or by using the computer system. The data, the authorised use and the intended disadvantage must be kept distinct.

Intent is assessed from the access and the subsequent use. Technical traces may be relevant. A login, an IP address or a single log entry cannot by itself replace a complete assessment of the authorisation and the person’s mental state.

How § 118a differs from other computer offences

§ 118a StGB treats unlawful access as a separate offence. The focus is access to another person’s computer system by overcoming a specific security measure. The article Cybercrime in Austria provides a broader overview of other computer offences.

Data damage under § 126a StGB concerns altering, deleting or rendering another person’s data unusable. § 126b StGB concerns serious disruption of the functioning of a computer system. Those offences may occur together with access, but they address a different centre of gravity.

Computer fraud under § 148a StGB requires manipulation of a data-processing operation, a financial loss and an intention to obtain an unlawful benefit. Data falsification under § 225a StGB focuses on creating false data with the intention of using it in legal dealings. Further information is available in the article Data falsification under § 225a StGB.

Which penalties § 118a StGB provides

The basic form under § 118a Abs. 1 StGB carries a maximum sentence of two years’ imprisonment. The actual legal consequence depends on the circumstances of the case, culpability and the applicable statutory rules. The statutory maximum therefore does not predict the outcome in an individual case.

If the offence concerns a computer system that is an essential component of critical infrastructure under § 74 Abs. 1 Z 11 StGB, § 118a Abs. 2 provides for up to three years’ imprisonment. The special status of the system must be established in the case.

§ 118a Abs. 4 provides an additional increase where the offence is committed as part of a criminal organisation. The assessment then also depends on which basic form and which type of infrastructure are involved. A mere cooperation between several people does not by itself establish this qualification.

Why authorisation by the injured party matters

Under § 118a Abs. 3 StGB, the offence is prosecuted only with the authorisation of the injured party. The identity of the injured party and the question who controlled the protected system or the affected data therefore need to be clarified at an early stage. In a company, internal responsibilities and system ownership may be relevant.

Authorisation does not replace the assessment of the offence. Unlawful access, the specific security measure, the lack of authority and the statutory purpose still have to be established. Conversely, technical access alone is insufficient if the required authorisation has not been given.

A person affected by possible access should preserve the discovery timeline, the systems involved and the available logs. A person accused should have the file and the technical evaluations reviewed before making a statement.

Which evidence matters in an access allegation

The evidentiary question has several parts. It may be necessary to establish the system architecture, the security measures, the person’s permissions, the access event and the use that followed. Only the relationship between these elements shows whether the statutory requirements may be met.

Technical reconstruction may involve authentication records, timestamps, access logs, configuration states, permission lists and indications of the devices used. Their value depends on how the data was generated, stored and evaluated. A timestamp or IP address does not, without further assessment, identify a particular person.

The authorisation history is also important. A former access right, an administrative assignment, a test environment or shared use can change the central question. The relevant point remains the specific authority at the time of access and the purpose of the conduct.

An access allegation requires a precise reconstruction. Preserve technical material in an unchanged form and connect permissions, systems and times. A premature technical explanation may make the later defence more difficult. An affected organisation should also clarify who can give the required authorisation.

Frequently asked questions

What matters in unlawful access cases

Is every access with someone else’s password criminal under § 118a StGB? +

No. § 118a StGB requires, among other things, overcoming a specific security measure, lack of authority and the purpose described by the statute. Whether those elements are present depends on the system, the permissions and the technical sequence.

What penalty applies to unlawful access? +

The basic form under § 118a Abs. 1 StGB carries up to two years’ imprisonment. Where an essential component of critical infrastructure is involved, § 118a Abs. 2 provides for up to three years. Further requirements may increase the penalty under § 118a Abs. 4.

What does authorisation by the injured party mean? +

§ 118a Abs. 3 StGB provides that the offence is prosecuted only with authorisation by the injured party. This declaration is separate from the technical and legal assessment of the offence. It must also be established who is entitled to give it.

What should an accused person do first? +

Before making a statement, the file and the technical allegation should be reviewed. The important points include the alleged security measure, the relevant authority, the logs and the alleged purpose. Documents showing authorised use should be preserved.

What should a company preserve after possible unauthorised access? +

The company should record the systems and times involved, preserve relevant logs and document the permission structure. The handling should remain traceable so that the creation and evaluation of the data can be explained. The company should then clarify who can give the injured party’s authorisation.

Subscribe to legal updates. Receive new articles and legal information from the firm through BRANDaktuelle Rechtsnews.

Topics
§ 118a StGBunauthorised accesscomputer systemsecurity measurecybercrimecriminal proceedings

Interview, house search, indictment?

In criminal matters every hour counts. Call us directly or send an email, callback within one business day, earlier in urgent cases.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg