Cybercriminal law
In an increasingly digitalized world, data-related crimes such as phishing attacks, hacking or data misuse are among the biggest challenges for companies and private individuals. These incidents are not only technically complex, but also require in-depth legal and strategic expertise. The support of specialized lawyers in cyber criminal law is therefore crucial in order to successfully represent your interests in such proceedings.
How can lawyers provide support in cybercriminal law?
Lawyers specializing in cyber criminal law offer valuable support when it comes to the legal processing of data-related crimes. They represent companies and private individuals in cases such as phishing attacks, data theft or online fraud and help to overcome the complex legal challenges. They not only advise on the legal consequences of an incident, but also develop strategies to limit the damage and defend against possible criminal charges or represent the injured party in the context of accessory prosecution. An experienced cyber criminal lawyer can help identify the perpetrator and use their technological knowledge to help you take the necessary legal steps to protect your interests. Our experts will also support you in working with law enforcement authorities and communicating with insurance companies, ensuring your case is handled efficiently and smoothly. In this way, they ensure that you have the best possible legal and practical protection.
What are the advantages of consulting a specialized lawyer?
Consulting a lawyer specializing in cybercriminal law offers significant advantages because they are not only familiar with the legal aspects, but also have a deep technical understanding of the underlying IT processes and cyber threats. This combination of legal expertise and technical know-how allows us to accurately analyze cyber incidents and correctly assess the impact on your business. We help to identify security gaps that have led to an incident and recommend appropriate measures to minimize further risks. We are also able to secure and evaluate technical evidence in a court of law, which is crucial for an effective defense or damage limitation.
Our services in the area of cybercriminal law
- Victim representation
We help those affected to legally process cyber attacks, assert claims for damages and hold those responsible accountable. - Defense in criminal proceedings
For defendants, we develop a sound defense strategy to protect your rights in court and against investigating authorities. - Technical analysis
We examine digital evidence, analyze security gaps and evaluate technical details in order to effectively incorporate them into the legal argumentation. - Crisis management
Quick and targeted action is crucial in the event of data-related allegations. We support you with our expertise and a clear strategy. - Cooperation with experts
If necessary, we work closely with IT forensic experts and other specialists to clarify the facts precisely.
Contact persons
Dirk Koch
Attorney at Law | Partner
CEHv11 – Certified Ethical Hacker | Data Protection Risk Manager | CIPP/E
Cybercrime Law
Of practical relevance are in particular data espionage under Section 202a StGB (German Criminal Code), interception of data under Section 202b StGB and the preparation of such offences under Section 202c StGB, for example by obtaining or making available passwords, access codes or malware. Data tampering under Section 303a StGB and computer sabotage under Section 303b StGB are also relevant, particularly in ransomware attacks that encrypt systems or bring business operations to a standstill. Depending on the case, computer fraud under Section 263a StGB or offences under GeschGehG (German Trade Secrets Act) may also be relevant. Companies are often victims of such offences; however, inadequate protective measures may additionally give rise to civil-law, data protection or regulatory consequences.
As a victim of an attack, the company generally does not commit a criminal offence; the persons responsible are the attackers. However, persons responsible within the company may be held liable under civil-liability or regulatory-offence law if inadequate security measures were taken; in particular, administrative fines under Article 83 GDPR, a breach of the duty of supervision under Section 130 OWiG and liability of corporate bodies may be considered. The criminal-law assessment and the data protection and liability assessment must therefore be considered separately.
In many cases, filing a criminal complaint is advisable to enable the offence to be prosecuted, secure evidence and, in some cases, satisfy requirements under the insurance contract. At the same time, it should be assessed in advance which information must be disclosed and whether disclosure can be reconciled with other interests, such as keeping internal vulnerabilities confidential or protecting trade secrets. Legal co-ordination before filing the complaint is therefore advisable.
Depending on the circumstances, the unauthorised copying or disclosure of particularly well-protected data may constitute data espionage under Section 202a StGB or an infringement of trade secrets under Section 23 GeschGehG. In particular, the data must have been specially protected against unauthorised access or protected by appropriate confidentiality measures, which is why establishing effective access and protection concepts also has significance under criminal law. Employment-law consequences, including dismissal without notice, and civil-law claims for damages by the company may also arise. The precise legal classification depends on the individual case and the type of data.
The payment itself is not generally a criminal offence under German law, but it may become problematic in an individual case, particularly if it is made to persons or organisations subject to sanctions lists, supporting terrorist organisations or attributable to a criminal organisation; in addition to criminal-law risks, this may entail breaches of sanctions and foreign trade law requirements. In many cases, criminal liability for supporting a criminal or terrorist organisation will already fail because persons responsible within the company generally do not act with the requisite intent but respond under the pressure of an extortion situation. From a company-law perspective, it must also be borne in mind that the decision to make a payment must be measured against management’s duties of care and that, if the assessment is inadequate, internal liability risks, including allegations of breach of trust, may arise. A payment may also in practice encourage further attacks, which should be taken into account in the decision. Before any payment, a legal assessment should therefore always be carried out and documented accordingly in order to limit management’s liability risks.

