Crime of intervention to the information system

Crime of intervention to the information system

Turkish Legal Insights & Judicial Precedents

Crime of intervention to the information system

Crime of intervention to the information system

Legal Notice

This article is an English translation of Turkish jurisprudence provided for international clients and informational reference. Under Turkish procedural and substantive law, official judicial proceedings, statutory interpretations, and court verdicts are governed exclusively by the authentic Turkish legal text.

Cyber ​​crimes are regulated under the title "Crimes in the Field of Information Technology" in the "Crimes Against Society" section of the Turkish Penal Code. The law regulates cyber crimes between Articles 243 and 245. The most common type of crime among cyber crimes is the crime of breaking into a computer system.

The crime of hacking into an information system, regulated in Article 243 of the Turkish Penal Code, is committed by unlawfully entering the whole or part of an information system. It was previously stipulated that the crime could be committed by combining the actions of entering and remaining in the system. With the amendment made in 2016, the conjunction and was changed to or. For this reason, there are two different ways to commit the crime: entering or staying.

The term "trespassing" is used in the law. However, considering that it will not be possible to physically enter information systems, it would be more appropriate to use the concept of access. Inserting a screwdriver into a computer case does not constitute access.

The method of communication is not important in terms of committing the crime. The system can be accessed via wired or wireless connection, and access distance does not matter. Just as entering a person's social media account will cause a crime, examining files from a forgotten computer is also sufficient to constitute a crime.

WHAT IS AN INFORMATION SYSTEM?

The legal subject of the crime of hacking into the information system is the information system. The justification of Article 243 of the Turkish Penal Code defines the information system as "The purpose of the information system is magnetic systems that allow collecting and placing data and then subjecting them to automatic transactions." However, informatics is a broader concept that covers both the processing and transmission of data. In this respect, the concept in the justification of the law has been criticized.

Based on the definition in TDK, it is possible to define an information system as a system that automatically performs functions such as storing, organizing, evaluating, transmitting and reproducing data.

Perpetrator and victim of the crime of hacking into the information system

The law does not seek any characteristics regarding the perpetrator. Therefore, crime can be committed by anyone. It can be said that this crime, which was known as white-collar crime in ancient times, can be easily committed by anyone, considering today's technology.

Anyone who has rights on the information system can become a victim of crime. Legal entities cannot be victims of crime. For this reason, when customers' accounts are examined by entering a bank's information systems, every customer whose data is examined is considered a victim. The bank is the victim of the crime. It is possible for one person's data to be stored in another person's system. In such cases, where data is obtained by entering information systems, both people will be victimized.

HOW IS THE CRIME OF BREAKING INTO AN INFORMATION SYSTEM COMMITTED?

First of all, the formation of a crime depends on the existence of intent. The crime of hacking into a computer system is a type of crime that can be committed intentionally.

Article 243 of the Turkish Penal Code regulates that the crime of hacking into an information system is committed by illegally entering or remaining in the whole or a part of an information system, and that the penalty to be given to the perpetrator will be increased if the action causes the data in the system to be destroyed or changed.

Crime is an optional and active crime. It can be processed by entering the system or staying there.

With the KVKK, which came into force in 2016, an additional paragraph was added to the article: monitoring system data.

Entering the IT system

We have stated above that what is meant by entering the information system is access. In order to talk about the existence of crime, a limited information system must first exist. A restricted computing system requires passwords, passwords, etc. It refers to a system in which only authorized persons can access the system with precautions. Systems that are accessible to everyone are not the subject of crime.

As a matter of fact, in a decision of the 8th Criminal Chamber of the Supreme Court of Appeals dated 2015, "Entering the information system" is accessing some or all of the data in an information system, physically or remotely, through another device. While loose security measures can be used to achieve access, gaps in existing security measures can also be exploited. By using viruses (in the form of attachments such as funny pictures, greeting cards or audio and video files), trojan horses, macro viruses, worms over the network, or by forcing open doors of the system. Unauthorized entry into computer data and systems is also defined as "computer intrusion", "code cracking" or "computer hacking". The crime can be committed by opening someone else's computer and viewing the data on it, or by logging into the information system via a network. In the case of entry, there is no difference between whether the communication is wired or wireless and whether the distance is close or distant. "It would also constitute a crime for another internet user to access the operating system of the victim's personal computer (Windows, Linux, etc.) without the consent of the victim." He stated as follows.

In addition, if the person accessing the system does not obtain the access authorization properly, he will still commit a crime. It may be regulated that some systems can only be used within certain rules. For example, some passwords may be specific to certain people. In such cases, it will be a crime to enter the system using a password assigned to someone else.

Staying in the IT system

Another of the optional acts of crime is to continue to remain in the system. Entering the information system illegally and continuing to stay in it cannot be considered as two different crimes. The perpetrator is punished for a single crime. However, as in the case of people who have permission to access the information system for a certain period of time not leaving the system at the end of the period, the system may be accessed legally and then continue to stay. If such situations exist, a crime occurs. There is no time limitation for the crime of staying in the information system.

Unlawfully monitoring data transfers within an information system or between information systems using technical means without entering the system

This situation of committing a crime was added to the law with the KVKK law. The purpose of adding the clause is to protect personal data. With the provision, monitoring the data in the system without entering the IT system has been regulated as a crime. The occurrence of a crime does not require entering the system. In order for this situation to occur, it is necessary and sufficient to monitor the data in the system. If the perpetrator who monitors the data also obtains personal data, he will be punished for different crimes depending on his actions. For example, the person who obtains people's correspondence is also punished for violating the confidentiality of the communication.

QUALIFIED FORM OF THE CRIME OF BREAKING INTO THE INFORMATION SYSTEM

TCK 243/3. According to the article, if the system data is destroyed or changed as a result of the act of entering the information system, the penalty to be given to the perpetrator is increased. There is a difference of opinion in the doctrine as to whether this situation is a qualified situation or an individual type of crime.

COMMITTING THE CRIME OF BREAKING INTO THE INFORMATION SYSTEM ON SYSTEMS THAT CAN BE BENEFITED FOR A COST

If the crime is committed against systems that can be used for a fee, it is considered a reason for a reduction in the sentence. No explanation has been made about the systems referred to in the article text and justification. In the doctrine, the prevailing view is that regulation refers to websites that are used for a fee.

PUNISHMENT FOR THE CRIME OF INTERVENTION TO THE INFORMATION SYSTEM

The crime of hacking into the information system is regulated in Article 243 of the Turkish Penal Code.

According to the article;

1- Anyone who illegally enters or remains in the whole or part of an information system will be sentenced to imprisonment for up to one year or a judicial fine.

2- If the acts defined in the above paragraph are committed on systems that can be used for a fee, the penalty to be imposed is reduced by half.

3- If the data contained in the system is destroyed or changed due to this act, a prison sentence of six months to two years is imposed.

4- Any person who unlawfully monitors data transfers within an information system or between information systems using technical means without entering the system will be sentenced to imprisonment from one to three years.

ATTEMPT TO BREAK INTO THE INFORMATION SYSTEM

Attempt is when a person directly begins to commit a crime that he intends to commit with appropriate actions, but cannot complete it due to reasons beyond his control.

We have stated that the crime of hacking into the IT system can be committed by entering or remaining in the system. The act of hacking into the information system is susceptible to attempt. In terms of entering the system, if the system cannot be accessed despite the attack, the crime will remain at the attempted stage.

But the act of staying in the system is not conducive to attempt due to its nature.

COMPLAINT FOR THE CRIME OF INTERVENTION TO THE INFORMATION SYSTEM

The pursuit of the crime of hacking into the IT system is not dependent on the complaint. Investigation or prosecution is carried out ex officio. The competent court is the Criminal Court of First Instance.

Legal Representation & Consultation

This article is provided for general legal guidance. To discuss your specific lawsuit or legal matter with a qualified attorney, please contact our office.