Computer Access and Computer Crimes
- The Cybercrime Convention
- Commonwealth Criminal Offences
- Fault Elements
- Jurisdiction
- Unauthorised Access
- Impairment
- Telecommunications Interception
- Other Computer Offences
- Other crimes involving computers
- 474.14 Using a telecommunications network with intention to commit a serious offence
- 474.15 Using a carriage service to make a threat
- 474.17 Using a carriage service to menace, harass or cause offence
- 474.22, 474.23 Child abuse material offences
- 474.26, 474.27 Using a carriage service to procure or groom a child
- Cyberstalking: Technology-Facilitated Abuse
- Child Sexual Exploitation Online
- Private Law: Electronic Contracts
Video Overview of Crimes Against Computer Systems by Nicolas Suzor
The Cybercrime Act 2001 introduced a series of computer-related offences into the Commonwealth Criminal Code. These were later expanded after Australia joined the Cybercrime Convention. There are also numerous provisions in State law that prohibit unauthorised access and misuse of computers.
The Cybercrime Convention
Video Overview of the Convention on Cybercrime by Lucy Jorgensen
The Council of Europe’s Convention on Cybercrime was the first international treaty on crimes committed via the Internet and other computer networks. It was ratified by Australia on the 1st March 2013 and has been ratified by 47 countries worldwide.
The Convention’s main objective is to promote a common criminal policy, which aims to protect society against cybercrime, by adopting legislation and promoting international co-operation.
The Convention primarily deals with:
-
Copyright Infringement
-
Computer-related fraud and forgery
-
Child pornography
-
Violations of network security
In order to achieve the goal of establishing a common criminal policy, the Convention requires signatories to:
-
Define criminal offenses and sanctions under their domestic laws according to the four categories of computer crimes listed above.
-
Establish domestic procedures for detecting, investigating and prosecuting computer crimes and collecting electronic evidence of any criminal offence.
-
Establish a rapid and effective system for international cooperation. This includes allowing law enforcement authorities in one country to collect computer-based evidence for those in another country.
Australia’s ratification of the Convention complements existing laws, increasing the capacity for international co-operation to deal with increasingly sophisticated forms of computer-related criminal activity. Being a party to the Convention is designed to help Australia combat criminal offences related to fraud, child pornography, copyright infringement and network security violations. Under the Convention, Australia participates in a 24/7 global network of high tech crime points of contact, allowing for speedy assistance between signatory countries. It aims to enable domestic agencies to access and share information to facilitate international investigations, and seeks to ensure that vital evidence is not lost before a mutual assistance request can be complete.
Commonwealth Criminal Offences
Definitions
- “unauthorised”: “not entitled to cause that access, modification or impairment.” (s 476.2)
- But access, modification, or impairment is “not unauthorised merely because he or she has an ulterior purpose for causing it.”
Fault Elements
Default fault elements are included in Criminal Code 1995 (Cth) s 5.6. Except where explicitly stated, all these offences require:
- Intent to access or modify; and
- Recklessness as to whether data was actually modified or access impaired.
Jurisdiction
These offences now apply to all conduct in Australia, against Australian computer systems, or by Australian citizens (s 15.1) There is some overlap with State laws. In many cases, conduct will be prohibited under both State and Federal law.
Unauthorised Access
Friedrich Kuepper Explains the Unauthorised Access Offences
Section 477.1 creates the offence of “Unauthorised access, modification or impairment with intent to commit a serious offence”
- Maximum penalty: 10 years imprisonment
- Requires intent to gain access (default fault element - s 5.6)
- Requires knowledge that access is unauthorised
- Requires intent to commit a serious offence (5+ years imprisonment)
478.1 Unauthorised Access to, or Modification of, Restricted Data
- Maximum penalty: 2 years imprisonment
- Requires knowledge that access is unauthorised
- Requires intent to gain access or modify
- Restricted data is any data within a computer that is protected by an access control system.
477.2 Unauthorised Modification of Data to Cause Impairment
- Maximum penalty: 10 years imprisonment
- Requires knowledge that the modification is unauthorised
- Requires intent to modify (default fault element - s 5.6)
- Requires recklessness as to whether the modification impairs or will impair access to data, reliability, security, or operation.
Impairment
477.3 Unauthorised Impairment of Electronic Communication
- Maximum penalty: 10 years imprisonment
- Requires knowledge that impairment was unauthorised
- Requires intent to cause impairment
Telecommunications Interception
Telecommunications (Interception and Access) Act 1979 (Cth), s 7
- Maximum penalty: 2 years imprisonment (s 105)
- There is also a summary offence: 6 months imprisonment (s 105)
A person shall not:
- intercept;
- authorize, suffer or permit another person to intercept;
- or do any act or thing that will enable him or her or another person to intercept;
a communication passing over a telecommunications system.
Other Computer Offences
478.2 Unauthorised impairment of data held on a computer disk etc.
478.3 Possession or control of data with intent to commit a computer offence
478.4 Producing, supplying or obtaining data with intent to commit a computer offence
Other crimes involving computers
474.14 Using a telecommunications network with intention to commit a serious offence
474.15 Using a carriage service to make a threat
474.17 Using a carriage service to menace, harass or cause offence
474.22, 474.23 Child abuse material offences
These offences are dealt with at Child abuse material below.
474.26, 474.27 Using a carriage service to procure or groom a child
These offences are dealt with at Grooming below.
Cyberstalking: Technology-Facilitated Abuse
Video: Sarah Lawrence explains how Section 359B of Queensland’s Criminal Code regulates cyberstalking
Editor’s note: needs edit for duplication and flow.
In Queensland, legislation specifically refers to the use of technology, such as computer and smartphone devices, emails, text messaging, and social media platforms, with respect to stalking offences (s 359B, Criminal Code Act 1899 (Qld)). Incidents of cyberstalking are recognised under the definition of unlawful stalking in Section 359b of Queensland’s Criminal Code. Through the inclusion of subsection (c)(ii) unlawful stalking extends to contact through the use of telephone, mail, fax, email or through any technology.
Cyberstalking includes email stalking, phone stalking and computer stalking. Both email and phone are expressly stated in section 359B of the Criminal Code as methods of contact for unlawful stalking. Computer stalking, while not expressly stated in the provision, would likely be covered by the phrase ‘any technology’ and therefore would still be caught by the stalking offence.
A major controversy surrounding the stalking offence is the that the victim must have suffered a real apprehension or fear of violence, however, cyberstalking is unlikely to meet this threshold due to its virtual and non-physical nature. In addition, the prosecution of cyberstalking is difficult and victims must turn to other avenues to find relief. The current and most realistic remedies for victims would be to approach social media services to have material removed, or to report the behaviour to the eSafety commissioner.
Cyberstalking, also referred to as adult cyber abuse, is a form of technology-facilitated abuse that utilises technology, smart devices, and online platforms or services to intimidate or cause a person to reasonably fear for their safety or that of others. It can begin with excessive attention or privacy invasion, but often it involves more harmful intentions like intimidating, humiliating, manipulating, or damaging someone’s reputation. Cyberstalking is often accompanied by offline stalking and it can lead to physical danger.
One example is using GPS tracking devices to monitor a person’s movements or location, such as Bluetooth tiles or Apple AirTags, which are ordinarily used to keep track of luggage or keys. These devices are being used as they are small enough to not be noticed when they are placed on a person or in their bag or car by the person stalking them. In June 2024 the NSW Crime Commission released a report that one in four people who purchased a GPS tracking device since the beginning of 2023 were also known to have a history of domestic violence.
Other studies have found that the use of tracking apps in mobile devices, such as smartphones which have geolocation software or GPS, are being more commonly used for the purpose of cyberstalking, as this kind of software or app often comes preloaded on the person’s phone, such as the ‘FindMy’ app on Apple devices.
NSW Legislation
In New South Wales, cyberstalking offences are provided for under section 13 of the Crimes (Domestic and Personal Violence) Act 2007 (NSW) (CDVP), as they are often found to relate to “stalking or intimidation with the intent to cause fear of physical or mental harm”, and section 7 of the Online Safety Act 2021 (Cth) (OSA). An offence under section 13 of the CDVP may also need to satisfy the provisions or definitions under the OSA to succeed in court.
Child Sexual Exploitation Online
Two distinct forms of conduct are dealt with here: grooming, which is the process by which an offender establishes access to a child, and child abuse material, which is the record of abuse and the principal subject of enforcement activity. Both are addressed by Commonwealth carriage service offences and by State and Territory offences, and both intersect with the online safety scheme discussed in the Content Regulation and Online Classification chapter.
Grooming
‘Grooming’ describes conduct by which an adult builds a relationship with a child — and often with the child’s family and support network — in order to perpetrate sexual abuse. The behaviours are frequently unremarkable in isolation and can include building trust through gifts, isolating the child from other adults, and introducing sexualised material. The Royal Commission into Institutional Responses to Child Sexual Abuse identified the purposes of this conduct as making the child accessible, securing compliance, maintaining silence, and avoiding discovery.1
Online grooming is grooming conducted through communications services, whether to enable abuse in person or to obtain material from the child directly. Messaging services, social platforms and games are facilitative because they provide access to the child without an intermediary adult’s knowledge, and allow the offender to misrepresent who they are.
Prevalence
The Australian Centre to Counter Child Exploitation (ACCCE) recorded 58,503 reports of online child abuse in the 2023–24 financial year, a 45% increase on the previous financial year’s total of 40,232 reports.2
Contextual data on children’s use of online services is relevant to exposure. eSafety research found that 95% of 13 to 15 year olds and 80% of 8 to 12 year olds had used at least one social media service, notwithstanding platform terms restricting accounts to users aged 13 and over.3 Earlier research found that 55% of Australians aged 8 to 17 had communicated with someone they first met online, and 12% had met such a person in person.4
Commonwealth offences
Australia (Commonwealth). Grooming is an offence in its own right, whether or not sexual abuse follows. Under s 474.27 of the Criminal Code Act 1995 (Cth), it is an offence for a person aged 18 or over to use a carriage service to groom a person under 16, with a maximum penalty of 15 years’ imprisonment.5 A ‘carriage service’ is a service for carrying communications by guided or unguided electromagnetic energy, which includes social media messaging: in R v Lidden the offender was convicted under s 474.27(1) in respect of messages sent through Facebook Messenger.6
Related offences in the same subdivision include s 474.26 (using a carriage service to procure a child under 16) and s 474.27A (using a carriage service to transmit indecent communication to a child under 16).
New South Wales offences
New South Wales. Section 66EB(3) of the Crimes Act 1900 (NSW) makes it an offence for a person aged 18 or over to expose a child under 16 to indecent material, an intoxicating substance, or a financial or material benefit, with the intention of making it easier to procure the child for unlawful sexual activity. The maximum penalty is 12 years’ imprisonment where the child is under 14, and 10 years otherwise.7
Child abuse material
Definitions and offences
Australia (Commonwealth). The principal carriage service offences are s 474.22, which covers accessing, transmitting, publishing, distributing, advertising or soliciting child abuse material using a carriage service, and s 474.23, which covers possessing, controlling, producing, supplying or obtaining such material for use through a carriage service. Each carries a maximum penalty of 15 years’ imprisonment.8
New South Wales. Section 91FB of the Crimes Act 1900 (NSW) defines child abuse material as material that depicts or describes, in a way that reasonable persons would regard as being in all the circumstances offensive, a person who is, appears to be, or is implied to be, a child: as a victim of torture, cruelty or physical abuse; engaged in or apparently engaged in a sexual pose or sexual activity; in the presence of another person who is engaged or apparently engaged in a sexual pose or sexual activity; or whose private parts are depicted or described. ‘Child’ is defined in s 91FA as a person under the age of 18 years.9 Production, dissemination and possession offences are in s 91H.10
Enforcement
Enforcement is coordinated across agencies. The ACCCE brings together the Australian Federal Police and partner agencies, working alongside State arrangements including the Joint Child Protection Response Programme and specialist units such as Queensland’s Task Force Argos.
The ACCCE reported that in 2022–23 it received 40,232 reports, that the AFP made 186 arrests resulting in 925 child exploitation related charges, that 141 victims were identified, and that 120 children were removed from harm.11
A multi-agency prosecution (2025)
Following a search warrant executed at his home on 25 September 2024 and a further arrest on 11 October 2024, the Australian Federal Police charged a 26-year-old man over alleged offending against ten children aged six and under at out-of-school-hours care services in Sydney. He has been remanded in custody since 12 October 2024. Non-publication orders over the investigation were revoked in July 2025, when the AFP made public the charges laid and the maximum penalties, which were: nine counts of aggravated use of a child under 14 to produce child abuse material under s 91G(3) of the Crimes Act 1900 (NSW) (20 years); one count under s 91G(1)(a) (14 years); two counts of possessing child abuse material under s 91H(2) (10 years); and one count of failing to comply with an order to provide access to a device under s 3LA(6) of the Crimes Act 1914 (Cth) (10 years).12
The last charge is the notable one for present purposes. Section 3LA allows a magistrate to order a person to assist in accessing data on a seized device, and non-compliance is itself an offence. It is the mechanism by which the encryption of a device is addressed in the ordinary course of an investigation, and it sits alongside the industry assistance framework discussed in the Privacy and Surveillance chapter.
Interaction with the online safety scheme
Child abuse material is class 1 material for the purposes of the online content scheme under the Online Safety Act 2021 (Cth), and is subject to the removal notice regime described in the Content Regulation and Online Classification chapter. The industry codes and standards registered under Part 9 of that Act impose obligations on services to take steps against this material at the systems level, rather than item by item.
The statutory review of the Online Safety Act recommended the adoption of an overarching duty of care, and that harms to children — including grooming — be identified for particular attention in any reform.13 The Online Safety Act does not currently address grooming as a distinct category.
The minimum age obligations that commenced in December 2025 are relevant but not directed at this problem: they require services to take reasonable steps to prevent under-16s from holding accounts, and are enforced against providers rather than against children or parents. Online games and some messaging services are excluded from those obligations, so the services on which grooming most often occurs are not uniformly covered.
Private Law: Electronic Contracts
Access to computer systems is typically constrained by both code and contract law. The code that makes computer systems interactive will often have some system for controlling access to the system. For example, websites are often made accessible to the public, but webservers can be configured to ensure that different parts of the website are only accessible to logged-in users with the correct permissions. Similarly, login controls prevent people from gaining access to computer systems without the correct password or credentials. Accessing computer systems by breaking these authentication mechanisms will usually be an offence under the unauthorised access or computer trespass provisions in the criminal law.
Shrink-wrap, click-wrap, and browse-wrap agreements
Video: What’s the difference between a click-wrap and a browse-wrap agreement? by Erin Laird
The link between access control systems and private law is typically made through a contract. Many websites now have contractual terms of use that purport to limit access to the website upon acceptance of those terms. When this is done in the registration process, where a user must affirmatively agree to contractual terms (typically by checking a box or clicking a button), this is called a ‘clickwrap’ contract. When contractual terms are instead incorporated by reference (for example, a link at the bottom of the page entitled ‘terms of use’), this is called a ‘browsewrap’ contract.
‘Shrink-wrap’ licence agreements are agreements found inside software packaged for sale. This raised the question of how software licence agreement of the provider was binding on the consumer, when the consumer entered into the sale contract with the retail shop. In ProCD Inc v Zeidenberg 86 F 3d 1447 (1996), the Court held that consumers will be bound to the licence agreement if they open the packaging and subsequently install the software, as they reliquished an opportunity to reject it by returning the software.
A ‘click-wrap’ agreement is an online agreement where the user actively gives consent to the terms and conditions. The user will do this by either clicking on a button or checking a box next to a statement saying “I agree to the terms and conditions”. A browse-wrap agreement is an online agreement where the user is assumed to have given passive consent by merely being on the website because being on the website is stated to amount to entering into an agreement with the provider.
Click-wrap and browse-wrap agreements differ from how the terms are incorporated to the agreement by reference. To be enforceable, it must be done by signature or reasonable notice.14 Click-wrap agreements do this by signature. Browse-wrap agreements attempt this through reasonable notice, but this is sometimes harder to enforce.15
Terms of Use documents are either click-wrap or browse-wrap agreements that typically deal with a series of different legal issues. They might include limitations of liability clauses, standards of acceptable conduct, copyright and other intellectual property policies, dispute resolution mechanisms, and many other terms. These can be very useful for online service providers. Because users must agree to the terms to use the website, these terms become enforceable through contract law and, in some cases, also through the criminal prohibitions on unauthorised access. In practice, the contractual component is the most important: through electronic contracts, online service providers are able to structure their rights and exposure to potential liability in a standardised, low cost manner.
Video unavailable. Please help by creating a new video on Explains the Authority In US v Drew that Breach of Terms of Service Does Not Constitute ‘Unauthorised’ Access.
Terms of Use documents are often criticised for the problems they pose for consumers. Click-wrap contracts are generally enforceable, regardless of whether the consumer has actually read the terms or not. Many firms abuse this system by including quite harsh terms in the fine print of the contract in order to minimise their potential risk. In response to this general concern, Australia has recently introduced unfair terms legislation that will limit the enforceability of standard form contracts that are deemed to be unfair.
Video Overview of the Contract Dispute in eBay v Creative Festival Entertainment
-
Royal Commission into Institutional Responses to Child Sexual Abuse (Final Report, December 2017) vol 2, 40. ↩
-
Australian Federal Police, ‘Reports of Child Exploitation to AFP-led ACCCE Increase 45% in Past Financial Year’ (Media Release, 2 September 2024) https://www.afp.gov.au/news-centre/media-release/reports-child-exploitation-afp-led-accce-increase-45-past-financial-year. ↩
-
eSafety Commissioner, Behind the Screen: The Reality of Age Assurance and Social Media Access for Young Australians (Transparency Report, February 2025). ↩
-
eSafety Commissioner, Mind the Gap: Parental Awareness of Children’s Exposure to Risks Online (Report, February 2022). ↩
-
Criminal Code Act 1995 (Cth) s 474.27. ↩
-
R v Lidden [2024] ACTSC 297. ↩
-
Crimes Act 1900 (NSW) s 66EB(3). ↩
-
Criminal Code Act 1995 (Cth) ss 474.22, 474.23. See also ss 474.22A, 474.24A. ↩
-
Crimes Act 1900 (NSW) s 91FB. ↩
-
Crimes Act 1900 (NSW) s 91H. ↩
-
Australian Federal Police and Australian Centre to Counter Child Exploitation, 2022–23 Highlights https://www.accce.gov.au/sites/default/files/2023-09/ACCCE%20achievements%2022-23.pdf. ↩
-
Australian Federal Police, ‘Sydney Man Charged with Allegedly Producing Child Abuse Material at Six Out-of-School Hours Care Services’ (Media Release, 31 July 2025) https://www.afp.gov.au/news-centre/media-release/sydney-man-charged-allegedly-producing-child-abuse-material-six-out. ↩
-
Delia Rickard PSM, Report of the Statutory Review of the Online Safety Act 2021 (Report, October 2024) recs 4–5. ↩
-
Toll (FGCT) Pty Ltd v Alphapharm Pty Ltd (2004) 219 CLR 165 approving L’Estrange v F Graucob Ltd [1934] 2 KB 394. ↩
-
Hotmail Corporation v Van Money Pie Inc (1998) 47 USPQ 102. ↩