Cyber Crime & Computer
Offences Lawyer Cairns
You have been charged with a computer or cyber crime offence. These charges cover a wide range of conduct — from accessing someone else's email or social media account, to using stolen identity information, to sophisticated hacking. What they have in common is that Queensland and Commonwealth law treats them seriously, the penalties are steeper than most people expect, and a conviction creates a criminal record that can end careers in IT, finance, government, and any role requiring a security clearance. The charges come in tiers. The lowest tier — basic unauthorised access — carries up to 3 years' imprisonment. Where financial benefit or detriment is involved, the maximum rises to 5 years. Where the value exceeds $5,000 or the access was to facilitate another indictable offence, the maximum rises to 10 years — and if the value reaches $30,000 or more and the charge is contested, the matter goes to the District Court. Getting the tier right, and testing whether the prosecution can prove the elements of the tier they have charged, is where the defence work begins.
The Queensland Offences — Criminal Code
Section 408E — Misuse of restricted computer The primary Queensland computer crime offence is section 408E of the Criminal Code Act 1899 . It has three tiers: Tier 1 — Basic access (s 408E(1)) Using a restricted computer without the consent of the computer's controller Classification: misdemeanour — must be dealt with in the Magistrates Court Maximum penalty: 3 years' imprisonment Tier 2 — Access causing detriment or obtaining benefit (s 408E(2)) The person causes or intends to cause detriment or damage, or gains or intends to gain a benefit Classification: crime — dealt with in the Magistrates Court (as a Part 6 offence under s 552BA) Maximum penalty: 5 years' imprisonment (capped at 3 years when dealt with summarily) Tier 3 — Serious computer crime (s 408E(3)) The detriment, damage, or benefit exceeds $5,000 in value, or the access was intended to facilitate an indictable offence Classification: crime — dealt with in the Magistrates Court unless the value is $30,000 or more and the defendant does not plead guilty, in which case it is an excluded offence under s 552BB and goes to the District Court Maximum penalty: 10 years' imprisonment (capped at 3 years when dealt with summarily) A "restricted computer" is defined in two parts: (a) a device, code, or particular sequence of electronic impulses is necessary to gain access, and (b) the controller withholds or restricts access to that device, code, or sequence. In practice, any computer, phone, or account protected by a password, PIN, biometric lock, or login credentials — where the controller has not freely shared access — is a restricted computer. Accessing your ex-partner's Facebook account using a password they once shared with you, logging into a colleague's work email, or using someone else's banking app all fall within the definition. The defence under s 408E(4) is that the use of the computer was authorised, justified, or excused by law . Where the person had standing consent — or reasonably believed they did — that is a live issue. Section 408D — Identity fraud Section 408D of the Criminal Code targets identity fraud — obtaining or dealing with another person's identification information for the purpose of committing or facilitating an indictable offence. Maximum penalty: 5 years' imprisonment (misdemeanour) Possessing equipment for identity fraud (s 408D(1A)): 5 years' imprisonment It is immaterial whether the other person is alive or dead, or consents to the dealing The Penalties and Sentences Act 1992 , s 161Q, states a serious organised crime circumstance of aggravation "Identification information" includes names, dates of birth, driver's licence numbers, tax file numbers, Medicare numbers, bank account details, passwords, PINs, digital signatures, and biometric data. The offence covers obtaining the information (buying stolen data, copying a card, photographing documents) and dealing with it (using it to open accounts, make purchases, or create false identity documents).
Commonwealth Computer Offences
Where the conduct involves telecommunications infrastructure — the internet, email services, mobile networks — Commonwealth offences under the Criminal Code Act 1995 (Cth) may also apply. These are prosecuted by the Commonwealth Director of Public Prosecutions and carry their own penalty framework: Part 10.7 — Computer offences Unauthorised access to, or modification of, restricted data (s 478.1 Cth) — max 2 years Unauthorised impairment of electronic communication (s 477.3 Cth) — max 10 years Unauthorised modification of data to cause impairment (s 477.2 Cth) — max 10 years Unauthorised access, modification, or impairment with intent to commit a serious offence (s 477.1 Cth) — max 10 years Using a carriage service to menace, harass, or offend Section 474.17 of the Criminal Code (Cth) makes it an offence to use a carriage service (the internet, a phone, email, social media) in a way that a reasonable person would regard as menacing, harassing, or offensive. Maximum penalty: 5 years' imprisonment . This is one of the most commonly charged Commonwealth offences in Queensland — it covers threatening messages, sustained online harassment, offensive communications, and coordinated bullying through digital platforms. Where both Queensland and Commonwealth offences arise from the same conduct, the prosecution chooses which jurisdiction to proceed in. Commonwealth matters are heard in Queensland courts exercising federal jurisdiction, but sentencing is governed by the Crimes Act 1914 (Cth) rather than Queensland sentencing legislation.
Common Scenarios in Cairns
Computer and cyber crime charges in the Cairns courts arise from a range of circumstances: Accessing an ex-partner's accounts The most common scenario. After a relationship breakdown, one party logs into the other's email, social media, or banking using a password they previously knew. Even if the password was shared during the relationship, using it after the relationship ends — without current consent — is unauthorised access. If the access reveals private messages or financial information, the prosecution may allege detriment (Tier 2) or charge identity fraud alongside. Workplace computer access An employee accesses systems, databases, or files beyond the scope of their authorisation. This may involve viewing client records for personal reasons, accessing a colleague's email, or downloading data before leaving a job. Employers report these matters to police, and the employee faces criminal charges alongside any employment consequences. Online fraud and scams Using someone else's identity information to make purchases, open accounts, apply for credit, or redirect payments. This typically attracts identity fraud charges (s 408D) alongside computer misuse charges. Where the financial value exceeds $5,000, the matter goes to the District Court. Hacking and unauthorised system access Gaining access to computer systems through technical means — exploiting vulnerabilities, brute-forcing passwords, phishing credentials. These matters often involve forensic evidence (IP addresses, server logs, device analysis) and may attract Commonwealth charges where telecommunications infrastructure is involved. Online harassment and threats Sustained online harassment, threatening messages, or offensive communications through social media, messaging apps, or email. These are commonly charged under the Commonwealth "using a carriage service" provisions (s 474.17 Cth) because the conduct involves telecommunications. The charges can be laid alongside Queensland stalking charges (s 359B Criminal Code ) where the conduct is repeated.
What 'Restricted Computer' and 'Unauthorised' Mean
Two elements are central to every s 408E charge: was the computer "restricted" and was the access "unauthorised"? Restricted computer A computer is restricted if two conditions are met: (a) a device, code, or particular sequence of electronic impulses is necessary to gain access, and (b) the controller withholds or restricts access to that device, code, or sequence from other persons, or restricts it to authorised persons. In practical terms, any device or account protected by a password, PIN, passcode, pattern lock, fingerprint, face recognition, or two-factor authentication — where the controller has not freely shared access — is a restricted computer. The term "computer" is defined broadly to include all or part of a computer, computer system, or computer network — and all external devices connected to it. A phone is a computer. A tablet is a computer. A cloud account accessed through a browser is a restricted computer. Unauthorised access Access is unauthorised if it occurs without the consent of the computer's controller. "Controller" means a person who has a right to control the computer's use. The critical question is whether consent existed at the time of the access — not whether it existed previously. Consent given during a relationship does not survive the end of the relationship unless explicitly renewed. Consent given by an employer for work purposes does not extend to personal use or access beyond the scope of the employee's role. The defence is that the use was authorised, justified, or excused by law . This covers situations where the person had a reasonable belief that they were authorised to access the computer — for example, a shared family computer with no discussion about access restrictions, or a work system where the boundaries of authorised access were unclear.
Sentencing — What Changes the Outcome
The sentencing range for computer crime depends heavily on the tier, the financial impact, and the offender's motivation: The tier charged. Tier 1 (basic access, 3 years max) is in the Magistrates Court and the realistic range for a first offender is a fine or good behaviour bond. Tier 3 (10 years max) is in the District Court and imprisonment is a realistic possibility where the financial loss is significant. Financial loss or gain. The amount of money involved — whether the offender gained a benefit or the victim suffered a loss — is the single most important sentencing factor for Tier 2 and Tier 3 matters. Courts look at both the actual loss and the intended loss. The nature of the access. Accessing an ex-partner's Facebook out of curiosity is treated very differently from systematically downloading a company's client database or draining a bank account. The sophistication and planning involved affect where the offending falls on the spectrum. Breach of trust. Where the access involved a breach of trust — an employee accessing employer systems, a professional accessing client data, a person in a position of authority — the courts treat the offending more seriously. Impact on the victim. Victim impact statements carry significant weight. Where the victim has suffered financial loss, emotional distress, or had their identity compromised, the court takes that into account. Cooperation with authorities. Early admissions, cooperation with police, and voluntary restitution (repaying money, returning data, closing fraudulent accounts) are recognised as mitigating factors. Collateral consequences. A computer crime conviction can end careers in IT, finance, government, education, healthcare, and any role requiring a national police check or security clearance. These consequences are relevant to the court's decision under section 12 of the Penalties and Sentences Act 1992 on whether or not to record a conviction.
Related Charges
Computer and cyber crime charges are often laid alongside related offences: Fraud (s 408C Criminal Code ) — where the computer access was used to obtain property, a financial advantage, or to cause a financial disadvantage to another person. Fraud carries up to 5 years (or 14 years where the offender is a director, employee, or the value is $30,000+, and up to 20 years where the value exceeds $100,000). Stealing (s 398 Criminal Code ) — where property (including data or money) was taken as a result of the unauthorised access. Stalking (s 359A Criminal Code ) — where the computer access was part of a pattern of conduct intended to cause apprehension or fear. Accessing an ex-partner's accounts repeatedly may attract both computer crime and stalking charges. Domestic violence offences — where the computer access occurs in a domestic relationship context. Monitoring a partner's phone, accessing their accounts, or using technology to control or surveil a partner may constitute domestic violence under the Domestic and Family Violence Protection Act 2012 . Weapons offences — in rare cases involving illegal online marketplaces or dark web activity.
Frequently Asked Questions
Is accessing someone's social media without permission a criminal offence?
Yes. Any account protected by a password is a 'restricted computer' under section 408E of the Criminal Code . Accessing it without the account holder's current consent — even if you previously knew the password — is a criminal offence carrying up to 3 years' imprisonment for basic access, and up to 5 years if you cause detriment or obtain a benefit.
What is the difference between Tier 1, Tier 2, and Tier 3 computer crime?
Tier 1 (s 408E(1)) is basic unauthorised access — 3 years max, Magistrates Court. Tier 2 (s 408E(2)) involves causing or intending detriment or obtaining a benefit — 5 years max, usually Magistrates Court. Tier 3 (s 408E(3)) involves a value exceeding $5,000 or intent to commit an indictable offence — 10 years max, and goes to the District Court if the value is $30,000 or more and the charge is contested. The prosecution must prove the elements of the tier they charge.
Can I be charged with a computer crime for accessing my own work computer?
If you access systems, files, or databases beyond the scope of your authorised access, yes. Your employer is the 'controller' of the work computer. If you access client records for personal reasons, download company data before leaving, or access a colleague's account, the access is unauthorised even though you had a login to the system. The question is whether your access was within the scope of your authorisation.
Will I get a criminal record for a computer offence?
For a first-offence Tier 1 matter with no financial loss, no conviction recorded is achievable with proper preparation. For Tier 2 and Tier 3 matters involving financial loss, a conviction is more likely — and for serious Tier 3 matters in the District Court, imprisonment is a realistic possibility. The collateral impact of a conviction on employment and professional registration is relevant to sentencing.
What is identity fraud under Queensland law?
Section 408D of the Criminal Code makes it an offence to obtain or deal with another person's identification information for the purpose of committing or facilitating an indictable offence. 'Identification information' includes names, dates of birth, licence numbers, tax file numbers, bank details, passwords, and biometric data. The maximum penalty is 5 years' imprisonment. Possessing equipment for identity fraud (s 408D(1A)) also carries 5 years.