A law published this Friday (28) in the Official Gazette toughens the penalties for crimes committed through electronic means. Now, there are specific aggravating factors for cyber actions: fraud involving the theft of WhatsApp accounts, for example, can result in prison sentences of up to eight years – three years more than the base penalty for this type of offense.
With the new wording, the crime of intrusion, such as installing spy apps and malware, has become broader. Previously, certain criminal behaviors, including copying open data, could not be prosecuted under this article.
With the increased penalty for this crime, it will also become harder to secure alternative sentences, which are used for sentences of up to four years. Now, the crime of intrusion can be punished with up to five years in prison.
Creators of intrusion software can also be prosecuted under this crime – which makes the increased penalty especially relevant to punish those who act as suppliers and avoid direct involvement.
An aggravating factor was also added for those who use computers outside of national territory – a tactic widely used by criminals to hinder police investigations.
As part of the wording is new, the practical application of the law will depend on court decisions and interpretations based on the concrete cases that reach the courts.
Even so, the blog took a chance on analyzing the text to point out how the changes bring the law at least closer to the daily practices of cybercrime.
The crime of fraud, the "171", received an exclusive wording for frauds in which some electronic means of contact was employed. The penalty can reach up to eight years.
The text provides for the classification of fraud "committed with the use of information provided by the victim or by a third party induced into error through social networks, telephone contacts, or sending fraudulent emails, or by any other analogous fraudulent means."
In practice, the theft of WhatsApp accounts, for example, where the victim is induced to provide their authorization code, could fall under this article.
The "fraudulent email", on the other hand, is the "phishing scam." This fraud is widely used in Brazil: criminals send fake messages on behalf of banks and other institutions (including the police themselves) to convince the victim to hand over information or download a password stealer onto their computer.
The crime of "intrusion of a computer device" was created in 2012. The law provided for a penalty of up to one year, which could reach two years if the intruder stole the content of communications, confidential information, or installed remote control software.
However, the law could only be applied "upon undue violation of a security mechanism." This passage was removed from the new wording. Now, it is enough that the intruder does not have "tacit authorization" from the device user when obtaining, altering, or destroying data.
In theory, this means that "opportunity intruders" – people who take advantage of some oversight and pick up a phone without the screen lock active, for example – could be prosecuted under this crime.
Another criminal conduct that does not involve the violation of a security mechanism is the extraction of open data. When companies or organizations forget to configure a password on a database or storage service, there is no security mechanism in place.
Hackers use scanning programs to find these open systems and simply copy the information – even without any authorization to do so.
The base penalty for this crime has quadrupled: the lowest, from three months, becomes one year, and the highest, which was one year, is now four years. The exclusive penalty for cases of communication theft and remote control software, in turn, is up to five years (previously two years).
Since most criminal intrusions use remote control software, intruders can now be punished with up to five years even if the police cannot indict them for other criminal activities carried out during the intrusion.
The intrusion law also applies to creators of digital malware. As they can cash in by selling or renting malicious code, avoiding the commission of other crimes, the toughening of penalties for the crime of intrusion directly affects this activity.
The law also expanded the crime of qualified theft with a specific section for actions carried out using electronic or computer devices.
For the law, it does not matter if a malicious program was used or even if the computer is connected to the network – the aggravating factor of an electronic device can still be applied.
The use of a foreign server – a common practice to minimize tracks and hinder investigations – can increase the penalty by up to two-thirds. Since the regular penalty is up to eight years, the maximum penalty exceeds ten years.
This wording shows that the conducts were defined in alignment with the methods employed by criminals to throw off the authorities.
The text also specifies that the aggravating factor for computer devices can be applied even if there is no violation of a security mechanism – in reference to the passage removed from the crime of intrusion.
Did you like it? Follow CodeBit on our social networks (Facebook, Instagram and LinkedIn) and keep an eye on the CodeBlog.




