Procuradoria-Geral da República Prosecutor General’s Office Cybercrime Office [email protected] phishing… Law109/2009 15September2009 Conven&ononCybercrime–BudapestConven&on DecretodoPresidentedaRepúblicanº91/2009,15September –ra6fiestheConven6on ResoluçãodaAssembleiadaRepúblicanº88/2009,15September –approvestheConven6on Framework-Decision2005/222-24February2005 and: DIRECTIVE2013/40/EUOFTHEPARLIAMENTANDTHECOUNCIL 12August2013 (aVacksagainstinforma6onsystems) SPAM SPAM • unsolicitedemailmessages • toanumberofrecipients • therecipientcannotavoid • some6mes,usedformeremarke6ngpurposes • frequentlyhidingmalware ALSOFORGERY ofthemessageand ofthewebpage Budapest Convention Ar&cle7– Computer-relatedforgery EachPartyshalladoptsuchlegisla6veandothermeasures asmaybenecessarytoestablishascriminaloffencesunderits domes6claw,whencommiVedinten&onallyandwithoutright,the input,altera&on,dele&on,orsuppressionofcomputerdata,resul6ng ininauthen&cdatawiththeintentthatitbeconsideredoractedupon forlegalpurposesasifitwereauthen&c,regardlesswhetherornot thedataisdirectlyreadableandintelligible.APartymayrequirean intenttodefraud,orsimilardishonestintent,beforecriminalliability aVaches. Law on Cybercrime Ar&cle3 Computerforgery 1-Whoever,withintenttocausedecep6oninlegalrela6ons,enters, modifies,deletesorsuppressescomputerdataorotherwiseinterferes withcomputerdatatoproduceinforma6onordocumentsthatarenot genuine,withtheinten6onthattheycanbeconsideredorusedfor legallyrelevantpurposesasiftheywere,ispunishedwith imprisonmentupto5yearsorafineof120to600days. Law on Cybercrime Ar&cle3 Computerforgery 1-Whoever,withintenttocausedecep6oninlegalrela6ons,enters, modifies,deletesorsuppressescomputerdataorotherwise interfereswithcomputerdatatoproduceinforma&onordocuments thatarenotgenuine,withtheinten6onthattheycanbeconsideredor usedforlegallyrelevantpurposesasiftheywere,ispunishedwith imprisonmentupto5yearsorafineof120to600days. • someonepretendstobesomeoneelse/orthe legi6materepresenta6vefromsomeins6tu6on • usingimages/simbols/logosfromlegi6mate ins6tu6ons • eventuallyorganizeswebpagesapparentlyfrom legi6mateins6tu6ons–butforged Thegreyarea: possessionofthe creden6als Budapest Convention Ar&cle6– Misuseofdevices 1 EachPartyshalladoptsuchlegisla6veandothermeasuresasmaybe necessarytoestablishascriminaloffencesunderitsdomes6claw,whencommiVed inten6onallyandwithoutright: a theproduc6on,sale,procurementforuse,import,distribu6onor otherwisemakingavailableof: i adevice,includingacomputerprogram,designedoradapted primarilyforthepurposeofcommidnganyoftheoffencesestablishedin accordancewiththeaboveAr6cles2through5; ii acomputerpassword,accesscode,orsimilardatabywhich thewholeoranypartofacomputersystemiscapableofbeingaccessed, withintentthatitbeusedforthepurposeofcommidnganyoftheoffences establishedinAr6cles2through5;and b thepossessionofanitemreferredtoinparagraphsa.ioriiabove, withintentthatitbeusedforthepurposeofcommiDnganyoftheoffences establishedinAr6cles2through5.APartymayrequirebylawthatanumberof suchitemsbepossessedbeforecriminalliabilityaVaches. (…) DIRECTIVE 2013/40/EU OF THE EP AND OF THE COUNCIL Ar#cle7 Toolsusedforcommi1ngoffences MemberStatesshalltakethenecessarymeasurestoensurethatthe inten6onalproduc&on,sale,procurementforuse,import,distribu&onor otherwisemakingavailable,ofoneofthefollowingtools,withoutrightand withtheinten6onthatitbeusedtocommitanyoftheoffencesreferredto inAr6cles3to6,ispunishableasacriminaloffence,atleastforcaseswhich arenotminor: (a) acomputerprogramme,designedoradaptedprimarilyforthe purposeofcommidnganyoftheoffencesreferredtoinAr6cles3to6; (b) acomputerpassword,accesscode,orsimilardatabywhichthe wholeoranypartofaninforma&onsystemiscapableofbeingaccessed. useofthe creden6als Budapest Convention Ar&cle2– Illegalaccess EachPartyshalladoptsuchlegisla6veandothermeasuresasmaybe necessarytoestablishascriminaloffencesunderitsdomes6claw, whencommiVedinten6onally,theaccesstothewholeoranypartofa computersystemwithoutright.APartymayrequirethattheoffence becommiVedbyinfringingsecuritymeasures,withtheintentof obtainingcomputerdataorotherdishonestintent,orinrela6ontoa computersystemthatisconnectedtoanothercomputersystem. DIRECTIVE 2013/40/EU OF THE EP AND OF THE COUNCIL Ar:cle3 Illegalaccesstoinforma&onsystems MemberStatesshalltakethenecessarymeasurestoensurethat,when commiVedinten6onally,theaccesswithoutright,tothewholeorto anypartofaninforma&onsystem,ispunishableasacriminaloffence wherecommiVedbyinfringingasecuritymeasure,atleastforcases whicharenotminor. Law on Cybercrime Ar&cle6 Illegalaccess 1-Anypersonwho,withoutlegalpermissionorwithoutbeing authorizedtodosobytheowner,inanymanneraccedestoa computersystem,shallbepunishedwithimprisonmentupto1yearor withafineofupto120days. Law on Cybercrime Ar&cle6 Illegalaccess 1-Anypersonwho,withoutlegalpermissionorwithoutbeing authorizedtodosobytheowner,inanymanneraccedestoa computersystem,shallbepunishedwithimprisonmentupto1yearor withafineofupto120days. Budapest Convention Ar&cle8– Computer-relatedfraud EachPartyshalladoptsuchlegisla6veandothermeasuresasmaybe necessarytoestablishascriminaloffencesunderitsdomes6claw,when commiVedinten&onallyandwithoutright,thecausingofalossofproperty toanotherpersonby: a anyinput,altera&on,dele&onorsuppressionofcomputer data; b anyinterferencewiththefunc&oningofacomputersystem, withfraudulentordishonestintentofprocuring,withoutright,aneconomic benefitforoneselforforanotherperson. Penal Code Ar&go221.º Burlainformá&caenascomunicações 1-Quem,comintençãodeobterparasiouparaterceiro enriquecimentoilegí6mo,causaraoutrapessoaprejuízopatrimonial, interferindonoresultadodetratamentodedadosoumediante estruturaçãoincorrectadeprogramainformá6co,u6lizaçãoincorrecta ouincompletadedados,u6lizaçãodedadossemautorizaçãoou intervençãoporqualqueroutromodonãoautorizadano processamento,épunidocompenadeprisãoaté3anosoucompena demulta. Penal Code Ar&go221.º Burlainformá&caenascomunicações 1-Quem,comintençãodeobterparasiouparaterceiro enriquecimentoilegí6mo,causaraoutrapessoaprejuízopatrimonial, interferindonoresultadodetratamentodedadosoumediante estruturaçãoincorrectadeprogramainformá6co,u6lizaçãoincorrecta ouincompletadedados,u6lizaçãodedadossemautorizaçãoou intervençãoporqualqueroutromodonãoautorizadano processamento,épunidocompenadeprisãoaté3anosoucompena demulta. interven6onof themoneymules RuadoValedePereironr21269-113LISBOA [email protected]