Rakh Abogados
Rakh Abogados Inherited Talent
Phishing, ransomware and card cloning

Computer Fraud Lawyer in Marbella

Text

Computer fraud

Computer fraud is now the criminal category with the highest volume of complaints filed in Spain, with sustained growth that multiplies year after year the figures recorded barely a decade ago. The Criminal Code responds to this reality with a catalogue of technically differentiated offences — computer fraud proper, computer damage, and related forgery offences — whose correct legal classification proves decisive both for the defense of the person under investigation and for the victim's claim. At RAKH ABOGADOS we handle these matters from both positions, backed by forensic computer experts who analyze the technical trace of the attack from the very first stage of the proceedings.

Phishing as computer fraud (Article 248.2.a of the Criminal Code): no deception, no error

Phishing — sending communications that impersonate a trusted institution to obtain the victim's banking access credentials — does not fit the traditional fraud offence under Article 248.1 of the Criminal Code, which requires deception that directly causes the victim an error determinative of their own act of asset disposal. Case law has clarified the specific nature of this offence:

"...cuando la conducta que desapodera a otro de forma no consentida de su patrimonio se realiza mediante manipulaciones del sistema informático... se incurre en la tipicidad del art. 248.2."

Tribunal Supremo, Sala de lo Penal, STS 838/2023, de 16 de noviembre de 2023

(The Court held that where conduct deprives another of assets without consent by manipulating a computer system, it falls under the offence defined in Article 248.2.) In banking phishing, the victim does not knowingly dispose of their assets: it is the criminals themselves who, once they have obtained the credentials through the initial deception, access the account directly and order the non-consented transfer. This technical distinction — the absence of a voluntary act of disposal by the victim — has significant practical consequences, including the quasi-strict liability regime that European payment-services regulations impose on banking institutions, which are obliged to immediately reimburse the amounts taken unless they prove gross negligence on the part of the account holder.

The "bank mule" figure: fraud, money laundering, or handling stolen goods

One of the most litigated issues in this area is the legal classification of a person who, recruited through false work-from-home offers, provides their bank account to receive the stolen money and forwards it abroad in exchange for a commission — the so-called "mule" or "cyber-mule". Case law has fluctuated between classifying this conduct as necessary cooperation in the offence of computer fraud, as handling stolen goods, or as money laundering, settling for the most part on the latter classification, in its reckless (negligent) form, where certain knowledge of the criminal origin of the money is not established but a reasonable suspicion arising from the circumstances is:

"...al aceptar en su cuenta una cantidad que procedía de una actividad delictiva, y contribuir a ocultarla, transfiriéndola a una persona... incurre en un blanqueo por imprudencia grave."

Tribunal Supremo, Sala de lo Penal, STS 506/2015, de 27 de julio de 2015

(The Court held that a person who accepts into their account an amount originating from criminal activity, and contributes to concealing it by transferring it to another person, incurs money laundering through gross negligence.) This classification carries a sentence markedly lower than that for computer fraud, a matter we work on systematically in defending those who intervene at the final link of these schemes without real knowledge of the complete criminal network. The total absence of any grounds for suspicion — where the offer of collaboration presented a reasonably lawful appearance — may further exclude criminal liability altogether.

Cloning and fraudulent use of cards (Article 248.2.c of the Criminal Code)

Article 248.2.c) of the Criminal Code independently penalizes anyone who, using credit or debit cards, traveler's cheques, or the data contained in any of them, carries out transactions of any kind to the detriment of the holder or a third party. This offence applies both to the physical cloning of a card's magnetic stripe or chip through skimming devices, and to the use of data obtained by other means — including phishing itself — to make purchases or cash withdrawals without the holder's consent. The Agreement of the Non-Jurisdictional Plenary Session of the Second Chamber of the Supreme Court of 28 June 2002 confirmed that this offence applies regardless of whether the use occurs at ATMs, point-of-sale terminals, or e-commerce platforms, provided there is knowledge of the lack of authorization over the data used.

Ransomware: between computer sabotage and cyber-extortion

Ransomware — the malicious encryption of a victim's systems or files with a demand for ransom in exchange for their release — has no specific offence defined in the Criminal Code, which requires a complex legal classification based on existing offences. The attack itself — the encryption or blocking of data — constitutes a computer damage offence under Article 264 of the Criminal Code, aggravated when it causes especially serious harm, affects a large number of systems, or is carried out by means of a program specifically designed for that purpose under Article 264 ter of the Criminal Code; where the attack is aimed at obstructing the functioning of the system as a whole, Article 264 bis of the Criminal Code applies. In addition, insofar as the attack is accompanied by a demand for a financial ransom under threat of not restoring access to the data — or, in its "double extortion" form, of publicly disclosing it if payment is not made — an offence of extortion under Article 243 of the Criminal Code may also apply, in a concurso medial (instrumental concurrence of offences) with the computer damage offence. Whether these facts are classified as computer sabotage, fraud, or extortion — each with its own sentencing and procedural regime — depends on a detailed technical analysis of the exact mechanics of the attack, a matter we address with the support of our forensic computer experts from the very first proceedings.

Our defense strategy

  • Distinguishing fraud from money laundering in "mule" cases: where applicable, we prove the absence of knowledge of the criminal origin of the funds or the merely negligent nature of the conduct, seeking the most favorable legal classification.
  • Forensic computer expert evidence: we reconstruct the complete technical trace of the attack — origin of the manipulation, systems affected, actual severity of the damage — to verify the legal classification put forward by the prosecution.
  • Challenging the classification in ransomware cases: we contest whether the facts should be classified as computer damage, as extortion, or as an instrumental concurrence of both, with direct repercussions on the applicable sentence.
  • Representation of the victim: when the client is the person or company attacked, we prepare the criminal complaint, the appearance as private prosecution (acusación particular), and the civil liability claim, including any potential action against the banking institution under the liability regime of payment-services regulations.

Have you been the victim of phishing, a ransomware attack, or the cloning of your bank card, or are you under investigation for involvement in any of these acts? The correct legal classification and forensic computer analysis are decisive. At RAKH ABOGADOS we combine legal rigor and forensic technical expertise to defend your interests throughout Spain.

Related resources

Frequently asked questions, glossary and comparisons

Frequently asked questions

Why is banking phishing not considered "fraud" in the classic sense?

See answer in Frequently Asked Questions →

What criminal risk does a person face who lends their bank account to receive another person's money in exchange for a commission?

See answer in Frequently Asked Questions →

Glossary

Bank mule (or cyber-mule)

A person who provides their bank account to receive money of criminal origin, subsequently forwarding it in exchange for a commission. Their criminal liability ranges between necessary cooperation in fraud, handling stolen goods, and, most commonly, money laundering through gross negligence where there was reasonable suspicion, though not certain knowledge, of the unlawful origin of the money.

See in the Glossary →
Initial consultation