Digital Sabotage Defense in Marbella
Digital sabotage, viruses, and damage to computer systems
Beyond its application to ransomware, which we already address in our content on computer fraud, the offences of damage to computer systems under Articles 264 to 264 quater of the Criminal Code present a dogmatic complexity of their own, recognized by specialized legal scholarship as one of the most difficult areas to interpret within the whole of Spanish computer criminal law, largely due to the absence of consolidated Supreme Court case law establishing uniform criteria. At RAKH ABOGADOS we approach this area with the support of forensic computer experts capable of reconstructing, with technical precision, the exact nature of the attack — a point on which, in practically every case, the very viability of the prosecution depends.
The "double seriousness" requirement: a concept with no legal definition
Article 264.1 of the Criminal Code punishes anyone who, without authorization and in a serious manner, erases, damages, deteriorates, alters, suppresses, or renders inaccessible another's computer data, programs, or electronic documents, when the result produced is serious. Specialized legal scholarship has identified in this wording a requirement of "double seriousness" — of the conduct and of the result — which the legislature has never defined, leaving its determination to case-by-case judicial interpretation. This lack of precision produces, in practice, inconsistent rulings: while some Provincial Courts have acquitted in cases of data deletion that was easily recoverable, on the grounds that the seriousness threshold for the result was not met, others have convicted in circumstances that, analyzed with dogmatic rigor, raise serious doubts as to whether they fit the offence. Subjecting the concurrence of this double seriousness requirement to adversarial scrutiny — and not merely confirming that some damage occurred — is the first and most effective line of our defense in these proceedings.
Damage to data (Article 264 of the Criminal Code) versus obstruction of the system (Article 264 bis of the Criminal Code)
The Code distinguishes two forms of conduct that should not be confused. Article 264 of the Criminal Code protects the integrity of the data, programs, or electronic documents themselves. Article 264 bis of the Criminal Code, on the other hand, punishes anyone who, without authorization and in a serious manner, obstructs or interrupts the operation of another's computer system by introducing or transmitting data, or by destroying, damaging, disabling, eliminating, or replacing that system — the typical scenario of denial-of-service or DDoS attacks, which overwhelm a server with a massive volume of simulated requests. The scarce case law existing on this offence illustrates the difficulty of applying it: in the well-known "Anonymous case," concerning a denial-of-service attack against institutional websites, the Criminal Court issued an acquittal, upheld on appeal, on the grounds that the seriousness of the obstruction caused was not sufficiently established. Precisely determining, through expert evidence, whether the attack under investigation actually reached that seriousness threshold is therefore decisive.
Punishable preparatory acts: the creation and distribution of malware (Article 264 ter of the Criminal Code)
Article 264 ter of the Criminal Code moves the line of criminal liability to a point before the attack itself: it punishes, with a sentence of imprisonment from six months to two years or a fine of three to eighteen months, anyone who, without being duly authorized, produces, acquires for use, imports, or supplies to third parties a computer program designed or adapted mainly to commit the offences of damage or obstruction under Articles 264 and 264 bis of the Criminal Code, or a password, access code, or similar data enabling access to all or part of a computer system. This is a stand-alone offence that does not require the malware to have actually been used: the mere creation, possession for use, or distribution of the harmful program already satisfies the elements of the offence, which makes the analysis of the purpose for which it was designed — and not just the result it may eventually have produced — the central element of the defense in these cases.
Aggravated subtypes: critical infrastructure and links to terrorism
Article 264.2 of the Criminal Code raises the sentence to imprisonment from two to five years when a qualifying circumstance is present: commission within the framework of a criminal organization, damage of particular seriousness or affecting a large number of computer systems, serious harm to the operation of essential public services or to the supply of basic necessities, or an effect on the computer system of critical infrastructure that creates a serious danger to the security of the State, of the European Union, or of a Member State. Article 264.3 of the Criminal Code further imposes the upper half of the sentence in cases of particular seriousness linked to these same circumstances. Of particular relevance, Article 573.2 of the Criminal Code allows these same facts to be classified as a terrorism offence where the specific purpose required by that provision is present, with the procedural and sentencing consequences this entails, including jurisdiction of the Audiencia Nacional (Spain's central criminal court with jurisdiction over terrorism, organized crime, and other serious offences of national scope). Rigorously analyzing whether that terrorist purpose is genuinely present, rather than a different motive — a grievance, financial gain, or mere vandalism — is essential to avoid a disproportionate legal classification.
Corporate criminal liability (Article 264 quater of the Criminal Code)
Article 264 quater of the Criminal Code extends criminal liability to legal persons when computer damage offences are committed in their name or on their behalf and for their direct or indirect benefit, with fines that can run for up to five years depending on the seriousness of the act. The existence of a specific criminal compliance program in the area of cybersecurity — access protocols, periodic audits, staff training, a whistleblowing channel — constitutes, just as in other economic offences, the organization's principal preventive and defensive tool against this liability, particularly relevant when the attack originates from an employee or a third party who acted by exploiting access enabled by deficiencies in internal controls.
Our defense strategy
- Challenging the double seriousness requirement: with independent computer expert evidence, we subject to adversarial scrutiny both the seriousness of the conduct and that of the result, verifying how easily the affected data or systems could be restored.
- Correct classification between damage and obstruction: we determine whether the facts fit Article 264 or Article 264 bis of the Criminal Code, depending on whether the attack affected the data itself or the overall operation of the system.
- Analysis of the program's purpose under Article 264 ter: when the creation or possession of malicious software is alleged, we analyze its design and actual purpose, distinguishing legitimate computer security tools from malware proper.
- Challenging the terrorism or critical-infrastructure classification: we verify whether the aggravating circumstances of Articles 264.2 and 264.3 of the Criminal Code, and the specific purpose required by Article 573.2 of the Criminal Code, are genuinely present.
Have you been investigated for a computer attack, for creating or distributing malware, or has your company suffered a digital sabotage attack? Correctly classifying these facts, both technically and legally, requires rigorous expert analysis. At RAKH ABOGADOS we combine legal rigor with forensic computer expertise to defend your interests throughout Spain.
Frequently asked questions, glossary and comparisons
Frequently asked questions
What is the difference between damaging computer data and bringing down a system with a DDoS attack?
See answer in Frequently Asked Questions →Is it an offence to create or possess malicious software (malware) even if it is never actually used?
See answer in Frequently Asked Questions →