For years, when a company or an individual suffered a computer attack, the conversation began —and often ended— on technical ground. People talked about servers, backups and firewalls, but rarely about criminal law. Ley 1273 de 2009 changed that starting point: it gave a criminal-law name to conduct that until then felt like nothing more than a technical problem, and it created a catalog of offenses that today defines how anyone affected must react.
This article does not explain in general terms what a criminal lawyer does in the face of a cyberattack; it concentrates on the statutory offenses. Knowing which of them fits what happened to you is not a technicality: it determines where the criminal complaint is filed, what has to be proven, what penalty the person responsible risks and how urgently you must act. One and the same incident —think of ransomware— usually amounts to several offenses at once, and it is that reading that organizes the response.
Below we go through, one by one, the offenses that Ley 1273 introduced, with their core conduct verb (verbo rector), their exact article and their penalty, illustrated with an example in which you are the victim; then we map today's real-world threats onto those offenses and close with what anyone who has been attacked should do: preserve the digital evidence, file a criminal complaint and prevent.
The essentials
If you have come here in the middle of an incident or while preparing your organization, these are the points worth keeping in mind before going into detail:
- The Ley 1273 de 2009 created in the Código Penal a new protected legal interest: "the protection of information and data" (Título VII BIS), with ten new articles (269A to 269J): nine statutory offenses and one aggravating circumstance (269H).
- They fall into two groups: those that attack the confidentiality, integrity and availability of data and systems (269A to 269H) and those that use technology to strike at estate (269I and 269J), the latter carrying the highest penalties.
- Several offenses are complete without any theft or gain: entering without permission, intercepting communications or creating a phishing page is already an offense.
- The attack from within —by a trusted employee or contractor— is usually the most heavily aggravated one (art. 269H), not the mildest.
- A typical incident (ransomware, CEO fraud) amounts to several offenses in concurrence; the correct characterization defines the penalty and the strategy.
- The digital evidence is fragile: what you do in the first hours —preserving instead of deleting— weighs as much as the criminal complaint.
With that map in mind, let us first see why Ley 1273 marked a before and an after.
Ley 1273 de 2009 and the legal interest of the "protection of information and data"
Ley 1273 de 2009 amended the Código Penal (Ley 599 de 2000) in order to create a Título VII BIS that is entirely new, called "De la protección de la información y de los datos". With it, the legislature recognized that information and computer systems are, in themselves, a value worthy of criminal-law protection —a protected legal interest in its own right—, and not a mere accessory of property. The law's own title says so: it creates "a new protected legal interest —known as the protection of information and data—".
That change has practical consequences. Before 2009, many computer attacks had to be forced into offenses that did not fit them well —people tried to read an improper access as a violation of correspondence, and data sabotage as damage to another's property— and the conduct frequently went unpunished or was wrongly characterized. Today each attack has an offense of its own, with a core conduct verb and a defined penalty, which makes it possible to file a criminal complaint with precision.
Título VII BIS is organized into two chapters that are worth keeping in mind, because they group together different logics. Chapter I, "De los atentados contra la confidencialidad, la integridad y la disponibilidad de los datos y de los sistemas informáticos", protects those three attributes of information (articles 269A to 269H). Chapter II, "De los atentados informáticos y otras infracciones", punishes the conduct in which technology is the means used to strike at property (articles 269I and 269J). Placing your case in one chapter or the other helps to anticipate the penalty and the strategy.
The same statute added two pieces that usually go unnoticed and that are worth knowing about. First, it incorporated into article 58 of the Código Penal a circumstance of greater punishability (subsection 17): where "computer, electronic or telematic means" are used to commit any offense, the judge may move toward the high end of the penalty, even if the offense is not one of those in Título VII BIS. Second, it assigned jurisdiction over these offenses to the municipal criminal court judges (subsection 6 of article 37 of the Código de Procedimiento Penal). These are technical details, but they explain why the use of technology "weighs" across the board in the criminal system.
Unauthorized access to a computer system (art. 269A)
Core conduct verb: to access or to remain without authorization. This offense is committed by anyone who, "without authorization or outside what was agreed", accesses all or part of a computer system —whether or not it is protected by a security measure— or remains within it "against the will of the person with the legitimate right to exclude them". The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 salarios mínimos legales mensuales vigentes (SMLMV, statutory monthly minimum wages).
Example. An employee you have just let go keeps getting into the corporate email or the accounting system with credentials they should no longer have; or a third party discovers the password to an administration panel and "just looks". In both cases there is unauthorized access, even though no one takes a file away.
The common misconception. Many victims —and many attackers— believe that "if nothing was stolen or damaged, nothing happened". That is false: the offense is complete on the mere unauthorized entry or remaining. Nor does it matter that the system had no password: the provision protects the system "whether or not it is protected by a security measure". And the phrase "outside what was agreed" is decisive in the corporate world: someone who had access for one purpose and uses it for another —for example, the systems administrator who enters an executive's inbox without authorization— may fall within the offense.
Unlawful obstruction of a computer system or telecommunications network (art. 269B)
Core conduct verb: to prevent or obstruct the functioning. It penalizes anyone who, "without being empowered to do so, prevents or obstructs the functioning or normal access" to a computer system, to the data it contains or to a telecommunications network. The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 SMLMV, "provided the conduct does not constitute an offense punishable by a greater penalty" —that is, it is a subsidiary offense—.
Example. A denial-of-service (DDoS) attack saturates your company's website and takes the store or the customer portal offline for hours; or someone deliberately blocks all users' access to the management system in order to paralyze operations.
The common misconception. It is commonly thought that "taking a page down" is only an availability problem that is solved by restarting servers. In criminal-law terms it is conduct in its own right: there is no need for information to be destroyed or for anything to be removed; it is enough to prevent the functioning or normal access. Since the offense is subsidiary, if the obstruction is part of a more serious attack (for example, ransomware), the characterization may shift toward the offense carrying the greater penalty.
Interception of computer data (art. 269C)
Core conduct verb: to intercept without a court order. It punishes anyone who, "without a prior court order, intercepts computer data at its origin, its destination or inside a computer system", or the electromagnetic emissions that carry it. The penalty is 36 to 72 months of imprisonment. It is the lowest in the chapter and the only one of these forms of conduct with no fine attached.
Example. Someone installs on your network a device or a program that silently captures the traffic —emails, credentials, documents traveling between machines— in order to read what is not theirs to read; or intercepts the communication between your computer and the bank's server. It is the espionage of communications carried over to the digital plane.
The common misconception. The fact that the penalty is lower leads people to underestimate it, but interception is usually the first link in much more serious frauds: whoever captures the passwords today transfers the money tomorrow. The phrase "without a prior court order" marks the boundary with lawful interception: only the authorities, with an order, may intercept; any private party who does so —including an employer who "monitors" a worker's private communications with no basis— enters criminal territory.
Computer damage (art. 269D)
Core conduct verb: to destroy, damage, erase, deteriorate, alter or suppress. Liability falls on anyone who, "without being empowered to do so, destroys, damages, erases, deteriorates, alters or suppresses computer data, or an information processing system or its parts or logical components". The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 SMLMV.
Example. A resentful former employee erases the client database before leaving; an attacker corrupts the files on the billing server; or an intruder alters accounting records to conceal a diversion of funds. The hostile encryption of information in ransomware also fits, insofar as it leaves the data unusable for its owner.
The common misconception. It is thought that computer damage requires the attacker to "gain something". That is not so: the offense protects the integrity and availability of information, and it is complete on the mere destruction or disabling of another's data or systems, even if the perpetrator obtains no benefit. Pure sabotage —erasing out of revenge— is an offense with the same penalty as an attack for profit.
Use of malicious software (art. 269E)
Core conduct verb: to produce, traffic in, acquire, distribute, sell, send, bring in or take out. It punishes anyone who, "without being empowered to do so, produces, traffics in, acquires, distributes, sells, sends, brings into or takes out of the national territory malicious software or other computer programs with harmful effects". The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 SMLMV.
Example. Someone who sends your company an email with a file that installs a Trojan; someone who sells a ransomware "kit" on a forum; or someone who introduces spyware into the network. The provision punishes the whole chain —manufacturing, buying, distributing, sending—, not only the person who ultimately carries out the attack.
The common misconception. Many believe that only the person who "presses the button" on the attack commits an offense. Article 269E is broader: it reaches anyone who produces, traffics in or distributes the tool, even if they do not use it themselves. That is why the technical component of ransomware —the software that encrypts— falls under this offense, which then usually concurs with computer damage and with the extortion of the ransom.
Violation of personal data (art. 269F)
Core conduct verb: to obtain, compile, remove, offer, sell, exchange, send, buy, intercept, disclose, modify or use. It penalizes anyone who, "without being empowered to do so, for their own benefit or that of a third party", carries out any of those forms of conduct on "personal codes, personal data contained in files, archives, databases or similar media". The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 SMLMV.
Example. An employee downloads the client database to take it to a competitor or sell it; an attacker extracts and publishes on the web a database with ID numbers, emails and phone numbers; or someone buys your users' leaked information on a clandestine market. It is the criminal offense behind the leaking and commercialization of databases.
The common misconception. This offense is often confused with the administrative penalties for data protection. They are different levels that can run in parallel: the violation of personal data under article 269F is an offense investigated by the Fiscalía, whereas breach of the data protection regime (Ley 1581 de 2012) is penalized by the administrative authority. One and the same event —a leaked database— can trigger criminal liability for the perpetrator and, in addition, duties and possible penalties for the company that had custody of it.
Website impersonation to capture personal data, "phishing" (art. 269G)
Core conduct verb: to design, develop, traffic in, sell, execute, program or send. This is, in criminal-law terms, phishing. The offense is committed by anyone who, "with an unlawful purpose and without being empowered to do so, designs, develops, traffics in, sells, executes, programs or sends electronic pages, links or pop-up windows" in order to induce the victim to hand over their data. The penalty is 48 to 96 months of imprisonment and a fine of 100 to 1,000 SMLMV, and it is subsidiary ("provided the conduct does not constitute an offense punishable by a more severe penalty").
The provision includes two clauses that broaden its scope. The first imposes the same penalty for pharming: anyone who "modifies the domain name resolution system" so that the user arrives "at a different IP in the belief that they are accessing their bank or another personal or trusted site". The second increases the penalty "by one third to one half" if, in order to complete the offense, "the perpetrator has recruited victims into the chain of the offense" —which happens, for example, when third parties are used as "money mules" to receive the money—.
Example. You receive an email identical to your bank's with a link to a cloned page that asks for your username and password; or a pop-up window that mimics the company's portal in order to capture credentials. Whoever designed, programmed or sent that page commits the offense.
The common misconception. The most widespread belief is that "phishing is only an offense if someone falls for it". That is not true: the offense is complete by the mere act of creating or sending the fraudulent page, link or window, regardless of whether the victim hands over their data or not. Where the deception does end in a fraud —a transfer, a payment—, phishing usually concurs with the offenses against property in the second chapter.
The aggravating circumstances (art. 269H): why an attack from the inside weighs more
Article 269H does not create a new offense: it describes the aggravating circumstances that increase the penalties for all the preceding offenses "by one half to three quarters". Several point directly at internal and sector-specific risk, which makes them decisive for any organization:
- Where the attack falls on networks or systems belonging to the State or to official bodies, or to the financial sector, whether domestic or foreign.
- Where it is committed by a public servant in the exercise of their duties.
- Where the offender takes advantage of the trust placed by the holder of the information, or of a contractual relationship with them.
- Where the information is disclosed to another's detriment; where a benefit is obtained for oneself or for a third party; where terrorist ends are pursued or a risk is created for national security or defense; or where a third party acting in good faith is used as an instrument.
And there is an eighth scenario that appears in almost every corporate case: if the person who commits the conduct is the person responsible for the administration, handling or control of the information —a systems administrator, an IT contractor, a database manager—, in addition to the aggravated penalty they are subject to disqualification for up to three years from practicing professions related to information systems.
The practical reading is uncomfortable but clear: an attack from within is not a "minor" case. On the contrary, whoever had the most trust and the most access is the one the law treats with the greatest severity. That is why, when the suspect is someone from inside the house, the criminal exposure is the highest in the catalog, and the way the incident is documented —without confronting the suspected wrongdoer out of the blue— must be handled with care from the very first moment.
The two computer offenses against property: theft by computer means (269I) versus unconsented transfer of assets (269J)
Chapter II of Ley 1273 punishes computer attacks that strike at property. They carry the highest penalties and, in practice, they are the ones most argued over when a fraud has to be characterized.
Theft by computer and similar means (art. 269I). Liability falls on anyone who, "overcoming computer security measures", carries out the theft described in article 239 "by manipulating a computer system, an electronic or telematic system network or another similar means, or by impersonating a user before the established authentication and authorization systems". The provision refers to the penalties for qualified theft (hurto calificado) under article 240 of the Código Penal, which in its base form are 6 to 14 years of imprisonment. This is no accident: article 240 itself aggravates theft where it is committed "by violating or overcoming electronic or other similar security measures".
Unconsented transfer of assets (art. 269J). It punishes anyone who, "with intent to profit and by means of some computer manipulation or similar artifice, obtains the unconsented transfer of any asset to the detriment of a third party". The penalty is 48 to 120 months of imprisonment and a fine of 200 to 1,500 SMLMV, and it increases by one half where the amount exceeds 200 SMLMV. The same penalty falls on anyone who "manufactures, introduces, possesses or supplies" the program intended to commit that fraud "or an estafa" (the Colombian offense of criminal fraud by deception). The offense is subsidiary: it applies "provided the conduct does not constitute an offense punishable by a more severe penalty".
How they are told apart, and why it matters. The boundary between the two is thin and is often argued over in court. In general terms, 269I comes closer to the taking that characterizes theft —the person who overcomes the security measures and takes the asset as one who carries it off—, whereas 269J points to the fraudulent transfer of an asset by manipulating or deceiving the system. The difference is not academic: theft by computer means refers to penalties of 6 to 14 years, whereas the unconsented transfer starts at 48 months. In addition, since 269J is subsidiary, if the facts also amount to computer theft (a higher penalty), the characterization tends to shift toward 269I.
Concurrence with estafa. Where the fraud involves the deception of a person —and not only the manipulation of a machine—, the estafa of article 246 comes into play (32 to 144 months' imprisonment —the original text read 2 to 8 years, increased by art. 14 of Ley 890 de 2004— and a fine of 50 to 1,000 SMLMV). Deciding whether the case is computer theft, an unconsented transfer, estafa, or a concurrence of several of them is a technical decision that should be reviewed case by case, because the penalty at stake depends directly on that characterization.
From the real-world threat to the statutory offense: how what happens today translates
The threats that companies and individuals face today rarely fit into a single article. Translating them into statutory offenses is what makes it possible to file a proper criminal complaint and to size up what is at stake. These are the most frequent ones:
Ransomware. The hijacking of data typically combines the use of malicious software (art. 269E), computer damage (art. 269D) and, frequently, unauthorized access (art. 269A). The ransom demanded may additionally amount to extortion (art. 244 of the Código Penal: 192 to 288 months' imprisonment, following the reform of Ley 733 de 2002 and the increase under Ley 890 de 2004). The decision whether or not to pay —and how to document it— should not be taken without legal advice.
CEO fraud (or "BEC", business email compromise). The email that impersonates an executive in order to instruct an urgent payment usually combines impersonation and deception with the unconsented transfer of assets (art. 269J) and, depending on the case, estafa (art. 246). We address the purely financial component of these frauds in the analysis of corporate financial crimes.
Bank fraud and the emptying of accounts. Where the attacker, overcoming the security measures, transfers or withdraws your money, the conduct falls somewhere between theft by computer means (art. 269I, with the penalties for qualified theft) and the unconsented transfer of assets (art. 269J), depending on how it was carried out.
Identity impersonation. Using your data to authenticate before a system as if it were you fits within 269I (impersonation "before the authentication and authorization systems") and, depending on the case, within the violation of personal data (art. 269F) or unauthorized access (art. 269A) to the accounts affected.
Leaking and sale of databases. The removal, offering or sale of personal data is a violation of personal data (art. 269F); if there was a prior intrusion into the system, it concurs with unauthorized access (art. 269A).
Social engineering. It is not a statutory offense in itself, but the deception technique that opens the door to other offenses: it enables phishing (art. 269G), unauthorized access (art. 269A) or the violation of data (art. 269F).
The practical rule is that one and the same attack amounts to several offenses in concurrence, and it is that combined reading —not the technical label of the incident— that organizes both the criminal complaint and the defense. The table below summarizes the mapping:
| Real-world threat | How it works, in brief | Statutory offense(s) | Reference penalty |
|---|---|---|---|
| Phishing | Fake email or page that asks for passwords or data | Website impersonation (269G); if there is fraud, it concurs with 269J or 246 | 48 to 96 months (269G) |
| Pharming | Redirection of the domain to a fake "bank" website | Website impersonation, paragraph 2 (269G) | 48 to 96 months |
| Ransomware | Hostile encryption of data + ransom | Malicious software (269E) + computer damage (269D) + unauthorized access (269A); ransom: extortion (244) | 48 to 96 months each; extortion 192 to 288 months |
| Bank fraud / emptying of an account | Transfer or withdrawal by overcoming security measures | Theft by computer means (269I) or unconsented transfer (269J) | 269I: 6 to 14 years; 269J: 48 to 120 months |
| CEO fraud (BEC) | Email that impersonates an executive and orders a payment | Unconsented transfer (269J) + estafa (246); it usually begins with 269G | 269J: 48 to 120 months; estafa 32 to 144 months |
| Identity impersonation | They use your data to authenticate as you | Theft by computer means (269I) and/or violation of data (269F) and unauthorized access (269A) | Depending on the offense: from 48 months up to 14 years |
| Leak / sale of databases | Removal and commercialization of personal data | Violation of personal data (269F); with intrusion, 269A concurs | 48 to 96 months |
| Interception of communications | Capture of traffic or of corporate email | Interception of data (269C) | 36 to 72 months |
| Sabotage / deletion by an employee | Destruction or alteration of data from the inside | Computer damage (269D), aggravated under 269H | 48 to 96 months, increased by one half to 3/4 |
| Denial of service (DDoS) | Saturating the platform until it is taken offline | Obstruction of a system (269B) | 48 to 96 months |
Remember, in addition, that where the offense is not one of those in Título VII BIS but is committed using computer means, the use of technology operates as a circumstance of greater punishability (subsection 17 of article 58 of the Código Penal). In the Colombian criminal system, the digital dimension aggravates rather than mitigates.
What to do if you are a victim: preserving the evidence, filing a criminal complaint and the chain of custody
Preserve the digital evidence. Computer evidence is fragile: it is easily altered or lost, and one false move can make it useless as evidence. In the first hours it is advisable to isolate the compromised equipment from the network without shutting it down or "cleaning" it blindly, to avoid handling or forwarding files, to keep emails, messages and logs exactly as they are, and to keep a running record of who did what and at what time. The Código de Procedimiento Penal (Colombia's criminal procedure code, Ley 906 de 2004) recognizes the data message —email, internet traffic, electronic data interchange— as an item of physical evidence (article 275, subparagraph g). Its value depends on a correct chain of custody (article 254), which documents the identity, the original condition and every person who came into contact with the evidence. That is why the support of qualified forensic personnel is decisive from the outset.
File a criminal complaint with the competent authority. Computer crimes are investigated by the Fiscalía General de la Nación, which has units specialized in cybercrime, and as a rule they are heard by the municipal criminal court judges (subsection 6 of article 37 of the C.P.P., added by Ley 1273). As support, the Policía Nacional offers the CAI Virtual of the Centro Cibernético Policial (caivirtual.policia.gov.co), a channel available for reporting the case and getting guidance. Bring an orderly chronology of the facts and the evidence available: a well-built complaint speeds up the investigation; always keep the case file number (radicado).
Attend, in parallel, to your data protection duties. If personal data of clients or employees was compromised in the incident, duties before the administrative data protection authority may be triggered in addition to the criminal complaint. These are separate responsibilities and it is advisable to coordinate them. We set out the full route for a company that has already been a victim —containment, communication and claim— in the company as the victim of a crime.
Digital evidence and its challenges
The great advantage of computer crime for an investigation is that almost everything leaves a trace; its great difficulty is that the trace is volatile and easy to contaminate. An email can be forwarded and lose its headers; a disk can be overwritten on restart; a screenshot, on its own, proves little if there is no way to establish where it came from and that no one altered it.
The Código de Procedimiento Penal requires items of physical evidence to be authentic —"detected, fixed, collected and packaged in a technical manner, and subjected to the rules of the chain of custody" (article 277)— and it requires them to be weighed according to their "lawfulness, authenticity, submission to the chain of custody and current degree of scientific or technical acceptance" (article 273). In practice, this means that digital evidence counts for how it was collected and preserved, not only for what it shows.
Several consequences follow for you: a screenshot or an email work as a starting point, but they gain evidentiary weight when they are preserved in a technical manner (with their metadata, their headers, forensic copies of the device); the evidence must be obtained lawfully —evidence obtained in breach of fundamental rights may end up excluded—; and traceability matters as much as content. Working hand in hand with a computer forensics expert and a lawyer from day one is what keeps a decisive piece of evidence from collapsing because of the way it was handled.
Prevention: reducing the risk before the next attempt
A good part of the damage —and of the exposure— is avoided before the attack. Prevention is not only a matter of technology; it is also a matter of organization, contracts and culture. Without claiming to exhaust the subject, these lines of work concentrate most of the risk:
- Access management. Each person should hold only the permissions their role requires, with immediate deactivation of credentials when someone leaves. Many cases of unauthorized access (269A) arise from access rights that were never closed.
- Segregation and traceability. Logs that make it possible to reconstruct who did what and when. Without that traceability, proving an attack from within is much harder.
- Tested backups. Frequent, isolated and verified backups: they are the best defense against ransomware, because they take bargaining power away from the attacker.
- Clauses and policies. Confidentiality agreements, acceptable use and data processing policies, and incident response protocols known to the team.
- Training. Most attacks come in through a person, not through a machine: training the team to recognize phishing and social engineering reduces the risk more than any tool.
We set out that preventive work in more detail, together with the criminal liability of the company and of its officers, in corporate criminal compliance.
What NOT to do in an incident
As important as knowing what to do is avoiding the mistakes that ruin a case. Faced with a cyber incident, try not to fall into the following:
- Do not delete "to start from scratch". Formatting, reinstalling or "cleaning" the equipment destroys the evidence and can leave you with no way to establish what happened. What looks like tidying up is, in reality, a loss of evidence.
- Do not pay the ransom without filing a criminal complaint and without legal advice. Paying finances the attacker, does not guarantee that the information will be returned and does not extinguish the offense. The demand for a ransom may constitute extortion (art. 244), and the decision to pay has implications that are best assessed beforehand.
- Do not handle the compromised devices. Restarting blindly, installing or uninstalling programs, or moving files alters metadata and breaks the chain of custody. Isolate the equipment, but do not work on it without technical support.
- Do not confront the suspected insider out of the blue. Alerting the person under suspicion before the evidence is secured makes it easier for them to erase traces. First you preserve; then you act.
- Do not make the details public before filing a criminal complaint. Communicating an incident badly can hinder the investigation and worsen the reputational damage.
- Do not reply through the same channel as the attack. Replying to the fraudulent email or clicking "to see what happens" only hands more information to the attacker.
Common myths about computer crimes
Mistaken ideas circulate around these offenses that lead people not to file a complaint or to mishandle an incident. These are some of the most common:
- "If no money was stolen from me, there was no offense." False. Unauthorized access (269A), interception (269C) or the violation of data (269F) are complete without any gain and without any loss of property.
- "Phishing is not an offense until someone falls for it." False. Article 269G punishes creating or sending the fraudulent page, link or window, whether or not the victim falls for it.
- "Logging in with the password a coworker gave me is nothing." With qualifications: accessing a system "outside what was agreed" may amount to unauthorized access (269A), even if you were given the password.
- "Since the attack came from abroad, nothing can be done." Colombian law applies and there are channels for filing complaints and for cooperation. Cross-border prosecution is complex, but the complaint is the first step and it often reveals local collaborators.
- "Paying the ransom closes the matter." False. It does not extinguish the offense, it does not guarantee the recovery of the data and it does not relieve you of filing a complaint; it can also feed future attacks.
- "A screenshot is enough as evidence." With qualifications: it is a valid starting point (the data message is an item of physical evidence, art. 275), but its strength depends on authenticity and on the chain of custody (arts. 254 and 277).
- "An attack from within is the mildest case." On the contrary: where it is committed by the person who administers the information or who abuses trust, the penalty is aggravated (269H), even with professional disqualification.
Checklist for a cyber incident
If you are going through an incident right now, this list orders the first decisions. It does not replace legal advice, but it helps you not to lose what will later prove decisive:
- Isolate the compromised equipment from the network, without shutting it down or formatting it blindly.
- Open a running record: note the date, the time and the person responsible for each action from minute one.
- Keep emails, messages, logs, screenshots and receipts exactly as they are; do not forward or modify them.
- Identify what information or asset was affected and estimate its approximate value.
- Put together an orderly chronology of the facts, with who, when and how.
- Change credentials and close the breach (patches, access review, session revocation) once the evidence has been preserved.
- File a criminal complaint with the Fiscalía or the CAI Virtual of the Centro Cibernético Policial and keep the case file number.
- If personal data was compromised, assess your duties before the data protection authority.
- Seek forensic and legal support from day one; do not negotiate with the attacker on your own.
Identifying the correct statutory offense, sizing up the penalty at stake and preserving the evidence are decisions that shape the outcome of a cybercrime case, and they are best taken with support from day one. If you or your company are facing an incident of this kind, at Cafore Abogados you can review your situation with a criminal lawyer at 313 8411825.
Laws and case law cited
- Ley 1273 de 2009 — created Título VII BIS of the Código Penal, "De la protección de la información y de los datos", a new protected legal interest; it added subsection 17 to art. 58 and subsection 6 to art. 37 of the C.P.P. Source
- Art. 269A of the Código Penal — unauthorized access to a computer system; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269B of the Código Penal — unlawful obstruction of a computer system or telecommunications network; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269C of the Código Penal — interception of computer data; 36 to 72 months' imprisonment. Source
- Art. 269D of the Código Penal — computer damage; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269E of the Código Penal — use of malicious software; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269F of the Código Penal — violation of personal data; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269G of the Código Penal — website impersonation to capture personal data (phishing), including pharming; 48 to 96 months' imprisonment and a fine of 100 to 1,000 SMLMV. Source
- Art. 269H of the Código Penal — aggravating circumstances; the penalties are increased by one half to three quarters, with disqualification for up to 3 years for the person responsible for administering the information. Source
- Art. 269I of the Código Penal — theft by computer and similar means; it refers to the penalties for qualified theft (art. 240). Source
- Art. 269J of the Código Penal — unconsented transfer of assets; 48 to 120 months' imprisonment and a fine of 200 to 1,500 SMLMV, increased by one half if the amount exceeds 200 SMLMV. Source
- Art. 239 of the Código Penal (Ley 599 de 2000) — theft; 32 to 108 months' imprisonment (the base conduct to which art. 269I refers). Source
- Art. 240 of the Código Penal (Ley 599 de 2000) — qualified theft; 6 to 14 years' imprisonment in its base form, the penalties to which art. 269I refers; subsection 4 aggravates it for "violating or overcoming electronic security measures". Source
- Art. 244 of the Código Penal — extortion; 192 to 288 months' imprisonment (Ley 733 de 2002, art. 5; Ley 890 de 2004, art. 14); relevant where the ransomware ransom coerces the victim. Source
- Art. 246 of the Código Penal — estafa; 32 to 144 months' imprisonment (the original text read 2 to 8 years, with the increase under Ley 890 de 2004) and a fine of 50 to 1,000 SMLMV; it may concur with CEO fraud and the unconsented transfer of assets. Source
- Art. 58, subsection 17, of the Código Penal — circumstance of greater punishability where computer, electronic or telematic means are used to commit the offense (added by Ley 1273 de 2009). Source
- Art. 37, subsection 6, of the Código de Procedimiento Penal (Ley 906 de 2004) — jurisdiction of the municipal criminal court judges over the offenses of Título VII BIS (added by Ley 1273 de 2009). Source
- Art. 254 of the Código de Procedimiento Penal (Ley 906 de 2004) — chain of custody; it preserves the authenticity and integrity of the evidence. Source
- Art. 273 of the Código de Procedimiento Penal — criteria for assessing the evidence: lawfulness, authenticity, chain of custody and scientific or technical acceptance. Source
- Art. 275, subparagraph g), of the Código de Procedimiento Penal — recognizes the data message (email, internet, EDI) as an item of physical evidence, governed by Ley 527 de 1999. Source
- Art. 277 of the Código de Procedimiento Penal — authenticity of items of physical evidence; it requires technical collection and submission to the chain of custody. Source
- Ley 733 de 2002 (art. 5) — set the penalty for the extortion of art. 244 at 12 to 16 years, the basis of the range in force today. Source
- Ley 890 de 2004 (art. 14) — general increase of the penalties in the Special Part: one third for the minimum and one half for the maximum. Source
- Ley 1581 de 2012 — administrative regime for the protection of personal data, a route separate from the criminal one. Source
- Corte Suprema de Justicia, Sala de Casación Penal, SP2685 de 2022 — unauthorized access to a computer system (Código Penal, art. 269A). Official text.
- Corte Suprema de Justicia, Sala de Casación Penal, SP1245 de 2015 — theft by computer means (art. 269I) versus the electronic estafa (art. 269J). Official text.
- Corte Suprema de Justicia, Sala de Casación Penal, SP2699 de 2022 — computer damage (art. 269D): the element of unlawfulness. Official text.
- Corte Suprema de Justicia, Sala de Casación Penal, SP903 de 2024 — unauthorized access and computer damage; the concept of «computer system». Official text.


