Skip to content

Specialist Cybercrime Attorneys in Spain

English-speaking cybercrime defence attorneys across Spain. Hacking, phishing, ransomware, DDoS. IP attribution challenges & chain of custody audits.

Cybercrime covers conduct such as unlawful access to computer systems or hacking (Article 197 bis of the Spanish Criminal Code (CP)), the discovery and disclosure of secrets (Article 197 CP), computer damage or ransomware (Article 264 CP), and computer fraud (Article 249.1.a CP). Penalties range from 6 months' imprisonment for unlawful access to 5 years for disseminating the secrets discovered (Article 197.3 CP), and up to 8 years for the most serious forms of computer fraud (Article 250.2 CP) or computer sabotage (Article 264 bis.2 CP). With more than 15 years of experience, we work the electronic evidence, the digital chain of custody, and the attribution of authorship to dismantle the prosecution's case.

You are under investigation for a cybercrime: what it means and what happens next

These proceedings rarely start with an arrest: they start with a request to the network operator, a device image or a complaint from the injured company, and the suspect finds out weeks later when the court summons arrives. The applicable offence depends on the conduct. Unauthorised access to an information system by breaching its security measures carries 6 months to 2 years' imprisonment (Art. 197 bis 1 CP). Seriously deleting or altering another party's data, programs or electronic documents carries 6 months to 3 years, rising to 2 to 5 years plus a fine where the circumstances of Art. 264.2 CP apply. And obtaining a non-consented transfer of assets through computer manipulation is punished as fraud, with 6 months to 3 years (Art. 249.1.a CP).

What to do (and what not to do) before making a statement

  • Do not touch the devices or delete anything. Deletion shows up in the forensic image and is read as concealment. It also destroys the metadata that usually proves the access was authorised or that several people used the machine.
  • Ask for the digital chain of custody from day one. Hashes of the copies, the imaging record, who seized the device and when. A broken chain is the most effective challenge in these cases, and it can only be raised if the paperwork is requested in time.
  • Do not reply in writing to the injured company. Self-drafted explanatory emails are later produced as an admission and, in computer offences, they usually supply precisely the technical detail the prosecution was missing.
  • Gather the evidence of your authorisation to access. The contract, the acceptable-use policy, credentials assigned to you, internal tickets or the email asking you to act. Authorisation, even informal, rules out Art. 197 bis CP.

Cybercrime: Concept, Types, Penalties and Digital Defence (Arts. 197-264 ter CP)

Cybercrime covers the set of offences committed through information and communication technologies, regulated dispersedly in the Spanish Criminal Code: discovery and disclosure of secrets (Arts. 197-201 CP), illicit access to computer systems (Art. 197 bis), computer damage and system obstruction (Arts. 264-264 ter), computer fraud (Art. 249.1.a CP), banking fraud and phishing, digital identity theft (Art. 401 CP), threats and harassment by digital means (Arts. 169-172 ter), child pornography (Art. 189 CP) and grooming (Art. 183). Supreme Court doctrine has consolidated criteria on electronic evidence, digital chain of custody, validity of forensic dumps and constitutional limitations on technological interventions. The protected legal interest is plural: privacy, secrecy of communications, integrity of computer systems, patrimony and collective security.

The commission modalities have proliferated at the pace of technology. Hacking covers unauthorized access to systems by breaching security measures, creation or distribution of exploits and introduction of backdoors. Phishing and its variants (spear-phishing, smishing, vishing, spoofing, CEO fraud) constitute technical fraud combined with social engineering, where "banking mules" are frequently accused as necessary cooperators. Ransomware and DDoS attacks are computer damage crimes that can affect critical infrastructure. Cryptocurrency fraud (rug pulls, fraudulent ICOs, crypto Ponzi schemes, mixing) requires specialized blockchain traceability. Paradigmatic current cases are SIM swapping, voice-cloning deepfakes, AI-driven digital cloning, labour intrusions (corporate espionage Art. 278 CP) and attacks on financial, health and energy sector infrastructure.

The statutory penalties are severe and modulated by type and aggravators. Illicit access to systems (Art. 197 bis CP) carries 6 months to 2 years' prison, and the penalty one degree higher if committed within a criminal organisation or group (Art. 197 quater CP). Disclosure of secrets (Art. 197 CP) carries 1 to 4 years' prison and a fine in its basic form; 2 to 5 years if the data or images are disseminated (Art. 197.3), the upper half of the range if sensitive data or a minor victim are involved (Art. 197.5), and 4 to 7 years where there is a profit motive and sensitive data are affected (Art. 197.6). Computer damage (Art. 264 CP) carries 6 months to 3 years' prison; aggravated (Art. 264.2), 2 to 5 years plus a fine, including where critical infrastructure is affected; obstructing or interrupting a system (Art. 264 bis) carries 6 months to 3 years, and 3 to 8 years with the same circumstances. Computer fraud (Art. 249 CP) carries 6 months to 3 years' prison, and 1 to 6 years where an aggravating circumstance of Art. 250 applies. Identity theft (Art. 401 CP), 6 months to 3 years' prison. Grooming carries 1 to 3 years' prison or a fine (Art. 183.1 CP), and child pornography 1 to 5 years, rising to 9 in the aggravated cases (Art. 189 CP). Additionally, courts may impose special disqualification from the profession or trade directly linked to the offence (Art. 56 CP), forfeiture of equipment and servers and civil compensation for patrimonial and reputational damage.

The technical defence rests on four consolidated axes. First, IP attribution challenge: case-law recalls that an IP address identifies a connection, not necessarily the user behind the keyboard; shared WiFi networks, dynamic IPs, VPN/Tor use and device malware sow reasonable doubt. Second, digital chain of custody: forensic dump must be performed with hash function (SHA-256, MD5) certifying integrity under ISO 27037 standard; any breach undermines the reliability of the evidence and allows it to be challenged (exclusion under Art. 11.1 LOPJ is reserved for evidence obtained in breach of fundamental rights). Third, absence of intent: in the "banking mule" deception must be proven (false job offer, fraudulent loan) that excludes criminal will; in cases of involuntary file download (cache, Telegram groups, unopened ZIP) knowledge must be excluded. Fourth, nullity of technological interventions: police use of trojans (Art. 588 septies LECrim), IMSI-catcher interventions, remote searches and requests to Facebook, Google or Microsoft require reasoned and proportionate judicial authorization; excesses open the door to evidence inadmissibility.

In current forensic practice we observe exponential growth of cybercrime. The Budapest Convention (Council of Europe Cybercrime Convention 2001 and its Second Additional Protocol 2022), the NIS2 Directive on cybersecurity, the EU AI Act (Regulation 2024/1689), the MiCA Regulation on crypto-assets, Organic Law 1/2025 on Justice Service Efficiency and Supreme Court case-law on electronic evidence configure a rapidly evolving regulatory framework. The UDEF, the Technology Investigation Brigade (BIT) and the Civil Guard's telematic crime teams have advanced forensic capabilities. At Alonso Sala, with more than 15 years of experience, we approach each case coordinating computer forensic experts, blockchain and crypto traceability experts, chain-of-custody specialists and, where necessary, AI and deepfake experts. We connect with disclosure-of-secrets crimes and data-protection compliance when GDPR/LOPDGDD violation concurs.

Our Cyber-Defence Strategies

IP Attribution

IP is not an ID. We challenge the automatic connection judges make between "Line Holder" and "Crime Author". We demonstrate third-party access possibilities (open WIFI, malware, shared use) to sow reasonable doubt.

Hash Integrity

Pure technique. If the "Hash" (cryptographic digest) of the police file does not match exactly the seized original, it means it has been altered. We challenge the reliability of poorly preserved digital evidence and, where it was obtained in breach of fundamental rights, seek its exclusion.

"Mule" Defence

For those accused of receiving fraudulent transfers (Phishing). We prove they were victims of deceit ("social engineering") and acted without intent, believing they were doing a lawful job. We turn the accused into a victim.

WhatsApp Challenge

Screenshots are fragile evidence. If the accusation relies on screenshots, we challenge their authenticity and demand the metadata or the original device: once challenged, it is for the party relying on them to prove they have not been tampered with.

ART. 197 BIS Hacking & Computer Intrusion

The Criminal Code harshly punishes "unauthorized access" to information systems by breaching security measures. It is the "Hacker's" crime.

Access

Entering is enough. No need to steal data. Merely bypassing the password is a crime

Facilitation

Beware: creating or distributing hacking programs (exploits, keyloggers) is also a crime

Companies

If the victim is a company, the access is equally an offence, with the same penalties. Art. 200 CP also extends this chapter to the confidential data of legal entities

ARTS. 248-249 CP Online Fraud: Phishing & Spoofing

Cyber fraud is the fastest-growing crime. From "Phishing" (impersonating a bank via email) to "Spoofing" (faking caller ID or SMS to appear legitimate). We defend victims who lost their savings demanding bank civil liability, and accused "money mules" who acted without intent.

ART. 172 TER Cyberstalking & Privacy

Harassment through social media, WhatsApp, or fake profiles ("Catfishing") disrupts the normal course of victims' daily lives. We secure digital evidence through notarial acts and technological certifiers. We also address crimes against privacy, such as "Sexting" or unauthorized access to devices.

Digital Typologies

Why Alonso Sala in Cybercrime?

Because we do not delegate the technical part. Our lawyers work side by side with computer engineering experts. In court, citing laws is not enough; you have to know how to explain to the Judge what a VPN, a Hash, or a Man-in-the-Middle attack is.

We have been defending both ethical 'hackers' unjustly accused and companies victims of sabotage for years. We know both sides of the digital trench.

  • Network of Computer Forensic Experts.
  • Digital Chain of Custody Specialists.
  • Experience in crypto scams and blockchain.
  • Technical defence in National Court.

Cybercrime in Spain: Hacking, Phishing & Digital Fraud — Defence Guide

Cybercrime encompasses illegal access to computer systems (Art. 197 bis CP), computer damage and ransomware (Art. 264 CP), phishing and digital fraud (Art. 249.1.a CP), and the production or distribution of hacking tools (Art. 197 ter). Spain's prosecution of cybercrime has intensified dramatically, with specialised units in the National Police (BIT) and Guardia Civil (GDT) leading investigations. Defence requires a unique combination of criminal law expertise and advanced technical knowledge.

Penalty Table: Cybercrime

OffenceArticleDescriptionPenalty
Illegal access to systemsArt. 197 bisUnauthorised access breaching security measures6 months – 2 years
Interception of dataArt. 197 bis.2Intercepting non-public data transmissions3 months – 2 years
Production/supply of hacking toolsArt. 197 terCreating or distributing tools designed for cybercrime6 months – 2 years
Computer damage (basic)Art. 264.1Deleting, damaging or making data inaccessible6 months – 3 years
Aggravated damage (critical infrastructure)Art. 264.2Affecting essential services or critical infrastructure2 – 5 years prison
Cyber fraud (phishing)Art. 249.1.aIT manipulation to obtain unlawful transfer of assets6 months – 3 years

Key Defence Strategies

IP Attribution Challenge

An IP address does not identify a person. Shared Wi-Fi networks, VPNs, Tor exit nodes and NAT configurations mean multiple users may share one IP. The prosecution must prove the accused was the actual user at the relevant time.

Chain of Digital Custody

Digital evidence is extremely fragile. If the police failed to image the hard drive with a write-blocker, if hash values don't match, or if evidence was handled improperly, the defence can seek exclusion of the entire digital evidence chain.

Authorised Security Testing

Ethical hacking and penetration testing carried out with the system owner's authorisation is legal. If the defendant had a written engagement contract, bug bounty agreement or responsible disclosure policy, there is no criminal offence.

Lack of 'Breaching Security Measures'

Art. 197 bis requires that security measures were breached. If the system had no password, no firewall, or the access point was public, the element of 'breaching security' may be absent, negating the offence.

Key Case Law

Supreme Court doctrineElements of illegal access (Art. 197 bis)

The Supreme Court confirmed that 'access' requires effectively entering the system, not merely attempting it. The prosecution must prove: (1) access occurred, (2) it was unauthorised, and (3) security measures were breached. Port scanning alone does not constitute the offence.

Supreme Court doctrineRansomware as combined offence

The Court ruled that ransomware attacks may constitute a concurrent offence of computer damage (Art. 264) and extortion (Art. 243 CP). The encryption of data satisfies the 'damage' element even if data is technically recoverable upon payment.

Supreme Court doctrinePhishing and the 'money mule' defence

In phishing operations, the Court distinguished between the organiser and the 'money mule' (account holder). The mule's liability depends on proof of knowledge that the funds were illicit. Wilful blindness may suffice, but mere negligence does not.

FAQs

Is an IP address enough to convict me?
Absolutely NOT. The Supreme Court has reiterated that an IP identifies a phone line, not the physical person behind the keyboard. If it's a dynamic IP or shared Wi-Fi, reasonable doubt is huge. Our defence demands additional authorship proof (hard drive analysis, schedules, witnesses).
What if police seize my laptop?
Crucial rule: never provide the password voluntarily (no one is obliged to self-incriminate). Contact Alonso Sala immediately. We must verify if the hard drive dump respected the 'hash' (integrity code) and chain of custody. If the chain of custody is broken, the reliability of the evidence is compromised and it can be challenged.
Am I liable if I only received money and forwarded it ('Mule')?
This is the 'Money Mule' figure. Police often accuse mules as necessary collaborators in fraud or money laundering. Our defence proves absence of intent: you were deceived (fake job offer) and believed to act legitimately. No criminal intent, no crime.
Is spying on my partner's WhatsApp a crime?
Yes, and serious. Discovery and revelation of secrets (Art. 197), punished with 1-4 years prison. Even if nothing is shared, mere unauthorized access violates constitutional privacy.
What is 'computer damage' crime?
Deleting files, formatting drives, or introducing viruses (sabotage). The basic offence requires a serious result (6 months to 3 years' prison); where the damage is especially serious or seriously disrupts essential public services, the penalty is 2 to 5 years plus a fine (Art. 264 CP).
What if servers are abroad?
Police use international letters rogatory to ask Facebook, Google, etc. If the Spanish court order doesn't meet destination country requirements (e.g., USA, Ireland), that info can be voided as evidence.
Is using VPN or Tor a crime?
No, anonymization tools are perfectly legal. Only criminal if used to commit offences. Merely using Tor cannot be used as an indication of criminality.
What is CEO fraud?
Sophisticated scam impersonating a CEO to ask for urgent transfer. If you are the deceived accountant, you are a victim. If accused, we prove if real identity theft occurred.
Can I be tracked if I deleted everything?
'Logical deletion' doesn't physically remove data. Forensic experts recover files months later. Definitive removal needs 'secure wipe'. Still, ISP logs are kept by law for 12 months.
What is 'Grooming'?
Cyber-harassment of minors for sexual purposes. An adult gains minor's trust online to get images or meetings. Highly prosecuted. Where the contact is with a child under 16 and seeks a meeting backed by acts of approach, it carries 1 to 3 years' imprisonment or a fine of 12 to 24 months (Art. 183.1 CP); where it seeks pornographic material, 6 months to 2 years (Art. 183.2). A special disqualification from working with minors is also imposed, lasting longer than the sentence itself (Art. 192.3 CP).
Is downloading pirated movies a crime?
In Spain, private download without profit is NOT a criminal offence (maybe civil). It is only a criminal offence where there is intent to obtain a direct or indirect economic benefit, to the detriment of a third party (Art. 270 CP): for example, selling copies or running an ad-supported link site.
Can they record me with a trojan (cam/mic)?
Police CAN use spy software (trojans) for serious crimes, but only with very specific judicial authorization. If they exceed or lack permission, recordings are void.
What is a DDoS attack?
Denial of Service. Saturating a web to crash it. It's a computer damage crime. Often committed via 'botnets' (zombie computer networks).
Company liability if hacked?
If no adequate security, GDPR fines apply, but rarely criminal unless intentional self-leak.
What is 'Sim Swapping'?
Duplicating victim's SIM to get bank SMS and empty account. Mixed scam: technical + social engineering against telco.
How to defend child porn (download) case?
We analyse if download was automatic (browser cache, pop-ups, WhatsApp groups). Intent requires 'knowing and wanting' the file. Involuntary download is not a crime.
Are screenshots valid proof?
They can be, but they are fragile evidence because they are easy to fake. If the other party challenges their authenticity, whoever submits them must prove it, usually with an expert report on the device and metadata, a comparison with the original phone or a notarial record.
What is crypto scam?
Fake investment promises. Issue is tracing money on Blockchain to an Exchange identifying the holder. We work with crypto-traceability experts.
When does cybercrime expire?
Depends on penalty. Minor (scams <400€) 1 year. Serious (attacks, secrets) 5-10 years. Internet doesn't forget, but law sets time limits.
What is 'Catfishing' or online identity theft?
Creating fake social media profiles impersonating someone else. Where the profile uses another person's image and causes them harassment, intimidation or humiliation, it is the offence in Art. 172 ter.5 CP (3 months to 1 year's prison or a fine of 6 to 12 months). If the offender actually assumes the other person's identity to exercise their rights, it may be usurpation of civil status (Art. 401 CP), and fraud if used to deceive and obtain money. Key is proving economic or moral damage.

Cybercrime and Digital Impersonation Defence

Cybercrimes are the fastest-growing criminal category. Defence requires technical mastery of digital evidence and case law on the validity of evidence obtained from private systems.

Cybercrime Modalities

Specialized defence in each type of cybercrime and computer crime:

All pages in this practice area

Need urgent criminal defence?

Contact our specialist criminal defence lawyers. We evaluate your case confidentially.

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Do you need specialised legal assistance?

The judicial system is complex. We have the criminal-law specialisation and technical resources required to take on the defence.