From the day someone got into your email without permission, two clocks are running, and only one of them leaves you any room. The criminal clock runs for five years, because unauthorised access to an information system under article 197 bis of the Spanish Criminal Code carries six months to two years in prison and offences with that penalty become time-barred after five years under article 131. The period runs from the day of the access and, if the intruder stayed inside reading or forwarding your mail, from the day he stopped, because article 132 starts the count when the unlawful situation ends. Once that period expires, criminal liability is extinguished and no conviction is possible however obvious the culprit.
The other clock appears in no statute and is the one that actually decides most of these cases. The records that identify the perpetrator (IP addresses, devices, connection times) are kept for a limited time. Telecommunications operators are required by Law 25/2007 to retain connection data for twelve months, but the activity history your email provider shows you depends on each company’s policy and is often measured in weeks. A complaint filed late reaches a court that can no longer ask anyone for the data that would have pointed to the perpetrator.
What the Criminal Code says when someone gets into your account
The question I am asked most often is whether there is an offence when the intruder took nothing. There is. Article 197 bis punishes anyone who, bypassing the security measures put in place to prevent it and without authorisation, accesses all or part of an information system or remains in it against the will of the person entitled to exclude him. A password-protected account is an information system and the password is the security measure. There is no need for data to have been stolen, published or any financial loss caused; the offence is complete on entry. The same applies to an email account, a social media profile, cloud storage or another person’s computer.
If he also read your messages, the conduct falls under article 197.1, which punishes anyone who seizes email messages or intercepts communications in order to discover secrets or violate another person’s privacy, with one to four years in prison and a fine of twelve to twenty-four months. If what he read or copied was passed on to third parties, article 197.3 raises the penalty to two to five years in prison. If he deleted emails or files or left the account unusable, article 264 comes into play, punishing computer damage with six months to three years in prison where the result is serious. If he used the access to order transfers or purchases, that is in addition computer fraud under articles 248 and 249, carrying six months to three years in prison. And whoever builds or sells the program, or supplies the password used to get in, is liable under article 197 ter.
| Conduct | Article of the Criminal Code | Penalty |
|---|---|---|
| Entering or remaining in another person’s account or system without authorisation | 197 bis | Six months to two years in prison |
| Seizing emails or intercepting communications to discover secrets | 197.1 | One to four years in prison and a fine of twelve to twenty-four months |
| Disclosing or passing on to third parties what was discovered | 197.3 | Two to five years in prison |
| Deleting, altering or rendering inaccessible data or files, with serious result | 264 | Six months to three years in prison |
| Transfers or purchases made through computer manipulation | 248 and 249 | Six months to three years in prison |
Two points change many cases. Knowing the password does not authorise its use. The most common scenario in our practice has a perpetrator with a name and surname, a partner, an ex-partner, a business partner or an employee who knew the password or guessed it, and the courts have taken the view that logging in with a password one is not authorised to use also bypasses the security measure. The second point is that the offences in the chapter on discovery and disclosure of secrets are only prosecuted if the injured party files a complaint (article 201 of the Criminal Code), unless they affect the general interest or a plurality of people. Nobody will open an investigation on your behalf, and your later forgiveness extinguishes the criminal action. The decision to report is yours and is best taken knowing what lies behind it.
What is really at stake when someone gets into your email
Email is the reset key for everything else. Whoever controls it can request a new password from the bank, from Amazon, from social networks or from your company’s domain registrar and receive the reset links himself. He can create an invisible forwarding rule and keep reading your messages months after you have changed the password. He can write to your contacts asking for money in your name, send your clients an invoice with a different account number or threaten to publish what he has found. If that last one is your situation, I explained on the blog what to do when you face threats or coercion.
Recovering access is the first step and by no means the last. The work begins once the email is yours again and it has three fronts, the evidence that identifies the perpetrator, the money and contracts that have moved through your account, and the consequences of what others have done believing it was you. Our firm acts for both prosecution and defence in cybercrime matters, and the first thing we do in a case like this is put those three fronts in order before the evidence disappears.
The first hours, what to keep before changing anything
The signs tend to be the same. Contacts receiving messages you did not send, login alerts from a city or device you do not recognise, emails showing as read without you having opened them, a password that suddenly fails, a recovery phone number or email address that is not yours, forwarding rules or filters you did not create. Services such as Have I Been Pwned let you check whether your address appears in known data breaches, which gives a clue as to how he got in, although it does not replace the rest.
The instinct is to change the password immediately, and you should, but five minutes beforehand it is worth fixing what is in front of you. Take screenshots, with the date and time visible, of the recent activity panel showing IP addresses, devices and connection times; of the forwarding rules and filters before deleting them; of the sent folder with the messages you did not write; of the altered recovery details. Do not delete the emails the intruder sent or the original phishing email if there was one, because its headers contain the route by which it arrived. Keep the provider’s security notifications. If you suspect your computer or phone is infected, do not wipe it yet and use another device to change your banking credentials.
A screenshot you took yourself is evidence, but the other side can argue it is incomplete or has been tampered with. For it to hold up in court it is backed by a report from a digital forensic expert, who documents where each item comes from and certifies it has not been altered, or by a notarial deed recording the content at that moment. Expert evidence is also the route by which, with judicial authorisation, the provider and the operator hand over the full access records. When to commission that report and what it should cover is a decision we take with the client depending on the objective, because not every case needs it and in those that do it is the piece that holds up the prosecution.
There are also things you should not do. Do not write to the suspect if you have one, because it tips him off to delete whatever he has. Do not pay any ransom or respond to extortion. Do not call the phone numbers or click the links in any «security alert» email, which are frequently the second blow of the same scam.
Where and how to report it in Spain
The complaint can be filed at any National Police station, at a Guardia Civil post, at the duty court or with the Public Prosecutor. The first two have units dedicated to cybercrime which end up carrying out the technical investigation. Online reporting exists for some offences, but it requires ratification in person and, when there is technical documentation to submit, the useful course is to file in writing with the evidence attached, so that the court can request the records from day one. INCIBE’s 017 helpline provides free technical help, but it is not a criminal complaint. When a lawyer is involved, the alternative is a querella, which allows the investigative steps you want carried out to be proposed from the outset.
As to the place, the Supreme Court applies the ubiquity rule to these offences, so the court of the place where the result occurred may hear the case, which in practice means the victim’s home district. The fact that the perpetrator is in another province or another country does not oblige you to report it there.
After the complaint, the investigating court writes to the email provider and the operators to identify the holder of the connections. If the trail ends at a Spanish line, that person is summoned to give evidence as a suspect. If it ends at a foreign server or a VPN, international cooperation is needed and the procedure drags on. One has to be honest about the real chances of identification. When the perpetrator is someone close to you, the identification rate is high because the connection usually comes from his home or his phone. When it is an anonymous attacker operating from abroad, the case frequently ends in a provisional dismissal, which does not close the matter for good and allows it to be reopened if new information emerges. That complaint, dismissed or not, remains the document you will need before the bank, the insurer, the companies that contracted in your name and the debtor registers.
The money and the damage, who you claim against
It depends on what moved through your account. If transfers were ordered from your online banking using your email, payment services regulation requires the bank to refund unauthorised transactions, with exceptions that turn on your own conduct. How that claim is framed and how an accusation of negligence is rebutted is the lawyer’s job, and the blog has two articles that map the ground, one on a bank refund after phishing and another on Bizum scams and what to do.
If what happened were purchases in a shop or platform with a stored card, the claim goes against the platform and against the card issuer for unauthorised payment. If the loss is the damage itself, deleted files, business downtime or the disclosure of private information, the debtor is the perpetrator, and that civil liability arising from the offence is claimed within the criminal proceedings themselves under articles 109 and following of the Criminal Code. If the case is dismissed without identifying the perpetrator or you prefer the civil route, a damages claim through the juicio verbal procedure covers amounts up to 15,000 euros, a threshold set by Royal Decree-Law 6/2023.
Against the email or hosting provider there is only a claim where the access was due to a breach on their side, for instance a mass leak of credentials, and in that case the basis lies in data protection law, which grants compensation to anyone who suffers damage from unlawful processing. When the intruder got in because you typed your password into a fake website, that route does not exist.
What has been done in your name
Identity theft has no offence of its own in the Spanish Criminal Code. Article 401 punishes the usurpation of civil status, but it requires assuming another person’s personality in full, and sending emails signed with your name rarely reaches that threshold. Whatever the intruder does with your account is prosecuted as fraud, unauthorised access or forgery depending on the case, and he is the one criminally liable. You do not answer for emails that left your account against your will, because there is no offence without intent or negligence, and civil liability towards a contact who paid the fraudster would require proof of negligence on your part, something very remote for a private individual.
What does protect you is the date. Warning your contacts as soon as you know, through a channel other than the compromised email, and keeping proof of that warning and of the complaint fixes the moment from which you no longer controlled the account, and that closes off any later argument. If your email has been used to open accounts, sign up for services or finance purchases in your name, the contract is void for lack of consent, but the company will not know that until you prove it, and the document that proves it is the complaint. If you end up in a debtor register for a debt that is not yours, the way out runs through data protection law and, again, through having reported the facts on an earlier date.
If the email account belongs to the business
When the hacked account is a professional one, the General Data Protection Regulation and Organic Law 3/2018 are added to the above. A third party’s access to a mailbox containing data on clients, employees or suppliers is a security breach, and article 33 of the Regulation requires it to be notified to the Spanish Data Protection Agency within seventy-two hours of becoming aware of it, unless it is unlikely to pose a risk to those affected. If the risk is high, article 34 further requires the affected individuals to be informed without undue delay. Doing it late or not at all is a sanctionable infringement independent of the hack, and the assessment of whether the breach reaches that threshold must be documented even if the conclusion is that notification is not required.
The most damaging scenario for businesses is the invoice with a changed account number. The intruder reads the correspondence with a client, waits until a payment is due and sends from the company mailbox an identical invoice with a different IBAN. Who bears that loss, the client who paid or the company whose email was compromised, is argued case by case according to each side’s diligence, and the company’s position depends largely on having reacted in time and being able to prove from when the mailbox was compromised. If the perpetrator is an employee or a former employee, the matter also has an employment law and trade secrets dimension that should be handled in a coordinated way.
What you risk doing it alone and what we do
Doing it on your own has a concrete cost. A complaint filed without the access records, with the forwarding rules already deleted and the password changed before anything was documented, reaches the court with nothing on which to request data from anyone, and by the time it is requested the data is no longer kept. The usual outcome is a quick dismissal that also leaves without the necessary document anyone who has to argue with the bank, with a company claiming under a contract you never signed or with a client who paid the wrong person.
In a case like this our firm secures the evidence with a forensic expert where needed, files the complaint or querella with the investigative steps already proposed and in parallel handles the claim for the money and the defence against whatever was done in your name, under a single direction. You can call us on +34 677 841 007 or write through the contact page and in the first conversation we tell you whether your case has prospects and which way to take it.
When you call, have to hand the approximate date you noticed the access, the screenshots of the activity panel and the forwarding rules, the emails sent by the intruder, the phishing email if there was one, the bank movements or purchases you do not recognise and, if you have already reported it, the police report number. That saves a week.
Frequently asked questions
Is it a crime for someone to get into my email even if they stole nothing?
Yes. Article 197 bis of the Spanish Criminal Code punishes with six months to two years in prison the mere act of accessing an information system by bypassing its security measures and without authorisation, and also remaining inside against the owner’s will. It does not require data to have been taken or any loss caused. If he also read your messages, the penalty rises under article 197.1, and if he disclosed them, under article 197.3. It is an offence that is only prosecuted if you file a complaint.
Do I have to report it before changing my password or will I lose the evidence?
You do not need to report it first, but you do need to document it first. Change the password as soon as possible, and in the minutes beforehand take dated screenshots of the login history, the forwarding rules and filters, the altered recovery details and the sent folder. Do not delete the intruder’s emails or the original phishing message. The full records that identify the perpetrator are kept by the provider for a limited time and are only handed over with judicial authorisation, so the complaint should be filed within days, not months.
Am I liable for the scams the hacker sends to my contacts from my account?
Not criminally, because there is no offence without intent or negligence on your part, and the person liable is whoever sent the messages. Civilly, a contact who paid the fraudster would have to prove negligence on your part, which is very difficult in the case of a private individual. What protects you is warning your contacts through another channel as soon as you know, keeping proof of that warning and filing a complaint, because that fixes the date from which the account was no longer under your control.
Do I need a lawyer to report that my email has been hacked?
Filing the complaint at a police station does not require one, and if they only got into your account, no money was involved and you suspect no one in particular, you can do it yourself with the screenshots and accept that the most likely outcome is a dismissal for lack of an identified perpetrator. A lawyer pays off when transfers or purchases have been made with your account, when you suspect someone close to you and the evidence needs securing for the prosecution to succeed, when something has been contracted in your name or when the email belongs to a business and third-party data is involved, because in those cases the complaint is only one of several pieces and the order in which they move decides the outcome.