Case details
Summary
Sentencing for serious computer-misuse offending must reflect the statutory purposes of punishment, deterrence and public protection, and the offender’s culpability and the actual, intended and reasonably foreseeable harm. A denial-of-service attack may cause serious harm even if it is short-lived and causes no permanent damage. Its effect on important public services, individual privacy and confidence in computer systems may be substantial.
Careful planning, persistence, anonymity measures, threats designed to increase disruption, breach of trust and the targeting of public institutions are material aggravating features. Financial gain is not required before a deterrent custodial sentence is justified. For offending of this scale, sentences will ordinarily be measured in years rather than months.
Factual background
The appellant pleaded guilty in the Crown Court at Maidstone to offences under the Computer Misuse Act 1990. They included repeated denial-of-service attacks on the websites of the Universities of Oxford and Cambridge and Kent Police, unauthorised access to personal and financial information, and the possession of software for use in such attacks.
He received concurrent sentences totalling two years’ imprisonment. He appealed against sentence, submitting that the attacks were motivated by bravado rather than profit, caused only temporary disruption, and that his mitigation and guilty pleas warranted a shorter sentence. The central issue was whether the total sentence was manifestly excessive.
Held
The appeal against sentence was dismissed. The concurrent total of two years’ imprisonment was amply justified.
The court applied sections 142(1) and 143(1) of the Criminal Justice Act 2003. Sentence had to reflect punishment, deterrence and public protection, as well as the offender’s culpability and the harm caused, intended or reasonably foreseeable. These offences involved the highest culpability because they were carefully planned and intended to cause harm.
The harm was serious. The individual victims suffered financial loss, disruption and a serious invasion of privacy, comparable in effect to burglary or identity theft. The universities and Kent Police incurred substantial disruption and expense. A denial-of-service attack can have far-reaching consequences even where it is temporary and causes no permanent damage. The potential consequences for important public institutions and their users were particularly significant.
The absence of financial motive was of limited mitigation. Bravado does not reduce the capacity for harm. Computer crime is comparatively easy for skilled offenders to commit, increasingly prevalent, and capable of damaging public confidence in essential systems. A real element of deterrence was therefore appropriate.
R v Mangham [2012] EWCA Crim 973 was not a sentencing benchmark. Its substantial personal mitigation did not undermine the need for substantially longer sentences in cases of this scale. Relevant aggravating features here included sophisticated planning, persistence over nearly a year, anonymising software, threats intended to increase disruption, attacks on major public institutions, invasion of privacy and a breach of trust.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Appellate history
Court of Appeal (Criminal Division) Dismissed the appellant’s appeal against his total sentence of two years’ imprisonment.
Crown Court at Maidstone On 12 April 2013, the appellant pleaded guilty to computer-misuse offences. On 16 May 2013, His Honour Judge Byers imposed concurrent sentences totalling two years’ imprisonment.
Lower court decision
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.