Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 regulates these forms of conduct through several different provisions. Accordingly, there is no single «hacking offence» carrying one uniform penalty; rather, the legal characterization depends on the method of access, the nature of the system attacked, and the result arising from the conduct.
What Is Meant by Hacking under the Law?
The Anti-Cyber and Information Technology Crimes Law defines hacking as unauthorized access, or access in violation of the terms of authorization, to an information system, computer, information network, or similar system.
Accordingly, hacking may occur where a person had no right of access in the first place, while a different form may arise where the person had legitimate authorization to access the system but exceeded the limits of the permission granted in terms of the level or duration of access.
Unauthorized Access to an Information System
Article 14 of the Law regulates the basic form of unauthorized access and penalizes any person who intentionally accesses – or accesses by mistake and then remains without authorization – a website, private account, or information system to which access is prohibited.
The Article provides for imprisonment for a period of not less than one year and a fine of not less than EGP 50,000 and not exceeding EGP 100,000, or either of these two penalties.
If the access results in destruction, deletion, alteration, copying, or republication of the data or information contained on the website, account, or system, the penalty is increased to imprisonment for a period of not less than two years and a fine of not less than EGP 100,000 and not exceeding EGP 200,000, or either of these two penalties.
An important distinction therefore arises: mere unauthorized access may constitute the offence even if it does not result in data theft or damage to the system. However, where an additional result specified by the provision occurs, the more severe form of the offence applies.
Employees or Users Exceeding Their Authorized Access
The offender does not have to be an outsider to the organization. The violation may be committed by an employee or user who already has a valid account or defined access rights but uses them beyond the permitted limits.
Article 15 addresses this situation and penalizes a person who accesses a website, private account, or information system using a right lawfully granted to them and then exceeds that right in terms of time or level of access.
This form differs from external hacking because the initial access is lawful, while the violation lies in exceeding the limits of the authorization. Examples include an employee accessing a database outside the scope of their duties or continuing to use access privileges after the right to do so has expired.
Interception of Data in Transit
The offender may not access the system itself, but instead intercept data transmitted through a network or computer devices in order to obtain, record, or use it without authorization.
Article 16 establishes a separate offence for the unlawful interception of data and information transmitted through networks or computer devices. Accordingly, hacking a system should not be confused with intercepting data traffic, although both may sometimes occur in the same incident.
Destroying, Disabling, or Altering Data
If the conduct is not limited to access but instead targets the integrity of the data or software itself, Article 17 of the Law may apply.
This Article penalizes any person who intentionally and without authorization destroys, disables, redirects, wholly or partially deletes, or alters programs, data, or information stored or processed on an information system, regardless of the means used.
This offence is broader than mere access; it may be committed by a person who obtained access and then deleted or altered a database, and it may also occur through software or other means affecting the data without requiring the traditional form of hacking.
Hacking Email Accounts, Websites, and Private Accounts
Article 18 addresses attacks on email accounts, websites, and private accounts. The acts criminalized by the provision include destruction, disabling, slowing down, and hacking.
The penalty is increased where the attack is directed against an email account, website, or private account belonging to a private legal person, such as a company or institution.
Accordingly, hacking a personal email account differs, in terms of the applicable provision and details, from attacking a company’s internal system or an entire information network.
Attacks on Website Design
Article 19 regulates a more specific situation: destroying, disabling, slowing down, distorting, concealing, or altering the design of a website belonging to a company, institution, establishment, or natural person without authorization.
Practical applications include changing the interface of a website after hacking it, replacing its content, or concealing its pages. However, if the attack extends to data or the website’s back-end system, other provisions may also apply depending on the result.
Hacking State Information Systems
Article 20 establishes a special rule for systems operated by or on behalf of the State, or owned by the State or by a public legal person.
The Article penalizes unauthorized access or remaining without authorization, exceeding the limits of access rights, or hacking a government website, email account, account, or information system, and increases the penalty where the purpose is to obtain government data or information without authorization.
The penalty is further increased where the attack results in destruction, distortion, alteration, copying, republication, or deletion of government data in the cases specified by the provision.
Accordingly, it is incorrect to describe Article 19 as the provision governing State systems; the specific provision applicable to such systems is Article 20.
Disruption of Information Networks
The purpose of an attack may be to disrupt a network rather than access its contents. Article 21 regulates offences against the integrity of information networks, including intentionally causing a network to stop operating, become disabled, operate at reduced efficiency, suffer interference, or become obstructed.
It should also be noted that the provision establishes liability in certain cases of negligent conduct, not only intentional conduct, and further increases the penalty where the network belongs to the State or a public legal person or is operated by them. :contentReference[oaicite:0]{index=0}
Hacking Programs and Tools
It is not always necessary to wait until an attack is carried out. Article 22 penalizes, in the cases it specifies, possession, acquisition, manufacture, import, making available, or circulation of devices, programs, codes, ciphers, and similar items where it is established that the purpose is to use them in committing one of the offences under the Law, facilitating such an offence, or concealing its traces.
This means that possession of a security testing tool or technical software is not, in itself, a crime; the standard is the existence of the criminal purpose or use required by the provision. Accordingly, a distinction must be drawn between legitimate penetration-testing tools used with authorization and the preparation or use of tools with the intention of committing a crime.
Is Mere Unauthorized Access Sufficient to Establish the Offence?
Yes. In relation to the form regulated by Article 14, the offender does not need to succeed in stealing data or causing financial loss for the basic offence to arise. The provision criminalizes unauthorized access itself and then treats destruction, deletion, copying, or republication of data as grounds for increasing the penalty.
This conclusion follows directly from the structure of the provision and does not require the assumption of separate material damage in every case.
Recent Judicial Applications
In information technology cases, the Court of Cassation focuses on applying the general rules of criminal evidence alongside the special provisions of Law No. 175 of 2018. One important principle is that a conviction must be based on conclusive evidence sufficient to attribute the act to the accused, rather than on mere suspicion or probability.
This is particularly important in hacking offences because proving the existence of a technical attack is not, by itself, sufficient to attribute it to a specific person. The matter may require examination of devices, access logs, connection addresses, accounts used, the chain of custody of digital evidence, and linking all of these elements to the accused.
The Law also grants evidentiary value in criminal proceedings to evidence derived or extracted from electronic devices, systems, and media where it satisfies the technical requirements prescribed by the Executive Regulations.
As for the judgment attributed in some sources to Appeal No. 4723 of Judicial Year 13 Economic – session of 20 November 2021, I was unable to verify its details or legal principle through the official Court of Cassation judgments database. Accordingly, it should not be published as an established judicial authority. The official judgments database permits searches of recent economic and criminal appeals and should be relied upon when attributing any specific principle to the Court of Cassation. :contentReference[oaicite:1]{index=1}
What Evidence Is Important in a Hacking Offence?
- System access logs: Including the time of access, the account used, and the permissions exercised.
- Connection addresses and devices: Bearing in mind that a connection address alone does not necessarily establish the identity of the offender.
- Modification logs: To identify the files or data that were accessed or altered.
- Seized devices: And any programs, data, or technical traces they contain that are connected to the incident.
- Malware: Including analysis of how it operates, its source, and indicators of compromise.
- User accounts: And determining whether they were compromised or used by their legitimate owner.
- Electronic communications: Where they contain instructions or coordination concerning execution of the attack.
- Chain of custody of digital evidence: To ensure that the data was not altered between the time of seizure and the time of examination.
Hacking Does Not Necessarily Mean That an IT Employee Is Liable
The mere fact that an employee has extensive technical privileges is not sufficient to attribute the offence to them. A particular access event may have formed part of their legitimate work, their account credentials may have been used after being compromised, or they may themselves have exceeded the permissions granted to them.
Accordingly, account activity must be compared with job duties, the permissions register, the timing of operations, the devices used, and any instructions or approvals that existed at the time of the incident.
Key Technical Protection Measures for Organizations
- Apply the principle of least privilege: So that each user receives only the level of access necessary to perform their duties.
- Enable multi-factor authentication: Particularly for administrative accounts and remote access.
- Regular updates: Because unpatched vulnerabilities represent one of the common routes into systems.
- Segregate networks and sensitive systems: To limit the spread of an attack if one device is compromised.
- Monitor access logs: And detect unusual activities and repeated access attempts.
- Disable unused accounts: And terminate employees’ access rights immediately when they are no longer required.
- Backups: While retaining copies that an attacker cannot easily alter.
- Periodic authorized penetration testing: To identify vulnerabilities before they are exploited.
- Incident response plan: Defining team responsibilities when a breach is discovered and how systems should be isolated and evidence preserved.
These measures are consistent with the practical recommendations issued by the Egyptian Computer Emergency Readiness Team EG-CERT, which emphasizes the importance of security updates, multi-factor authentication, network monitoring, isolation of affected systems, and review of access logs. :contentReference[oaicite:2]{index=2}
Legal and Regulatory Protection within the Organization
Protection does not depend on software alone. It is necessary for an organization to define in writing the permissions of users and persons responsible for managing systems, and to establish a clear policy governing the use of accounts, devices, and remote access.
Approvals for penetration testing or technical maintenance should also be documented because the legal distinction between legitimate security testing and unauthorized access may depend on the existence of clear authorization defining the scope, timing, and systems that may be accessed.
It is also preferable to retain records of incidents, technical reports, and the measures taken to address vulnerabilities, which may assist in establishing how the incident occurred and the responsibility of each party if a subsequent dispute arises.
What Should an Organization Do When a Breach Is Discovered?
The priority is to contain the incident without compromising digital evidence. Accordingly, affected systems should be isolated where necessary, logs and copies of evidence should be preserved properly, credentials suspected of being compromised should be changed, and the scope of the breach and affected data should be identified.
EG-CERT provides services for incident response, digital forensics, and malware analysis, and also provides channels for reporting cybersecurity incidents. :contentReference[oaicite:3]{index=3}
From a legal perspective, it must be determined whether the incident requires a criminal report, notification to a regulatory authority, or notification to other parties depending on the nature of the organization, the data affected by the breach, and the specific laws governing its activity.
Competent Courts
Law No. 175 of 2018 falls within the laws under which disputes and offences arising from its application are subject to the jurisdiction of the Economic Courts in accordance with the rules governing the jurisdiction of those courts.
However, describing the court as a «specialized and fast court» does not add a precise legal rule. What matters is identifying the type of offence, the level of the competent court, and the available route of appeal according to the characterization of the charge and the prescribed penalty.
Conclusion
Electronic systems hacking under Egyptian law does not constitute a single form of offence. The Law distinguishes between unauthorized access, exceeding authorized access rights, interception of data, destruction of data, hacking of accounts and websites, and attacks on State systems or information networks.
Proper legal characterization begins by determining what the accused accessed, whether they previously had a right of access, the limits of that right, what they did after gaining access, and the result arising from their conduct.
For organizations, the most effective protection combines technical security with legal safeguards: access management, continuous updates, multi-factor authentication, log monitoring, authorized penetration testing, and a clear incident response and digital evidence preservation plan.