09Evidence A

Testing someone else’s systems without written permission — “good intentions” and “reporting afterward” are not excuses

Whether a crime is established depends solely on whether you had permission and how much access you obtained — not on your intentions. Possessing 500 sets of ordinary account credentials, or earning 5,000 yuan while causing 10,000 yuan in losses, is enough to warrant a sentence of up to three years. Even a single attempt to export a user list to prove a vulnerability often exceeds that 500‑credential threshold. Using credentials you already possess outside their authorized scope also constitutes unauthorized access.

Cost

No cost at all. Before joining a vendor’s SRC or public be…

Benefit

This law applies to computer information systems belonging to ordinary companies and individuals, excluding th…

Cost

No cost at all. Before joining a vendor’s SRC or public beta test, obtain a document that clearly defines the permitted scope, target systems, and allowed testing windows. An SRC is a vendor-run security response center designed to receive external vulnerability reports. Once a vulnerability is confirmed, testing must stop. The real challenge is resisting the urge to “give it a quick try.”

Benefit

This law applies to computer information systems belonging to ordinary companies and individuals, excluding those used for national affairs, defense, or cutting‑edge scientific research. Unauthorized intrusion or use of any technical means to obtain stored, processed, or transmitted data may lead to imprisonment of up to three years, a fine, or both, if the circumstances are serious; for especially serious cases, the sentence ranges from three to seven years with a fine. “Serious circumstances” include obtaining ten or more authentication credentials for online financial services such as payments or securities trading, 500 or more other authentication credentials, illegally controlling 20 or more computers, or earning illicit profits exceeding 5,000 yuan or causing losses above 10,000 yuan. Five times these thresholds define “especially serious” circumstances. Prosecutorial Example No. 36 states that “using accounts or passwords beyond the granted scope to log into a computer system is itself an act of unauthorized intrusion.” In that case, three individuals used work‑related credentials to access their company’s internal system, downloaded non‑work data, and sold it for 37,000 yuan; they received sentences of 4 years, 3 years 9 months, and 4 years respectively, plus fines of 40,000 yuan each.

Original sources

全国人大 (2020). 刑法(根据刑法修正案(十一)修正,第二百八十五条第一款、第二款). https://jtgl.beijing.gov.cn/jgj/jgxx/flfg/fl/11033925/index.html;最高人民法院、最高人民检察院 (2011). 关于办理危害计算机信息系统安全刑事案件应用法律若干问题的解释(第一条). https://ga.sz.gov.cn/ZWGK/ZCFG/ZCJD/content/post_1304363.html(深圳市公安局转载);最高人民检察院 (2017). 第九批指导性案例(检例第 36 号,卫梦龙、龚旭、薛东东非法获取计算机信息系统数据案). https://www.spp.gov.cn/spp/jczdal/201710/t20171017_202593.shtml

Open source link
Book note

Prosecutorial Example No. 36 involves a data‑selling scheme; it is cited only for the principle that exceeding authorized scope counts as intrusion, not to suggest that well‑meaning tests incur identical penalties. Intentions and post‑test reporting cannot erase criminal liability; they may only influence sentencing or whether charges are filed. A vendor’s initial thanks and later filing of a report are not mutually exclusive — gratitude does not equal permission. At the time of writing, no publicly documented cases on permissible testing were found on the Supreme People’s Court or Supreme People’s Procuratorate websites; therefore this description relies on statutory provisions and penalty criteria. Always participate through a vendor’s official SRC or under a written contract that specifies scope, targets, and time limits. To prove a vulnerability, collect only minimal evidence and avoid bulk data extraction. Even conduct that does not meet criminal thresholds remains subject to administrative penalties, professional bans, and fines comparable to those outlined in Section 8 (running unauthorized programs on others’ machines). Guidance on post‑disclosure procedures appears in Section 10 (reporting vulnerabilities as required).

My note