Cybercrime · Alicante · Madrid · All Spain
Charged with a computer crime in Spain, or the victim of one?
Spanish cybercrime cases are won and lost on the digital evidence, and that is where a specialist defence makes the difference.
In brief. Defence in Spanish computer crime cases: hacking, ransomware, phishing and computer fraud. We attack the digital evidence and the chain of custody.
At a glance
Spanish law does not have a single offence called cybercrime. It has a group of offences in the Criminal Code that are committed through information systems, and each one carries its own penalty:
The same conduct is often charged under two or three of these articles at once, which changes the sentencing exposure considerably. One of the first tasks of the defence is to challenge that overlapping classification.
In a cybercrime prosecution the file is rarely built on witnesses. It is built on IP logs, server records, device images, cryptocurrency traces and reports from the Guardia Civil or the Policia Nacional technology units. That evidence has to be obtained and preserved according to the rules in articles 588 bis a) to 588 octies of the Criminal Procedure Act.
Those rules are demanding, and they are frequently not followed to the letter. We examine whether the judicial authorisation covered the device or account actually examined, whether the chain of custody of the hard drives and mobile phones is documented from seizure to expert analysis, whether the hash values match, whether the remote search of a device had specific judicial authorisation, and whether the data was obtained from a foreign service provider through a valid channel of international cooperation.
When one of those links fails, the evidence can be excluded as unlawfully obtained under article 11.1 of the Judiciary Act, and with it a substantial part of the prosecution case. This is technical work, and it is the reason our practice combines criminal defence with forensic capability.
Companies and individuals who have lost money or data need to act in the first hours, not the first weeks. Practical priorities are preserving the evidence before it is overwritten, documenting the intrusion with a forensic report that a Spanish court will accept, requesting the urgent freezing of the destination accounts, and filing a complaint drafted so that the investigating court can act rather than shelve the file.
Where the money has moved through cryptocurrency, tracing is possible far more often than victims assume, and a well-drafted request can reach the exchange before the funds are cashed out. Where the attack came from inside the organisation, the internal investigation has to be run carefully so that its findings can later be used in court and do not themselves breach data protection or employment law.
Every case starts with a technical audit of the file before a single line of legal argument is written. We identify what the prosecution can actually prove, separate it from what it merely asserts, and then decide the strategy: challenging the classification of the offence, attacking the evidence, disputing the authorship of the conduct behind an IP address or a device, or negotiating where the evidence is solid and the client interest lies in limiting the outcome.
Attribution deserves particular attention. An IP address identifies a connection, not a person. Shared networks, compromised devices and family or corporate accounts are common in these files, and the burden of proving who was at the keyboard remains with the prosecution.
The Criminal Code addresses a range of conduct in the digital sphere: unauthorised access to systems and the breach of the confidentiality of data and communications under article 197, damage to data and systems under articles 264 and following, and computer fraud under article 248, paragraph two, committed through computer manipulation to bring about a transfer of assets.
Because these offences often cross borders, questions of jurisdiction and of judicial cooperation arise early and can be as important as the substance of the accusation itself.
We act in cases of phishing and card fraud, unauthorised access to accounts and corporate systems, the non-consensual distribution of images, ransomware and the theft of data. Each raises distinct legal and technical questions.
In many of these matters the accused is identified through an IP address or an account, which is not by itself proof that a particular person carried out the conduct. Attribution is therefore a recurring battleground.
We scrutinise how the digital evidence was obtained and preserved, whether the search of devices or accounts was covered by a proper judicial authorisation, and whether the activity can genuinely be attributed to the accused rather than to a shared device or a compromised account.
Independent forensic analysis is frequently decisive, because the prosecution’s case often rests on logs and metadata that require expert interpretation to mean anything at all.
We act for both accused persons and victims, coordinating the criminal proceedings with any civil or data-protection dimension of the matter.
For urgent situations, such as an ongoing extortion or a device seizure, we intervene immediately to protect the client’s position and to secure the evidence that supports it.
FAQ
Speak to a criminal lawyer
Criminal defence in English before the courts of Alicante, Madrid and the whole of Spain. Tell us what has happened and we will tell you what the real exposure is.