The legal and evidential questions
SIM-Swap and Online Banking Fraud. The first task is to preserve volatile digital evidence without altering it. The statutory starting point shown on this page is Article 180 (Fraud). The investigation must distinguish alleged deceptive appropriation from contractual non-performance, commercial risk or a later inability to pay.
Request carrier SIM-change and authentication logs, bank session and payment records, device identifiers, account-recovery events, recipient accounts and notification timing.
A device or account does not identify its user automatically
Ownership of a phone, SIM, mailbox, profile or wallet may be relevant, but attribution requires reliable evidence of access, control, authorisation and conduct at the material time.
Questions to answer first
Preserve volatile digital evidence without altering it
Separate device ownership from authorship and account control
Identify authorisation, access method, intent and alleged consequence
Coordinate criminal, privacy, employment, platform and recovery issues
Evidence that may matter
- Device images, logs and authentication records
- Messages, emails and platform data
- IP, location, SIM and account-recovery records
- Wallet, bank and payment evidence
- Forensic acquisition and chain-of-custody material
Criminal Code articles to check
Fraud
The investigation must distinguish alleged deceptive appropriation from contractual non-performance, commercial risk or a later inability to pay.
Read full Article 180 text on this pageDisclosure of information on private life or personal data
Covers specified unlawful obtaining, storage, use or disclosure that satisfies the article's consequence and circumstance requirements; privacy concern alone does not settle criminal liability.
Read full Article 157 text on this pageUnauthorised access to a computer system
Ownership of a device or account does not prove unauthorised access; permission, attribution, method and consequence should be tested.
Read full Article 284 text on this pageInterference with computer data or systems
May be relevant where alteration, deletion, damage or obstruction is alleged; reliable forensic attribution is critical.
Read full Article 286 text on this pageRead the relevant Criminal Code provisions
The panel below reproduces the available official English wording for convenient reading. Check the current Georgian text and the exact article part before relying on it, because later amendments may not yet appear in translation.
Article 180Fraud+
1. Fraud, i.e. taking property of another person or obtaining of title to the property by deceit for its unlawful appropriation, –
shall be punished by a fine or community service from 170 to 200 hours, or by corrective labour or house arrest for a term of one to two years, or by imprisonment for a term of two to four years.
2. The same act:
a) committed by more than one person with a preliminary agreement;
b) causing substantial damage, –
shall be punished by a fine or by imprisonment for a term of four to seven years.
3. The same act committed:
a) using the official position;
b) in large quantities;
c) repeatedly, –
shall be punished by a fine or by imprisonment for a term of six to nine years.
4. The same act committed:
a) by an organised group;
b) by a person who has two or more previous convictions for unlawful appropriation or extortion of another person’s property, –
shall be punished by imprisonment for a term of seven to ten years.
The consolidated official source is listed in the source section at the end of this guide.
Article 157Disclosure of information on private life or of personal data+
1. Unlawful obtaining, storage, use, dissemination of or otherwise making available information on private life or personal data, which has resulted in considerable damage, –
shall be punished by a fine or corrective labour for up to two years, or by imprisonment for up to three years.
2. Unlawful use and/or dissemination of information on private life or of personal data through a piece of work disseminated in a certain way, through internet, including social network, mass media or other public appearance, which has resulted in considerable damage, –
shall be punished by a fine or corrective labour for up to two years, or by imprisonment for up to four years.
3. The act provided for in paragraph 1 or 2 of this article committed:
a) for mercenary purposes;
b) repeatedly, –
shall be punished by a fine or imprisonment for a term of up to five years.
4. The act under paragraphs 1, 2 or 3 of this article committed by a person, who, due to his/her official position, professional activities or other circumstances, was obliged to keep this information or data confidential, or who committed the above act using his/her official position, –
shall be punished by imprisonment for a term of four to seven years, with or without deprivation of the right to hold an office or to carry out activities for up to three years.
Note:
1. A person shall not incur criminal liability for a crime (obtaining, storage) under paragraph 1 of this article if he/she has submitted the obtained/stored information specified in paragraph 1 of this article to investigative authorities and communicated information on any other committed/anticipated criminal act in this manner.
2. For committing an act under this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.
The consolidated official source is listed in the source section at the end of this guide.
Article 284Unauthorised access to a computer system+
1. Unauthorised access to a computer system, –
shall be punished by a fine or corrective labour for up to two years, or by imprisonment for the same term.
2. The same act:
a) committed by a group of persons with preliminary agreement;
b) committed using an official position;
c) committed repeatedly;
d) that has resulted in substantial damage, –
shall be punished by a fine or corrective labour for up to two years, or by imprisonment for a term of two to five years.
3. The act provided for by paragraphs 1 and/or 2 of this article, committed against a critical information system subject, –
shall be punished by imprisonment for a term of three to six years.
Note:
1. A computer system is any equipment/mechanism or a group of inter-connected equipment/mechanisms that automatically processes data (including personal computers, any equipment with a microprocessor, or a mobile phone) by means of software.
2. Computer data are any information displayed in any form that can be processed in the computer system, including software that ensures the operation of the computer system.
3. Unauthorised shall mean illegal, also those cases when the holder of the right has not, directly or indirectly, transferred the right to the person committing the act.
4. For the purposes of this Chapter, ‘substantial damage’ shall be considered damage exceeding GEL 2 000, except in cases provided for by Article 2861 of this Code.
5. A crime provided for by this Chapter shall be deemed as having been committed repeatedly if it has been preceded by any of the crimes provided for by this Chapter.
6. A critical information system subject shall be a critical information system subject as provided for by the Law of Georgia on Information Security.
7. For the act provided for by this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.
The consolidated official source is listed in the source section at the end of this guide.
Article 286Interference with computer data and/or computer systems+
1. Unauthorised damage, deletion, modification or concealment of computer data, –
shall be punished by a fine or corrective labour for up to two years and/or by imprisonment for the same term.
2. The act provided for by paragraph 1 of this article, and unauthorised insertion or transfer of computer data that has resulted in considerable and intentional disruption of the operation of a computer system, –
shall be punished by a fine or corrective labour for up to two years and/or by imprisonment for up to three years.
3. The act provided for by paragraph 1 or 2 of this article:
a) committed by a group of persons with preliminary agreement;
b) committed using an official position;
c) committed repeatedly;
d) that has resulted in substantial damage, –
shall be punished by a fine or corrective labour for up to two years, or by imprisonment for a term of three to five years.
4. The act provided for by paragraphs 1 and/or 2 of this article, committed against a critical information system subject, –
shall be punished by imprisonment for a term of four to seven years.
Note: For committing an act provided for by this article, a legal person shall be punished by a fine, with deprivation of the right to carry out activities, or by liquidation and a fine.
The consolidated official source is listed in the source section at the end of this guide.
How the process may develop
Primary sources for this guide
Before acting, compare this guide with the current Georgian text and the exact document served in the case. The official English translation may not include the latest amendment.
Criminal Procedure Code of Georgia↗︎Criminal Code of Georgia↗︎Constitution of Georgia↗︎