Key points at a glance
- Cybercrime is not a specific criminal offense., but rather a collective term for a multitude of offenses under the Criminal Code and supplementary penal law.
- The Federal Criminal Police Office recorded a total of 63,459 reports in 2025 in the field of cybercrime; 21,988 of these accounted for cybercrime in the narrower sense.
- The fraudulent data processing abuse (Section 148a of the German Criminal Code) is by far the most frequent offense in the narrower sense with 17,799 reports in 2025.
- Since January 1, 2025 does the seizure and evaluation of data media such as mobile phones require prior judicial authorization (Sections 115f et seq. of the German Code of Criminal Procedure).
- The NISG 2026 entered into force on October 1, 2026 and significantly expands the circle of companies obligated under cybersecurity law.
- In the event of a data breach, simultaneously runs the 72-hour period under Article 33 GDPR – regardless of whether a criminal complaint is filed.
- Paying a ransom is not generally prohibited in Austria, but it is not generally permitted either. Whether it is permissible and economically justifiable must be examined and documented on a case-by-case basis – negotiations with the attackers are almost always advisable regardless of this.
- Speed decides. In payment and crypto transactions, the time window of the first few hours determines whether security measures take effect.
What does cybercrime mean in Austria?
Cybercrime refers to criminal offenses that are either directed against computer systems and data themselves or in which information and communication technology is used as a means to commit the crime. A specific criminal offense of „cybercrime“ does not exist in Austrian law.
Based on the Budapest Convention, the Federal Criminal Police Office distinguishes between two categories:
Cybercrime in the strict sense detects attacks targeting networks, devices, services, or data. Typical examples include hacking, data corruption, and DDoS attacks.
cybercrime in the broader sense covers classic offenses planned, prepared, or committed using information and communication technology (ICT) – primarily internet fraud, but also extortion, dangerous threats, or drug trafficking on the darknet.
Cybercrime in Austria: the 2025 figures
According to the 2025 Cybercrime Report by the Federal Criminal Police Office, 63,459 cases of cybercrime were reported in Austria in 2025. This corresponds to an increase of 1.8 percent compared to 2024. The clearance rate fell by 0.9 percentage points to 30.8 percent.
Development 2021–2025
| Year | Reported crimes | Solved crimes | clearance rate |
|---|---|---|---|
| 2021 | 46.179 | 17.020 | 36,9 % |
| 2022 | 60.195 | 20.378 | 33,9 % |
| 2023 | 65.864 | 20.818 | 31,6 % |
| 2024 | 62.328 | 19.785 | 31,7 % |
| 2025 | 63.459 | 19.570 | 30,8 % |
Source: Federal Criminal Police Office, Cybercrime Report 2025 (Police Crime Statistics)
Cybercrime in the narrower sense: offences in a year-on-year comparison
Strictly speaking, the number of reports rose by 8.6 percent to 21,988 cases in 2025.
| Offense | Advertisements 2024 | Ads 2025 |
|---|---|---|
| Section 148a of the Criminal Code (StGB) – Fraudulent abuse of data processing | 16.192 | 17.799 |
| Section 118a StGB – Unlawful access to a computer system | 1.991 | 2.060 |
| Section 225a StGB – Falsification of data | 713 | 887 |
| Section 107c of the Criminal Code (StGB) – Continued harassment by means of a computer system | 462 | 521 |
| Section 126a StGB – Data Corruption | 241 | 270 |
| Section 126c StGB – Misuse of computer programs or access data | 496 | 258 |
| Section 126b StGB – Disruption of the functionality of a computer system | 76 | 111 |
| Total (in the strict sense) | 20.246 | 21.988 |
Source: Federal Criminal Police Office, Cybercrime Report 2025
Further key figures from 2025
- Internet Fraud (§§ 146 to 148 StGB): 31,001 reported cases, a decrease of 2.4 percent compared to 2024.
- Cyber Trading Fraud: According to the Federal Criminal Police Office, the total damage amounted to around 120 million euros. The Federal Criminal Police Office has set up a dedicated investigative team for this purpose.
- Ransomware: 111 reported cases nationwide. In around 40 percent of the reports, no clear assignment to a perpetrator group was possible. INC, Akira, RansomHub, LockBit 4.0, and Qilin, among others, were identified.
- Cyber extortion (§§ 144, 145 Swiss Criminal Code): 2,380 reports, a decrease of 18.8 percent with a clearance rate of 9.6 percent.
The Federal Criminal Police Office explicitly points out that the number of unreported cases in cybercrime is particularly high because many victims do not report the crimes out of shame, fear, or due to the low amount of damage.
The most important cybercrime offenses in the Austrian Criminal Code
The central criminal offenses for cybercrime in the strict sense can be found in Sections 118a, 119, 119a, 126a, 126b, 126c, 148a, and 225a of the Criminal Code (StGB). In the broader sense, cybercrime also includes, in particular, fraud (§§ 146 et seq. SCC), extortion (§§ 144, 145 SCC), dangerous threats (§ 107 SCC), and coercion (§ 105 SCC).
| Destiny | Subject matter regulated | Typical case scenario |
|---|---|---|
| Section 118a of the Criminal Code | Unauthorized access to a computer system | Account takeover, hacking of email or cloud access |
| Section 119 of the German Criminal Code | Violation of telecommunications secrecy | Interception of communication |
| Section 119a of the German Criminal Code | Abusive data interception | Reading out data transmissions |
| Section 126a of the Criminal Code | Data corruption | Encryption of corporate data by ransomware |
| Section 126b of the German Criminal Code | Disruption of the functionality of a computer system | DDoS attack on online store or public authority |
| Section 126c of the German Criminal Code | Misuse of computer programs or access data | Trading in malware or access credentials |
| Section 148a of the German Criminal Code | Fraudulent data processing abuse | Unauthorized debit after phishing, order placed in someone else's name |
| Section 225a of the German Criminal Code | Data falsification | Fake documents for opening online accounts |
| Sections 144, 145 of the German Criminal Code | extortion, aggravated extortion | sextortion, ransom demand after ransomware attack |
| Section 107c of the German Criminal Code | Continuous harassment by means of a computer system | Cyberbullying |
Practical tip: In reality, almost never is there a single offense. A ransomware attack typically fulfills Section 118a of the Criminal Code (intrusion), Section 126a of the Criminal Code (encryption), and Sections 144 et seq. of the Criminal Code (ransom demand) concurrently. For reporting the crime, this multiple qualification is relevant because it influences the sentencing range and thus also the permissible investigative measures.
The five major case groups in practice
1. Crypto and investment fraud
Cyber Trading Fraud refers to investment fraud via fake trading platforms where victims are shown simulated price gains while the deposited funds have actually been siphoned off. According to the Federal Criminal Police Office, this form of fraud alone caused damage of around 120 million euros in Austria in 2025.
Typical manifestations: fake trading platforms, pig butchering (long-term trust-building before the investment request), love scams, rug pulls, and so-called recovery scams, in which scam victims are defrauded a second time.
From a legal perspective, §§ 146 et seq. of the Austrian Criminal Code (StGB), the seizure of assets under the Austrian Code of Criminal Procedure (StPO) and – in the case of an identifiable crypto service provider – civil and regulatory approaches are the primary focus. Since December 30, 2024, Regulation (EU) 2023/1114 (MiCAR) is fully applicable; the competent authority for crypto-asset service providers in Austria is the Financial Market Authority (FMA) pursuant to the MiCA Regulation Implementation Act (MiCA-VVG, Federal Law Gazette I No. 111/2024). This significantly improves the accessibility of regulated service providers.
2. Ransomware and attacks on companies
In Austria, a ransomware attack regularly triggers three parallel lines of obligation: under criminal law, the question of reporting it; under data protection law, the notification duty pursuant to Art. 33 GDPR; and under corporate law, the duty of care of the management board.
There is no general obligation for the victim of a crime to report it in Austria. However, a different standard applies to managers: they act on behalf of the company and must protect its interests to avoid liability. Whether to report a crime is therefore a documented balancing decision—not a matter of gut feeling.
The question of ransom payment raises distinct criminal and liability law issues – in particular regarding breach of trust (Section 153 of the Criminal Code), participation in a criminal organization (Section 178 of the Criminal Code), as well as sanctions and anti-money laundering compliance. It cannot be answered without a case-by-case assessment. How negotiations with attackers are conducted and what legal aspects must be considered during payment processing is covered in the section „Negotiation with Ransomware Attackers and Assistance with Ransom Payment“ below.
3. Phishing and Account Fraud
In the event of an unauthorized payment transaction, the payer's payment service provider must refund the amount pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) without undue delay, and in any event no later than the end of the following business day, after becoming aware of or being notified of the transaction.
The liability of the payer is governed by Section 68 of the 2018 Payment Services Act (ZaDiG 2018): In the event of a slightly negligent breach of the due diligence obligations pursuant to Section 63 ZaDiG 2018, the payment service provider may claim a maximum of 50 euros. In the event of intent or gross negligence, however, the payer is fully liable. In practice, disputes therefore almost always revolve around the question of whether gross negligence exists – and who has to prove it.
At the EU law level, a clarification is underway: The Advocate General at the ECJ on March 5, 2026, in Case C-70/25 to take the view that a bank may not refuse the immediate refund of an unauthorized payment transaction by invoking gross negligence on the part of the customer; any potential claim for recovery must be asserted separately. Regarding the legal status at the time of this article, a final judgment by the Court could not be established. Opinions of the Advocate General are not binding on the Court.
4. Criminal proceedings and digital evidence
Since January 1, 2025, access to data media and data for the purpose of analysis has been independently regulated in Austria under Sections 115f to 115l of the Code of Criminal Procedure (StPO) and requires prior judicial authorization.
The background is the realization of Constitutional Court of December 14, 2023, G 352/2021. The VfGH annulled § 110 para 1 no 1 and para 4 as well as § 111 para 2 of the Code of Criminal Procedure (StPO) effective December 31, 2024, because the seizure of data media without judicial authorization and without sufficient legal protection constitutes a disproportionate interference with the fundamental right to data protection (§ 1 Data Protection Act) and the right to respect for private life (Art. 8 ECHR).
Following this, the Code of Criminal Procedure Amendment Act 2024 created a dedicated investigative measure. It separates the technical data preparation from the substantive analysis and strengthens the transparency and participation rights of the accused.
Why this is relevant for those affected: If a mobile phone or laptop is seized today, the procedure is different from before 2025. The order must narrow down the categories of data to be confiscated, and defendants can influence the determination of the evaluation parameters. This is a defense approach that must be established early on.
5. Cyber Extortion and Personal Rights
Sextortion, cyberbullying, identity theft, and deepfakes predominantly affect private individuals. In 2025, the Federal Criminal Police Office observed, among other things, extortion using so-called „police fake emails,“ in which a sender from the law enforcement sector is impersonated and criminal proceedings are threatened.
In addition to the criminal law aspect (§§ 107c, 144, 145, 107 StGB), civil law claims for injunction and removal as well as claims for deletion against platforms must be examined here.
Legal framework beyond criminal law
Cybercrime regularly triggers obligations outside of criminal law in Austria. The following overview summarizes the key deadlines.
| Legal basis | Who is affected? | Deadline / Time |
|---|---|---|
| Art. 33 GDPR | Each controller in the event of a personal data breach | Notification to the data protection authority generally within 72 hours of becoming aware, provided the legal requirements are met |
| Art. 34 GDPR | Controller in cases of likely high risk to data subjects | Notification of the data subjects without undue delay |
| NISG 2026 | Essential and important entities in the covered sectors | Entry into force on October 1, 2026; registration within three months of entry into force; multi-stage incident reporting based on the framework of the NIS 2 Directive (early warning within 24 hours, notification within 72 hours) |
| ZaDiG 2018, § 67 | Payment service provider in the event of an unauthorized payment transaction | Refund without delay, at the latest by the end of the following business day |
| MiCAR / MiCA-VVG | Cryptoasset service providers | MiCAR fully applicable since 12/30/2024; supervision by the FMA |
NISG 2026: What changed on October 1, 2026
The Network and Information Systems Security Act 2026 (NISG 2026) was published in the Federal Law Gazette on December 23, 2025 (Federal Law Gazette I No. 94/2025) and entered into force on October 1, 2026. At the same time, the NISG 2018 ceases to be in force.
The National Council passed the law on December 12, 2025, with the required two-thirds majority, after a first implementation attempt had failed in 2024. Being established is a Federal Office for Cybersecurity as the central cybersecurity authority. Affected entities must register within three months of entry into force—that is, by December 31, 2026.
The scope of application is expanding significantly: while the 2018 NIS Act covered only a small circle of designated operators of critical infrastructure, around 4,000 affected entities are now being discussed in Austria. Decisive factors are sector affiliation, company size, and territoriality. The NIS2 Directive provides for fines of up to 10 million euros or 2 percent of total worldwide annual turnover for essential entities.
Practical consequence: Companies that were not previously NIS-regulated must check their status themselves. Official designation does not happen automatically.
What to do in an acute case
For individuals
- Stop payment process immediately. In the event of account debits, contact the bank immediately and arrange for the account to be blocked. The obligation to refund pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) is contingent upon reporting it to the payment service provider.
- Secure evidence before deletion. Screenshots with visible date, complete email headers, chat histories, transaction IDs, wallet addresses, bank statements.
- Check possible legal action / file a report at a police station. As a rule, it is recommended to seek (at least) an initial legal consultation. Criminal offenses can be reported to any police station.
- Do not make a second payment. Do not respond to so-called recovery services or alleged authorities that contact you and promise to bring back your money or claim to have found your money. This is secondary fraud.
- For crypto transactions: Fully document transaction data. Traceability depends on whether the recipient addresses and transaction hashes have been saved.
For businesses
- Activate the incident response team and define decision-making paths. Who decides on shutdown, communication, payment?
- Evidence preservation before restoration. The Federal Criminal Police Office points out that systems are often repaired or reinstalled even before a crime is reported—and this very act destroys the possibility of attributing the attack to a perpetrator group.
- Check the 72-hour period under Art. 33 GDPR. It runs regardless of whether the technical incident has already been fully resolved and knows no weekends.
- Check NISG affectedness and observe the reporting obligations to the cybersecurity authority.
- Involve insurance at an early stage. Cyber insurance terms and conditions regularly contain obligations for immediate notification and the coordination of service providers.
- Prepare communication, don't improvise. A communicating company can help shape the framework of disclosure; one that is caught out afterwards is permanently on the defensive.
- Review of legal admissibility and sanctions screening prior to any consideration of payment.
Negotiation with ransomware attackers and assistance with ransom payment
Negotiations with ransomware attackers are worthwhile even if payment is not seriously considered. They buy time, provide insights into the attack vector and the actual data leaked, and create the basis for decision-making that management needs for a liability-secure decision.
ATB.LAW manages communication with attackers in ransomware cases and guides affected companies through the decision-making process regarding a potential ransom payment – from the legal admissibility review and negotiation management to technical execution.
Negotiation is a discipline in its own right, or why management shouldn't conduct the negotiation itself
The negotiation of cyber extortion follows its own rules and has little in common with a commercial negotiation. On the other side is not a contractual partner, but a gang of perpetrators organized on a division-of-labor basis, which has a well-rehearsed procedure, empirical values from a large number of parallel cases, and an economic interest in the continuation of its business model.
This asymmetry shapes the entire communication. The attackers deliberately set short deadlines and threaten to publish or resell the data to make informed decisions more difficult. They know the typical response patterns of affected companies because they bring about this situation regularly—whereas for the affected company, it is almost always the first case of this kind.
Additionally, every statement made in the perpetrator group's chat portal is potentially relevant as evidence—vis-à-vis authorities, the insurance company, and potentially later vis-à-vis shareholders. Conducting negotiations in cyber extortion cases is therefore a specialized discipline at the intersection of criminal law, compliance, and IT forensics, and should not be handled by management itself, but rather by an experienced external entity.
Conducting communication through a lawyer has three practical effects:
– Decoupling the decision from the pressure. Negotiations take place before a decision is made. Gaining time is an independent negotiation goal in the process.
– Experience from conducted negotiations. ATB.LAW has been regularly conducting negotiations with ransomware perpetrator groups for several years. This practice yields assessments that are not available to a company affected for the first time: how a specific group reacts to delays, counteroffers, or demands for proof; which demand amounts are realistically negotiable; which statements by the perpetrators are empirically reliable; and which strategies can be used to negotiate the ransom demand downwards.
– Documentation. The entire course of the negotiations is recorded in a structured manner and is thus part of the executive management's decision-making documentation.
Attorney-client communication is also subject to a duty of confidentiality. As a result, discussions between management, IT forensics, and legal counsel can be conducted more openly than within a purely internal structure.
The legal admissibility check before a ransom payment
Paying a ransom is not explicitly prohibited in Austria. However, depending on the circumstances, it can be relevant under criminal law, in particular pursuant to Section 153 of the Criminal Code (breach of trust), Section 278 of the Criminal Code (criminal organization), Section 278b of the Criminal Code (terrorist organization), and Section 278d of the Criminal Code (terrorist financing).
The most important inspection points at a glance:
Embezzlement (§ 153 StGB). What is decisive is whether, after a careful balancing of the pros and cons, the payment is in the interest of the company. If the averted disadvantages outweigh the advantages, there is no damage to assets. Where possible, it is also recommended to involve the shareholders. Corporate liability under the Austrian Corporate Liability Act (VbVG) is ruled out because the company itself would be the victim of the breach of trust.
Money laundering (Section 165 StGB). Contrary to a widespread assumption, a legitimately operating company does not commit money laundering by paying a ransom: the assets used do not originate from a predicate offense, but are the victim's own property.
Criminal and terrorist organization (Sections 278, 278b of the Criminal Code). Here lies the actual risk. In literature concerning ransomware cases in such scenarios, reference is regularly made to grounds of justification and excuse, in particular the excusatory emergency under Section 10 of the Criminal Code. The balancing of interests depends on the individual case and must be documented.
Sanctions law. Before any payment, it must be checked whether sanction law prohibits it. Several ransomware groups and the natural persons associated with them are listed on international sanctions lists. If there is a US nexus—for example through service providers or marketplaces—US legal requirements may additionally be relevant. The check is carried out both for the perpetrator group and for the specific recipient address.
Ransom Payment – Processing: What to Consider When Making the Payment
If, after consideration, it is decided to pay, the processing itself is a separate work step:
1. Pre-transaction wallet screening. The recipient address provided by the attacker is checked for sanctions and connections to known clusters.
2. Acquisition of crypto assets via a regulated service provider. Since December 30, 2024, MiCAR has been in effect. Crypto-asset service providers in Austria are subject to the supervision of the FMA. The short-term procurement of larger amounts is generally not feasible without preparation—one reason to clarify solvency already in the crisis plan.
3. Secure processing. An orderly and secure processing of ransom payments / cryptocurrency transactions requires experience and know-how. A seamless documentation chain is a prerequisite for potential reimbursement by cyber insurance.
4. Complete documentation. Transaction hashes, timestamps, negotiation history, screening results and basis of decision – required for insurance, authorities, auditing and the discharge of corporate bodies.
A ransom payment does not eliminate a reporting obligation. The deadline under Article 33 GDPR runs independently of whether negotiations take place or payment is made. Furthermore, the attackers' promise to delete stolen data does not change the fact that a personal data breach has occurred.
Securing evidence: legal and technical level
Cybercrime proceedings regularly require a combination of legal expertise and technical analysis. In practice, legal enforcement often depends on whether technical traces were documented in a timely, complete, and verifiable manner.
Relevant trace evidence includes, among other things: IP addresses and timestamps (taking Carrier-Grade NAT into account), device and log data, email headers, KYC data at payment and crypto service providers, bank accounts, and blockchain transactions.
Transactions on public blockchains such as Bitcoin are permanently stored and can therefore generally be analyzed even years later. Crucial for recovery is not traceability alone, but the question of whether the funds have arrived at a regulated service provider with identification obligations – and whether security measures are initiated there in time.
The division of labor is clear: TRCN GmbH creates the technical transaction analysis and the forensic documentation. ATB.LAW handles legal advice and representation – vis-à-vis public prosecutors, courts, banks, crypto exchanges, or insurance companies.
Responsible authorities in Austria
| Position | Responsibility |
|---|---|
| Every police station | Receipt of criminal complaints |
| Federal Criminal Police Office – Cybercrime Competence Center (C4) | National Coordination Office; operates a reporting office for cybercrime (against-cybercrime@bmi.gv.at). Filing a report via the reporting office is not possible. |
| Public Prosecutor's Office | Direction of the investigation proceedings |
| Public Prosecutor's Office for Combating White-Collar Crime and Corruption | Certain economic criminal cases (§ 20a StPO) |
| Data protection authority | Notifications pursuant to Art. 33 GDPR, supervisory authority |
| Federal Office for Cybersecurity | Central cybersecurity authority under the NISG 2026 (as of October 1, 2026) |
| FMA | Supervision of crypto-asset service providers under MiCAR/MiCA-VVG; investor warnings |
| CERT.at / GovCERT Austria | Technical Incident Coordination |
| Watchlist Internet, Internet Ombudsstelle | Consumer information and initial consultation |
Common errors
- The GDPR deadline is being overlooked, because the IT analysis is the priority. Article 33 GDPR ties into gaining knowledge, not complete clarification.
- The management is negotiating with the attackers themselves. Inadvised information regarding revenue, insurance coverage, or data criticality immediately increases the demand.
- Payment without prior sanction and wallet screening. The risk lies not only with the perpetrator group, but also with the specific recipient address.
- The report is not filed because „nothing happens anyway“. This also eliminates seizure options and access to the case file.
- No private party participation. Anyone who does not join the criminal proceedings as a private participant (§ 67 Code of Criminal Procedure) loses the right to inspect the files, the right to file motions, and the possibility of being awarded damages.
- German legal information is accepted without verification. Sections 675u et seq. of the German Civil Code (BGB) do not apply in Austria; Sections 63, 67, and 68 of the Payment Services Act 2018 (ZaDiG 2018) are decisive.
- Systems are being reconfigured before backups were made. This complicates both criminal prosecution and proof of insurance.
- Second payments to alleged recovery services. Recovery scams are a standalone business model.
When legal representation makes sense
ATB.LAW regularly advises and represents victims of cybercrime cases as well as companies in incident response situations and defendants in cybercrime criminal proceedings.
Legal support is typically indicated when one of the following questions arises:
- Is the damage still recoverable via a payment service provider or a crypto exchange?
- Should preventive measures in criminal proceedings be applied for?
- Are there civil law claims against the bank, platform, or service provider?
- Is a reporting or disclosure deadline running?
- Were data carriers seized and is the analysis to be restricted?
- Is a decision on a ransom payment pending and has it been clarified whether it is permissible?
- Should communication with the attackers be conducted in a professional and documented manner?
- Does a payment need to be screened for sanctions and processed technically?
ATB.LAW also takes over the negotiation management with the perpetrator group in ransomware cases and guides companies through the processing of a potential ransom payment – together with TRCN GmbH for the blockchain forensic examination of the payment address.
Conclusion
Cybercrime is not a fringe phenomenon in Austria, but rather a mass offense with a declining clearance rate. For victims, this has a practical consequence: the probability of a case being solved solely through filing a report is statistically low. What is decisive is the actual execution of securing, reporting, and evidence-gathering steps in the first hours and days.
For companies, an additional factor came into play in 2026: With the entry into force of the NISG 2026 on October 1, 2026, cybersecurity became an enforceable legal obligation for a significantly larger circle of entities—with registration, reporting, and compliance obligations, and a sanction regime reaching into the tens of millions.
If you are affected by a cybercrime incident, we will examine the legal and technical courses of action – from securing evidence, filing a criminal complaint, and joining criminal proceedings as a private party, to enforcing civil claims. In cases of cyber extortion / ransomware, in addition to traditional legal activities, we also handle ransom negotiations and organize – if necessary – the ransom payment.
Frequently asked questions:
Yes. Cybercrime is a collective term. Punishability arises from individual offenses under the Criminal Code (StGB), in particular Sections 118a, 119, 119a, 126a, 126b, 126c, 148a, and 225a StGB, as well as – when ICT is used as the instrument of the offense – from general offenses such as fraud (Sections 146 et seq. StGB) or extortion (Sections 144 et seq. StGB). In any given case, multiple offenses are frequently met simultaneously.
Where do I file a report for cybercrime?
At every police station in Austria. The Cybercrime Competence Center of the Federal Criminal Police Office also operates a reporting office (against-cybercrime@bmi.gv.at) for suspicious transaction reports and information; filing a report through this reporting office is currently not possible. As a general rule, prior legal advice is recommended.
Will I get my money back after a phishing attack?
In the event of an unauthorized payment transaction, the payment service provider must refund the amount pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) without undue delay, and no later than by the end of the following business day. The obligation to provide a refund may lapse or be reduced if the payer has breached their duty of care pursuant to Section 63 of the 2018 Payment Services Act (ZaDiG 2018): In cases of slight negligence, a maximum of 50 euros is to be borne, while in cases of gross negligence or intent, the payer is fully liable. Therefore, the assessment of one's own conduct in the individual case is regularly decisive.
Can stolen cryptocurrency be recovered?
A recovery is possible under certain conditions, but not guaranteed. Decisive factors are the traceability of the transactions on the blockchain, the identification of a regulated crypto service provider as the recipient, and the speed of the initiated security measures. The Federal Criminal Police Office expressly points out that the recovery of lost assets is not always successful.
Can the police just take my cell phone?
Since January 1, 2025, access to data media and data for the purpose of evaluation has been independently regulated in Sections 115f to 115l of the Code of Criminal Procedure (StPO) and requires prior judicial approval. This is based on the ruling of the Constitutional Court of December 14, 2023, G 352/2021. The order must narrow down the data categories to be seized; accused persons have rights of cooperation and inspection.
Do I have to report a cyber attack?
That depends on the role. In Austria, there is generally no mandatory requirement for victims to report a crime. Under data protection law, in the event of a personal data breach, there is generally an obligation to report it to the data protection authority within 72 hours (Art. 33 GDPR). For essential and important entities, the reporting obligations of the NISG 2026 apply as of October 1, 2026.
From when does the NISG 2026 apply?
The NISG 2026 was promulgated on December 23, 2025 (Federal Law Gazette I No. 94/2025) and will enter into force on October 1, 2026. Affected entities must register within three months of it entering into force, i.e., by December 31, 2026. The NISG 2018 will cease to be in force on October 1, 2026.
How much does an initial legal consultation cost?
That depends on the scope. A clearly defined initial assessment makes sense, in which it is examined whether security measures are still possible, what deadlines apply, and which claims can be realistically enforced. The terms and conditions are agreed upon in advance.
Is it a criminal offense to pay ransom?
There is no explicit ban on the payment of ransom in Austria. Depending on the specific circumstances, however, criminal offenses may be involved, in particular breach of trust (Section 153 of the Criminal Code) and participation in a criminal or terrorist organization (Sections 278, 278b of the Criminal Code) if the company is aware that the attack is backed by such an association. Money laundering pursuant to Section 165 of the Criminal Code can be ruled out for a legitimately operating company because the assets used do not originate from a prior offense. In addition, it must always be checked whether sanctions-related prohibitions on the provision of funds apply. The assessment depends on the individual case and should be carried out and documented prior to payment.
Should one even negotiate with ransomware attackers?
In practice, there are good reasons to enter into negotiations—regardless of whether a payment is being considered. Negotiations buy time for forensics, backup verification, and reporting, enable a proof of concept for decryption, and provide clues regarding the attack vector and the actual data exfiltrated. It is advisable to have the communication handled not by management itself, but by an experienced external entity.
Do I have to report a data breach even if I pay the ransom?
Yes. The reporting obligation under Art. 33 GDPR is triggered by the breach of personal data protection and the acquisition of knowledge, not by the outcome of the negotiations. Even a promise by the attackers to delete captured data does not eliminate the breach that has occurred and is not verifiable in practice.