{"id":9333,"date":"2026-09-13T20:37:13","date_gmt":"2026-09-13T18:37:13","guid":{"rendered":"https:\/\/atb.law\/?post_type=blog-post&#038;p=9333"},"modified":"2026-09-13T20:40:50","modified_gmt":"2026-09-13T18:40:50","slug":"cybercrime-austria","status":"publish","type":"blog-post","link":"https:\/\/atb.law\/en\/blog-post\/cybercrime-oesterreich\/","title":{"rendered":"Cybercrime in Austria"},"content":{"rendered":"<h2 dir=\"ltr\" id=\"page-das-wichtigste-in-kurze\">Key points at a glance<\/h2>\n<ul dir=\"ltr\">\n<li><strong>Cybercrime is not a specific criminal offense.<\/strong>, but rather a collective term for a multitude of offenses under the Criminal Code and supplementary penal law.<\/li>\n<li>The <strong>Federal Criminal Police Office recorded a total of 63,459 reports in 2025<\/strong> in the field of cybercrime; 21,988 of these accounted for cybercrime in the narrower sense.<\/li>\n<li>The <strong>fraudulent data processing abuse (Section 148a of the German Criminal Code)<\/strong> is by far the most frequent offense in the narrower sense with 17,799 reports in 2025.<\/li>\n<li>Since <strong>January 1, 2025<\/strong> does the seizure and evaluation of data media such as mobile phones require <strong>prior judicial authorization<\/strong> (Sections 115f et seq. of the German Code of Criminal Procedure).<\/li>\n<li>The <strong>NISG 2026 entered into force on October 1, 2026<\/strong> and significantly expands the circle of companies obligated under cybersecurity law.<\/li>\n<li>In the event of a data breach, simultaneously runs the <strong>72-hour period under Article 33 GDPR<\/strong> \u2013 regardless of whether a criminal complaint is filed.<\/li>\n<li><strong>Paying a ransom is not generally prohibited in Austria, but it is not generally permitted either.<\/strong> Whether it is permissible and economically justifiable must be examined and documented on a case-by-case basis \u2013 negotiations with the attackers are almost always advisable regardless of this.<\/li>\n<li><strong>Speed decides.<\/strong> In payment and crypto transactions, the time window of the first few hours determines whether security measures take effect.<\/li>\n<\/ul>\n<h2 dir=\"ltr\" id=\"page-was-bedeutet-cybercrime-in-osterreich\">What does cybercrime mean in Austria?<\/h2>\n<blockquote>\n<p dir=\"ltr\"><strong>Cybercrime refers to criminal offenses that are either directed against computer systems and data themselves or in which information and communication technology is used as a means to commit the crime.<\/strong> A specific criminal offense of \u201ecybercrime\u201c does not exist in Austrian law.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">Based on the Budapest Convention, the Federal Criminal Police Office distinguishes between two categories:<\/p>\n<p dir=\"ltr\"><strong>Cybercrime in the strict sense<\/strong> detects attacks targeting networks, devices, services, or data. Typical examples include hacking, data corruption, and DDoS attacks.<\/p>\n<p dir=\"ltr\"><strong>cybercrime in the broader sense<\/strong> covers classic offenses planned, prepared, or committed using information and communication technology (ICT) \u2013 primarily internet fraud, but also extortion, dangerous threats, or drug trafficking on the darknet.<\/p>\n<h2 dir=\"ltr\" id=\"page-cybercrime-in-osterreich-die-zahlen-2025\">Cybercrime in Austria: the 2025 figures<\/h2>\n<blockquote>\n<p dir=\"ltr\"><strong>According to the 2025 Cybercrime Report by the Federal Criminal Police Office, 63,459 cases of cybercrime were reported in Austria in 2025. This corresponds to an increase of 1.8 percent compared to 2024. The clearance rate fell by 0.9 percentage points to 30.8 percent.<\/strong><\/p>\n<\/blockquote>\n<h4 dir=\"ltr\" id=\"page-entwicklung-2021-2025\">Development 2021\u20132025<\/h4>\n<div dir=\"ltr\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Year<\/th>\n<th scope=\"col\">Reported crimes<\/th>\n<th scope=\"col\">Solved crimes<\/th>\n<th scope=\"col\">clearance rate<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>2021<\/td>\n<td>46.179<\/td>\n<td>17.020<\/td>\n<td>36,9 %<\/td>\n<\/tr>\n<tr>\n<td>2022<\/td>\n<td>60.195<\/td>\n<td>20.378<\/td>\n<td>33,9 %<\/td>\n<\/tr>\n<tr>\n<td>2023<\/td>\n<td>65.864<\/td>\n<td>20.818<\/td>\n<td>31,6 %<\/td>\n<\/tr>\n<tr>\n<td>2024<\/td>\n<td>62.328<\/td>\n<td>19.785<\/td>\n<td>31,7 %<\/td>\n<\/tr>\n<tr>\n<td>2025<\/td>\n<td>63.459<\/td>\n<td>19.570<\/td>\n<td>30,8 %<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p dir=\"ltr\"><em>Source: Federal Criminal Police Office, Cybercrime Report 2025 (Police Crime Statistics)<\/em><\/p>\n<h4 dir=\"ltr\" id=\"page-\">\u00a0<\/h4>\n<h4 dir=\"ltr\" id=\"page-cybercrime-im-engeren-sinn-delikte-im-jahresvergleich\">Cybercrime in the narrower sense: offences in a year-on-year comparison<\/h4>\n<p dir=\"ltr\">Strictly speaking, the number of reports rose by 8.6 percent to 21,988 cases in 2025.<\/p>\n<div dir=\"ltr\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Offense<\/th>\n<th scope=\"col\">Advertisements 2024<\/th>\n<th scope=\"col\">Ads 2025<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Section 148a of the Criminal Code (StGB) \u2013 Fraudulent abuse of data processing<\/td>\n<td>16.192<\/td>\n<td>17.799<\/td>\n<\/tr>\n<tr>\n<td>Section 118a StGB \u2013 Unlawful access to a computer system<\/td>\n<td>1.991<\/td>\n<td>2.060<\/td>\n<\/tr>\n<tr>\n<td>Section 225a StGB \u2013 Falsification of data<\/td>\n<td>713<\/td>\n<td>887<\/td>\n<\/tr>\n<tr>\n<td>Section 107c of the Criminal Code (StGB) \u2013 Continued harassment by means of a computer system<\/td>\n<td>462<\/td>\n<td>521<\/td>\n<\/tr>\n<tr>\n<td>Section 126a StGB \u2013 Data Corruption<\/td>\n<td>241<\/td>\n<td>270<\/td>\n<\/tr>\n<tr>\n<td>Section 126c StGB \u2013 Misuse of computer programs or access data<\/td>\n<td>496<\/td>\n<td>258<\/td>\n<\/tr>\n<tr>\n<td>Section 126b StGB \u2013 Disruption of the functionality of a computer system<\/td>\n<td>76<\/td>\n<td>111<\/td>\n<\/tr>\n<tr>\n<td><strong>Total (in the strict sense)<\/strong><\/td>\n<td><strong>20.246<\/strong><\/td>\n<td><strong>21.988<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p dir=\"ltr\"><em>Source: Federal Criminal Police Office, Cybercrime Report 2025<\/em><\/p>\n<h4 dir=\"ltr\" id=\"page--2\">\u00a0<\/h4>\n<h4 dir=\"ltr\" id=\"page-weitere-kennzahlen-aus-dem-jahr-2025\">Further key figures from 2025<\/h4>\n<ul dir=\"ltr\">\n<li><strong>Internet Fraud (\u00a7\u00a7 146 to 148 StGB):<\/strong> 31,001 reported cases, a decrease of 2.4 percent compared to 2024.<\/li>\n<li><strong>Cyber Trading Fraud:<\/strong> According to the Federal Criminal Police Office, the total damage amounted to around 120 million euros. The Federal Criminal Police Office has set up a dedicated investigative team for this purpose.<\/li>\n<li><strong>Ransomware:<\/strong> 111 reported cases nationwide. In around 40 percent of the reports, no clear assignment to a perpetrator group was possible. INC, Akira, RansomHub, LockBit 4.0, and Qilin, among others, were identified.<\/li>\n<li><strong>Cyber extortion (\u00a7\u00a7 144, 145 Swiss Criminal Code):<\/strong> 2,380 reports, a decrease of 18.8 percent with a clearance rate of 9.6 percent.<\/li>\n<\/ul>\n<p dir=\"ltr\">The Federal Criminal Police Office explicitly points out that the number of unreported cases in cybercrime is particularly high because many victims do not report the crimes out of shame, fear, or due to the low amount of damage.<\/p>\n<h2 dir=\"ltr\" id=\"page-die-wichtigsten-cybercrime-tatbestande-im-osterreichischen-stgb\">The most important cybercrime offenses in the Austrian Criminal Code<\/h2>\n<blockquote>\n<p dir=\"ltr\"><strong>The central criminal offenses for cybercrime in the strict sense can be found in Sections 118a, 119, 119a, 126a, 126b, 126c, 148a, and 225a of the Criminal Code (StGB).<\/strong> In the broader sense, cybercrime also includes, in particular, fraud (\u00a7\u00a7 146 et seq. SCC), extortion (\u00a7\u00a7 144, 145 SCC), dangerous threats (\u00a7 107 SCC), and coercion (\u00a7 105 SCC).<\/p>\n<\/blockquote>\n<div dir=\"ltr\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Destiny<\/th>\n<th scope=\"col\">Subject matter regulated<\/th>\n<th scope=\"col\">Typical case scenario<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Section 118a of the Criminal Code<\/td>\n<td>Unauthorized access to a computer system<\/td>\n<td>Account takeover, hacking of email or cloud access<\/td>\n<\/tr>\n<tr>\n<td>Section 119 of the German Criminal Code<\/td>\n<td>Violation of telecommunications secrecy<\/td>\n<td>Interception of communication<\/td>\n<\/tr>\n<tr>\n<td>Section 119a of the German Criminal Code<\/td>\n<td>Abusive data interception<\/td>\n<td>Reading out data transmissions<\/td>\n<\/tr>\n<tr>\n<td>Section 126a of the Criminal Code<\/td>\n<td>Data corruption<\/td>\n<td>Encryption of corporate data by ransomware<\/td>\n<\/tr>\n<tr>\n<td>Section 126b of the German Criminal Code<\/td>\n<td>Disruption of the functionality of a computer system<\/td>\n<td>DDoS attack on online store or public authority<\/td>\n<\/tr>\n<tr>\n<td>Section 126c of the German Criminal Code<\/td>\n<td>Misuse of computer programs or access data<\/td>\n<td>Trading in malware or access credentials<\/td>\n<\/tr>\n<tr>\n<td>Section 148a of the German Criminal Code<\/td>\n<td>Fraudulent data processing abuse<\/td>\n<td>Unauthorized debit after phishing, order placed in someone else's name<\/td>\n<\/tr>\n<tr>\n<td>Section 225a of the German Criminal Code<\/td>\n<td>Data falsification<\/td>\n<td>Fake documents for opening online accounts<\/td>\n<\/tr>\n<tr>\n<td>Sections 144, 145 of the German Criminal Code<\/td>\n<td>extortion, aggravated extortion<\/td>\n<td>sextortion, ransom demand after ransomware attack<\/td>\n<\/tr>\n<tr>\n<td>Section 107c of the German Criminal Code<\/td>\n<td>Continuous harassment by means of a computer system<\/td>\n<td>Cyberbullying<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p dir=\"ltr\"><strong>Practical tip:<\/strong> In reality, almost never is there a single offense. A ransomware attack typically fulfills Section 118a of the Criminal Code (intrusion), Section 126a of the Criminal Code (encryption), and Sections 144 et seq. of the Criminal Code (ransom demand) concurrently. For reporting the crime, this multiple qualification is relevant because it influences the sentencing range and thus also the permissible investigative measures.<\/p>\n<h2 dir=\"ltr\" id=\"page-die-funf-grosen-fallgruppen-in-der-praxis\">The five major case groups in practice<\/h2>\n<h3 dir=\"ltr\" id=\"page-1-krypto-und-anlagebetrug\">1. Crypto and investment fraud<\/h3>\n<blockquote>\n<p dir=\"ltr\"><strong>Cyber Trading Fraud refers to investment fraud via fake trading platforms where victims are shown simulated price gains while the deposited funds have actually been siphoned off.<\/strong> According to the Federal Criminal Police Office, this form of fraud alone caused damage of around 120 million euros in Austria in 2025.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">Typical manifestations: fake trading platforms, pig butchering (long-term trust-building before the investment request), love scams, rug pulls, and so-called recovery scams, in which scam victims are defrauded a second time.<\/p>\n<p dir=\"ltr\">From a legal perspective, \u00a7\u00a7 146 et seq. of the Austrian Criminal Code (StGB), the seizure of assets under the Austrian Code of Criminal Procedure (StPO) and \u2013 in the case of an identifiable crypto service provider \u2013 civil and regulatory approaches are the primary focus. Since December 30, 2024, Regulation (EU) 2023\/1114 (MiCAR) is fully applicable; the competent authority for crypto-asset service providers in Austria is the <strong>Financial Market Authority (FMA)<\/strong> pursuant to the MiCA Regulation Implementation Act (MiCA-VVG, Federal Law Gazette I No. 111\/2024). This significantly improves the accessibility of regulated service providers.<\/p>\n<h3 dir=\"ltr\" id=\"page-2-ransomware-und-angriffe-auf-unternehmen\">2. Ransomware and attacks on companies<\/h3>\n<blockquote>\n<p dir=\"ltr\"><strong>In Austria, a ransomware attack regularly triggers three parallel lines of obligation: under criminal law, the question of reporting it; under data protection law, the notification duty pursuant to Art. 33 GDPR; and under corporate law, the duty of care of the management board.<\/strong><\/p>\n<\/blockquote>\n<p dir=\"ltr\">There is no general obligation for the victim of a crime to report it in Austria. However, a different standard applies to managers: they act on behalf of the company and must protect its interests to avoid liability. Whether to report a crime is therefore a documented balancing decision\u2014not a matter of gut feeling.<\/p>\n<p dir=\"ltr\">The question of ransom payment raises distinct criminal and liability law issues \u2013 in particular regarding breach of trust (Section 153 of the Criminal Code), participation in a criminal organization (Section 178 of the Criminal Code), as well as sanctions and anti-money laundering compliance. It cannot be answered without a case-by-case assessment. How negotiations with attackers are conducted and what legal aspects must be considered during payment processing is covered in the section \u201eNegotiation with Ransomware Attackers and Assistance with Ransom Payment\u201c below.<\/p>\n<h3 dir=\"ltr\" id=\"page-3-phishing-und-kontobetrug\">3. Phishing and Account Fraud<\/h3>\n<blockquote>\n<p dir=\"ltr\"><strong>In the event of an unauthorized payment transaction, the payer's payment service provider must refund the amount pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) without undue delay, and in any event no later than the end of the following business day, after becoming aware of or being notified of the transaction.<\/strong><\/p>\n<\/blockquote>\n<p dir=\"ltr\">The liability of the payer is governed by Section 68 of the 2018 Payment Services Act (ZaDiG 2018): In the event of a slightly negligent breach of the due diligence obligations pursuant to Section 63 ZaDiG 2018, the payment service provider may claim a maximum of 50 euros. In the event of intent or gross negligence, however, the payer is fully liable. In practice, disputes therefore almost always revolve around the question of whether gross negligence exists \u2013 and who has to prove it.<\/p>\n<p dir=\"ltr\">At the EU law level, a clarification is underway: The <strong>Advocate General at the ECJ on March 5, 2026, in Case C-70\/25<\/strong> to take the view that a bank may not refuse the immediate refund of an unauthorized payment transaction by invoking gross negligence on the part of the customer; any potential claim for recovery must be asserted separately. Regarding the legal status at the time of this article, a final judgment by the Court could not be established. Opinions of the Advocate General are not binding on the Court.<\/p>\n<h3 dir=\"ltr\" id=\"page-4-strafverfahren-und-digitale-beweismittel\">4. Criminal proceedings and digital evidence<\/h3>\n<blockquote>\n<p dir=\"ltr\"><strong>Since January 1, 2025, access to data media and data for the purpose of analysis has been independently regulated in Austria under Sections 115f to 115l of the Code of Criminal Procedure (StPO) and requires prior judicial authorization.<\/strong><\/p>\n<\/blockquote>\n<p dir=\"ltr\">The background is the realization of <strong>Constitutional Court of December 14, 2023, G 352\/2021<\/strong>. The VfGH annulled \u00a7 110 para 1 no 1 and para 4 as well as \u00a7 111 para 2 of the Code of Criminal Procedure (StPO) effective December 31, 2024, because the seizure of data media without judicial authorization and without sufficient legal protection constitutes a disproportionate interference with the fundamental right to data protection (\u00a7 1 Data Protection Act) and the right to respect for private life (Art. 8 ECHR).<\/p>\n<p dir=\"ltr\">Following this, the Code of Criminal Procedure Amendment Act 2024 created a dedicated investigative measure. It separates the technical data preparation from the substantive analysis and strengthens the transparency and participation rights of the accused.<\/p>\n<p dir=\"ltr\"><strong>Why this is relevant for those affected:<\/strong> If a mobile phone or laptop is seized today, the procedure is different from before 2025. The order must narrow down the categories of data to be confiscated, and defendants can influence the determination of the evaluation parameters. This is a defense approach that must be established early on.<\/p>\n<h3 dir=\"ltr\" id=\"page-5-cyber-erpressung-und-personlichkeitsrechte\">5. Cyber Extortion and Personal Rights<\/h3>\n<p dir=\"ltr\">Sextortion, cyberbullying, identity theft, and deepfakes predominantly affect private individuals. In 2025, the Federal Criminal Police Office observed, among other things, extortion using so-called \u201epolice fake emails,\u201c in which a sender from the law enforcement sector is impersonated and criminal proceedings are threatened.<\/p>\n<p dir=\"ltr\">In addition to the criminal law aspect (\u00a7\u00a7 107c, 144, 145, 107 StGB), civil law claims for injunction and removal as well as claims for deletion against platforms must be examined here.<\/p>\n<h2 dir=\"ltr\" id=\"page-rechtsrahmen-uber-das-strafrecht-hinaus\">Legal framework beyond criminal law<\/h2>\n<p dir=\"ltr\">Cybercrime regularly triggers obligations outside of criminal law in Austria. The following overview summarizes the key deadlines.<\/p>\n<div dir=\"ltr\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Legal basis<\/th>\n<th scope=\"col\">Who is affected?<\/th>\n<th scope=\"col\">Deadline \/ Time<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Art. 33 GDPR<\/strong><\/td>\n<td>Each controller in the event of a personal data breach<\/td>\n<td>Notification to the data protection authority generally within 72 hours of becoming aware, provided the legal requirements are met<\/td>\n<\/tr>\n<tr>\n<td><strong>Art. 34 GDPR<\/strong><\/td>\n<td>Controller in cases of likely high risk to data subjects<\/td>\n<td>Notification of the data subjects without undue delay<\/td>\n<\/tr>\n<tr>\n<td><strong>NISG 2026<\/strong><\/td>\n<td>Essential and important entities in the covered sectors<\/td>\n<td>Entry into force on October 1, 2026; registration within three months of entry into force; multi-stage incident reporting based on the framework of the NIS 2 Directive (early warning within 24 hours, notification within 72 hours)<\/td>\n<\/tr>\n<tr>\n<td><strong>ZaDiG 2018, \u00a7 67<\/strong><\/td>\n<td>Payment service provider in the event of an unauthorized payment transaction<\/td>\n<td>Refund without delay, at the latest by the end of the following business day<\/td>\n<\/tr>\n<tr>\n<td><strong>MiCAR \/ MiCA-VVG<\/strong><\/td>\n<td>Cryptoasset service providers<\/td>\n<td>MiCAR fully applicable since 12\/30\/2024; supervision by the FMA<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 dir=\"ltr\" id=\"page-nisg-2026-was-sich-am-1-oktober-2026-anderte\">NISG 2026: What changed on October 1, 2026<\/h2>\n<blockquote>\n<p dir=\"ltr\"><strong>The Network and Information Systems Security Act 2026 (NISG 2026) was published in the Federal Law Gazette on December 23, 2025 (Federal Law Gazette I No. 94\/2025) and entered into force on October 1, 2026. At the same time, the NISG 2018 ceases to be in force.<\/strong><\/p>\n<\/blockquote>\n<p dir=\"ltr\">The National Council passed the law on December 12, 2025, with the required two-thirds majority, after a first implementation attempt had failed in 2024. Being established is a <strong>Federal Office for Cybersecurity<\/strong> as the central cybersecurity authority. Affected entities must register within three months of entry into force\u2014that is, by December 31, 2026.<\/p>\n<p dir=\"ltr\">The scope of application is expanding significantly: while the 2018 NIS Act covered only a small circle of designated operators of critical infrastructure, around 4,000 affected entities are now being discussed in Austria. Decisive factors are sector affiliation, company size, and territoriality. The NIS2 Directive provides for fines of up to 10 million euros or 2 percent of total worldwide annual turnover for essential entities.<\/p>\n<p dir=\"ltr\"><strong>Practical consequence:<\/strong> Companies that were not previously NIS-regulated must check their status themselves. Official designation does not happen automatically.<\/p>\n<h2 dir=\"ltr\" id=\"page-was-im-akuten-fall-zu-tun-ist\">What to do in an acute case<\/h2>\n<p dir=\"ltr\"><strong>For individuals<\/strong><\/p>\n<ol dir=\"ltr\">\n<li><strong>Stop payment process immediately.<\/strong> In the event of account debits, contact the bank immediately and arrange for the account to be blocked. The obligation to refund pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) is contingent upon reporting it to the payment service provider.<\/li>\n<li><strong>Secure evidence before deletion.<\/strong> Screenshots with visible date, complete email headers, chat histories, transaction IDs, wallet addresses, bank statements.<\/li>\n<li><strong>Check possible legal action \/ file a report at a police station.<\/strong> As a rule, it is recommended to seek (at least) an initial legal consultation. Criminal offenses can be reported to any police station.\u00a0<\/li>\n<li><strong>Do not make a second payment.<\/strong> Do not respond to so-called recovery services or alleged authorities that contact you and promise to bring back your money or claim to have found your money. This is secondary fraud.<\/li>\n<li><strong>For crypto transactions: Fully document transaction data.<\/strong> Traceability depends on whether the recipient addresses and transaction hashes have been saved.<\/li>\n<\/ol>\n<p dir=\"ltr\"><strong>For businesses<\/strong><\/p>\n<ol dir=\"ltr\">\n<li><strong>Activate the incident response team and define decision-making paths.<\/strong> Who decides on shutdown, communication, payment?<\/li>\n<li><strong>Evidence preservation before restoration.<\/strong> The Federal Criminal Police Office points out that systems are often repaired or reinstalled even before a crime is reported\u2014and this very act destroys the possibility of attributing the attack to a perpetrator group.<\/li>\n<li><strong>Check the 72-hour period under Art. 33 GDPR.<\/strong> It runs regardless of whether the technical incident has already been fully resolved and knows no weekends.<\/li>\n<li><strong>Check NISG affectedness<\/strong> and observe the reporting obligations to the cybersecurity authority.<\/li>\n<li><strong>Involve insurance at an early stage.<\/strong> Cyber insurance terms and conditions regularly contain obligations for immediate notification and the coordination of service providers.<\/li>\n<li><strong>Prepare communication, don't improvise.<\/strong> A communicating company can help shape the framework of disclosure; one that is caught out afterwards is permanently on the defensive.<\/li>\n<li><strong>Review of legal admissibility and sanctions screening <\/strong>prior to any consideration of payment.<\/li>\n<\/ol>\n<h2 id=\"page-verhandlung-mit-ransomware-angreifern-und-begleitung-der-losegeldzahlung\">Negotiation with ransomware attackers and assistance with ransom payment<\/h2>\n<blockquote>\n<p><strong>Negotiations with ransomware attackers are worthwhile even if payment is not seriously considered.<\/strong> They buy time, provide insights into the attack vector and the actual data leaked, and create the basis for decision-making that management needs for a liability-secure decision.<\/p>\n<\/blockquote>\n<p><strong>ATB.LAW manages communication with attackers in ransomware cases and guides affected companies through the decision-making process regarding a potential ransom payment \u2013 from the legal admissibility review and negotiation management to technical execution.<\/strong><\/p>\n<p><strong>Negotiation is a discipline in its own right, or why management shouldn't conduct the negotiation itself<\/strong><\/p>\n<blockquote>\n<p><strong>The negotiation of cyber extortion follows its own rules and has little in common with a commercial negotiation.<\/strong> On the other side is not a contractual partner, but a gang of perpetrators organized on a division-of-labor basis, which has a well-rehearsed procedure, empirical values from a large number of parallel cases, and an economic interest in the continuation of its business model.<\/p>\n<\/blockquote>\n<p>This asymmetry shapes the entire communication. The attackers deliberately set short deadlines and threaten to publish or resell the data to make informed decisions more difficult. They know the typical response patterns of affected companies because they bring about this situation regularly\u2014whereas for the affected company, it is almost always the first case of this kind.<\/p>\n<p>Additionally, every statement made in the perpetrator group's chat portal is potentially relevant as evidence\u2014vis-\u00e0-vis authorities, the insurance company, and potentially later vis-\u00e0-vis shareholders. Conducting negotiations in cyber extortion cases is therefore a specialized discipline at the intersection of criminal law, compliance, and IT forensics, and should not be handled by management itself, but rather by an experienced external entity.<\/p>\n<h3 id=\"page-die-fuhrung-der-kommunikation-durch-einen-rechtsanwalt-hat-drei-praktische-effekte\"><strong>Conducting communication through a lawyer has three practical effects:<\/strong><\/h3>\n<p>\u2013 <strong>Decoupling the decision from the pressure.<\/strong>\u00a0Negotiations take place before a decision is made. Gaining time is an independent negotiation goal in the process.<br \/>\u2013 <strong>Experience from conducted negotiations. <\/strong>ATB.LAW has been regularly conducting negotiations with ransomware perpetrator groups for several years. This practice yields assessments that are not available to a company affected for the first time: how a specific group reacts to delays, counteroffers, or demands for proof; which demand amounts are realistically negotiable; which statements by the perpetrators are empirically reliable; and which strategies can be used to negotiate the ransom demand downwards.\u00a0<br \/>\u2013 <strong>Documentation.<\/strong> The entire course of the negotiations is recorded in a structured manner and is thus part of the executive management's decision-making documentation.<\/p>\n<p>Attorney-client communication is also subject to a duty of confidentiality. As a result, discussions between management, IT forensics, and legal counsel can be conducted more openly than within a purely internal structure.<\/p>\n<h2 id=\"page-die-rechtliche-zulassigkeitsprufung-vor-einer-losegeldzahlung\">The legal admissibility check before a ransom payment<\/h2>\n<p><strong>Paying a ransom is not explicitly prohibited in Austria. However, depending on the circumstances, it can be relevant under criminal law, in particular pursuant to Section 153 of the Criminal Code (breach of trust), Section 278 of the Criminal Code (criminal organization), Section 278b of the Criminal Code (terrorist organization), and Section 278d of the Criminal Code (terrorist financing).<\/strong><\/p>\n<p>The most important inspection points at a glance:<\/p>\n<p><strong>Embezzlement (\u00a7 153 StGB).<\/strong> What is decisive is whether, after a careful balancing of the pros and cons, the payment is in the interest of the company. If the averted disadvantages outweigh the advantages, there is no damage to assets. Where possible, it is also recommended to involve the shareholders. Corporate liability under the Austrian Corporate Liability Act (VbVG) is ruled out because the company itself would be the victim of the breach of trust.<\/p>\n<p><strong>Money laundering (Section 165 StGB).<\/strong> Contrary to a widespread assumption, a legitimately operating company does not commit money laundering by paying a ransom: the assets used do not originate from a predicate offense, but are the victim's own property.<\/p>\n<p><strong>Criminal and terrorist organization (Sections 278, 278b of the Criminal Code).<\/strong> Here lies the actual risk. In literature concerning ransomware cases in such scenarios, reference is regularly made to grounds of justification and excuse, in particular the excusatory emergency under Section 10 of the Criminal Code. The balancing of interests depends on the individual case and must be documented.<\/p>\n<p><strong>Sanctions law.<\/strong> Before any payment, it must be checked whether sanction law prohibits it. Several ransomware groups and the natural persons associated with them are listed on international sanctions lists. If there is a US nexus\u2014for example through service providers or marketplaces\u2014US legal requirements may additionally be relevant. The check is carried out both for the perpetrator group and for the specific recipient address.<\/p>\n<h2 id=\"page-losegeldzahlung-abwicklung-was-bei-der-zahlung-zu-beachten-ist\">Ransom Payment \u2013 Processing: What to Consider When Making the Payment<\/h2>\n<p>If, after consideration, it is decided to pay, the processing itself is a separate work step:<\/p>\n<p>1. <strong>Pre-transaction wallet screening.<\/strong> The recipient address provided by the attacker is checked for sanctions and connections to known clusters.<br \/>2. <strong>Acquisition of crypto assets via a regulated service provider.<\/strong> Since December 30, 2024, MiCAR has been in effect. Crypto-asset service providers in Austria are subject to the supervision of the FMA. The short-term procurement of larger amounts is generally not feasible without preparation\u2014one reason to clarify solvency already in the crisis plan.<br \/>3. <strong>Secure processing.<\/strong> An orderly and secure processing of ransom payments \/ cryptocurrency transactions requires experience and know-how. A seamless documentation chain is a prerequisite for potential reimbursement by cyber insurance.<br \/>4. <strong>Complete documentation.<\/strong> Transaction hashes, timestamps, negotiation history, screening results and basis of decision \u2013 required for insurance, authorities, auditing and the discharge of corporate bodies.<\/p>\n<p><strong>A ransom payment does not eliminate a reporting obligation.<\/strong> The deadline under Article 33 GDPR runs independently of whether negotiations take place or payment is made. Furthermore, the attackers' promise to delete stolen data does not change the fact that a personal data breach has occurred.<\/p>\n<h2 dir=\"ltr\" id=\"page-beweissicherung-rechtliche-und-technische-ebene\">Securing evidence: legal and technical level<\/h2>\n<blockquote>\n<p dir=\"ltr\"><strong>Cybercrime proceedings regularly require a combination of legal expertise and technical analysis.<\/strong> In practice, legal enforcement often depends on whether technical traces were documented in a timely, complete, and verifiable manner.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">Relevant trace evidence includes, among other things: IP addresses and timestamps (taking Carrier-Grade NAT into account), device and log data, email headers, KYC data at payment and crypto service providers, bank accounts, and blockchain transactions.<\/p>\n<blockquote>\n<p dir=\"ltr\"><strong>Transactions on public blockchains such as Bitcoin are permanently stored and can therefore generally be analyzed even years later.<\/strong> Crucial for recovery is not traceability alone, but the question of whether the funds have arrived at a regulated service provider with identification obligations \u2013 and whether security measures are initiated there in time.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">The division of labor is clear: <a href=\"http:\/\/www.trcn.at\"><strong>TRCN GmbH<\/strong><\/a> creates the technical transaction analysis and the forensic documentation. <strong>ATB.LAW<\/strong> handles legal advice and representation \u2013 vis-\u00e0-vis public prosecutors, courts, banks, crypto exchanges, or insurance companies.<\/p>\n<h2 dir=\"ltr\" id=\"page-zustandige-stellen-in-osterreich\">Responsible authorities in Austria<\/h2>\n<p>&nbsp;<\/p>\n<div dir=\"ltr\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Position<\/th>\n<th scope=\"col\">Responsibility<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Every police station<\/strong><\/td>\n<td>Receipt of criminal complaints<\/td>\n<\/tr>\n<tr>\n<td><strong>Federal Criminal Police Office \u2013 Cybercrime Competence Center (C4)<\/strong><\/td>\n<td>National Coordination Office; operates a reporting office for cybercrime (<a href=\"mailto:against-cybercrime@bmi.gv.at\">against-cybercrime@bmi.gv.at<\/a>). <strong>Filing a report via the reporting office is not possible.<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Public Prosecutor's Office<\/strong><\/td>\n<td>Direction of the investigation proceedings<\/td>\n<\/tr>\n<tr>\n<td><strong>Public Prosecutor's Office for Combating White-Collar Crime and Corruption<\/strong><\/td>\n<td>Certain economic criminal cases (\u00a7 20a StPO)<\/td>\n<\/tr>\n<tr>\n<td><strong>Data protection authority<\/strong><\/td>\n<td>Notifications pursuant to Art. 33 GDPR, supervisory authority<\/td>\n<\/tr>\n<tr>\n<td><strong>Federal Office for Cybersecurity<\/strong><\/td>\n<td>Central cybersecurity authority under the NISG 2026 (as of October 1, 2026)<\/td>\n<\/tr>\n<tr>\n<td><strong>FMA<\/strong><\/td>\n<td>Supervision of crypto-asset service providers under MiCAR\/MiCA-VVG; investor warnings<\/td>\n<\/tr>\n<tr>\n<td><strong>CERT.at \/ GovCERT Austria<\/strong><\/td>\n<td>Technical Incident Coordination<\/td>\n<\/tr>\n<tr>\n<td><strong>Watchlist Internet, Internet Ombudsstelle<\/strong><\/td>\n<td>Consumer information and initial consultation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 dir=\"ltr\" id=\"page-haufige-fehler\">Common errors<\/h2>\n<p>&nbsp;<\/p>\n<ul dir=\"ltr\">\n<li><strong>The GDPR deadline is being overlooked<\/strong>, because the IT analysis is the priority. Article 33 GDPR ties into gaining knowledge, not complete clarification.<\/li>\n<li><strong>The management is negotiating with the attackers themselves.<\/strong> Inadvised information regarding revenue, insurance coverage, or data criticality immediately increases the demand.<\/li>\n<li><strong>Payment without prior sanction and wallet screening.<\/strong> The risk lies not only with the perpetrator group, but also with the specific recipient address.<\/li>\n<li><strong>The report is not filed because \u201enothing happens anyway\u201c.<\/strong> This also eliminates seizure options and access to the case file.<\/li>\n<li><strong>No private party participation.<\/strong> Anyone who does not join the criminal proceedings as a private participant (\u00a7 67 Code of Criminal Procedure) loses the right to inspect the files, the right to file motions, and the possibility of being awarded damages.<\/li>\n<li><strong>German legal information is accepted without verification.<\/strong> Sections 675u et seq. of the German Civil Code (BGB) do not apply in Austria; Sections 63, 67, and 68 of the Payment Services Act 2018 (ZaDiG 2018) are decisive.<\/li>\n<li><strong>Systems are being reconfigured before backups were made.<\/strong> This complicates both criminal prosecution and proof of insurance.<\/li>\n<li><strong>Second payments to alleged recovery services.<\/strong> Recovery scams are a standalone business model.<\/li>\n<\/ul>\n<h3 dir=\"ltr\" id=\"page-wann-anwaltliche-vertretung-sinnvoll-ist\">When legal representation makes sense<\/h3>\n<p dir=\"ltr\">ATB.LAW regularly advises and represents victims of cybercrime cases as well as companies in incident response situations and defendants in cybercrime criminal proceedings.<\/p>\n<p dir=\"ltr\">Legal support is typically indicated when one of the following questions arises:<\/p>\n<ul dir=\"ltr\">\n<li>Is the damage still recoverable via a payment service provider or a crypto exchange?<\/li>\n<li>Should preventive measures in criminal proceedings be applied for?<\/li>\n<li>Are there civil law claims against the bank, platform, or service provider?<\/li>\n<li>Is a reporting or disclosure deadline running?<\/li>\n<li>Were data carriers seized and is the analysis to be restricted?<\/li>\n<li>Is a decision on a ransom payment pending and has it been clarified whether it is permissible?<\/li>\n<li>Should communication with the attackers be conducted in a professional and documented manner?<\/li>\n<li>Does a payment need to be screened for sanctions and processed technically?<\/li>\n<\/ul>\n<blockquote>\n<p><strong>ATB.LAW also takes over the negotiation management with the perpetrator group in ransomware cases and guides companies through the processing of a potential ransom payment \u2013 together with TRCN GmbH for the blockchain forensic examination of the payment address.<\/strong><\/p>\n<\/blockquote>\n<h3 dir=\"ltr\" id=\"page-fazit\"><strong>Conclusion<\/strong><\/h3>\n<p dir=\"ltr\">Cybercrime is not a fringe phenomenon in Austria, but rather a mass offense with a declining clearance rate. For victims, this has a practical consequence: the probability of a case being solved solely through filing a report is statistically low. What is decisive is the actual execution of securing, reporting, and evidence-gathering steps in the first hours and days.<\/p>\n<p dir=\"ltr\">For companies, an additional factor came into play in 2026: With the entry into force of the NISG 2026 on October 1, 2026, cybersecurity became an enforceable legal obligation for a significantly larger circle of entities\u2014with registration, reporting, and compliance obligations, and a sanction regime reaching into the tens of millions.<\/p>\n<p dir=\"ltr\">If you are affected by a cybercrime incident, we will examine the legal and technical courses of action \u2013 from securing evidence, filing a criminal complaint, and joining criminal proceedings as a private party, to enforcing civil claims. In cases of cyber extortion \/ ransomware, in addition to traditional legal activities, we also handle ransom negotiations and organize \u2013 if necessary \u2013 the ransom payment.<\/p>\n<h3 dir=\"ltr\" id=\"page-haufige-fragen\">Frequently asked questions:<\/h3>\n<p>&nbsp;<\/p>\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1789293140184\"><strong class=\"schema-faq-question\">Is cybercrime punishable in Austria?<\/strong> <p class=\"schema-faq-answer\">Yes. Cybercrime is a collective term. Punishability arises from individual offenses under the Criminal Code (StGB), in particular Sections 118a, 119, 119a, 126a, 126b, 126c, 148a, and 225a StGB, as well as \u2013 when ICT is used as the instrument of the offense \u2013 from general offenses such as fraud (Sections 146 et seq. StGB) or extortion (Sections 144 et seq. StGB). In any given case, multiple offenses are frequently met simultaneously.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293204717\"><strong class=\"schema-faq-question\"><br>Where do I file a report for cybercrime?<\/strong> <p class=\"schema-faq-answer\">At every police station in Austria. The Cybercrime Competence Center of the Federal Criminal Police Office also operates a reporting office (<a href=\"mailto:against-cybercrime@bmi.gv.at\">against-cybercrime@bmi.gv.at<\/a>) for suspicious transaction reports and information; filing a report through this reporting office is currently not possible. As a general rule, prior legal advice is recommended.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293294629\"><strong class=\"schema-faq-question\"><br>Will I get my money back after a phishing attack?<\/strong> <p class=\"schema-faq-answer\">In the event of an unauthorized payment transaction, the payment service provider must refund the amount pursuant to Section 67 of the 2018 Payment Services Act (ZaDiG 2018) without undue delay, and no later than by the end of the following business day. The obligation to provide a refund may lapse or be reduced if the payer has breached their duty of care pursuant to Section 63 of the 2018 Payment Services Act (ZaDiG 2018): In cases of slight negligence, a maximum of 50 euros is to be borne, while in cases of gross negligence or intent, the payer is fully liable. Therefore, the assessment of one's own conduct in the individual case is regularly decisive.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293316419\"><strong class=\"schema-faq-question\"><br>Can stolen cryptocurrency be recovered?<\/strong> <p class=\"schema-faq-answer\">A recovery is possible under certain conditions, but not guaranteed. Decisive factors are the traceability of the transactions on the blockchain, the identification of a regulated crypto service provider as the recipient, and the speed of the initiated security measures. The Federal Criminal Police Office expressly points out that the recovery of lost assets is not always successful.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293333101\"><strong class=\"schema-faq-question\"><br>Can the police just take my cell phone?<\/strong> <p class=\"schema-faq-answer\">Since January 1, 2025, access to data media and data for the purpose of evaluation has been independently regulated in Sections 115f to 115l of the Code of Criminal Procedure (StPO) and requires prior judicial approval. This is based on the ruling of the Constitutional Court of December 14, 2023, G 352\/2021. The order must narrow down the data categories to be seized; accused persons have rights of cooperation and inspection.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293353406\"><strong class=\"schema-faq-question\"><br>Do I have to report a cyber attack?<\/strong> <p class=\"schema-faq-answer\">That depends on the role. In Austria, there is generally no mandatory requirement for victims to report a crime. Under data protection law, in the event of a personal data breach, there is generally an obligation to report it to the data protection authority within 72 hours (Art. 33 GDPR). For essential and important entities, the reporting obligations of the NISG 2026 apply as of October 1, 2026.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293397538\"><strong class=\"schema-faq-question\"><br>From when does the NISG 2026 apply?<\/strong> <p class=\"schema-faq-answer\">The NISG 2026 was promulgated on December 23, 2025 (Federal Law Gazette I No. 94\/2025) and will enter into force on October 1, 2026. Affected entities must register within three months of it entering into force, i.e., by December 31, 2026. The NISG 2018 will cease to be in force on October 1, 2026.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789293409872\"><strong class=\"schema-faq-question\"><br>How much does an initial legal consultation cost?<\/strong> <p class=\"schema-faq-answer\">That depends on the scope. A clearly defined initial assessment makes sense, in which it is examined whether security measures are still possible, what deadlines apply, and which claims can be realistically enforced. The terms and conditions are agreed upon in advance.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789295439710\"><strong class=\"schema-faq-question\"><br>Is it a criminal offense to pay ransom?<\/strong> <p class=\"schema-faq-answer\">There is no explicit ban on the payment of ransom in Austria. Depending on the specific circumstances, however, criminal offenses may be involved, in particular breach of trust (Section 153 of the Criminal Code) and participation in a criminal or terrorist organization (Sections 278, 278b of the Criminal Code) if the company is aware that the attack is backed by such an association. Money laundering pursuant to Section 165 of the Criminal Code can be ruled out for a legitimately operating company because the assets used do not originate from a prior offense. In addition, it must always be checked whether sanctions-related prohibitions on the provision of funds apply. The assessment depends on the individual case and should be carried out and documented prior to payment.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789295463598\"><strong class=\"schema-faq-question\"><br>Should one even negotiate with ransomware attackers?<\/strong> <p class=\"schema-faq-answer\">In practice, there are good reasons to enter into negotiations\u2014regardless of whether a payment is being considered. Negotiations buy time for forensics, backup verification, and reporting, enable a proof of concept for decryption, and provide clues regarding the attack vector and the actual data exfiltrated. It is advisable to have the communication handled not by management itself, but by an experienced external entity.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1789295494201\"><strong class=\"schema-faq-question\"><br>Do I have to report a data breach even if I pay the ransom?<\/strong> <p class=\"schema-faq-answer\">Yes. The reporting obligation under Art. 33 GDPR is triggered by the breach of personal data protection and the acquisition of knowledge, not by the outcome of the negotiations. Even a promise by the attackers to delete captured data does not eliminate the breach that has occurred and is not verifiable in practice.<\/p> <\/div> <\/div>","protected":false},"template":"","categories":[28],"class_list":["post-9333","blog-post","type-blog-post","status-publish","has-post-thumbnail","hentry","category-cybercrime"],"acf":[],"post-kategorie":"28","_post-kategorie":"field_66d947537140a","post-kurzbeschreibung":"Rechtslage, Zahlen und Handlungsschritte","_post-kurzbeschreibung":"field_66d949fe1efe2","post-beitragsbild":"9337","_post-beitragsbild":"field_66d94a4a1efe3","post-author_post-author-name":"Roman Taudes","_post-author_post-author-name":"field_66d94a801efe5","post-author_post-author-foto":"5984","_post-author_post-author-foto":"field_66d94aa11efe6","post-author":"","_post-author":"field_66d94ee2827ca","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cybercrime \u00d6sterreich: Rechtslage, Zahlen &amp; Hilfe<\/title>\n<meta name=\"description\" content=\"Cybercrime in \u00d6sterreich: Zahlen 2025, relevante StGB-Delikte, Fristen nach DSGVO und NISG 2026 sowie Verhandlung bei Ransomware. \u00dcberblick von ATB.LAW.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/atb.law\/en\/blog-post\/cybercrime-austria\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybercrime \u00d6sterreich: Rechtslage, Zahlen &amp; Hilfe\" \/>\n<meta property=\"og:description\" content=\"Cybercrime in \u00d6sterreich: Zahlen 2025, relevante StGB-Delikte, Fristen nach DSGVO und NISG 2026 sowie Verhandlung bei Ransomware. \u00dcberblick von ATB.LAW.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/atb.law\/en\/blog-post\/cybercrime-austria\/\" \/>\n<meta property=\"og:site_name\" content=\"ATB.LAW\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T18:40:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/atblaw-cybercrime-og-petrol-1200x630-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/\",\"name\":\"Cybercrime \u00d6sterreich: Rechtslage, Zahlen & Hilfe\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/atblaw-cybercrime-og-petrol-1200x630-1.png\",\"datePublished\":\"2026-09-13T18:37:13+00:00\",\"dateModified\":\"2026-09-13T18:40:50+00:00\",\"description\":\"Cybercrime in \u00d6sterreich: Zahlen 2025, relevante StGB-Delikte, Fristen nach DSGVO und NISG 2026 sowie Verhandlung bei Ransomware. \u00dcberblick von ATB.LAW.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293140184\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293204717\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293294629\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293316419\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293333101\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293353406\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293397538\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293409872\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295439710\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295463598\"},{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295494201\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#primaryimage\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/atblaw-cybercrime-og-petrol-1200x630-1.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/atblaw-cybercrime-og-petrol-1200x630-1.png\",\"width\":1200,\"height\":630,\"caption\":\"ATB.LAW Cybercrime Anwalt\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/atb.law\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybercrime in \u00d6sterreich\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/atb.law\\\/#website\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"name\":\"atb Rechtsanw\u00e4lte\",\"description\":\"Rechtsanwaltskanzlei in Wien\",\"publisher\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/atb.law\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\",\"name\":\"atb Rechtsanw\u00e4lte\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"width\":1572,\"height\":1110,\"caption\":\"atb Rechtsanw\u00e4lte\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293140184\",\"position\":1,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293140184\",\"name\":\"Ist Cybercrime in \u00d6sterreich strafbar?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Ja. Cybercrime ist ein Sammelbegriff. Die Strafbarkeit ergibt sich aus einzelnen Tatbest\u00e4nden des StGB, insbesondere den \u00a7\u00a7 118a, 119, 119a, 126a, 126b, 126c, 148a und 225a StGB sowie \u2013 bei Einsatz von IKT als Tatmittel \u2013 aus den allgemeinen Delikten wie Betrug (\u00a7\u00a7 146 ff StGB) oder Erpressung (\u00a7\u00a7 144 f StGB). In einem Fall sind h\u00e4ufig mehrere Tatbest\u00e4nde gleichzeitig erf\u00fcllt.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293204717\",\"position\":2,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293204717\",\"name\":\"Wo erstatte ich Anzeige wegen Cybercrime?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Bei jeder Polizeidienststelle in \u00d6sterreich. Das Cybercrime Competence Center des Bundeskriminalamts betreibt zus\u00e4tzlich eine Meldestelle (<a href=\\\"mailto:against-cybercrime@bmi.gv.at\\\">against-cybercrime@bmi.gv.at<\\\/a>) f\u00fcr Verdachtsmeldungen und Informationen; eine Anzeigeerstattung \u00fcber diese Meldestelle ist derzeit nicht m\u00f6glich. In der Regel empfielt sich eine vorherige anwaltliche Beratung.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293294629\",\"position\":3,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293294629\",\"name\":\"Bekomme ich mein Geld nach einem Phishing-Angriff zur\u00fcck?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Bei einem nicht autorisierten Zahlungsvorgang hat der Zahlungsdienstleister den Betrag nach \u00a7 67 ZaDiG 2018 unverz\u00fcglich, sp\u00e4testens bis zum Ende des folgenden Gesch\u00e4ftstags zu erstatten. Die Erstattungspflicht kann entfallen oder sich verringern, wenn der Zahler seine Sorgfaltspflichten nach \u00a7 63 ZaDiG 2018 verletzt hat: Bei leichter Fahrl\u00e4ssigkeit sind h\u00f6chstens 50 Euro zu tragen, bei grober Fahrl\u00e4ssigkeit oder Vorsatz haftet der Zahler voll. Entscheidend ist daher regelm\u00e4\u00dfig die Bewertung des eigenen Verhaltens im Einzelfall.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293316419\",\"position\":4,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293316419\",\"name\":\"Kann gestohlene Kryptow\u00e4hrung zur\u00fcckgeholt werden?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Eine R\u00fcckholung ist unter bestimmten Voraussetzungen m\u00f6glich, aber nicht garantiert. Ma\u00dfgeblich sind die Nachverfolgbarkeit der Transaktionen auf der Blockchain, die Identifizierung eines regulierten Kryptodienstleisters als Empf\u00e4nger und die Geschwindigkeit der eingeleiteten Sicherungsma\u00dfnahmen. Das Bundeskriminalamt weist ausdr\u00fccklich darauf hin, dass die Wiedererlangung abhandengekommener Verm\u00f6genswerte nicht immer gelingt.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293333101\",\"position\":5,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293333101\",\"name\":\"Darf die Polizei mein Handy ohne Weiteres mitnehmen?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Seit 1. J\u00e4nner 2025 ist der Zugriff auf Datentr\u00e4ger und Daten zum Zweck der Auswertung in den \u00a7\u00a7 115f bis 115l StPO eigenst\u00e4ndig geregelt und setzt eine vorherige gerichtliche Bewilligung voraus. Grundlage ist das Erkenntnis des Verfassungsgerichtshofs vom 14. Dezember 2023, G 352\\\/2021. Die Anordnung hat die zu beschlagnahmenden Datenkategorien einzugrenzen; Beschuldigte haben Mitwirkungs- und Einsichtsrechte.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293353406\",\"position\":6,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293353406\",\"name\":\"Muss ich einen Cyberangriff melden?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Das h\u00e4ngt von der Rolle ab. Eine allgemeine strafrechtliche Anzeigepflicht f\u00fcr Opfer besteht in \u00d6sterreich nicht. Datenschutzrechtlich besteht bei einer Verletzung des Schutzes personenbezogener Daten grunds\u00e4tzlich eine Meldepflicht an die Datenschutzbeh\u00f6rde binnen 72 Stunden (Art. 33 DSGVO). F\u00fcr wesentliche und wichtige Einrichtungen kommen seit 1. Oktober 2026 die Meldepflichten des NISG 2026 hinzu.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293397538\",\"position\":7,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293397538\",\"name\":\"Ab wann gilt das NISG 2026?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Das NISG 2026 wurde am 23. Dezember 2025 kundgemacht (BGBl. I Nr. 94\\\/2025) und tritt am 1. Oktober 2026 in Kraft. Betroffene Einrichtungen m\u00fcssen sich innerhalb von drei Monaten ab Inkrafttreten registrieren, also bis 31. Dezember 2026. Das NISG 2018 tritt mit 1. Oktober 2026 au\u00dfer Kraft.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293409872\",\"position\":8,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789293409872\",\"name\":\"Was kostet eine anwaltliche Ersteinsch\u00e4tzung?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Das h\u00e4ngt vom Umfang ab. Sinnvoll ist eine klar abgegrenzte Ersteinsch\u00e4tzung, in der gepr\u00fcft wird, ob Sicherungsma\u00dfnahmen noch m\u00f6glich sind, welche Fristen laufen und welche Anspr\u00fcche realistisch durchsetzbar sind. Die Konditionen werden vorab vereinbart.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295439710\",\"position\":9,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295439710\",\"name\":\"Ist es strafbar, L\u00f6segeld zu zahlen?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Ein ausdr\u00fcckliches Verbot der L\u00f6segeldzahlung besteht in \u00d6sterreich nicht. Je nach Konstellation k\u00f6nnen jedoch Straftatbest\u00e4nde ber\u00fchrt sein, insbesondere Untreue (\u00a7 153 StGB) sowie die Beteiligung an einer kriminellen oder terroristischen Vereinigung (\u00a7\u00a7 278, 278b StGB), wenn dem Unternehmen bekannt ist, dass hinter dem Angriff ein entsprechender Zusammenschluss steht. Geldw\u00e4scherei nach \u00a7 165 StGB scheidet bei einem redlich wirtschaftenden Unternehmen aus, weil das eingesetzte Verm\u00f6gen nicht aus einer Vortat stammt. Zus\u00e4tzlich ist stets zu pr\u00fcfen, ob sanktionsrechtliche Bereitstellungsverbote entgegenstehen. Die Beurteilung ist einzelfallabh\u00e4ngig und sollte vor der Zahlung erfolgen und dokumentiert werden.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295463598\",\"position\":10,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295463598\",\"name\":\"Sollte man \u00fcberhaupt mit Ransomware-Angreifern verhandeln?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"In der Praxis sprechen gute Gr\u00fcnde daf\u00fcr, Verhandlungen aufzunehmen \u2013 unabh\u00e4ngig davon, ob eine Zahlung erwogen wird. Verhandlungen verschaffen Zeit f\u00fcr Forensik, Backup-Pr\u00fcfung und Meldungen, erm\u00f6glichen einen Funktionsnachweis der Entschl\u00fcsselung und liefern Hinweise auf den Angriffsvektor und den tats\u00e4chlich abgeflossenen Datenbestand. Sinnvoll ist, die Kommunikation nicht durch die Gesch\u00e4ftsf\u00fchrung selbst, sondern durch eine erfahrene externe Stelle f\u00fchren zu lassen.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295494201\",\"position\":11,\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/cybercrime-oesterreich\\\/#faq-question-1789295494201\",\"name\":\"Muss ich eine Datenschutzverletzung auch dann melden, wenn ich das L\u00f6segeld zahle?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Ja. Die Meldepflicht nach Art. 33 DSGVO kn\u00fcpft an die Verletzung des Schutzes personenbezogener Daten und die Kenntniserlangung an, nicht an den Ausgang der Verhandlungen. Auch eine Zusage der Angreifer, erbeutete Daten zu l\u00f6schen, beseitigt die eingetretene Verletzung nicht und ist faktisch nicht \u00fcberpr\u00fcfbar.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybercrime Austria: Legal Situation, Statistics &amp; Help","description":"Cybercrime in Austria: 2025 figures, relevant Austrian Criminal Code offenses, deadlines under the GDPR and NISG 2026, and ransomware negotiations. Overview by ATB.LAW.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/atb.law\/en\/blog-post\/cybercrime-austria\/","og_locale":"en_US","og_type":"article","og_title":"Cybercrime \u00d6sterreich: Rechtslage, Zahlen & Hilfe","og_description":"Cybercrime in \u00d6sterreich: Zahlen 2025, relevante StGB-Delikte, Fristen nach DSGVO und NISG 2026 sowie Verhandlung bei Ransomware. \u00dcberblick von ATB.LAW.","og_url":"https:\/\/atb.law\/en\/blog-post\/cybercrime-austria\/","og_site_name":"ATB.LAW","article_modified_time":"2026-09-13T18:40:50+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/atblaw-cybercrime-og-petrol-1200x630-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["WebPage","FAQPage"],"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/","url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/","name":"Cybercrime Austria: Legal Situation, Statistics &amp; Help","isPartOf":{"@id":"https:\/\/atb.law\/#website"},"primaryImageOfPage":{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#primaryimage"},"image":{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#primaryimage"},"thumbnailUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/atblaw-cybercrime-og-petrol-1200x630-1.png","datePublished":"2026-09-13T18:37:13+00:00","dateModified":"2026-09-13T18:40:50+00:00","description":"Cybercrime in Austria: 2025 figures, relevant Austrian Criminal Code offenses, deadlines under the GDPR and NISG 2026, and ransomware negotiations. Overview by ATB.LAW.","breadcrumb":{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293140184"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293204717"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293294629"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293316419"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293333101"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293353406"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293397538"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293409872"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295439710"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295463598"},{"@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295494201"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#primaryimage","url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/atblaw-cybercrime-og-petrol-1200x630-1.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/09\/atblaw-cybercrime-og-petrol-1200x630-1.png","width":1200,"height":630,"caption":"ATB.LAW Cybercrime Anwalt"},{"@type":"BreadcrumbList","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/atb.law\/"},{"@type":"ListItem","position":2,"name":"Cybercrime in \u00d6sterreich"}]},{"@type":"WebSite","@id":"https:\/\/atb.law\/#website","url":"https:\/\/atb.law\/","name":"atb Attorneys at Law","description":"Law firm in Vienna","publisher":{"@id":"https:\/\/atb.law\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/atb.law\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/atb.law\/#organization","name":"atb Attorneys at Law","url":"https:\/\/atb.law\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/","url":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","width":1572,"height":1110,"caption":"atb Rechtsanw\u00e4lte"},"image":{"@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/"}},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293140184","position":1,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293140184","name":"Is cybercrime punishable in Austria?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Ja. Cybercrime ist ein Sammelbegriff. Die Strafbarkeit ergibt sich aus einzelnen Tatbest\u00e4nden des StGB, insbesondere den \u00a7\u00a7 118a, 119, 119a, 126a, 126b, 126c, 148a und 225a StGB sowie \u2013 bei Einsatz von IKT als Tatmittel \u2013 aus den allgemeinen Delikten wie Betrug (\u00a7\u00a7 146 ff StGB) oder Erpressung (\u00a7\u00a7 144 f StGB). In einem Fall sind h\u00e4ufig mehrere Tatbest\u00e4nde gleichzeitig erf\u00fcllt.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293204717","position":2,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293204717","name":"Where do I file a report for cybercrime?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Bei jeder Polizeidienststelle in \u00d6sterreich. Das Cybercrime Competence Center des Bundeskriminalamts betreibt zus\u00e4tzlich eine Meldestelle (<a href=\"mailto:against-cybercrime@bmi.gv.at\">against-cybercrime@bmi.gv.at<\/a>) f\u00fcr Verdachtsmeldungen und Informationen; eine Anzeigeerstattung \u00fcber diese Meldestelle ist derzeit nicht m\u00f6glich. In der Regel empfielt sich eine vorherige anwaltliche Beratung.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293294629","position":3,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293294629","name":"Will I get my money back after a phishing attack?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Bei einem nicht autorisierten Zahlungsvorgang hat der Zahlungsdienstleister den Betrag nach \u00a7 67 ZaDiG 2018 unverz\u00fcglich, sp\u00e4testens bis zum Ende des folgenden Gesch\u00e4ftstags zu erstatten. Die Erstattungspflicht kann entfallen oder sich verringern, wenn der Zahler seine Sorgfaltspflichten nach \u00a7 63 ZaDiG 2018 verletzt hat: Bei leichter Fahrl\u00e4ssigkeit sind h\u00f6chstens 50 Euro zu tragen, bei grober Fahrl\u00e4ssigkeit oder Vorsatz haftet der Zahler voll. Entscheidend ist daher regelm\u00e4\u00dfig die Bewertung des eigenen Verhaltens im Einzelfall.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293316419","position":4,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293316419","name":"Can stolen cryptocurrency be recovered?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Eine R\u00fcckholung ist unter bestimmten Voraussetzungen m\u00f6glich, aber nicht garantiert. Ma\u00dfgeblich sind die Nachverfolgbarkeit der Transaktionen auf der Blockchain, die Identifizierung eines regulierten Kryptodienstleisters als Empf\u00e4nger und die Geschwindigkeit der eingeleiteten Sicherungsma\u00dfnahmen. Das Bundeskriminalamt weist ausdr\u00fccklich darauf hin, dass die Wiedererlangung abhandengekommener Verm\u00f6genswerte nicht immer gelingt.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293333101","position":5,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293333101","name":"Can the police just take my cell phone?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Seit 1. J\u00e4nner 2025 ist der Zugriff auf Datentr\u00e4ger und Daten zum Zweck der Auswertung in den \u00a7\u00a7 115f bis 115l StPO eigenst\u00e4ndig geregelt und setzt eine vorherige gerichtliche Bewilligung voraus. Grundlage ist das Erkenntnis des Verfassungsgerichtshofs vom 14. Dezember 2023, G 352\/2021. Die Anordnung hat die zu beschlagnahmenden Datenkategorien einzugrenzen; Beschuldigte haben Mitwirkungs- und Einsichtsrechte.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293353406","position":6,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293353406","name":"Do I have to report a cyber attack?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Das h\u00e4ngt von der Rolle ab. Eine allgemeine strafrechtliche Anzeigepflicht f\u00fcr Opfer besteht in \u00d6sterreich nicht. Datenschutzrechtlich besteht bei einer Verletzung des Schutzes personenbezogener Daten grunds\u00e4tzlich eine Meldepflicht an die Datenschutzbeh\u00f6rde binnen 72 Stunden (Art. 33 DSGVO). F\u00fcr wesentliche und wichtige Einrichtungen kommen seit 1. Oktober 2026 die Meldepflichten des NISG 2026 hinzu.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293397538","position":7,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293397538","name":"From when does the NISG 2026 apply?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Das NISG 2026 wurde am 23. Dezember 2025 kundgemacht (BGBl. I Nr. 94\/2025) und tritt am 1. Oktober 2026 in Kraft. Betroffene Einrichtungen m\u00fcssen sich innerhalb von drei Monaten ab Inkrafttreten registrieren, also bis 31. Dezember 2026. Das NISG 2018 tritt mit 1. Oktober 2026 au\u00dfer Kraft.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293409872","position":8,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789293409872","name":"How much does an initial legal consultation cost?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Das h\u00e4ngt vom Umfang ab. Sinnvoll ist eine klar abgegrenzte Ersteinsch\u00e4tzung, in der gepr\u00fcft wird, ob Sicherungsma\u00dfnahmen noch m\u00f6glich sind, welche Fristen laufen und welche Anspr\u00fcche realistisch durchsetzbar sind. Die Konditionen werden vorab vereinbart.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295439710","position":9,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295439710","name":"Is it a criminal offense to pay ransom?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Ein ausdr\u00fcckliches Verbot der L\u00f6segeldzahlung besteht in \u00d6sterreich nicht. Je nach Konstellation k\u00f6nnen jedoch Straftatbest\u00e4nde ber\u00fchrt sein, insbesondere Untreue (\u00a7 153 StGB) sowie die Beteiligung an einer kriminellen oder terroristischen Vereinigung (\u00a7\u00a7 278, 278b StGB), wenn dem Unternehmen bekannt ist, dass hinter dem Angriff ein entsprechender Zusammenschluss steht. Geldw\u00e4scherei nach \u00a7 165 StGB scheidet bei einem redlich wirtschaftenden Unternehmen aus, weil das eingesetzte Verm\u00f6gen nicht aus einer Vortat stammt. Zus\u00e4tzlich ist stets zu pr\u00fcfen, ob sanktionsrechtliche Bereitstellungsverbote entgegenstehen. Die Beurteilung ist einzelfallabh\u00e4ngig und sollte vor der Zahlung erfolgen und dokumentiert werden.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295463598","position":10,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295463598","name":"Should one even negotiate with ransomware attackers?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"In der Praxis sprechen gute Gr\u00fcnde daf\u00fcr, Verhandlungen aufzunehmen \u2013 unabh\u00e4ngig davon, ob eine Zahlung erwogen wird. Verhandlungen verschaffen Zeit f\u00fcr Forensik, Backup-Pr\u00fcfung und Meldungen, erm\u00f6glichen einen Funktionsnachweis der Entschl\u00fcsselung und liefern Hinweise auf den Angriffsvektor und den tats\u00e4chlich abgeflossenen Datenbestand. Sinnvoll ist, die Kommunikation nicht durch die Gesch\u00e4ftsf\u00fchrung selbst, sondern durch eine erfahrene externe Stelle f\u00fchren zu lassen.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295494201","position":11,"url":"https:\/\/atb.law\/blog-post\/cybercrime-oesterreich\/#faq-question-1789295494201","name":"Do I have to report a data breach even if I pay the ransom?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Ja. Die Meldepflicht nach Art. 33 DSGVO kn\u00fcpft an die Verletzung des Schutzes personenbezogener Daten und die Kenntniserlangung an, nicht an den Ausgang der Verhandlungen. Auch eine Zusage der Angreifer, erbeutete Daten zu l\u00f6schen, beseitigt die eingetretene Verletzung nicht und ist faktisch nicht \u00fcberpr\u00fcfbar.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post\/9333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post"}],"about":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/types\/blog-post"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media\/9337"}],"wp:attachment":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media?parent=9333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/categories?post=9333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}