Late one night, I received a call from a family member.
“Attorney Shao, my younger brother has always worked in Location A. Why did the public security authorities in Location B, 1,000 kilometers away, arrest him?”
Initially, the family was also confused about this matter. Only after making inquiries through various channels did they learn that the suspect had once used a mobile phone in Location B to log into an account and transfer virtual assets.
In other words, relying solely on the login IP address, the public security authorities in Location B determined that location to be the place where the criminal act was committed, thereby establishing jurisdiction over the case.
In criminal cases involving virtual assets, disputes over jurisdiction are more likely to arise in practice due to the often substantial amounts involved and the relatively blurred line between criminal and non-criminal conduct. It is not uncommon for authorities to compete for jurisdiction or even artificially create connecting factors for jurisdiction. As previously reported in the media,the "black-on-black" virtual asset theft caseserves as a typical example, where the same facts were separately investigated and filed by public security organs in two different locations.
A similar situation existed in a virtual asset criminal case I handled, involving an amount exceeding RMB 100 million, where the local public security authority relied on an IP address as the basis for its judicial jurisdiction.
The question is—can an IP address truly determine jurisdiction in criminal cases?
For instance, in property crimes such as theft or embezzlement by taking advantage of one's position, if the perpetrator merely logs into an account via a mobile phone in a certain location to complete the transfer of virtual assets, can that location be deemed the "place where the criminal act was committed"? Does this approach have sufficient legal basis, or does it give rise to procedural controversies?
I. Author of this Article: Attorney Shao Shiwei
1
Legal Basis: Special Jurisdiction Rules for Cybercrimes
When public security authorities assert jurisdiction in a different location based on an IP address in such cases, they typically cite the "Opinions on Several Issues Concerning the Application of Criminal Procedure in Handling Cybercrime Cases" issued in 2022 by the Supreme People's Court, the Supreme People's Procuratorate, and the Ministry of Public Security (hereinafter referred to as the "Opinions").
According to Article 2 of the Opinions:
"The place of crime in cybercrime cases includes the location of servers used for network services employed to commit the criminal act, the location of the network service provider, the location of the infringed information network system and its administrator,the location of the information network system used by the criminal suspect, the victim, or other persons involved in the caseduring the commission of the crime,the location of the victim at the time of infringement, and the location where the victim suffered property losses, among others."
In practice, investigative authorities usually form the following logic based on this provision:
Step 1: Locate the IP address to determine the IP address used by the suspect when performing the relevant network operations;
Step 2: Trace the server to determine the physical location of the server corresponding to that IP address;
Step 3: Accordingly, deem the server's location as the place of crime, thereby allowing the public security authority in that location to file and investigate the case.
However, for this logic to hold, there is an important prerequisite: the case in question must constitute a "cybercrime."
If the case is essentially a traditional property crime such as theft or embezzlement by taking advantage of one's position, and network tools were merely used during its commission, can the jurisdiction rules for cybercrimes be directly applied?
2
Prerequisite for Determining Jurisdiction via IP Address: The Case Must Constitute a "Cybercrime"
Some case-handling personnel believe that as long as the criminal process "involves" an information network, the expanded jurisdiction rules of the Opinions can be applied—even if a mobile phone or the internet was used in certain stages of traditional crimes such as theft or embezzlement.
However, according to the Opinions, cybercrime cases include:
-
Cases of crimes endangering the security of computer information systems;
-
Cases of crimes involving refusal to fulfill obligations for information network security management, illegal use of information networks, or aiding information network criminal activities;
-
Other crime cases, such as fraud, gambling, or infringement of citizens' personal information, where the principal acts are carried out through information networks.
Therefore, Attorney Shao believes that "cybercrime" should refer to crimes where the information network constitutes the space of the crime, meaning crimes that could not be committed without an information network, such as the crime of illegally controlling computer information systems or the crime of sabotaging computer information systems. The executory acts of such crimes occur within cyberspace itself, making it difficult to determine the place of crime using traditional physical connecting factors, thus necessitating special jurisdiction rules.
Although the on-chain transfer of virtual assets is facilitated by the internet, the constitutive elements of crimes such as theft or embezzlement by taking advantage of one's position do not depend on an information network. The act of transferring virtual assets by the perpetrator is essentially the disposal of proceeds from the crime, rather than the executory act of the crime itself. Equating the "internet-involved aspects" of traditional crimes with "cybercrimes" constitutes an excessive expansion of the scope of application of the Opinions, confusing the essential distinction between criminal means and types of crime.
3
If the Charge Changes, Does Jurisdiction Based on IP Address Still Hold?
In some cases involving virtual assets, another situation may arise.
For example, in certain cases, at the filing stage, public security authorities may file the case under charges of cybercrimes, such as the "crime of illegally obtaining data from computer information systems." Since it is classified as a cybercrime, investigative authorities can assert jurisdiction in a different location based on rules such as the server's location.
However, as the investigation deepens, or after a renewed review of evidence during the examination for prosecution stage, the nature of the case may change. For instance, a case initially filed as a cybercrime may ultimately be determined to be a traditional property crime such as embezzlement by taking advantage of one's position or theft.
In such circumstances, the following issue arises:
Does the jurisdiction originally established on the basis of the IP address still hold?
If insistence is maintained on handling the case according to the initial charge, difficulties often arise in factual determination and insufficient evidentiary support;
however, if the charge is changed to an ordinary property crime, the jurisdictional foundation originally established on the "server location" may become unstable, leading to procedural issues such as the need to transfer the case or designate jurisdiction.
From the perspective of procedural law logic, jurisdiction should be established on the basis of the facts of the crime, rather than being retroactively determined by the charge selected at the time of filing.
If jurisdiction is determined first, and then maintained by manipulating the charge, procedural inversion may easily occur.
4
Is an IP Address Equivalent to the Actual Place of Crime? What Technical Issues Exist?
Even if an IP address is acknowledged as a reference basis for determining jurisdiction, from a technical perspective, this basis itself remains subject to significant uncertainty.
1. Network Address Translation (NAT) Technology: One Public IP May Correspond to Multiple Devices
In home or corporate Wi-Fi environments, multiple devices typically share the same public IP address. The public IP address queried by public security authorities often points only to a network exit location, such as a building or an office area, and cannot be directly mapped to a specific device.
To further identify a specific device, it is usually necessary to combine data such as the router's Network Address Translation (NAT) records, terminal device information, and precise timestamps to determine the correspondence between the internal network IP and the public IP.
2. Dynamic IP Allocation: IP Addresses May Change Over Time
When a mobile phone accesses the internet via a mobile network, the IP address is typically dynamically assigned by the carrier. The IP address may change when the device switches between different base stations or when the network reconnects.
Therefore, when determining the network location at the time of the incident, it is often necessary to make a comprehensive judgment by combining data such as base station logs, connection records, and timestamps. Relying solely on the IP attribution information queried after the fact may not accurately reflect the actual physical location where the act occurred.
3. Cloud Computing and Content Delivery Networks (CDN): Server Locations Are Not Fixed
Many virtual asset trading platforms or wallet services use Content Delivery Networks (CDNs) for network acceleration. In such cases, the server IP to which the user's device connects may merely be an edge node server of the CDN, rather than the platform's actual origin server.
Therefore, the "server location" indicated by the IP attribution may not have a direct correspondence with the actual location where the conduct relevant to the case took place.
Against this technical backdrop, if case jurisdiction is determined solely based on IP attribution information, a situation may arise where a region with no substantive connection to the case obtains jurisdiction merely because a server node or network exit is located there. From the perspective of procedural review, this approach may also trigger controversies regarding the reasonableness of jurisdiction.
5
Can an IP Address Alone Prove the Place of Crime? Rules for Examining Electronic Data Evidence
Article 25 of the "Provisions on Several Issues Concerning the Collection, Extraction, Examination, and Judgment of Electronic Data in Handling Criminal Cases" (hereinafter referred to as the "Provisions") explicitly stipulates:
"The identity consistency between the online identity and the real-world identity of a criminal suspect or defendant may be comprehensively judged by verifying relevant IP addresses, network activity records, ownership of internet terminals, relevant witness testimonies, as well as the statements and defenses of the criminal suspect or defendant."
This provision establishes theprinciple of comprehensive judgment. An IP address is merely one type of electronic data evidence; its probative value requires corroboration with other evidence and cannot serve as the sole basis for determination.
In the collection of electronic data evidence, it is usually necessary to cross-reference data such as network activity records (e.g., server logs), information on the ownership of internet terminals (e.g., NAT records), and precise timestamps to reliably determine whether a specific network behavior was performed by a particular device.
Furthermore, Article 23 of the Provisions requires that, when examining electronic data, verification should be conducted regarding integrity check values, and the processes of seizing and extracting original storage media, to confirm the authenticity and integrity of the electronic data and prevent tampering or contamination.
In practice, tracing network behavior back to specific devices and individuals often requires forming an evidentiary system where multiple pieces of electronic data corroborate each other. For example:
-
IP address records used by mobile phones or terminal devices, to prove that the device accessed the network at a specific time;
-
Network Address Translation (NAT) records (such as NAT mapping information when accessing via Wi-Fi), to correlate with specific terminal devices;
-
Precise timestamps, to confirm the specific time when the network behavior occurred;
-
Platform or server logs, to record relevant account operations or fund transfer behaviors;
-
In cases involving technical architectures such as Content Delivery Networks (CDNs), further tracing to the actual origin server is required to confirm the true path of network requests.
If there is a lack of mutual corroboration among the above data, relying solely on IP attribution information cannot independently and accurately lock in the physical location at the time the crime occurred, and jurisdiction determined on this basis lacks substantive connection.
6
Concluding Remarks
In criminal proceedings, case jurisdiction is an important safeguard for procedural justice. Which regional judicial authority files, investigates, examines for prosecution, and ultimately tries the case directly relates to the boundaries of investigative power and the realization of the litigation rights of the accused.
Therefore, jurisdiction should be established on connecting factors that have a genuine and specific link to the facts of the crime. If the relevant legal bases for jurisdiction are interpreted with unlimited expansion, jurisdiction rules may evolve into tools for competing for case jurisdiction, thereby weakening the constraining function that the jurisdiction system ought to possess, and affecting the fairness and predictability of case handling.

Recommended Reading


