Special Declaration: This article is an original work by Attorney Shao Shiwei. It represents only the personal views of the author and does not constitute legal consultation or legal advice on specific matters. For article reprints, legal consultations, or professional exchanges, please add: sswls66.
In internet companies (especially gaming platforms), personnel in technical, operational, and other roles who have direct access to system interfaces, backend data, and internal administrative privileges may, once they engage in unauthorized operations or misconduct driven by profit, rapidly evolve into typical scenarios involving suspected duty-related crimes. This is not uncommon in judicial practice.
However, in judicial practice,acts such as “modifying data” and “reselling for cash”,depending on the region, the handling personnel, or even between the first and second instances of the same case, may indeed result in completely different legal characterizations: theft, embezzlement by reason of position, or illegally obtaining data from computer information systems?
The sentencing disparities among these three offenses are significant—
The maximum sentence for the crime of illegally obtaining data from computer information systems typically does not exceed seven years;
whereas for theft and embezzlement by reason of position, when the amount involved is relatively large,the sentence may reach ten years or more, or even life imprisonment.。
Therefore, clarifying the boundaries among the three offenses,and selecting the most favorable characterization direction for each case,often directly determines the trajectory of the case and the scope of sentencing. This article will take typical case facts as a starting point to systematically review the constituent elements, judicial application logic, and potential defense spaces for these three offenses.
I. Author of this Article: Attorney Shao Shiwei
1
Typical Case:
Case of a Programmer Illegally Calling Interfaces and Modifying Data for Profit
Li Mou was a senior JAVA development engineer at a certain technology company. The procuratorial organ accused him of two criminal facts during his employment [(2020) Hu 01 Xing Zhong No. 74]:
Fact One:
Unauthorized use of POSTMAN softwareto illegally callthe prize redemption program interface in the “Diamond” lucky draw activity of the “Bixin” mobile app,the prize redemption program interface,and, bymodifying parameters,falsely increased the number of “Diamonds” in two software accounts under his controlby a total of 14,990,000 “Diamonds”,which were then converted into “Charm Points” within the software and withdrawn or sold externally for profit. The victim entity suffered a total loss of more than RMB 62,000.
Fact Two:
Unauthorized use of POSTMAN software tomodify data,thereby upgrading the levels of four software accounts registered by himto “Emperor”,and selling two of these accounts to software users with the WeChat nickname “Shuli” for RMB 7,500 and RMB 8,000, respectively.
Regarding the above acts, should Li Mou be characterized as committing theft, embezzlement by reason of position, or illegally obtaining data from computer information systems?
[Analysis]
Regarding Fact One, what offense does Li Mou’s conduct constitute?
In this case, Li Mou’s position was that of a senior JAVA development engineer. His responsibilities were “responsible for the backend development of transaction-related functions of the ‘Bixin’ mobile app,” rather than an operational management role. The “convenience of position” required for the crime of embezzlement by reason of position must reflect the perpetrator’s authority to supervise, manage, or handle the entity’s property.
Due to his development work, Li Mou was aware of the system’s backend interfaces, data structures, and working principles. This is akin to the builder of a bank vault knowing the vault’s structure and security vulnerabilities, but this does not mean the bank authorized him to manage the money inside the vault.
In the company’s lucky draw marketing campaign, he had no responsibility to modify software parameter data to bypass the lucky draw process and directly obtain or dispose of “Diamonds.” This means the company never granted him the lawful authority to increase or distribute “Diamonds.” He exploited system vulnerabilities discovered during his work as a technician and the technical knowledge he possessed. This constitutes “convenience arising from work,” not “convenience of position.” Therefore, since Li Mou’s job duties did not include the authority to manage or dispose of “Diamonds,” he cannot constitute the crime of embezzlement by reason of position. His conduct resembles an “insider utilizing internal knowledge to steal,” which aligns with the characteristics of theft.
As for why it is not characterized as “illegally obtaining data from computer information systems,” the reason is as follows: Li Mou’s technical operations of calling interfaces and modifying parameters were merely the means adopted to ultimately illegally possess “Diamonds” and monetize them for profit. When the ultimate purpose of the act is to steal property, and computer methods are merely the pathway, the principle of “evaluating based on the heavier offense” should be applied, treating the act according to its purpose—namely, theft.
Regarding Fact Two, what offense does Li Mou’s conduct constitute?
From the above analysis, the crime of embezzlement by reason of position can be excluded first. So, does his conduct constitute theft or illegally obtaining data from computer information systems? Judging from the case description, Li Mou’s two acts were very similar in method (both involved using POSTMAN software to modify backend data). Does Li Mou’s conduct constitute theft?
In Fact One, Li Mou called the prize redemption interface to falsely increase the “Diamonds” in his account. The “Diamonds” in this case were not ordinary game items; they could be converted into “Charm Points” and then withdrawn or sold for profit. This means that within the company’s business model, “Diamonds” already possessed clear and direct economic value, linked to real-world property. Therefore, legally, they can be recognized as “property” in the sense of criminal law. Li Mou’s act was equivalent to directly creating money out of thin air in the company’s vault and putting it into his own pocket. This directly caused the company to suffer a property loss of more than RMB 60,000.
However, in Fact Two, Li Mou modified data to upgrade his account level to “Emperor” and sold it. The “Emperor” level itself is an identity marker, service qualification, or backend data. It cannot be directly withdrawn, and its value is indirect (such as appearing prestigious or potentially possessing certain privileges). The court does not directly recognize it as “property.” Li Mou’s act directly violated national regulations by intruding into the company’s computer information system and obtaining and modifying key account level data stored therein. What he undermined was the company’s exclusive management rights and security over its computer information system data. The company did not immediately lose an equivalent amount of cash because his account became “Emperor.”
The company’s losses might be potential (such as undermining the fairness of the level system and affecting other users’ willingness to recharge), but such losses are indirect and difficult to calculate precisely. Therefore, it does not meet the core characteristic of theft, which requires “causing direct property loss.” According to Article 285, Paragraph 2 of the Criminal Law, as long as the act of “illegally obtaining data from computer information systems” is committed and the “circumstances are serious,” it constitutes a crime.
When the direct object of an act is data within a computer information system, and such data itself cannot be directly equated with traditional property, even if the perpetrator indirectly profits from the data, it more closely aligns with the constituent elements of the crime of illegally obtaining data from computer information systems.
It is not difficult to discover from the above case that theft, embezzlement by reason of position, and illegally obtaining data from computer information systems indeed exhibit significant overlap in the scenario of “employees utilizing technical means to operate company systems and achieve monetization.” In judicial practice, identical or similar acts are frequently subject to different legal characterizations. Whether the involved act constitutes “stealing property,” “embezzling entity property,” or “illegally obtaining system data” hinges on the precise judgment of the object of the act, the technical means employed, and the source of authority.
The above analysis serves only as the foundational logic starting from individual cases.
In this article’s“Part II”,we will further systematically review the application boundaries of these three offenses in internal crimes within internet companies, including:
How exactly are the three offenses distinguished?
-
What is the difference between utilizing “convenience of position” and “convenience arising from work”?
-
Can virtual currencies, virtual items, points, accounts, etc., all be recognized as “property”?
-
Can all crypto assets be included within the scope of legal protection for “virtual property”?
-
Which technical acts are more likely to be characterized as “data-related crimes”?
Once these issues are clarified, they will directly impact the legal characterization of the case, the scope of sentencing, and the direction of defense efforts, thus holding decisive significance in practice.



