What crime does someone actually commit by breaking into your company's server without permission? Before 2009, the answer in Colombia was awkward: probably none, specifically. Prosecutors had to force the facts into generic categories — theft, property damage — that didn't really describe what had happened. Law 1273 of 2009 closed that gap by amending the Criminal Code to create its own protected legal interest: the protection of information and data.
Today it's the statute any criminal defense lawyer, digital forensic expert, or prosecutor invokes when a Colombian company reports a cyberattack. You don't need to be a lawyer to understand it — but you do need to know what it says.
Anatomy of the attack described in the article.
The Crimes It Actually Defines
The law added Articles 269A through 269J to the Criminal Code. In practice, these are the ones most commonly used:
Unauthorized access to a computer system (269A) penalizes entering a protected system without authorization, or beyond the authorization one holds. It applies to an outside attacker just as much as to an employee poking around systems outside their role — something many companies don't even consider a crime until it happens.
Obstruction of a computer system or network (269B) covers denial-of-service (DDoS) attacks and any attempt to bring down normal system operation.
Interception of computer data (269C) is the legal basis against man-in-the-middle attacks — intercepting data in transit without a court order.
Computer damage (269D) is probably the most invoked article in Colombia today, since it covers destroying, deleting, or altering data without authorization. It's the legal foundation in most ransomware and internal sabotage cases.
Use of malicious software (269E) criminalizes producing, distributing, or introducing malware into the country — without needing it to have caused damage yet. Simply holding and distributing it is already a crime.
Violation of personal data (269F) connects directly to obligations under Law 1581: obtaining, selling, or disclosing personal data without authorization.
Website impersonation (269G) is the legal basis against phishing — designing pages that mimic legitimate sites to capture credentials.
Theft by computer means (269I) is the category applied to most digital banking fraud, including cases like SIM swapping.
How Heavy the Penalties Actually Are
They're not symbolic. Depending on the crime, sentences range from 48 to 96 months in prison, with fines that can exceed 1,000 monthly minimum wages. If the crime targets critical infrastructure, abuses a position of trust, or involves disclosing the stolen information to third parties, penalties can increase by up to half. That has a practical consequence worth spelling out: an employee who pokes around another department's systems "just out of curiosity" isn't in some administrative gray zone. They're potentially committing a crime.
What to Do If It Happens to You
The order matters more than it might seem:
A 24/7 incident response team is what makes the difference between preserving useful evidence in the first hours, and losing it exactly when it matters most.
Frequently asked questions
Does the law apply if the attacker is outside Colombia?
Territorially it applies within the country, but international cooperation treaties exist to pursue cross-border crimes when the damage occurs in Colombia.
Can an employee face criminal charges for unauthorized access?
Yes. Article 269A doesn't distinguish between an outside attacker and an internal one.
Does filing under Law 1273 replace a complaint with the SIC?
No, they're complementary. Law 1273 is criminal — it pursues whoever is responsible. Law 1581 is administrative — it evaluates whether your business met its obligations as the data controller. A single incident can trigger both.
Is technical evidence enough, or do I need a lawyer?
Both. Well-preserved technical evidence is the foundation, but a lawyer specialized in computer crimes translates that into the correct legal procedure.
Controls and monitoring that stop the attack.
Let's talk
Knowing Law 1273 gives you the framework to act, but the first line of defense is still technical. If your business is in the middle of an incident right now, our [24/7 incident response](https://tirescue.com/en/respuesta-ante-incidentes-247/) team contains the attack and preserves the evidence your legal case will need. Dealing with an active incident? [Contact us immediately](https://tirescue.com/en/contacto-ti-rescue/).
Contact usYou may also like
Comments (0)
Be the first to comment.