Safety & lawIdea 9 · 3 min read

Do not test someone else's systems without written authorization; good intentions and later reporting do not erase an offense

Grade A evidenceValue: High
In plain language

Authorization and what you obtain matter, not merely your intention. In China, obtaining 500 ordinary credential sets, earning RMB 5,000 or causing RMB 10,000 loss can trigger a serious-offense threshold carrying up to 3 years. Exporting one user table to prove a flaw can exceed 500 sets. Possessing credentials does not authorize using them outside their permitted scope.

MoneyNo cost
TimeQuick and easy
EffortSome effort

What it takes

Free. Before a vendor security-response-center program or crowd test, obtain a document stating authorized scope, targets and testing windows. An SRC is the vendor's security response center for external vulnerability reports. Stop when you have minimal proof of the issue. Resist testing “just to see.”

What you may gain

Ordinary company and personal systems fall outside the special categories of state affairs, national defense and advanced science and technology. Intruding into them, or using other technical means to obtain stored, processed or transmitted data, carries up to 3 years' imprisonment or criminal detention and/or a fine in serious cases; particularly serious cases carry 3–7 years plus a fine. Serious thresholds include at least 10 authentication sets for online financial services such as payments, securities or futures; 500 other authentication sets; control of 20 systems; RMB 5,000 in illegal proceeds; or RMB 10,000 in economic loss. Five times these thresholds qualifies as particularly serious. Procuratorial Guiding Case 36 establishes that logging into a computer system with credentials beyond their authorized scope constitutes intrusion. Three defendants used work credentials and tokens to access internal systems remotely, downloaded data beyond their duties and sold it online, earning RMB 37,000. Sentences were 4 years, 3 years 9 months and 4 years, with RMB 40,000 fines each. Chinese rules apply.

Context & considerations

Guiding Case 36 involved selling data for profit. It is cited for the authorization principle, not to claim that benevolent testing receives the same sentence. Intent and later reporting may affect prosecution or punishment but do not themselves cancel an offense. A vendor's thanks followed by a police report are compatible; thanks are not authorization. No verbatim-verifiable good-faith testing case was found on the Supreme Court or Procuratorate websites when this chapter was written, so the entry relies on statutes and thresholds. Use a public vendor SRC or a written assessment engagement specifying scope, targets and dates. Gather minimal proof, not bulk data. Below-threshold conduct can still bring public-security penalties and occupational bans described in entry 8. For reporting after discovery, see entry 10.

Research & references

National People's Congress of China (2020). Criminal Law incorporating Amendment XI, Article 285(1)–(2). https://jtgl.beijing.gov.cn/jgj/jgxx/flfg/fl/11033925/index.html; Supreme People's Court and Supreme People's Procuratorate (2011). Computer Information System Security Criminal Interpretation, Article 1. https://ga.sz.gov.cn/ZWGK/ZCFG/ZCJD/content/post_1304363.html (Shenzhen Public Security Bureau reprint); Supreme People's Procuratorate (2017). Ninth Batch of Guiding Cases, case 36, Wei Menglong, Gong Xu and Xue Dongdong's illegal acquisition of computer-system data. https://www.spp.gov.cn/spp/jczdal/201710/t20171017_202593.shtml