1. Territoriality as a starting point – “domestic criminal act”
In principle, the principle of territoriality applies in Austria. Accordingly, criminal acts are subject to Austrian criminal law if they are committed in Austria (Section 62 StGB). What specifically is to be regarded as “committed in Austria” is governed by Section 67 (2) StGB. An offense is deemed to have been committed at the place where
- the perpetrator has acted(place of action), or
- where the actual success occurs(place of success).
This is exactly where the problems with cybercrime begin. The place of action and the place of success are often in different countries.
Example: A perpetrator writes a phishing email in Germany, the victim transfers money from Austria to an account in France. It is not always clear whether Austrian authorities are responsible in such constellations.
2. Jurisdiction even in the absence of a domestic offense (Section 64 StGB)
In certain cases, the Austrian criminal prosecution authorities also have jurisdiction if the offense was committed entirely abroad (act and outcome). § Section 64 StGB covers certain criminal offenses extraterritorially. Particularly relevant for cybercrime:
- Exploring trade secrets for the benefit of foreign countries
- Criminal organization
- Serious coercion
- Money laundering
Contributory offenders who contribute to a domestic crime from abroad may also be liable to prosecution in Austria (Section 64(1)(8) StGB).
Example: An offender in Switzerland shares, likes or comments on criminal content posted on Instagram or Facebook by an offender acting in Austria.
3. Cybercrime Offenses Relevant to Practice and Austrian Jurisdiction
a) Fraud (§ 146 StGB) and extortion (§ 144 StGB)
Both offenses are classic success offenses. The place of success is where the financial loss occurs. This means the place where the victim loses the ability to freely dispose of the assets concerned – e.g. in the case of transfers to a third-party bank account at the registered office of the victim’s bank. It was therefore previously decisive that the victim’s transfer was made from a domestic bank account.
Important OGH update (2025): The OGH issued This year, the new law makes it clear that an intervening act is also sufficient for Austrian jurisdiction – even if the actual loss only occurs abroad. This brings great relief for victims of crypto fraud or investment scams, where perpetrators use an intermediary foreign bank account or crypto account of the victim.
b) Cyberbullying (Section 107c StGB)
Cyberbullying is both a successful offense and a potentially dangerous offense. The decisive factor is whether the perpetrator uses telecommunications or a computer system in Austria to commit the offense or whether the defamation can be perceived in Austria “for a longer period of time“. This means that the Austrian criminal prosecution authorities are regularly responsible if the content in question can be accessed here in Austria.
c) Hacking – unlawful access (Section 118a StGB)
Hacking in the sense of criminal law occurs when the perpetrator gains access to a computer system over which he is not authorized or not authorized alone by overcoming a specific security measure. A domestic place of offense is given if the perpetrator gains access to the foreign computer system from Austria (place of action) or if the computer system attacked is located in Austria (place of success).
d) Data corruption (§ 126a StGB)
Data damage under criminal law occurs when someone harms another person by altering, deleting or otherwise rendering unusable or suppressing data that has been processed, transmitted or provided by automated means and over which they have no or no sole right of disposal. The offense is a success offense, as the occurrence of damage is a prerequisite. The Austrian criminal prosecution authorities are therefore also responsible if the perpetrator commits the alteration, deletion, otherwise rendering unusable or suppression abroad, but the damage to data has occurred in Austria.
e) Misuse of computer programs (§ 126c StGB)
The production of computer programs in order to gain unlawful access to data is punishable. This is a common preparatory act for other cybercrime offenses. § Section 126c StGB is a pure activity offense, without a requirement for success. Austrian law enforcement authorities are responsible if the “preparatory act” takes place in Austria.
f) Data falsification (§ 225a StGB)
Anyone who creates false data by entering, changing, deleting or suppressing data with the intention of creating false data or falsifying genuine data with the intention of using it to prove a right or a fact is also liable to prosecution in Austria. It is sufficient for domestic jurisdiction that genuine data is falsified domestically or false data is produced domestically.
4. conclusion
Whether the Austrian police and public prosecutor’s office investigate depends on the type of offense in question (action or successful offense). If the perpetrator is acting from abroad, Austrian jurisdiction is only possible for successful offenses. However, in complex cybercrime cases in particular, interim successes or domestic visibility can be sufficient.
For further information, please refer to the specialist publication by Dr. Paul Krepil “Cybercrime and domestic jurisdiction” (ecolex 2025/426).

Do you need support?
Cybercrime cases are technically and legally challenging. Questions of international jurisdiction often determine whether the Austrian police or public prosecutor’s office take action and start investigations or whether those affected are referred to foreign prosecution authorities. This is relevant for victims of cybercrime, but also for the defense of perpetrators.
We support you with
- Analysis and examination of criminal liability and jurisdiction
- Representation of victims and defense of defendants in criminal and civil proceedings
- International cooperation and legal assistance in cross-border matters
- Tracing and recovering lost assets
Contact LEUKOS for a confidential initial consultation.