• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact

DDOS attacks: Criminal liability, warning and compensation?

18. July 2023
in Law on the Internet
Reading Time: 4 mins read
0 0
A A
0
neourban 1734495 1280

In the digital world, distributed denial of service (DDoS) attacks are a common form of cybercrime. They aim to cripple servers or networks by flooding them with requests, which can cause significant operational disruptions. But what is the legal side? Is a DDoS attack a criminal offense and is it possible to take action against the attacker? This blog post highlights these issues and provides a detailed look at the legal aspects of DDoS attacks.

Content Hide
1. What is a DDoS attack?
2. Criminal liability of DDoS attacks
3. Warning and compensation
4. Conclusion
4.1. Author: Marian Härtel
Key Facts
  • DDoS attacks are a common form of cybercrime that paralyzes servers and networks by flooding them with requests.
  • In Germany, DDoS attacks are expressly punishable under Section 303b StGB and are considered computer sabotage.
  • Victims of DDoS attacks have the right to a warning and compensation for lost profits and restoration costs.
  • Penalties for DDoS attacks vary depending on their severity and can range from fines to several years' imprisonment.
  • Enforcing claims for damages can be challenging, as DDoS attackers often act anonymously.
  • Preventive measures such as firewalls and DDoS protection services are crucial in defending against such attacks.
  • Professional help from IT security experts and lawyers is important to effectively combat DDoS attacks.

What is a DDoS attack?

A Distributed Denial of Service (DDoS) attack is a specific type of cyber attack in which an attacker aims to render a server, service or network inaccessible through a flood of Internet traffic. This attack aims to disrupt and interrupt normal functionality and access to a network, system or service.

The method used is usually the use of a botnet. A botnet is a group of hacked computers that are under the control of the attacker. These computers, often referred to as “zombies,” are tricked into sending coordinated requests to the target. These can be simple requests, such as calling a web page, or more complex actions, such as sending large packets of data designed to overload the target’s bandwidth.

The primary goal of a DDoS attack is to put so much strain on the server’s resources that it is no longer able to handle legitimate requests. This can cause the server to respond slowly, become unreliable, or even fail completely. The consequences can be significant, especially when it comes to mission-critical services where downtime can lead to substantial financial losses and reputational damage.

It is important to note that DDoS attacks are not aimed at stealing data or infecting systems. Instead, their main goal is to disrupt normal operations. Despite their apparent simplicity, DDoS attacks can be extremely effective and require careful planning and preparation to successfully defend against them.

Criminal liability of DDoS attacks

In many countries around the world, including Germany, DDoS attacks are explicitly punishable by law. These types of cyberattacks violate the law because they are specifically designed to interfere with the functioning of computers and networks. They generate massive traffic, which results in legitimate requests not being able to be processed, causing significant operational disruptions.

In Germany, the legal basis for the criminal liability of DDoS attacks is enshrined in Section 303b of the German Criminal Code (StGB). This paragraph explicitly criminalizes data alteration and computer sabotage. Data modification is the unauthorized deletion, suppression, rendering unusable or alteration of data. Computer sabotage, on the other hand, refers to acts intended to disrupt data processing operations that are essential to the operation of a company or government agency.

In this context, a DDoS attack can be considered a form of computer sabotage. Flooding a server or network with requests disrupts normal operations and, in many cases, completely paralyzes it. This can cause significant economic damage, especially when it comes to commercial websites or online services that rely on constant access from their customers.

It is important to emphasize that criminal liability for DDoS attacks applies not only to the actual perpetrators, but also to individuals who commission or support such attacks. This can be done, for example, by deploying botnets or developing and distributing special software to carry out DDoS attacks. These acts can also be prosecuted under Section 303b of the German Criminal Code.

Penalties for DDoS attacks can vary depending on the severity of the attack and the damage caused. They range from fines to prison sentences. In particularly serious cases, for example if the attack results in significant economic damage, prison sentences of several years may be imposed.

Warning and compensation

If you become a victim of a DDoS attack, you have the right to take legal action. This may include warning the aggressor and claiming damages. Damages may include the cost of restoring the system, lost profits, and other direct or indirect damages.

The legal basis for such claims may arise from a variety of sources. One of them is § 823 para. 2 of the German Civil Code (BGB) in conjunction with Section 303b para. 1 No. 2, para. 2 of the Criminal Code (StGB). According to these provisions, the person who intentionally or negligently violates the property, the right of another unlawfully is obliged to pay damages. A DDoS attack can be considered such a wrongful infringement because it affects the functioning of a computer system that is the property of the victim.

In addition, a claim for damages may also be asserted on the basis of impairment of the established and practiced business. This claim arises from case law and is recognized if the DDoS attack disrupts the operations of a company. This may be the case in particular if the attack results in operations having to be shut down for a certain period of time or if customers migrate away as a result of the attack.

In addition, a so-called quasinegatory injunctive relief pursuant to §§ 1004 para. 1, 823 para. 2 BGB in conjunction with § 303b para. 1 No. 2 StGB may be invoked. This claim exists if there is a risk of repetition, i.e. if it is to be feared that the attacker will carry out a DDoS attack again. The claim is directed at the omission of such attacks.

However, enforcing these rights can be challenging. DDoS attacks are often difficult to trace because attackers mask their identities through the use of botnets and other techniques. As a result, it is often difficult to identify the polluter and hold them legally responsible. In such cases, it may be helpful to consult an expert in IT law or a specialized lawyer who has experience with such cases and can assist in enforcing the claims.

Conclusion

DDoS attacks pose a serious threat to the stability of IT systems and are a clear violation of the law. They can cause significant damage that goes far beyond technical problems and can have a significant economic impact. Victims of such attacks have the right to warn the attacker and claim damages. This may include the cost of restoring the system, lost profits, and other direct or indirect damages.

However, enforcing these rights can be challenging. The nature of DDoS attacks and the techniques used by attackers can make it difficult to identify who is responsible. This can make legal prosecution more difficult and make it difficult to enforce claims for damages.

Therefore, it is crucial to take preventive measures to protect against such attacks. This can include implementing security measures such as firewalls and DDoS protection services, monitoring network traffic, and training employees on cybersecurity practices.

If you become a victim of a DDoS attack, it is important to seek professional help. This may include IT security professionals, attorneys, and law enforcement. They can help investigate the attack, identify those responsible and take legal action.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: DamagesWarning

Weitere spannende Blogposts

When can I avoid the cookie banner?

ECJ: Cookies require explicit consent of users
18. October 2019

The ECJ has just ruled on the subject of cookies in the Planet49 case(see this article). Because of this procedure...

Read moreDetails

Abusive warnings are punishable by law

Abusive warnings are punishable by law
7. November 2022

Although the concept of the warning notice, contrary to the often expressed opinion of many non-lawyers, is basically a very...

Read moreDetails

BGH on the costs of partially successful warning letters

abmahnung
7. November 2022

The German Federal Court of Justice recently issued an interesting decision on questions of costs of a warning letter if...

Read moreDetails

Sales at trade fairs and the right of withdrawal?

Publication of sales advertisements and classification as a trader
7. November 2022

In online retailing, the issue of the right of withdrawal is actually dead in the water. Anyone who sells products...

Read moreDetails

Costs of a patent attorney in the UWG trial

Costs of a patent attorney in the UWG trial
25. April 2019

Experienced colleagues know that legal proceedings can also be won simply with a potentially overwhelming cost burden. Often also in...

Read moreDetails

YouTube is only liable for infringements if there is a clear indication of infringement

YouTube: What to do about copyright extortion?
11. September 2023

Introduction: In a landmark decision, the Hamburg Higher Regional Court has specified the requirements for YouTube's liability for copyright infringement....

Read moreDetails

File sharing and instruction by parents

File sharing and instruction by parents
7. November 2022

An interesting, but in this respect, based on the case law of the Federal Court of Justice (BGH), consistent ruling...

Read moreDetails

Social media accounts and imprint

Social media accounts and imprint
4. March 2019

Obligation to impress? For the occasion, it should be remembered once again that in the case of commercial use of...

Read moreDetails

Influencer: Just tag every post with advertising?

Legal form as an influencer? A few hints!
7. November 2022

After the current rulings around influencers, which I have summarized a little in this post, I received a few questions...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

This insightful podcast episode takes an in-depth look at the startup and innovation landscape in Germany and Europe. The discussion...

Read moreDetails
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025
d5ab3414c7c4a7a5040c3c3c60451c44

The metaverse – legal challenges in virtual worlds

26. September 2024
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung