GUEST PRACTICE NOTE · CRIMINAL ROLL
A prosecution and adjudication note for the magistrates’ court
Manivasen Munsamy
Internal Audit Manager, Financial Crime · Guest contributor
Cyber-enabled banking crime is now a regular feature of the South African criminal roll. A customer’s account is compromised; funds move within minutes; the file arrives as logs, statements, a SIM-swap record and a forensic affidavit. The court’s work is not to be impressed by the technology. It is to decide whether the prosecution has proved a recognised offence, linked the accused to the conduct, and put reliable digital evidence on the record.1
1. Offence theory — name the crime
Cybercrime is not one count. The conduct must be translated into a statutory or common-law offence the accused can meet. The Cybercrimes Act 19 of 2020 supplies the framework: unlawful access;2 unlawful interception of data;3 unlawful interference with data, a program, a storage medium or a system;4 the unlawful acquisition or use of a password or access code;5 and cyber fraud.6 Theft of incorporeal property is separately preserved.7 Depending on the facts, those counts travel with common-law fraud, theft, and money-laundering under the Prevention of Organised Crime Act.8
Typical retail-banking patterns are account takeover by phishing, malware or SIM-swap; authorised-push-payment scams in which the victim is deceived into releasing the transfer; mule accounts used to receive and move the proceeds; and unauthorised interference with a bank’s system or a customer’s data. The questions that must appear on the record are modest and decisive: was there unauthorised access or interference; did that conduct cause the loss; has intention or knowledge been proved; and did this accused initiate, facilitate, control or benefit from the scheme? Attribution is the recurring failure. Bank records often prove what moved. They do not, without more, prove who moved it.
2. Charging — charge the role the evidence can carry
A useful sequence is: the unlawful cyber act; the financial harm; the accused’s place in the chain. That chain may run from the compromise of credentials, through the fraudulent instruction, through mule accounts, to cash-out or concealment. The charge sheet should still track this accused — direct perpetrator, accomplice, facilitator or mule — and not the whole architecture of the syndicate. Distinguish the person who performed the access or the transaction from the person who supplied a SIM, an account or a device. Checklist: what unlawful cyber conduct is alleged; what harm followed; how is the harm linked to the conduct; what mental element must be proved; what did this accused actually do?
3. Digital evidence — reliability before weight
The usual bundle is system and banking logs (access, beneficiary changes, transactions); telecom records of a SIM-swap, calls or messages; the trail of the funds; and an expert who reconstructs a timeline. Computer-generated banking records may be proved on affidavit under section 236 of the Criminal Procedure Act.9 Data messages are not to be refused merely because they are electronic; section 15 of the Electronic Communications and Transactions Act directs the court to authenticity, integrity and origin.10 Where a human being’s credibility sits behind the print-out, the document may be hearsay and must be treated as such — the starting point in S v Ndiki.11
Ask, in every file: is the record authentic; was it preserved; is there a chain of custody; who extracted it; were integrity checks done; and does the expert opinion rest on verified facts? Logs may show that credentials, a device or an IP address were used. They do not automatically identify a person. Attribution hardens when the State can add control of the SIM or the device, receipt of the stolen funds, or conduct consistent with participation. Experts explain the machinery. Guilt remains a judicial finding.
4. Sentencing — harm, role, then deterrence
Separate the organiser who directed the scheme from the mule who received the proceeds and the facilitator who supplied an account, a device or a SIM.12
Aggravation commonly includes multiple or vulnerable victims, organised or repeated conduct, substantial loss, concealment of proceeds, and the abuse of legitimate banking access. Mitigation — a clean record, co-operation, limited role, genuine remorse — weighs less where the accused knowingly stayed inside a sustained scheme or tried to obstruct the investigation. Work in this order: the harm; culpability from role and intent; deterrence, because cybercrime scales; then rehabilitation. Where the value engages the Criminal Law Amendment Act, say so on the record and apply the minimum-sentence enquiry properly.13
A working frame for Monday: name the unlawful cyber act and map it onto the elements; charge the role the evidence can prove; test digital evidence for reliability, preservation and attribution before you give it weight; sentence for harm and culpability, not for the novelty of the method. The technology will keep moving. The elements will not.
Manivasen Munsamy · BProc (University of Durban-Westville, 1996); admitted as an attorney in 1998. More than twenty-five years in financial services, specialising in regulatory compliance and financial crime. He is currently an Internal Audit Manager at an international bank in the United Arab Emirates, focusing on financial crime. This note is written in his personal capacity. It is not the position of his employer, and it is not a JASA policy paper.
1 Practice aid only. Not a directive of the Magistrates Commission or the Office of the Chief Justice.
2–7 Cybercrimes Act 19 of 2020: s 2 (unlawful access); s 3 (unlawful interception of data); ss 5–6 (interference with data, a program, a storage medium or a system); s 7 (password, access code or
similar device); s 8 (cyber fraud; see also ss 9–10); s 12 (theft of incorporeal property).
8 Prevention of Organised Crime Act 121 of 1998, ss 4–6; Financial Intelligence Centre Act 38 of 2001.
9 Criminal Procedure Act 51 of 1977, s 236 — bank records and computer print-outs.
10 Electronic Communications and Transactions Act 25 of 2002, s 15 — data messages.
11 S v Ndiki and Others 2008 (2) SACR 252 (Ck); Law of Evidence Amendment Act 45 of 1988, s 3.
12 Ordinary principles of participation; sentencing under Chapter 2 of the Cybercrimes Act.
13 Criminal Law Amendment Act 105 of 1997 — minimum sentences for fraud in the prescribed amounts.
