The Cybersecurity and Cybercrime Act 2021 criminalises distinct conduct involving computer systems and data. “Hacking” is an imprecise label: a case may concern unauthorised access, interception, interference, fraud, forgery, a fake profile or disclosure of a password. The prosecution must still prove the elements of the particular offence and connect the accused person to the relevant act and state of mind.
Unauthorised access depends on the boundary of permission
Section 7 addresses access to a computer system without authorisation. The Act’s test looks to whether the person was entitled to control that access and whether consent had been given by a person entitled to authorise it. A valid password does not necessarily equal permission: a former employee may retain credentials after access ends, while an administrator may be authorised to maintain a database but not to extract customer information for another purpose.
Section 10 separately addresses access with intent to commit another offence. The alleged purpose therefore matters. Account-assignment records, access policies, termination times, multi-factor authentication logs and server records can show both the technical event and the scope of legitimate access.
Interception, interference and modification are not the same offence
Section 8 concerns unauthorised interception of non-public transmissions of computer data. Section 9 addresses interference with a computer system, and section 11 covers unauthorised modification of computer data. An incident that disrupts a website, captures communications and alters records may engage more than one provision, but each allegation needs its own evidence.
Section 12 deals with unlawful disclosure of a password, access code or similar data. Section 13 addresses misuse of devices and data associated with cybercrime. Security-testing tools are not proved criminal merely because they can be misused; authorisation, circumstances and statutory intent need examination.
Electronic fraud, forgery and fake profiles
Section 14 creates an electronic-fraud offence involving specified manipulation or interference carried out dishonestly or fraudulently to obtain an unlawful benefit. Section 15 addresses electronic forgery, while section 16 deals with creation of a fake profile in the circumstances defined by the Act. Phishing may combine impersonation, credential theft and manipulated payment instructions, but investigators must identify what conduct is actually charged.
Suppose an accounts employee in Ebene receives an email appearing to come from a supplier, announcing a new bank account. After payment, the real supplier denies sending it. Preserve the native email with full headers, the fraudulent invoice, genuine earlier correspondence, approval trail, bank transfer reference and login records. A screenshot alone may omit routing data and does not prove who operated the sending account.
First response for a victim or business
Contain the incident without erasing it. Isolate affected equipment from networks where technically appropriate, preserve logs and cloud audit data, and obtain a forensic copy before rebuilding critical devices when feasible. Contact the bank immediately for payment fraud; speed may affect whether funds can be stopped or traced. Reset exposed credentials from a known-clean device after relevant evidence has been captured.
Suspected offences can be reported to Police. CERT-MU’s MAUCORS platform also receives cyber-incident reports, and CERT-MU publishes hotline 800 2378. A report to CERT-MU supports incident response and coordination; it should not be confused with making a criminal complaint to Police. Record which institution received what material and any reference number.
Preservation and production powers under the Act
Section 26 permits specified expedited preservation of traffic data, while section 27 provides for production orders in statutory circumstances. These tools address information that can disappear through routine deletion or account changes. A recipient should preserve the identified material, restrict internal access and obtain advice on the order’s exact scope instead of either ignoring it or volunteering unrelated data.
Under section 28, an investigatory authority may apply to a Judge in Chambers for a warrant where the statutory grounds are met. A warrant may authorise access, search and seizure in relation to systems or data. The warrant, location, items taken, forensic acquisition and continuity records are important to later scrutiny.
What digital evidence can and cannot prove
The Mauritius Police IT Unit includes a Digital Forensic Laboratory whose stated work covers search and seizure, acquisition, examination, analysis and preservation of digital evidence. Sound acquisition aims to preserve original content and document how the working copy was produced. Hash values, device identifiers, time settings and access records may assist, but their significance still requires interpretation.
An IP address can identify a connection, not automatically the human at the keyboard. An account may be shared or compromised; a device may be used by several people; timestamps may reflect a different time zone. Conversely, several independent records—device possession, authentication, messages, account recovery details and transaction benefit—may reinforce attribution. The defence and prosecution should avoid treating one technical indicator as a complete identity proof.
Responding to an allegation
Do not wipe, sell, reset or remotely alter a device once an investigation is anticipated. Preserve employment permissions, system documentation and legitimate work instructions if authorisation is disputed. Record who else had physical or credential access. A suspect should obtain advice before a detailed statement, while complying with lawful court orders and bail conditions.
A defence may concern lack of access, valid authority, mistaken attribution, absence of dishonesty or another missing statutory element. It may also examine the legality and execution of investigative powers and the continuity of exhibits. Those are evidence-based issues, not invitations to contact the complainant or coordinate accounts with possible witnesses.
Reporting, court process and support
A victim should avoid public attribution while an investigation is live. Publishing names, edited chat logs or confidential customer data may create further harm and complicate proof. The guides to victims’ rights, the court structure and sentencing explain later stages. Related organised offending is addressed separately in human-trafficking offences, while representation information appears on the criminal defence practice page.
Frequently asked questions
Is hacking a criminal offence in Mauritius?
Unauthorised access can be an offence under section 7 of the Cybersecurity and Cybercrime Act 2021, and related conduct may engage other sections. The prosecution must prove the charged act, lack of authorisation and any required state of mind.
How is digital evidence collected?
Investigators may use statutory preservation, production and warrant powers. Forensic acquisition should document the source, method, integrity and custody of data; a screenshot or IP address may assist but rarely answers attribution and context by itself.
What should a business do after a cyber attack?
Contain affected systems without wiping evidence, preserve logs and native messages, involve competent incident-response support, contact the bank immediately for payment fraud, and report suspected crime to Police. CERT-MU’s MAUCORS platform and hotline 800 2378 provide a separate cyber-incident reporting channel.
How Lex Aquila Advocates can help
Lex Aquila Advocates can advise a complainant, business or accused person on the specific 2021 Act provisions, preservation steps, investigatory orders and court process. The chambers can work from the warrant, device records and technical report rather than an undifferentiated allegation of “hacking”. See the the chambers' criminal law practice, or contact use the enquiry form; enquire on WhatsApp; or call +230 5858 7956 · urgent matters.
This article is general legal information for Mauritius, not legal advice. For advice on your situation, consult a barrister.