• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

Shanghai High People’s Court Releases Cybercrimes Typical Cases Focused on Penalties

Published 2 June 2026 Sarah Xuan
On May 28, 2026, the Shanghai High People’s Court released typical cases on punishing new types of cybercrime in accordance with law, with the aim of responding, through representative individual cases, to difficulties in characterizing new types of cybercrime, unifying adjudicative standards, and providing compliance guidance for platform enterprises, online business operators, and technical service providers.
This group of cases covers various types of conduct, including the illegal acquisition of tokens and cookies, compulsory advertising promotion, cracking of unmanned aerial vehicle systems, decryption of express waybill data, paid publication of AI-paraphrased articles, online commercial disparagement, exploiting platform settlement loopholes to obtain traffic, and trafficking in digital renminbi account information. It reflects the trend that cybercrime is evolving from traditional intrusion and destruction toward data grabbing, traffic manipulation, platform arbitrage, technological abuse, and organized industrial chains. From the perspective of adjudicative rules, the relevant cases penetrate the technical appearance through substantive judgment, clarify the criminal-law attributes of identity-authentication data such as tokens and cookies, bring smartphones, unmanned aerial vehicle flight-control systems, platform backend servers, and the like within the scope of protection for computer information systems, and subject such conduct as AI paraphrasing, malicious “traffic scalping,” and trafficking in digital renminbi wallet information to criminal-law regulation respectively, demonstrating the judicial authorities’ precise identification of the infringement of legal interests and disruption of market order caused by new types of cybercrime.
The following is an organization and analysis of these cases.
I. Case of Li et al. Illegally Acquiring Data from a Computer Information System (I) Basic FactsThe case of Li et al. illegally acquiring data from a computer information system focused on addressing the criminal-law attributes of technical authentication data such as website tokens and cookies. According to the facts of the case, beginning in September 2022, the defendant Li recruited others online to form a team and, by means such as implanting illegal code into repackaged apps, inducing users to download and install such apps, or inducing users to log in to websites, illegally acquired the tokens and cookies data of website users, and used such data to log in to users’ website accounts and profit by increasing the apparent popularity of livestream rooms.
The criminal team had a clear division of labor: Li was responsible for team management, soliciting business externally, and contacting part-time offline promoters; Rong Mouwei was responsible for formulating protocols for using illegally acquired tokens and cookies data to increase the popularity of livestream rooms; Jiang Mouwen was responsible for repackaging apps and implanting code for illegally acquiring token data; Wang Moubing was responsible for managing the servers storing website account data; and Zou Mouneng was responsible for developing new technologies. Upon appraisal, the servers involved in the case stored a total of 47,219 deduplicated pieces of token-containing information and 1,421 deduplicated pieces of cookies-containing information.
(II) Key Points of the JudgmentThe court held that Li and the other four persons jointly and illegally acquired computer data with identity-authentication functions, and that the circumstances were especially serious; their conduct therefore constituted the crime of illegally acquiring data from a computer information system and constituted a joint crime. On this basis, the court sentenced the five defendants respectively to fixed-term imprisonment ranging from three years and two months to one year, with probation applied to some defendants, and imposed fines.
The core adjudicative point of this case lies in the fact that, although tokens and cookies are not information such as names, identification numbers, or mobile phone numbers that can directly identify a natural person in the traditional sense, they perform the functions of user identity authentication, maintenance of login status, and identification of permissions in network systems. Once an actor illegally acquires such data, the actor may bypass the normal login mechanism and invoke account permissions in the user’s identity. Therefore, in evaluating such conduct, attention should be paid to the functional attributes of the relevant data in the computer information system. The court expressly identified tokens and cookies as computer information system data possessing identity-authentication functions, thereby providing an important rule basis for handling similar cases.
(III) AnalysisThe typical significance of this case is mainly reflected in two aspects. First, the case clarifies the criminal-law protection status of identity-authentication technical data. As Internet platform account systems, session mechanisms, and interface invocation mechanisms become increasingly complex, data such as tokens, cookies, keys, verification codes, and dynamic credentials have become important carriers for user identity identification and permission control. Illegally acquiring such data is, in substance, a breakthrough of account control and system security mechanisms, and should be included within the evaluative scope of crimes involving computer information system data.
Second, this case responds to a key issue in the governance of the “online water army” industrial chain. Conduct such as boosting the popularity of livestream rooms, generating false traffic, and manipulating reviews and comments commonly relies on account resources, automated tools, and the acquisition of data permissions, and the related black and gray industrial chains have seriously disrupted the fair competition environment of online platforms. Through this case, the judicial authorities have moved the point of attack forward to the key data-acquisition conduct behind false traffic, which helps compress the living space of the online water army industrial chain at its source. At the same time, this case also reminds platform enterprises to strengthen the protection of authentication data, improve app security verification, abnormal-login monitoring, and session-credential management mechanisms, and prevent technical vulnerabilities from being exploited by criminals.
II. Case of Cai Illegally Controlling a Computer Information System (I) Basic Facts The case of Cai illegally controlling a computer information system involved a relatively typical compulsory promotion of “rogue advertising” in the mobile Internet ecosystem. After registering an account on a promotion platform, Cai engaged in information-promotion cooperation with several mobile app development companies and configured SDK modules within the apps. When mobile phone users installed and ran the relevant apps, an APK program written by Cai would be downloaded and run. When a user opened a certain e-commerce app on the user’s own initiative or invoked it through other channels, the mobile phone would first be forced to display the promotion-link page associated with Cai’s promotion account. After the user completed a purchase, Cai could obtain a promotion commission.
Cai obtained more than RMB 6 million in promotion commissions in this manner and withdrew more than RMB 2 million. After the incident came to light, Cai appeared before the authorities and truthfully confessed the main criminal facts, and during the trial returned part of the illegal gains.
(II) Key Points of the JudgmentThe court of first instance had convicted and punished Cai for fraud. Upon trial, the court of second instance held that Cai used technical means to illegally control users’ mobile phones to complete corresponding instructions and thereby obtained huge promotion commissions; such conduct constituted the crime of illegally controlling a computer information system, and the circumstances were especially serious. The court of second instance ultimately sentenced Cai to fixed-term imprisonment of six years and six months for the crime of illegally controlling a computer information system and imposed a fine.
This case clarifies two important rules. First, a smartphone with the function of automatically processing data should be identified as a computer information system within the meaning of criminal law. Second, where an actor uses technical means to cause a mobile phone user, when opening or invoking the relevant e-commerce app on the user’s own initiative, to be forcibly shown a designated promotion-link page, such conduct constitutes the illegal control of a computer information system by other technical means.
(III) AnalysisThis case accurately grasps the technical essence of the crime of compulsory promotion on mobile terminals. The premise for Cai’s obtaining promotion commissions was that he changed the operating logic of users’ mobile phone terminals through SDK modules and APK programs, and forced the terminals to execute instructions to display designated links. His conduct directly infringed users’ autonomous control over their smart terminals, and also disrupted platform promotion-settlement rules and the order of fair competition.
The court of second instance placed the evaluative focus of the case on the technical act of “illegally controlling users’ mobile phone terminals,” which is more consistent with the substance of the conduct. This adjudicative approach has strong guiding significance for the governance of conduct such as forced redirects, malicious invocation, advertising hijacking, and traffic hijacking. In mobile Internet scenarios, app developers, SDK providers, and promotion service providers often participate in commercial monetization through complex technical chains. If they control terminal devices without users’ consent, forcibly display advertisements, or tamper with users’ normal access paths, they may cross the boundary of criminal liability.
III. Case of Gao and Liu Moukang Providing Programs for Intruding into Computer Information Systems (I) Basic FactsThe case of Gao and Liu Moukang providing programs for intruding into computer information systems involved cracking services for civilian unmanned aerial vehicle flight-control systems. The two defendants were originally unmanned aerial vehicle enthusiasts. Later, they opened online stores on network platforms, advertised that they could crack unmanned aerial vehicle operating systems and remove the no-fly-zone and altitude-limit restrictions set by the systems, and used relevant software to remotely control unmanned aerial vehicle control systems, providing cracking services to customers and charging fees.
By the time the case came to light, Gao had cracked the control systems of more than 60 unmanned aerial vehicles, and Liu Moukang had cracked more than 40. During the cracking and use of the relevant unmanned aerial vehicles, crashes, explosions, falls, and other incidents occurred repeatedly.
(II) Key Points of the JudgmentThe court held that, for the purpose of seeking illegal benefits, the two defendants provided and installed for others programs that cracked restrictions such as no-fly zones and altitude limits for unmanned aerial vehicles. Their conduct infringed national information-network security, seriously threatened public safety, infringed the personal and property safety of the people, disrupted normal living order, and constituted the crime of providing programs for intruding into computer information systems. On this basis, the court sentenced Gao to fixed-term imprisonment of seven months and a fine, and sentenced Liu Moukang to criminal detention of five months, suspended for five months, and a fine.
This case clarifies that a civilian unmanned aerial vehicle flight-control system has the function of automatically processing data and conforms to the characteristics of a computer information system within the meaning of criminal law. Where an actor uses relevant software to provide others with services for cracking no-fly-zone and altitude-limit restrictions on civilian unmanned aerial vehicles, the actor shall, pursuant to Article 285, paragraph 3 of the Criminal Law, be convicted and punished for the crime of providing programs for intruding into computer information systems.
(III) AnalysisThis case brings civilian unmanned aerial vehicle flight-control systems within the scope of criminal-law protection and has distinct contemporary significance. An unmanned aerial vehicle flight-control system can automatically process flight data and execute key functions such as altitude restrictions, area restrictions, and return-to-home control, and is an important technical barrier for ensuring low-altitude flight safety. Cracking no-fly-zone and altitude-limit rules is, in substance, bypassing system security policies and weakening the public-airspace risk-control mechanism.
Against the background of rapid development of the low-altitude economy, the application scenarios for unmanned aerial vehicles are expanding day by day, and related safety risks are increasing accordingly. If cracking services become industrialized, public-safety hazards will be significantly amplified. Through criminal sanctions, this case makes clear that technology enthusiasts, repair service providers, or third-party merchants may not break through legally prescribed safety boundaries in the name of “personalized modification” or “unlocking functions.” Its significance lies not only in protecting the security of computer information systems, but also in safeguarding, through criminal justice, the development of the low-altitude economy on a safe and orderly track.
IV. Case of Peng and Guo Mouye Illegally Acquiring Data from a Computer Information System (I) Basic FactsThe case of Peng and Guo Mouye illegally acquiring data from a computer information system targeted the conduct of “backend intrusion plus batch decryption” in the black and gray industry involving express waybill information. From August to September 2024, Peng, without authorization from a certain express delivery company, together with others illegally intruded into that company’s computer information system, decrypted express waybill numbers in batches, sold the plaintext data, and thereby obtained illegal gains of more than RMB 9,000.
Guo Mouye used automated scripts and simulators developed by the IT department of the company where he was employed to illegally intrude into the backend servers of the express delivery company, decrypt express waybill numbers in batches, obtain plaintext information such as recipients’ mobile phone numbers, names, and addresses, and sell the information, obtaining illegal gains of more than RMB 30,000. Upon appraisal, the relevant automated scripts and simulators were programs specially used to query and decrypt recipients’ mobile phone numbers, names, and addresses within the express delivery company’s system.
(II) Key Points of the JudgmentThe court held that Peng and Guo Mouye violated state provisions and, respectively together with others, used illegal technical means to obtain data processed in computer information systems. Among them, Peng’s circumstances were serious, and Guo Mouye’s circumstances were especially serious; both persons’ conduct constituted the crime of illegally acquiring data from a computer information system. On this basis, the court sentenced Guo Mouye to fixed-term imprisonment of three years and a fine, and sentenced Peng to fixed-term imprisonment of one year and a fine.
The adjudicative focus of this case is that where actors, by means such as unauthorized invocation of interfaces, simulated access through automated scripts, and batch parsing in the backend, restore information that had originally been desensitized or encrypted by the platform into plaintext data, such conduct constitutes typical illegal acquisition of data from a computer information system.
(III) AnalysisExpress logistics data are highly sensitive and usually contain names, telephone numbers, addresses, and other information that can directly identify natural persons and reflect their life trajectories. By using technical means to decrypt express waybill numbers in batches, actors re-expose information that should have been protected by desensitization, making it highly susceptible to being used for telecom fraud, precision marketing, harassment, or even personal harm.
The harm in this case is not limited to the resale of individual pieces of information, but lies in the actors’ realization of large-scale and batch data theft through automated tools and backend interfaces. The court’s identification of such conduct as the illegal acquisition of data from a computer information system captured the technical essence that the conduct involved unauthorized entry into, or invocation of, the system’s internal data interfaces. This case provides direct compliance lessons for logistics enterprises: waybill desensitization is not the endpoint of data protection. Enterprises still need to continuously strengthen interface-permission management, abnormal-access monitoring, internal-tool control, and audits of data-decryption conduct, so as to prevent personal information from being technologically and systematically stolen in the circulation process.
V. Case of Xu et al. Illegal Business Operations (I) Basic FactsThe case of Xu et al. illegal business operations is one of the typical cases in this release with relatively significant relevance to artificial-intelligence governance. From November 2023 to May 2024, Xu, Luo Mouxiong, and Kan Mouqi jointly operated an information technology company. The company’s main business was to search for and extract trending articles and news from the Internet, then use AI software to “paraphrase” them, generate so-called pseudo-original content, and thereafter recruit netizens with accounts on online self-media platforms as trainees, publish pseudo-original articles and news through the trainees’ accounts, earn platform traffic commissions, and share the proceeds with the trainees.
According to the audit, Xu, Luo Mouxiong, Kan Mouqi, and others obtained total illegal gains of more than RMB 50,000 through the foregoing conduct.
(II) Key Points of the JudgmentThe court held that the three defendants jointly violated state provisions and, for the purpose of profit, fabricated false information and provided paid publication through the Internet, thereby disrupting market order, and that the circumstances were serious; their conduct therefore constituted the crime of illegal business operations. On this basis, the court sentenced the three defendants respectively to fixed-term imprisonment ranging from one year and ten months to one year and six months, with probation applied to some defendants, and imposed fines on all of them.
This case clarifies that the conduct of organizing the use of AI software to search for, extract, and “paraphrase” trending articles and news, and then using recruited self-media accounts to publish pseudo-original information and obtain platform traffic commissions, falls within the scope of fabricating false information for profit and providing paid publication through the Internet, and may lawfully be identified as illegal business operations.
(III) AnalysisThis case does not deny the legitimate value of AI technology itself; rather, it clarifies the criminal liability that arises when AI tools are used to manufacture false information on a large scale, organize paid publication, and disrupt the order of the online information-services market. AI paraphrasing is usually highly concealed. The generated text appears on its face to be “new content,” but in substance it often consists of rewriting, splicing, replacing, and pseudo-original processing of existing news and articles. When such conduct further develops into corporate operations, trainee recruitment, account distribution, and revenue sharing, it forms an illegal business model that exploits platform traffic mechanisms for profit.
This case has important implications for content governance in the era of artificial intelligence. Technological neutrality does not mean that the manner of use is necessarily lawful. The commercialization of generative AI must comply with requirements relating to truthfulness, copyright protection, platform rules, and public order. The use of AI as a tool to commit unlawful or criminal acts will not evade criminal liability because the technology is novel. For self-media operating entities, MCN agencies, and content service providers, this case indicates that they should establish mechanisms for reviewing content sources, labeling AI-generated content, ensuring copyright compliance, and controlling false-information risks, so as to avoid crossing the red line of criminal law in pursuit of traffic revenue.
VI. Case of a Technology Company, Chen, and Zhou Damaging Commodity Reputation (I) Basic FactsThe case of a technology company, Chen, and Zhou damaging commodity reputation demonstrates the boundary at which online commercial disparagement rises from civil unfair competition to a criminal offense. The defendant entity’s principal business was A-brand hair-removal devices, and its main competing product was B-brand hair-removal devices. On the eve of the Women’s Day peak sales season in 2021, in order to attack a competitor, Chen and Zhou commissioned an unqualified testing institution to issue a false testing report stating that indicators for B-brand hair-removal devices were non-compliant.
On that basis, Chen and Zhou further instructed others to fabricate allegations that B-brand products failed to meet mandatory national standards and might cause serious harms such as retinal damage or even blindness, genetic mutations, miscarriages in pregnant women, or infant deformities, and published promotional articles through public accounts and Weibo. At the same time, the two also commissioned others to attempt to push the relevant topics onto trending searches through blogger reposts, team hype, and other means. After the relevant articles were published and reposted, serious consequences occurred, including the delisting of B-brand hair-removal devices on multiple platforms and the cancellation of livestreams, with economic losses reaching several million yuan.
(II) Key Points of the JudgmentThe court held that the defendant entity, a technology company, fabricated and disseminated false facts, damaged the commodity reputation of another, and caused another person significant losses; Chen and Zhou, as the directly responsible persons in charge, each committed the crime of damaging commodity reputation. On this basis, the court imposed a fine on the defendant entity and sentenced Chen and Zhou respectively to fixed-term imprisonment and fines. The court of second instance dismissed the appeal and upheld the original judgment.
In the trial, the court focused on examining whether the two parties had a competitive relationship, whether the defendants fabricated and disseminated false facts, whether the disparaging articles were sufficient to cause consumers to establish a connection between the article content and the quality of the competing product, and factors such as the timing of publication of the disparaging articles, their scope of dissemination, the abnormal market consequences caused, and the communications among the defendants, so as to comprehensively determine the defendants’ subjective intent and the nature of the conduct.
(III) AnalysisThis case has important warning significance for regulating online marketing and commercial competition. In commercial competition, business operators may lawfully engage in product comparisons, consumer evaluations, and market publicity, but may not damage the commodity reputation of competitors by means such as false testing, exaggerating hazards, creating panic, or manipulating public opinion. Especially in e-commerce and social-media environments, means of dissemination such as online articles, blogger reposts, and trending-search hype are characterized by rapid diffusion, broad influence, and concentrated harmful consequences. Once used for commercial disparagement, they may cause competing products to be delisted, sales to be interrupted, and brand reputation to be damaged within a short period of time.
Through this case, the court makes clear that using information networks to carry out commercial disparagement and causing significant losses may constitute the crime of damaging commodity reputation. This judgment powerfully deters market entities that attempt to obtain competitive advantages through “black public relations,” “fake reviews,” and “rumor-based marketing,” and also reflects the clear position of the judicial authorities in maintaining the order of fair competition and protecting the lawful rights and interests of market entities. For brand owners, marketing agencies, and MCN agencies, this case indicates that, when conducting evaluations of competing products and commercial promotion, they should ensure that information sources are truthful, testing bases are lawful, and dissemination content is objective, and avoid transforming market competition into online rumor-mongering and public-opinion attacks.
VII. Case of Wu Mouqing and Wu Moudan Contract Fraud (I) Basic FactsThe case of Wu Mouqing and Wu Moudan contract fraud addressed the criminal-law evaluation of malicious exploitation of platform settlement loopholes. Wu Mouqing was the legal representative of Company A, whose principal business was cross-border e-commerce, and Wu Moudan was a regional operations manager. The victim entity, Company B, was the agent in mainland China for a certain overseas platform and provided advertising-placement services to customers with advertising-placement needs. After Company A registered an account on Company B’s platform, it settled advertising-placement fees with Company B in real time by means of prepayment, and Company B would subsequently pay fees according to the bills of the overseas platform.
Beginning in December 2022, during Company A’s placement of advertisements on Company B’s platform, it discovered that after applying to Company B for zeroing out and refunding the account balance, the overseas platform would still continue to place advertisements for a period of time, while the advertising-traffic fees during that period would not be deducted by Company B or the amount deducted would be significantly lower than the amount that should have been deducted. In order to obtain advertising traffic free of charge or at low cost, Wu Mouqing instructed Wu Moudan and others to purchase in large quantities more than 1,800 platform accounts and corresponding advertising accounts on Company B’s platform, and directed company employees to maliciously zero out and request refunds immediately after advertising placement, causing Company B losses of more than RMB 20 million.
(II) Key Points of the JudgmentThe court held that Wu Mouqing, as the directly responsible person in charge of Company A, and Wu Moudan, as another directly responsible person, during the operation and management of Company A, for the purpose of illegal possession, defrauded the victim entity of money during the conclusion and performance of contracts, and that the amount was especially huge; their conduct therefore constituted the crime of contract fraud. The court of second instance dismissed the appeal and upheld the original judgment.
This case clarifies that where an e-commerce operator, during the conclusion and performance of an advertising-services contract, exploits a platform settlement loophole, creates the appearance of normal advertising placement, obtains free traffic by means of malicious zeroing out, and thereby causes the platform to suffer major economic losses reaching the statutory amount threshold, the operator shall be convicted and punished for the crime of contract fraud in accordance with law.
(III) AnalysisThis case provides a clear characterization path for “non-technical-intrusion-type” platform arbitrage conduct. The actors mainly exploited loopholes in platform settlement rules and, by registering accounts in large quantities, repeatedly placing advertisements, and immediately zeroing out and requesting refunds, created the appearance of normal advertising placement and normal settlement, while in substance shifting the cost of advertising traffic to the platform agent. Such conduct occurred during the conclusion and performance of advertising-services contracts. The actors exploited the victim entity’s reliance on the normal transaction status, concealed their true purpose of maliciously exploiting the loophole to obtain free traffic, and caused huge losses to the platform.
In the digital economy, platform rules, settlement mechanisms, and account systems constitute an important foundation of transactional reliance. After discovering a platform loophole, business operators should comply with the principle of good faith and promptly cease abnormal transaction conduct, and may not repeatedly, extensively, and maliciously obtain benefits on the grounds that “the rules allowed it” or “the system did not block it.” This case also indicates that platform enterprises should promptly improve risk-control models, refund rules, abnormal-account identification mechanisms, and advertising-settlement audit mechanisms, so as to prevent institutional loopholes from being exploited on a large-scale and industrialized basis.
VIII. Case of Wang et al. Infringing Citizens’ Personal Information (I) Basic FactsThe case of Wang et al. infringing citizens’ personal information extends the protected object of personal information to new types of digital financial account information, such as digital renminbi wallets. In April 2025, Wang and Miao Moujie contacted upstream personnel through certain software and trafficked in citizens’ personal information, including digital renminbi wallets. Miao Moujie recruited part-time workers in the name of attracting new account openings for securities, banking, and other companies, brought large numbers of part-time workers to office premises leased by Wang, and induced them, in the course of registering accounts on loan platforms and the like, to download and register the digital renminbi app, open digital renminbi wallets, and complete real-name authentication.
Thereafter, the two changed the binding of the relevant digital renminbi wallets to mobile phone numbers provided by upstream personnel, and sold complete sets of information materials, including the part-time workers’ identity-card photographs, digital renminbi wallet information, rebound accounts, login passwords, and payment passwords, to the upstream personnel. Upon investigation, the two sold to others 81 sets of citizens’ personal information containing citizens’ identity documents, digital renminbi accounts, and other information, and obtained illegal gains of more than RMB 20,000. The procuratorial organ separately brought a criminal incidental civil public-interest action, requesting that the two persons publicly apologize, delete the relevant information, and compensate for losses.
(II) Key Points of the JudgmentThe court held that Wang and Miao Moujie violated state provisions by illegally acquiring and selling citizens’ personal information to others, and that the circumstances were serious; their conduct therefore constituted the crime of infringing citizens’ personal information. The court rendered a criminal incidental civil judgment, sentencing the two persons respectively to fixed-term imprisonment with probation and imposing fines, and ordering the two persons to make public apologies to society, delete the information data involved in the case, compensate for losses, and take other measures.
This case clarifies that a digital renminbi wallet authenticated by real name falls within the category of citizens’ personal information. Conduct involving the illegal acquisition and sale of real-name-authenticated digital renminbi wallets and related account materials shall be identified, in accordance with law, as the crime of infringing citizens’ personal information.
(III) Analysis Digital renminbi wallets are closely related to personal identity authentication, financial payment, account control, and funds circulation. They can identify specific natural persons, reflect individuals’ financial activities, and may be used for funds transfer and money laundering. The actors induced part-time workers to complete real-name registration, change the bound mobile phone numbers, and provide login passwords and payment passwords. In substance, this amounted to selling complete sets of other persons’ real-name financial accounts to an upstream criminal chain. Such conduct not only infringes citizens’ personal-information rights and interests, but may also become a tool for downstream crimes such as telecom and online fraud, money laundering, and transfer of criminal proceeds.
Another important value of this case lies in achieving the connection between criminal sanctions and civil public-interest protection. In addition to pursuing the defendants’ criminal liability in accordance with law, the court also ordered them to delete the information involved in the case, publicly apologize, and compensate for losses, forming an integrated governance model of “criminal crackdown plus civil accountability plus public-interest restoration.” This handling method helps eliminate the risk of continued dissemination of personal information and also reflects the judicial trend of extending personal-information protection from case-by-case punishment to the restoration of social public interests.
Comment The typical cases released by the Shanghai High People’s Court on punishing new types of cybercrime in accordance with law constitute a concentrated response to new forms of cybercrime in recent years and are also important samples of the generation of judicial rules in the construction of digital rule of law. The relevant cases show that criminal justice is continuously refining, through specific cases, adjudicative rules that are replicable, applicable, and capable of providing guidance, and is making timely responses to security risks arising in the development of the digital economy, artificial intelligence, the low-altitude economy, the platform economy, and digital finance.
In the face of technological innovation and business-model innovation, the judicial authorities, by clarifying behavioral boundaries, punishing serious violations and crimes, restoring impaired rights and interests, and guiding industry governance, promote the formation of a safe, honest, fair, and orderly online rule-of-law environment. For members of the public, these cases indicate that individuals should enhance their awareness of account security, data security, and financial-account protection. For platforms and enterprises, these cases demonstrate that technological innovation and business-model innovation must always operate within the track of the rule of law.
© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.