Discovering that someone has accessed our corporate email without authorisation can involve far more than losing control of a password. The intruder may have read confidential conversations, downloaded documents, created forwarding rules, sent messages in our name or used the account to prepare further fraud.
At Barcelona Penal, we are criminal law lawyers in Barcelona and advise companies, executives and professionals where there may have been unlawful access to corporate systems or communications. In these matters, one of the most important issues is properly preserving digital evidence from the outset, because some records may disappear and certain actions may inadvertently alter information that we will later need to analyse.
Quick answer: if we suspect that someone has accessed a corporate email account without permission, we should restrict the intruder's access without unnecessarily destroying evidence, preserve login and audit logs, retain original emails and their headers, document forwarding rules or changes made to the account, and consider a forensic extraction. We should also determine whether the access may constitute an offence under Article 197 bis of the Criminal Code and, if personal data has been affected, assess the obligations set out in the GDPR.
Why accessing corporate email without authorisation may be a criminal offence
Unauthorised access to a corporate account may be criminally relevant where the requirements established in the Criminal Code are met.
If someone has accessed your corporate email without permission, every minute counts. Tell us about your case and we will explain which evidence is key to protecting your rights from the outset.
We must distinguish between several situations. Entering a computer system without authorisation is not exactly the same as accessing, obtaining or using certain communications or data protected by privacy rights.
Article 197 bis and unlawful access to computer systems
Article 197 bis of the Criminal Code punishes anyone who, by breaching the security measures established to prevent it and without being duly authorised, accesses all or part of an information system or remains in it against the wishes of the person entitled to exclude them.
The penalty provided for this conduct is six months to two years' imprisonment.
This offence may be particularly relevant where someone obtains credentials through phishing, uses stolen passwords or unlawfully accesses an account protected by mechanisms designed to prevent such access.
Article 197 may also be relevant where communications or confidential data are accessed
Depending on what the intruder did after accessing the account, we must also examine the different conduct covered by Article 197 of the Criminal Code, especially where communications, documents or confidential data are accessed with the aim of discovering secrets or infringing privacy.
For this reason, we do not recommend reducing every case to the generic label of “email hacking”. We must determine how the access occurred, what information was viewed, what was downloaded or modified, and how it was subsequently used.
Can it be committed by an employee, partner or former employee?
Yes. The possible perpetrator does not necessarily have to be an external attacker.
An employee, partner, former worker, systems administrator or collaborator may engage in criminally relevant conduct if they access a system or account without being duly authorised and the other requirements of the offence are met.
However, in cases of internal access, we must carefully assess what permissions that person actually had. We do not recommend assuming that every access by an employee automatically constitutes a crime: we must review the credentials assigned, internal policies, their role and whether there were effective access restrictions.
What evidence should we preserve after detecting the access?
Digital evidence may be altered or cease to be available over time. For this reason, we consider it important for the legal and technical teams to work in coordination from the outset.
Login and audit logs
Logs or audit records are one of the most relevant sources of information. Depending on the provider, they may show access dates and times, IP addresses, devices, approximate locations, actions taken, configuration changes and other security events.
If we use Google Workspace or Microsoft 365, we recommend asking the administrator to preserve and export the available logs as soon as possible.
Retention periods are not the same across all platforms and plans. For example, Google Workspace retains numerous log events for approximately six months, whereas Microsoft Purview Audit retains many standard logs for 180 days and offers longer periods under certain licences and configurations.
In our experience, this difference matters: we should not wait to file a complaint before beginning to preserve technical logs.
Affected emails and technical headers
We should preserve messages that we suspect were read, forwarded, sent, modified or deleted during the unauthorised access.
Where possible, we recommend saving the email in its original format, such as .eml or equivalent, and retaining its technical headers.
Headers may contain information about the message route, servers used, timestamps and the results of authentication mechanisms such as SPF, DKIM or DMARC.
We should not assume that headers will identify the perpetrator on their own, but they can be an important piece of evidence when combined with access logs and other technical information.
Forwarding rules, filters and configuration changes
This is one of the points we particularly recommend checking and documenting.
An attacker may enter an account and create an automatic rule that forwards certain messages to another address. They may also add authorised applications, modify recovery methods, create filters or alter settings in order to maintain access to information.
We should therefore record these changes before removing them whenever it is technically possible and safe to do so.
Connected applications and active sessions
Changing the password alone may not fully resolve the incident.
Depending on the service used, there may be open sessions, connected applications, authentication tokens or other mechanisms that allow a certain level of access to be retained.
In our experience, this is particularly important because a company may believe it has removed the intruder after changing a password when another access mechanism previously authorised by the compromised account still exists.
Screenshots
Screenshots can be useful for visually documenting alerts, unknown sessions, messages, suspicious rules or configurations.
We recommend retaining the full screen and avoiding any unnecessary editing.
However, a screenshot does not always prove its origin, date, integrity or authorship on its own. Therefore, where the matter has financial or criminal significance, we advise supplementing it with technical logs, original files and, where necessary, computer forensic evidence.
The computer forensic report
A computer forensic expert can extract, analyse and technically document digital evidence using procedures that make it possible to demonstrate its integrity.
Depending on the incident, they may analyse logs, devices, metadata, IP addresses, configurations, malware, sessions, files and other elements related to the intrusion.
At Barcelona Penal, we consider it especially useful to coordinate the forensic examination with the legal strategy. There is no need to accumulate thousands of technical data points if they do not answer the questions relevant to the proceedings: who accessed the account, how they did so, when, what actions they took and what harm resulted.
Chain of custody and the integrity of digital evidence
Preserving evidence does not simply mean saving a copy.
When digital evidence is to be used in proceedings, we must be able to reasonably explain how it was obtained, who held it in custody, what operations were carried out on it and whether it has remained intact.
What it means to maintain the integrity of evidence
Digital files can easily be copied, modified and overwritten. For this reason, a forensic examination may use hash functions or other technical mechanisms to identify a set of data and subsequently check whether it has been altered.
The existence of an issue in the chain of custody does not automatically mean that all evidence is invalidated, but it may give rise to disputes over its authenticity or reliability.
We therefore recommend properly documenting its collection and preservation from the outset.
We should not unnecessarily manipulate the compromised system
If there is an active intrusion, we must also prioritise the company's security. It would not be reasonable to keep access open solely to preserve evidence.
The appropriate approach is to coordinate containment with the incident response team or IT professional, while seeking to avoid unnecessary destructive actions.
Depending on the case, it may be necessary to isolate a device from the network, revoke sessions, block credentials or change passwords. The specific order will depend on the risk and the evidence we can preserve beforehand.
In our experience, the mistake is not “touching” the system, but making significant changes without documenting them and then being unable to reconstruct what existed before the intervention.
How to report unauthorised access to corporate email in Barcelona
Once the account has been secured and the initial evidence preserved, we must assess the criminal route.
In Barcelona, we can file a complaint with the competent police authorities, particularly the Mossos d'Esquadra, or bring criminal proceedings before the relevant court where the strategy calls for filing a criminal complaint.
What should a complaint for unlawful access to email explain?
We do not recommend simply stating that “we have been hacked”.
It is advisable to build a clear timeline: when we detected the access, what alerts appeared, which sessions we do not recognise, which emails were affected, what records we have preserved, what information may have been exposed and what consequences resulted.
If there is also reasonable suspicion regarding a specific person, we must explain what objective elements support that hypothesis without presenting as established facts matters that still require investigation.
Report or criminal complaint: it depends on the case
A report serves to bring potentially criminal facts to the attention of the authorities.
A criminal complaint, which requires a lawyer and court representative, makes it possible to formally bring criminal proceedings and become a party to them.
We do not recommend stating that a criminal complaint is always the best option. At Barcelona Penal, we assess the amount of the loss, the technical complexity, whether the possible perpetrator is identified and the investigative steps that may be necessary before deciding on the strategy.
What we do not recommend doing after discovering the access
Immediately formatting devices
Resetting a computer, deleting an account or reinstalling a system may destroy useful information for determining how the intrusion occurred.
Before taking irreversible steps, we recommend assessing what evidence needs to be preserved and coordinating security recovery with forensic analysis.
Only changing the password
Changing credentials may be necessary, but it is not always sufficient.
We must also review open sessions, connected applications, recovery methods, automatic rules, authorised devices and security settings.
Trying to identify the perpetrator ourselves based solely on an IP address
An IP address may provide information, but we should not assume that it automatically identifies an individual.
It may correspond to a shared connection, a VPN, corporate infrastructure, an intermediary service or a dynamic address.
For this reason, we recommend analysing technical data as a whole and, where it is necessary to identify a specific user, requesting the relevant investigative steps within the proceedings.
Communicating all suspicions internally without control
If there is a possibility that the access came from within the organisation itself, indiscriminate communication may alert the person under investigation.
We recommend initially limiting information to those who need to know it in order to protect systems, preserve evidence and make legal decisions.
What happens if the email contained personal data?
Unlawful access to corporate email may also be a personal data breach if the attacker has gained unauthorised access to information concerning employees, clients, suppliers or other natural persons.
In that case, the criminal response and the data protection response must be coordinated.
Not all breaches must automatically be reported to the AEPD
Article 33 of the GDPR requires the controller to notify the breach to the supervisory authority where it is likely to result in a risk to the rights and freedoms of individuals.
Where that obligation applies, notification must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
We therefore do not recommend stating that every email access automatically requires notification to the AEPD. We must first assess what information was compromised, how many people are affected, the possibilities of misuse and the level of risk.
When we must also inform affected individuals
If the breach is likely to result in a high risk to the rights and freedoms of individuals, we must also assess the obligation to communicate what has happened directly to them.
Breaches must be documented internally even where, after the risk assessment, it is concluded that notification to the authority is not required.
Can a company review an employee's corporate email?
Where the possible access is carried out by the company itself, we must distinguish unlawful intrusion from legitimate powers of employer oversight.
Do not act alone when facing unauthorised access to your email: poorly managed evidence may lose its value before a court. Our criminal lawyers guide you in preserving it correctly.
Article 87 of Organic Law 3/2018 recognises workers' right to privacy in the use of digital devices made available to them by the company.
At the same time, it allows the employer to access content resulting from the use of those resources to monitor compliance with employment obligations or ensure the integrity of devices, within the limits established by law.
Prior information and usage criteria are particularly important
The company must establish criteria for the use of digital devices that respect privacy protection standards and inform employees of those criteria.
For this reason, when we assess whether company access to an email account was lawful, we must review internal policies, the purpose of the monitoring, the prior information provided and the proportionality of the action.
We cannot automatically equate access by an employer acting within its legal powers with the covert access of a colleague, former employee or third party.
How to strengthen security after unauthorised access
Once the evidence has been preserved and the incident brought under control, we must investigate why the access was possible.
Multi-factor authentication
We recommend enabling multi-factor authentication (MFA) on corporate accounts.
Where possible, phishing-resistant methods, such as certain security keys or mechanisms based on modern authentication standards, offer particularly valuable protection against credential theft.
Unique, strong passwords
We do not recommend reusing the same password across different services.
A corporate password should be sufficiently long, unique and difficult to predict. A password manager can make it easier to use different credentials for each service.
Reviewing permissions and old accounts
We must also apply the principle of least privilege and review which people have access to each system.
When the relationship with an employee, supplier or collaborator ends, we must revoke credentials and permissions they no longer need.
Alerts and monitoring
Google Workspace, Microsoft 365 and other providers offer mechanisms for detecting certain anomalous access, activities or configurations.
In organisations with greater security requirements, it may be advisable to centralise events using SIEM solutions or other monitoring tools.
From our perspective, the aim is not simply to prevent every attack, which is difficult to guarantee, but to detect intrusions sooner and have sufficient records to reconstruct what happened.
How we approach these cases at Barcelona Penal
When a company consults us about unauthorised access to its corporate email, our first task is to separate the urgent security response from the strategy aimed at subsequently establishing the facts.
We analyse when the intrusion was detected, which credentials may have been compromised, what logs exist, what information was accessed or extracted, what settings were changed and which individuals had legitimate access.
We then determine what evidence should be technically preserved and what investigative steps may be necessary within the criminal proceedings.
In our experience, an IP address alone should rarely be the sole basis for attributing access to an individual. Attribution is much stronger when we can link logs, devices, times, communications, credentials, subsequent activity and other objective elements.
We also examine whether the intrusion gave rise to other offences. For example, email access may subsequently be used to impersonate an executive, divert payments, obtain confidential business information or commit BEC fraud.
At Barcelona Penal, we can coordinate the legal analysis with the work of the computer forensic expert, prepare the report or criminal complaint, and act as private prosecutor where appropriate.
Conclusion: properly preserving evidence can determine the investigation
When we discover that someone has entered a corporate email account without authorisation, we must act quickly, but not improvisedly.
We need to regain control of the account, contain the risk and, at the same time, preserve the logs and evidence that will later allow us to reconstruct what happened.
Logs, original emails, headers, sessions, forwarding rules, connected applications and forensic analysis can become important parts of a criminal investigation.
For this reason, our recommendation is to coordinate the IT and legal response from the very first steps, especially where sensitive information has been accessed, there has been financial loss or we suspect that the access forms part of broader criminal conduct.
Contact Barcelona Penal, specialists in cybercrime in Barcelona
At Barcelona Penal, we are criminal law lawyers in Barcelona and represent both victims and individuals under investigation in proceedings relating to cybercrime, unlawful access to systems, disclosure of secrets, fraud and other offences committed through technological means.
If we have suffered unlawful access to a corporate email account, we can analyse the available evidence, coordinate work with computer forensic specialists, determine the potential criminal relevance of the facts and design the appropriate procedural strategy.
Frequently Asked Questions about evidence of unauthorised access to corporate email
Do you have questions about what evidence to preserve or how to report this cybercrime? At Barcelona Penal, we analyse your situation with no obligation and give you a clear answer.
