A business owner may discover that the company’s administrative email account has been compromised, customer information has been copied, financial reports have been exposed or confidential documents have fallen into the hands of an unknown person.
The incident may become more serious if the attacker deletes company records, disables business systems, impersonates a senior manager or sends fraudulent payment instructions to employees, customers or suppliers.
These risks are no longer limited to financial institutions or multinational businesses. Any organization that stores or processes information electronically may face a cyber incident capable of interrupting operations, damaging customer relationships and causing substantial financial losses.
Qatari law addresses these risks through provisions criminalizing unauthorized access, interception of electronic data, electronic impersonation, fraud, misuse of payment-card information and infringement of legally protected trade secrets.
In summary, unauthorized access may be punishable by imprisonment for up to three years, a fine of up to QAR 500,000, or either penalty. The penalty may be doubled where the unauthorized access results in specific consequences identified in Article 3, including deleting, altering, copying or disclosing data, disabling a system or causing harm to users.
Which Law Regulates Account Hacking in Qatar?
Cybercrime offences are primarily regulated by Law No. 14 of 2014 Promulgating the Cybercrime Prevention Law.
Depending on the circumstances, the law may apply to conduct including:
- Unauthorized access to websites, information systems and information networks.
- Exceeding the limits of authorized access.
- Remaining inside a system after becoming aware that the access is unauthorized.
- Capturing, intercepting or monitoring electronic data.
- Deleting, altering, copying, disclosing or publishing electronic information.
- Electronic impersonation and fraud.
- Misuse of electronic transaction-card information.
- Infringement of legally protected trade secrets and intellectual property rights.
The law was amended by Law No. 11 of 2025, which added Article 8 bis concerning the publication or circulation of photographs and video clips of individuals in public places in the circumstances specified by that provision.
Article 8 bis should not, however, be treated as the principal legal provision governing the hacking of corporate accounts. Corporate cyber incidents are more likely to be examined under provisions concerning unauthorized access, data interference, fraud, impersonation, payment-card information and protected trade secrets.
Is Unauthorized Access a Crime Without Data Theft?
Yes. A person does not necessarily have to steal money, delete files or damage a system before criminal liability may arise.
Article 3 criminalizes intentionally accessing, without lawful right, a website, information system, information network, information-technology means or any part of them.
The provision also addresses exceeding authorized access and continuing to remain inside a system after becoming aware that the access is unauthorized.
The basic offence is punishable by imprisonment for a term not exceeding three years, a fine not exceeding QAR 500,000, or either penalty.
A technically valid password does not automatically make every use of an account lawful. Access may still require examination where a person had no permission to use the credentials or exceeded the level of access granted.
However, the legal position of an employee who uses legitimate credentials for an unauthorized purpose depends on the facts, the scope of the employee’s authority, the applicable policies and the conduct that can be proved. It should not be assumed that every breach of an internal access policy automatically constitutes the same criminal offence.
When Is the Penalty for Hacking Accounts in Qatar Doubled?
Article 3 provides for doubling the basic penalty when unauthorized access results in one or more of the consequences expressly identified by law.
These consequences include:
- Cancelling or deleting electronic data.
- Adding false information.
- Disclosing data or confidential information.
- Damaging or altering data.
- Transferring, capturing or copying information.
- Publishing or republishing electronic data.
- Causing harm to users or beneficiaries.
- Destroying, stopping or disabling a website, system or network.
- Altering a website’s content, design or method of use.
- Impersonating the website owner or administrator.
There is therefore an important distinction between entering a system without permission and using that access to leak customer information, destroy accounting records or interrupt business operations.
The latter conduct may trigger the statutory doubling of the Article 3 penalty where the required legal elements and consequences are established.
The statement that “the penalty is doubled” should not be used as a general description of every harmful cyber incident. It applies where the conditions set out in the relevant provision are satisfied.
What Is the Penalty for Intercepting Electronic Data?
A cybercrime may occur without the offender directly entering the victim’s account.
Article 4 addresses intentionally capturing, intercepting or monitoring electronic data or traffic data without lawful right.
The offence is punishable by imprisonment for a term not exceeding two years, a fine not exceeding QAR 100,000, or either penalty.
Depending on the technical evidence, this provision may be relevant to unlawful monitoring of electronic communications or interception of information while it is being transmitted.
Hacking and the Theft of Corporate Trade Secrets
A company’s valuable assets are not limited to the money in its bank accounts. Important corporate information may include:
- Customer and supplier lists.
- Internal pricing models.
- Financial projections.
- Business expansion plans.
- Product specifications.
- Software architecture.
- Marketing strategies.
- Confidential contracts.
- Private negotiations and correspondence.
- Passwords, authentication codes and access keys.
A distinction should be made between access credentials and trade secrets.
Passwords, authentication codes and access keys are sensitive security information that must be protected. They do not necessarily qualify as trade secrets merely because they are confidential.
Other business information, such as non-public pricing models, technical specifications, strategies or confidential customer databases, may qualify for trade-secret protection where the statutory requirements are satisfied and the company has taken appropriate steps to preserve secrecy.
Article 13 of the Cybercrime Prevention Law penalizes the use of information networks or information technology to infringe or facilitate infringement of legally protected trade secrets and other protected intellectual property rights.
The penalty may include imprisonment for a term not exceeding three years, a fine not exceeding QAR 500,000, or either penalty.
Law No. 5 of 2005 on the Protection of Trade Secrets also prohibits obtaining, exploiting or disclosing a trade secret without the prior approval of its lawful holder. The holder may seek compensation for damage resulting from infringement or misuse.
Internal security measures are therefore legally and commercially important. A company should be able to demonstrate that it treated sensitive business information as confidential through access restrictions, contractual clauses, internal policies, employee training and appropriate technical controls.

Impersonating a Company Director After an Account Is Hacked
After compromising an email account, an attacker may impersonate a chief executive, finance director, employee or corporate entity.
Common examples include:
- Sending fraudulent bank-transfer instructions.
- Requesting an urgent payment in the name of a senior manager.
- Changing a supplier’s bank-account details.
- Issuing false invoices using the company’s identity.
- Requesting passwords or financial information from employees.
- Contacting customers through a compromised corporate email account.
Article 11 addresses conduct involving electronic impersonation and the use of information technology to obtain money, documents, signatures or other property through fraudulent means.
The offence is punishable by imprisonment for a term not exceeding three years, a fine not exceeding QAR 100,000, or either penalty.
A single incident may engage several provisions. A person may, for example, unlawfully access an account, impersonate a company officer and use that identity to obtain a fraudulent payment.
The exact charges and penalties depend on the conduct proved and the legal characterization adopted by the competent authorities and court.
Hacking Bank Accounts and Payment-Card Information
Cyber incidents involving financial accounts require careful legal classification.
Article 12 establishes specific offences concerning electronic transaction cards. These include unlawfully obtaining card numbers or data, producing or possessing equipment used to issue or forge cards, and knowingly using forged or unlawfully obtained card information.
The maximum penalty under Article 12 is imprisonment for up to three years, a fine of up to QAR 200,000, or either penalty.
Unauthorized access to an online bank account does not automatically fall exclusively under the payment-card provision.
Depending on the method and purpose of the attack, the conduct may involve:
- Unauthorized system access.
- Electronic impersonation.
- Electronic fraud.
- Interception of data.
- Use of stolen payment-card information.
- Forgery or use of forged electronic records.
It is therefore inaccurate to state that every banking-related cybercrime necessarily carries a more severe penalty than ordinary unauthorized access. The applicable penalty depends on the particular offence or offences established in the case.
Does Article 8 Bis Protect Corporate Data?
Article 8 bis should be distinguished from provisions governing corporate hacking and the theft of business information.
The provision, added by the 2025 amendment, addresses the publication or circulation online of photographs or video clips of individuals while they are in public places, without their knowledge or consent or outside the circumstances permitted by law.
The maximum penalty is imprisonment for one year, a fine not exceeding QAR 100,000, or either penalty.
Article 8 bis is therefore not the main legal basis for prosecuting the hacking of company accounts or theft of corporate documents.
Such incidents are more likely to be assessed under the provisions concerning unauthorized access, disclosure or alteration of data, electronic fraud, impersonation, payment cards and infringement of protected trade secrets.
Can a Company Claim Compensation After a Cyberattack?
Criminal proceedings do not necessarily prevent an affected company from seeking civil compensation.
Article 199 of the Qatari Civil Code establishes the general principle that a person who causes damage to another through an unlawful act is responsible for compensating that damage.
Article 201 provides that compensation may cover the loss suffered and the profit forfeited, provided that the damage is a natural result of the unlawful act.
Depending on the evidence and circumstances, a company’s claim may include:
- Direct financial losses.
- Money transferred as a result of fraud.
- Data-recovery expenses.
- System-restoration costs.
- Digital-forensic investigation costs.
- Business-interruption losses.
- Lost commercial opportunities.
- Costs of notifying or supporting affected customers.
- Other losses directly caused by the incident.
These amounts are not awarded automatically.
The company must establish the existence of the damage, its value and the causal relationship between the unlawful conduct and the claimed loss.
Financial records, expert reports, incident timelines, invoices, customer communications and evidence of interrupted business activity may all be relevant when assessing compensation.
Read also: 5 essential requirements for conducting commercial or industrial activities in Qatar.
Is a Criminal Conviction Binding in Civil Proceedings?
A conclusive criminal conviction may have binding effect before the civil courts, but that effect is limited to specific matters.
Article 319 of the Criminal Procedure Code provides that a conclusive criminal judgment by conviction may bind the civil court concerning the commission of the offence, its legal characterization and its attribution to the offender.
A criminal conviction does not, however, automatically determine the amount of civil compensation.
The company will generally still need to prove the nature, value and components of its losses. Expert accounting and technical evidence may therefore remain necessary.
What Should a Company Do Immediately After Discovering a Hack?
The first hours following a cyber incident may affect the company’s ability to identify the attacker, contain the incident and preserve reliable evidence.
1. Contain the Incident Carefully
Affected accounts and systems may need to be isolated, but this should be done through a coordinated incident-response process.
Immediately formatting devices, deleting suspicious files or reinstalling systems may destroy information needed for technical investigation.
Each action should be recorded, including what was done, when it was done, who performed it and why it was necessary.
2. Preserve Digital Evidence
The company should preserve potentially relevant evidence, including:
- Login, logout and authentication records.
- Server and application logs.
- IP addresses and device information.
- Suspicious emails, links and attachments.
- File-creation, modification and deletion timestamps.
- Screenshots and original electronic records.
- Security alerts.
- Access-control records.
- Backup copies.
- Messages received from the attacker.
- Records of every action taken after discovery.
Evidence should be handled in a manner that preserves its integrity and chain of custody.
Q-CERT describes its digital-forensic objective as investigating cybercrime systematically while maintaining the chain of forensic evidence. Its published service is directed at government and critical-sector organizations and requires written authorization from executive management and the legal department.
Private companies should not assume that Q-CERT assistance is automatically available in every case. Eligibility and the appropriate reporting route should be confirmed according to the organization and incident concerned.

3. Secure Accounts Without Destroying the Incident Timeline
Passwords, open sessions, recovery methods and compromised accounts may need to be secured immediately.
Where possible, changes should be made from a trusted device and should be fully documented.
The company should also review:
- Multi-factor authentication settings.
- Email-forwarding rules.
- Password-recovery addresses.
- Newly created users.
- Administrator privileges.
- API keys and application access.
- Remote-access sessions.
4. Report the Incident to the Competent Authorities
The Ministry of Interior lists the Economic and Cyber Crimes Department within the General Directorate of Criminal Investigation.
The Ministry also publishes cybercrime-reporting contact information through its official cyber-security awareness pages.
When submitting a report, the company should preserve original evidence and provide available logs, reports and communications without altering their contents.
5. Prepare a Legal and Technical Incident Report
An initial incident report should record:
- The date and time the breach was discovered.
- How the incident was detected.
- The affected accounts, systems and devices.
- The data accessed, copied, altered or deleted.
- The employees and service providers involved.
- The containment measures taken and their timing.
- Any ransom or extortion communications.
- The estimated financial impact.
- The impact on customers and business operations.
- The location and custody of preserved evidence.
- Potential notification obligations.
The report should clearly distinguish confirmed facts from assumptions or preliminary technical theories.
Corporate Obligations to Protect Customer Data
Legal protection does not begin only after the attacker has been identified.
Law No. 13 of 2016 on Protecting Personal Data Privacy requires controllers and processors to take necessary precautions to protect personal data against loss, damage, alteration, disclosure, unauthorized access and unlawful use.
Practical data-protection measures may include:
- Role-based access controls.
- Multi-factor authentication.
- Encryption of sensitive information.
- Regular software and security updates.
- Tested backup procedures.
- Employee cybersecurity training.
- Phishing-awareness programmes.
- Periodic reviews of access rights.
- Prompt cancellation of former employees’ access.
- Incident-response and business-continuity plans.
- Confidentiality and data-security clauses in employment contracts.
- Cybersecurity requirements in supplier contracts.
A company should document the implementation of these controls. A policy that exists only on paper is less persuasive than evidence of actual training, access reviews, monitoring, testing and enforcement.
Must a Company Report a Personal-Data Breach?
Where a cyber incident affects personal data, the company should assess not only the criminal offence but also its notification duties under the Personal Data Privacy Law.
Article 14 requires the controller to inform the affected individual and the competent department of a breach of the applicable protective precautions where the breach is capable of causing serious damage to personal data or individual privacy.
The assessment should consider:
- The type and sensitivity of the affected information.
- The number of individuals concerned.
- Whether the information was encrypted.
- Whether credentials or identity documents were exposed.
- The likelihood of fraud, identity theft or other misuse.
- The seriousness and duration of the potential harm.
- Whether the breach has been contained.
Notification decisions should be coordinated between legal, technical, compliance and management teams.
Communications should be accurate and timely while avoiding unsupported statements that could mislead customers or prejudice an ongoing investigation.
Read also: Inclusion programs in Qatari universities and support for people with disabilities.
Is an Unsuccessful Hacking Attempt Always Punishable?
It is not legally accurate to state that every failed attempt to access an account is automatically punishable in the same way as completed unauthorized access.
Article 28 of the Penal Code defines an attempt as beginning the execution of an act intended to commit a felony or misdemeanor where the act is stopped or fails for reasons beyond the offender’s control.
Merely intending to commit an offence or carrying out preparatory acts does not ordinarily constitute an attempt.
Article 30 further provides that the law determines the misdemeanors for which an attempt is punishable and the applicable penalty.
The legal treatment of an unsuccessful hacking incident therefore depends on:
- The actions actually performed.
- Whether execution of the offence had begun.
- Why the attempt failed.
- The classification of the intended offence.
- Whether the relevant legislation penalizes an attempt.
- Whether the conduct constitutes another completed offence.
A failed attempt to enter one system may, for example, involve a separate completed offence if the person intercepted data, committed fraud, used stolen information or forged an electronic record.
Each incident must be assessed on its facts rather than through a general assumption that every unsuccessful login attempt attracts the full penalty for completed unauthorized access.
Frequently Asked Questions
What Is the Penalty for Accessing Another Person’s Account Without Permission in Qatar?
Unauthorized access may be punishable by imprisonment for up to three years, a fine of up to QAR 500,000, or either penalty, where the legal elements of Article 3 are established.
Is It Illegal to Access an Account Using a Password Given by Someone Else?
It may be unlawful where the account owner did not authorize the access, the password was obtained or provided unlawfully, or the user exceeded the permission granted.
The legal position depends on the source of the credentials, the scope of authorization and the conduct carried out after access.
Is the Penalty Doubled When Data Is Deleted?
Article 3 provides for doubling the basic penalty when unauthorized access results in specified consequences, including deleting, disclosing, altering, copying or publishing data, disabling a system or causing harm to users.
Can Leaking a Customer List Be Treated as a Cybercrime?
Potentially. Depending on the circumstances, the conduct may involve unauthorized access, unlawful disclosure of electronic information or infringement of a legally protected trade secret.
Not every customer list automatically qualifies as a trade secret. Its legal status depends on its nature, confidentiality, commercial value and the measures taken to protect it.
Can a Company Recover Losses Caused by Business Interruption?
A company may claim loss suffered and profit forfeited where it proves that they were a natural result of the unlawful act.
The amount should be supported by financial records, technical reports and evidence connecting the interruption to the cyber incident.
Does a Criminal Conviction Guarantee Compensation?
No. A conclusive conviction may bind the civil court concerning the commission and attribution of the offence, but the company will generally still need to prove the nature and amount of its damages.
When Should a Company Contact a Cybercrime Lawyer?
Legal advice should be obtained as soon as a serious breach is discovered, particularly before:
- Communicating with a suspected attacker.
- Paying a ransom or transferring funds.
- Making public statements.
- Notifying customers or regulators.
- Dismissing an employee connected with the incident.
- Taking technical action that may affect evidence.
Conclusion
The penalty for hacking accounts in Qatar reflects the serious legal and commercial consequences of unauthorized access to electronic systems.
A person may face criminal liability even where no physical property has been stolen. Where unauthorized access results in deletion, disclosure, copying or alteration of data, system disruption or other consequences specified by Article 3, the basic penalty may be doubled.
Companies may also pursue compensation for financial losses and lost profits, provided that they preserve digital evidence and prove the damage and its connection to the incident.
Where personal data is affected, the company should also evaluate its protection and breach-notification duties under Law No. 13 of 2016.
Effective protection requires three connected elements: appropriate technical controls, enforceable internal policies and a coordinated legal response immediately after an incident.

