Scalping Bots, Tampered Exam Applications, Hacked Robots: The Legal Boundaries of Computer Crime in the AI Era

Analyzing the legal boundaries of computer crime in the AI era, from ticket bots to hacked robots.
Drawing on law professor Luo Xiang's legal-education content, this article dissects the crime of destroying computer information systems through real cases—tampered gaokao applications, scalper ticket bots, traffic hijacking, and hacked smart devices—clarifying where technical acts cross into criminal territory in the AI era.
In an age where artificial intelligence and smart devices are becoming increasingly ubiquitous, what counts as a "prank," and what has already crossed the red line of criminal law? In his latest legal-education content, law professor Luo Xiang systematically examines the legal boundaries of the crime of destroying computer information systems and its related offenses, using vivid, real-world cases such as "tampering with college entrance exam applications," "scalper ticket bots," and "hacking companion robots." This article draws on his views to offer an analysis from the intersection of technology and law.
The Legal Boundaries of Pranks: Why Tampering With College Application Choices Is a Crime
Every year after the college entrance examination (gaokao), incidents occur in which someone, out of jealousy, tampers with a classmate's application choices. Many view this as a harmless prank, but Luo Xiang makes it clear: even pranks have legal boundaries.
He uses two extreme cases to illustrate how a prank can lead to disaster: poking someone's hornet's nest, resulting in the person being stung to death, or disguising a watermelon as a severed head and scaring someone to death—both of these acts could constitute negligent homicide. Likewise, tampering with someone's gaokao application choices is an illegal or even criminal act.
A judgment published on China Judgments Online is clear proof. A student at a vocational and technical school, out of jealousy, secretly logged into the gaokao application accounts of seven classmates and altered their choices, causing seven victims to be unable to attend their first-choice schools. The court found that the student "violated state regulations by tampering with data stored, processed, and transmitted in a computer information system, with serious consequences," constituting the crime of destroying computer information systems, and ultimately sentenced the student to one and a half years' imprisonment.
It is worth noting that the gaokao application system is a typical "educational administrative information system," and its data is highly one-time and irreversible—once an application choice has been tampered with and has passed the review period, victims often only discover the change after admission results are announced, leaving an extremely limited window for remedy. From a technical architecture perspective, gaokao application systems typically employ a time-window locking mechanism: once the submission deadline passes, data enters a read-only state and is synchronized to the admissions database, and any subsequent correction requires a cumbersome administrative approval process that, in most provinces, is effectively impossible. This characteristic of being "technically simple to carry out yet difficult to undo" is precisely an important basis for classifying the act as having "serious consequences." Such cases also follow a strong psychological-motive pattern: perpetrators usually have a direct competitive relationship with the victims, and jealousy-driven crimes often occur among acquaintances—which echoes Luo Xiang's closing warning about "controlling jealousy."

This judgment reveals a key point: merely deleting or modifying data in a computer information system may constitute a criminal offense, rather than being merely a "moral issue."
The Three Types of Conduct Constituting the Crime of Destroying Computer Information Systems
The crime of destroying computer information systems is stipulated in Article 286 of the Criminal Law, and Luo Xiang summarizes it into three typical forms of conduct. It is worth noting that this provision was first established in the 1997 revision of the Criminal Law, when the internet in China had only just gotten started—in 1997, China had only about 620,000 internet users, and cybercrime was still a novel phenomenon, yet legislators had the foresight to criminalize related conduct. As internet technology developed rapidly, in 2011 the Supreme People's Court and the Supreme People's Procuratorate jointly issued the "Interpretation on Several Issues Concerning the Application of Law in Handling Criminal Cases Endangering the Security of Computer Information Systems," which refined the standards for determining "serious consequences" and the scope of destructive programs, enabling the offense to adapt to new forms of crime in the era of cloud computing and mobile internet. Subsequently, with the implementation of the Cybersecurity Law in 2017, the scope of protection for computer information systems was further extended to critical information infrastructure, forming a two-tier system of coordinated protection through administrative regulations and criminal law.
Type One: Interfering With System Functions
Violating state regulations by deleting, modifying, adding to, or interfering with the functions of a computer information system, causing the system to fail to operate normally, with serious consequences. In short: "delete, modify, add, interfere."
Type Two: Tampering With System Data
Violating state regulations by deleting, modifying, or adding to data and applications stored, processed, or transmitted within a computer information system, with serious consequences. The aforementioned gaokao application tampering case falls into this category.
Type Three: Spreading Destructive Programs
Intentionally creating or spreading destructive programs such as computer viruses, affecting the normal operation of computer systems, with serious consequences.
The so-called "destructive programs" were explicitly expanded in the 2011 judicial interpretation to include multiple forms such as Trojans, worms, and botnet control programs, and are no longer limited to "viruses" in the traditional sense. This expansion carries significant real-world importance: modern network attack tools often lack the self-replicating characteristics of viruses, yet still possess extremely strong destructive capabilities. Ransomware is a typical example—it encrypts victims' files and demands a ransom, and while it is technically not a traditional virus, it can still be classified as a "destructive program" under the judicial interpretation's framework. The WannaCry ransomware attack that swept the globe in 2017 paralyzed medical, telecommunications, and financial systems in more than 150 countries, with estimated direct economic losses exceeding $8 billion, profoundly revealing the real-world harm of such programs and confirming the necessity of the judicial interpretation's expanded reading.
The basic penalty for this offense is up to five years' imprisonment, and where the consequences are especially serious, the maximum penalty can reach 15 years. This range of penalties reflects legislators' high regard for the security of information systems.
Scalper Ticket Bots: Why They May Constitute Computer Crime
The most practically significant part of this content is Luo Xiang's legal characterization of "scalper ticket-grabbing" behavior.
Whether it's grabbing concert tickets, proxy-buying Spring Festival train tickets, snapping up study-abroad visa appointment slots, or grabbing course registrations, many people habitually turn to "scalpers" for help. Luo Xiang points out that the ticket-grabbing software these scalpers develop is, in judicial practice, interpreted as "interfering with a computer information system," and therefore may constitute the crime of destroying computer information systems.
From a technical standpoint, ticket-grabbing software typically works by simulating human requests, high-frequency polling of interfaces, bypassing CAPTCHA mechanisms, and similar means, sending a large number of concurrent requests in an extremely short time to seize ticketing resources that should be subject to fair competition. The core technical features of such software include: using automated scripts to bypass CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) verification, maintaining large pools of proxy IPs to evade rate limiting, and reverse-engineering the API protocols of ticketing platforms. Among these, reverse-engineering API protocols itself may already violate platform terms of service and the Anti-Unfair Competition Law; while the abnormal traffic generated by maintaining hundreds or even thousands of proxy IPs bears a certain technical resemblance to DDoS (Distributed Denial of Service) attacks—both use abnormal traffic to prevent the target system from responding normally to legitimate user requests. Such software causes abnormal load on target servers and interferes with the system's normal service responses to ordinary users, meeting the judicial interpretation's criteria for "interfering with the normal operation of a computer information system"—this is the core logic behind why ticket-grabbing behavior, which seemingly "technically does not destroy any data," may still violate criminal law.

According to the relevant judicial interpretation, a scalper who obtains illegal gains of 5,000 yuan or more, or causes economic losses of 10,000 yuan or more, may meet the threshold for criminal liability. The seemingly gray-area business of "grabbing tickets for people to earn a small service fee" can, in fact, cross the threshold of crime at any moment.
The Supreme People's Court has also published a guiding case on "traffic hijacking": a user accessing a certain portal website was redirected to a gambling site—technically manifesting as the IP address for accessing a particular domain being tampered with and redirected to a designated IP address, preventing users from accessing the original site or directing them to a fraudulent site, thereby stealing data or disrupting normal service.
Understanding this case requires knowing the technical mechanism of DNS hijacking: DNS (Domain Name System) is the internet's "phone book," responsible for resolving human-readable domain names (such as www.example.com) into machine-recognizable IP addresses. DNS hijacking refers to attackers redirecting users' access to legitimate websites toward malicious servers by poisoning DNS caches, controlling DNS servers, or tampering with DNS response packets at the network transport layer. Broader traffic hijacking also includes BGP route hijacking (redirecting large-scale network traffic to attacker-controlled nodes by forging routing announcements) and HTTP hijacking (carriers or man-in-the-middle attackers injecting malicious content into plaintext HTTP transmissions), among other methods. Due to the widespread adoption of HTTPS encryption, pure HTTP hijacking has gradually declined, but BGP route hijacking and attacks targeting the DNS-over-UDP protocol remain the primary threats today. Such attacks are completely transparent to users, and victims are often entirely unaware, making the harm especially insidious—an important reason the Supreme Court listed it as a guiding case. The court ultimately found the defendant guilty of destroying computer information systems, providing important guidance for the legal characterization of technical black-market activities such as traffic hijacking and DNS hijacking.
New Questions in the AI Era: Do Phones and Robots Count as "Computers"?
As smart devices become widespread, a natural question emerges: the law says "computer," so does damaging a phone or hacking a robot count as computer crime?
Luo Xiang's answer is clear: smart devices can all be interpreted as computers. Today's phones are essentially no different from computers; and in an era of continuously advancing artificial intelligence, all kinds of AI devices can likewise be included within the scope of "computers."
From the perspective of legal interpretation, this conclusion adopts the methods of purposive and expansive interpretation—the legislative purpose is to protect the security of information systems, not to be bound by the literal meaning of "computer." This trend is not unique to China: the EU's Network and Information Systems Security Directive (NIS2) defines "information system" as any device or group of interconnected devices that stores, processes, retrieves, or transmits digital data; the U.S. Computer Fraud and Abuse Act (CFAA) extends the definition of "protected computer" to "any computer used in interstate or international commerce or communication," which in practice covers nearly all networked devices. Neither law uses the device's form as a condition for protection, but rather uses its data-processing function as the core criterion, reflecting a common legislative strategy across nations in the face of the wave of intelligent devices.
Luo Xiang gave two rather forward-looking examples: Zhang San attacks the control device of a companion robot, directly causing the robot to beat its owner to death; or Wang Wu breaks into a robot vacuum and uses its camera to spy on someone's life—both of these acts constitute intrusion into computer devices.

As home robots, smart speakers, robot vacuums, and other devices enter countless households, the cameras, microphones, and control systems they carry—once illegally intruded upon or controlled—not only involve privacy breaches but may also pose personal safety risks. From an information security research perspective, such IoT (Internet of Things) devices often have security weaknesses such as delayed firmware updates, unchanged default passwords, and weak encryption of communication protocols, making them prime targets for network attackers. The Mirai botnet attack that shocked the world in 2016 launched DDoS attacks by controlling hundreds of thousands of IoT devices such as cameras and routers, causing large-scale internet outages along the U.S. East Coast—this real-world case profoundly reveals the tangible harm of smart-device security vulnerabilities. With the rapid development of Embodied AI technology, future household robots will possess stronger action capabilities and environmental awareness, and once maliciously controlled, their potential harm will far exceed the data-level harm of traditional network attacks, extending to threats to personal safety in real physical space. The law's expansive interpretation of "computer" is precisely a response to this increasingly severe reality.
The System of Computer Crime Offenses: Distinguishing the Target of Intrusion and the Nature of the Conduct
Computer crime is not limited to the crime of destroying computer information systems; it also includes the crime of illegally intruding into computer information systems, the crime of illegally obtaining computer information system data, the crime of illegally controlling computer information systems, and the crime of providing programs or tools for intruding into or illegally controlling computer information systems.
Understanding this system of offenses helps grasp its internal logic: China's criminal law designs computer crime offenses following the behavioral-chain logic of "intrusion—acquisition—control—destruction—tool provision," which aligns closely with the actual technical path of network attacks. In a typical APT (Advanced Persistent Threat) attack, the attacker often first completes initial intrusion through vulnerability exploitation, then moves laterally to obtain sensitive data, then establishes a persistent control channel, and finally carries out destruction or long-term dormancy—this technical path corresponds precisely to each link in the criminal law's system of offenses. The "persistent" nature of APT attacks is particularly noteworthy: attackers may remain dormant within a target system for months or even years, achieving long-term residency by implanting backdoor programs, during which time they continuously infiltrate the internal network and steal data while the target remains completely unaware. The SolarWinds supply chain attack exposed in 2020 is a classic case—attackers implanted malicious code into a software update package and, leveraging the distribution channels of legitimate software, breached thousands of government agencies and enterprises worldwide, fully embodying the complete criminal chain of "tool provision—system intrusion—data acquisition—long-term control," and validating the legislative necessity of bringing upstream tool developers within the scope of criminal prosecution.
Luo Xiang particularly distinguishes several easily confused offenses:
The crime of illegally intruding into computer information systems specifically refers to intruding into systems in the fields of "state affairs, national defense construction, and cutting-edge science and technology," with a maximum penalty of three years. For example, if Zhang San intrudes into the traffic management bureau's website to delete traffic violation records, this constitutes this offense.
But if Zhang San intrudes into a school's academic affairs office website and changes his own grades to abnormal values, since the intrusion is not into one of the three special fields above, it does not constitute the crime of illegal intrusion; however, since it involves deleting or altering data, it may constitute the crime of destroying computer information systems.

As for controlling companion robots or intruding into robot vacuums, such conduct may constitute the crime of illegally controlling computer information systems. If it also meets the elements of other crimes such as intentional homicide, it is handled under the principle of "punishment according to the more serious offense."
Beyond Technology: Control Jealousy, Return to Reason
In his conclusion, Luo Xiang turns from law back to human nature. He frankly admits that almost everyone harbors some degree of jealousy, and the closer someone is to us, the more easily they trigger jealousy—people rarely envy Musk, but may envy the dormitory roommate who got into Tsinghua or Peking University.
His advice is: control your emotions, and don't let jealousy turn into hatred or even crime. "A person's true competitor is really oneself," and when jealousy wells up, it's worth trying to inwardly send blessings to the other person.
From a technology practitioner's perspective, the value of this content lies in the way it clearly delineates the legal risks of common technical behaviors such as data tampering, ticket-grabbing software, traffic hijacking, and smart-device intrusion. In an era of AI and the Internet of Everything, the stronger one's technical capabilities, the more one must maintain reverence for legal boundaries.
Key Takeaways
Key Takeaways
Key Takeaways
Related articles

Disaster and Glory of the Apollo Program: The History We Must Revisit Before Returning to the Moon
From the fatal Apollo 1 fire to Apollo 8's daring lunar orbit to Apollo 11's successful landing—revisiting the disasters, fears, and compromises of the Apollo program and their lessons for today's return to the Moon.

Netflix Trust Exercise Turns Into Firing Trap: Where Are the Boundaries of Corporate Trust?
A Netflix employee was fired after sharing private info in a trust exercise. We analyze the risks of corporate trust exercises and how employees can protect themselves.

AMD CDNA5 Architecture Deep Dive: Technical Evolution and the AI Computing Competition Landscape
Deep analysis of AMD's CDNA5 architecture covering Chiplet packaging upgrades, HBM memory evolution, and low-precision compute optimization, examining how AMD challenges NVIDIA's AI chip dominance.