Allsopp [2019] EWCA Crim 95
- Summary
- Citing
- Cited By
Connor Douglas Allsopp v Regina [2019] EWCA Crim 95 concerned an appeal against sentence for offences arising from the October 2015 hacking of TalkTalk’s computer systems by the Court of Appeal (Lord Justice Flaux, Mr Justice Sweeney and Mr Justice Soole).
The appellant pleaded guilty on 30 March 2017 at the Central Criminal Court before His Honour Judge Topolski QC to count 6, supplying an article for use in fraud contrary to section 7(1) of the Fraud Act 2006, and to count 8, supplying articles for use in an offence under sections 1, 3 or 3ZA of the Computer Misuse Act 1990. On 19 November 2018, Her Honour Judge Dhir QC sentenced him to eight months’ imprisonment on count 6 and seven months concurrent on count 8. A co-accused, Matthew Hanley, pleaded guilty to four counts including unauthorised access to a computer, supplying and obtaining articles for use in Computer Misuse Act offences, and supplying an article for use in fraud, and received an overall sentence of twelve months’ imprisonment. The appellant appealed with leave of the single judge.
The TalkTalk hacking attack took place between 18 and 22 October 2015. Hackers unlawfully accessed the company’s data, causing estimated losses of £77 million. The Chief Executive Officer was subjected to repeated blackmail attempts for payment of Bitcoins in return for stolen data. Neither the appellant nor Hanley was involved in the blackmail. At the time of the offending the appellant was aged 18 and Hanley was aged 20. They both lived in Tamworth and knew each other. Hanley was a dedicated computer hacker who was involved in the original hacking of the TalkTalk database. On 24 October 2015, concerned about police investigation, he wiped his computer. His involvement was pieced together from a large number of Skype conversations.
On 23 October 2015, Hanley supplied the appellant with a computer file containing the personal and financial details of 8,000 TalkTalk customers. The appellant had asked Hanley for the TalkTalk database. In a Skype conversation Hanley warned the appellant: “Be careful with that dump. Don’t sell unless £1,000 plus and you didn’t get it from me.” On the same day the appellant supplied that file to an online user called “Reign”, knowing it was for use in connection with fraud. It was clear the appellant knew he had obtained the file illegally and that Hanley and “Reign” were concerned with fraud and hacking. In exchange “Reign” was to provide a list of credit cards but in fact supplied a series of computer files with personal data and website details and passwords, including for NASA, which proved next to worthless. Between 23 and 29 October 2015 the appellant supplied those files to Hanley. The files included one containing 77 websites with additional syntax information and a text file containing 492,000 unique email addresses with passwords in plain text and a hash diary for the passwords.
Hanley was arrested on 1 November 2015. The appellant was arrested on 20 April 2016. On arrest he claimed his computer had been destroyed in a house fire. His involvement was pieced together from Skype conversations and from significant admissions in police interviews. The appellant had no previous convictions but had a caution from 2013 for possession of an offensive weapon in a public place. Hanley had no previous convictions but a caution from 2016 for possession of cannabis.
The pre-sentence report on the appellant noted that at the time he acted without any regard for the impact of his behaviour on victims of the hacking. Although he regretted his involvement, he did not grasp the enormous negative reputation and significant financial impact on TalkTalk. He was assessed as low risk of re-offending and low risk of harm. The author concluded he was impressionable and immature, in awe of Hanley’s computer hacking skills and wanted to emulate him. The report on Hanley noted he denied financial motivation and said comments about demanding money were to impress friends. He presented as socially isolated with a long history of anxiety and low self-esteem. He was assessed as having a 39 per cent likelihood of re-offending within two years and as low risk of harm to others. Given his history of anxiety and depression, self-harm and suicidal ideation, the probation officer took the view he would be vulnerable within a custodial environment. A psychologist’s report dated December 2016 recommended Hanley be viewed as meeting the criteria for a social anxiety disorder and concluded that a custodial environment was likely significantly to exacerbate his anxiety.
The judge noted both defendants were involved in a significant, sophisticated, planned attack on TalkTalk’s computer systems. They had not exposed the vulnerabilities but had joined an attack started by others. The attack led to gaining access to TalkTalk’s confidential client information. The estimated loss to TalkTalk was £77 million. Confidential information was stolen and passed to others, causing misery and distress to thousands of customers. The judge noted there were no sentencing guidelines for offences under the 1990 Act. She was referred to R v Martin [2013] EWCA Crim 1420 and R v Mudd [2017] EWCA Crim 1395. In Martin, Leveson LJ said such offences fell into the highest level of culpability because of financial loss and destruction to private and business affairs. The seriousness of the criminality could not necessarily be measured by the length of an attack or directly measurable financial consequences. The disabling of a website for even a short period may have far-reaching consequences. The wider implications for society could not be ignored. Mudd involved more serious offending by a 20 year-old with no serious convictions, diagnosed with Asperger’s syndrome, whose offending occurred when he was 16. The Court of Appeal had reduced the sentence to 21 months but concluded immediate custody was appropriate and that it was important the courts sent the clear message that cyber crime on this scale was not a game but would be taken very seriously and punished accordingly.
In relation to counts 5 and 6 the judge applied the Fraud, Bribery and Money Laundering guideline for offences under section 7 of the Fraud Act 2006. The judge considered that in the case of both defendants the offending fell towards the lower end of medium culpability and was in the category of greater harm. The starting point was two years six months’ custody with a range of eighteen months to five years. For Hanley the court took a starting point of two years six months, then reduced it to fifteen months taking account of his age at the time, his lack of previous convictions, the relatively short period over which the offending occurred, the reports about him, his basis of plea, and the absence of further offending. The court gave him 20 per cent credit for his guilty plea and passed a sentence of twelve months’ immediate custody on count 5 with concurrent shorter sentences on the other counts. In relation to the appellant the judge said his involvement was less than that of Hanley. Taking account of everything said on his behalf and the pre-sentence report, including that he had been 18 years old at the time and immature, had no previous convictions, and the considerable period of time between offending and sentence was not his fault, the mitigating factors reduced the starting point from 20 months to twelve months. The judge gave full one-third credit for his considerable admissions in police interviews. On count 6 the sentence was eight months’ imprisonment and on count 8 seven months’ imprisonment concurrent. The judge concluded she could not suspend the sentence in view of the seriousness of the offending.
On behalf of the appellant Mr Bell raised three grounds of appeal. First, he submitted the judge overstated the appellant’s involvement in the hacking and therefore took too high a starting point, which should have been between twelve and eighteen months, not twenty months. He submitted the judge had mistakenly assumed the appellant had taken part in the original attack. The Court of Appeal held that if the judge’s statement at the outset that the appellant was involved in a “significant, sophisticated, systematic, planned attack” were taken in isolation it might suggest she had proceeded on the assumption that the appellant was involved to a greater extent than he was. However, when the judge’s careful consideration of the facts was taken into account, it was quite clear there was no question of her having misunderstood the extent of the appellant’s involvement.
The second ground was that the judge did not distinguish sufficiently between the culpability of the two co-defendants. Hanley was a dedicated hacker who had early access to the TalkTalk “dump”, whereas the appellant was only given access to part of it. While Hanley suggested it was worth in excess of £1,000, the appellant had failed to achieve that but only something of minimal value which he did not use himself. It was submitted his culpability was less than Hanley’s and the one-third less starting point of 20 months, rather than 30 months in Hanley’s case, did not reflect their respective culpability. The Court of Appeal rejected those submissions. The judge was right to put the appellant’s offending towards the bottom end of the medium culpability category in the guideline and her starting point of 20 months, slightly above the bottom of the sentencing range, faithfully reflected that. Contrary to the views expressed by the single judge, the judge took full account of the appellant’s youth and immaturity and of the delay in sentencing. In reducing the starting point from 20 months to twelve months, then giving full one-third credit when he had not pleaded guilty until four months after the plea and case management hearing and four months before trial, the judge might be thought to have been somewhat generous. The court did not consider the sentence could be said to be excessive or that the appellant had any legitimate complaint about alleged disparity of sentence between himself and Hanley.
The final ground was that the judge erred in not suspending the sentence. Particular emphasis was placed by Mr Bell on the considerable period of delay between the plea of guilty and sentence, during which the prospect of a custodial sentence was hanging over the appellant and his family, and that since he was sentenced the appellant had been incarcerated in Belmarsh Prison for 20 weeks, which was submitted to be sufficient to reflect the seriousness of the offending. The Court of Appeal rejected those submissions. The judge took account of the delay in reducing the starting point and the issue of suspension was not related to the delay but to the seriousness of the offending. Although the appellant may not have initiated the cyber attack, he took advantage of it. It was accepted on his behalf that this was a case of greater harm within the guideline, since the offending facilitated fraudulent acts which could have affected a large number of victims. The court considered that applying the analysis in both Martin and Mudd, which the judge helpfully referred to in her sentencing remarks, only an immediate custodial sentence was appropriate.
The only amendment the Court of Appeal made to the sentences passed was that they should have been sentences of detention in a young offender institution rather than imprisonment, because at the date of his conviction on 30 March 2017 the appellant was under 21. Apart from that technical defect in the sentencing, which the court corrected, the appeal was dismissed. In short, the sentences of eight months concurrent with seven months for supplying hacked data and articles for computer misuse were upheld, albeit re-characterised as detention in a young offender institution, as only immediate custody was appropriate for cyber crime causing such harm.