Social networks are experiencing exponential growth on the web. But as social networks have grown, the phenomenon of identity theft has developed on the Internet. It has therefore become essential for internet users to know how to master their identity in the digital space. To this end, authorities have attempted to create a framework adapted to the digital reality, by participating in the creation of a crime of identity theft on the Internet.
The phenomenon of identity theft on the Internet
As new communication technologies have developed, various identity theft techniques have emerged on the Internet and constitute means of harming a person’s interests.
Identity theft techniques
The number of scams, breach of trust of others, or collection of personal data continues to increase. This is why, within the framework of protecting the identity of internet users, an arsenal of measures aimed at preventing and repressing such actions is gradually being put in place. The protection of personal identity in the digital world has become a major challenge.
Initially, no text was planned to repress the crime of identity theft or to fight against fraud techniques. The gap was not due to the lack of a definition of digital identity or the lack of incrimination of a crime of online identity theft, but due to the strict interpretation of criminal law. Identity theft was repressed in the first paragraph of Article 434-23 of the Code pénal in the terms that: “The act of taking the name of a third party, in circumstances which have determined or could have determined criminal proceedings against the latter, is punished by five years’ imprisonment and a fine of €75,000“. But in application of these provisions, the offense of identity theft did not allow the fraudster to be sanctioned when they usurped something other than the victim’s name. Then, thanks to the Internet, many identity theft techniques emerged. It therefore seemed necessary to consolidate the legal framework.
Furthermore, until now in France, identity theft was not considered a specific offense, but as a “preparatory offense in the commission of other infringements or crimes.” The consequences of identity theft were sanctioned when it placed a criminal risk on the person whose identity was stolen. The identity thief was convicted when the purpose they pursued was to directly harm the person whose identity they had stolen. In this way, the Cour de cassation ruled that stealing a person’s identity and making them say defamatory remarks towards themselves did not fall within the scope of the prevention of Article 434-23 of the Code pénal. Therefore, to be able to consider conviction, the defamatory remarks made by the stolen identity would have had to target a third person. However, no legislation allowed for fighting against fraud processes on the Internet, which is why the multiplicity and the incessant and evolving development of these new processes had to be reconsidered.
It is in this context that the Loi d’orientation et de programmation pour la performance de la sécurité intérieure (LOPPSI) bill adopted in the 1st reading on February 16, 2011 by the Assemblée nationale, attempted to remedy this state of affairs. In practice, the bill was revised as part of the LOPPSI 2 bill. Then Law No. 2011-267 of March 14, 2011, for the orientation and programming for the performance of internal security was voted. This law implements the concept of the crime of identity theft on the Internet, based on the fact that stealing a person’s identity is deliberately taking the identity of that person, generally with the intention of carrying out a fraudulent action, such as accessing that person’s finances or committing a crime or offense in their name, or even accessing rights improperly.
In the real world, if determining the components of identity poses no difficulty, it is quite different in the digital sphere. Indeed, there is no real authority involved in the allocation of identity. Nevertheless, it is possible to define its outlines in order to better frame the concept of personal identity in the digital world and more particularly in social networks.
In principle, digital identity can be composed of an email address, identifiers, and passwords, but also IP address, PIN code, avatar, URL address, and various codes. This identity is the one composed of elements chosen by the user themselves.
In reality, there is no definition of personal identity in the digital world and there is no real online identity theft. But limits have been set to reduce attacks on the identity of internet users via various effective legal measures aimed at preventing and repressing this type of action; prevention campaigns have also been developed and carried out by authorities to warn consumers about the risks that their browsing on the Internet can represent for the security of their identity. However, these campaigns are in reality insufficient. So, the use of a pseudonym is suggested to internet users to defend their identity against the risks of theft. But other users prefer to create several identities on the Internet depending on their uses, to blur the tracks and not be easily identifiable.
Although various protective measures are taken in favor of internet users, the risk of identity theft remains very present. In fact, the techniques used by internet users often present the risk of leading them, without knowing it, to steal the identity of other people or create confusion. Also, the implementation of a system for identity protection against online theft was done gradually. But faced with the innovation of fraudsters, gaps have been felt more and more and attacks on a person’s interests have multiplied.
The means of harming the interests of the person
Identity theft techniques have diversified over time and have become increasingly advanced. This is particularly the case with “phishing,” which consists of sending an email to an internet user pretending to be a company or a public authority by reproducing the logo or header characterizing the legal entity. The same applies to email, which may contain a hypertext link pointing to a web page that looks like the company’s, such as a true copy. The user is invited to click on the hypertext link to enter confidential information about them, such as password and identifier. The author of the phishing thus accesses the confidential content of the targeted person directly and easily.
In principle, phishing is based on the gullibility of the internet user who naively thinks they are revealing their information to the legal entity, to the trusted company. Until recently, phishing was used for economic interest. Subsequently, it could become a tool for industrial espionage, finally affecting the naming system of an Internet site via “pharming.” The fraudster hijacks a domain name. To perform this hijacking, pharming authors use a virus that installs itself on the user’s hard drive. Generally, the virus will be a Trojan horse, which is a “malicious software disguised behind the appearance of legitimate software designed to discreetly perform actions without the user’s knowledge.” Via this virus, the internet user will be redirected to a fake website imitating that of the company or institution when they enter the Internet address. When entering confidential information on the fake site, this information will be stolen. This technique, difficult to detect, concerns even a vigilant user; therefore, every internet user is likely to be a victim.
Regarding social networks, until now, no system exists to check the accuracy of data provided by users at the time of their registration. Consequently, network users are free not to provide their real identity and to take that of another person in order to impersonate them (username squatting). By adopting this approach, the identity thief can copy a person’s pre-existing digital identity or create a digital identity for a person who did not have one initially to steal it.
We emphasize that online identity theft can harm feelings, honor, reputation, and personality rights, generating significant harmful consequences. It can also be practiced in order to obtain a financial interest or advantage. Indeed, identity theft has extended to other considerations than a person’s name and has been fleshed out with non-negligible property interests.
Identity theft can also constitute an infringement of the Code de la propriété intellectuelle, particularly when a trademark is counterfeited (use of the name of an existing trademark on a falsely created account whose products and services are similar to those of the trademark already filed) or when there is an infringement of copyright (use of an original artist’s name protected by copyright).
Until recently, law and technology have shown themselves to be ineffective or unsuitable in the face of the constant development of these malicious practices. This is why many provisions have been adopted in favor of the offense of identity theft on the Internet.
Sources:
– O.C.D.E., Document exploratoire sur le vol d’identité en ligne, Réunion ministérielle de l’OCDE sur le futur de l’économie Internet, 2008;
– Cass. crim., 29 mars 2006, no 05-85857;
– BENSOUSSAN (A.), Informatique, Télécoms, Internet, Éditions Francis Lefebvre, Paris, 5th ed., 2012, § 2570 and seq.;
– Encyclopédie Wikipédia, article “Usurpation d’identité”;
– O.C.D.E., Online Identity Theft, March 2009, definition of digital identity;
– CORNU (G.), Vocabulaire juridique, PUF, coll. Quadrige, 9th edition, Paris, 2011;
– ITEANU (O.), L’identité numérique, Eyrolles, Paris, 2008, p. 143.


