Skip to main content

Criminal Defense · Counsel brief · 14 min · Updated 7 Sep 2026

Defending a Telecom-Fraud Case in China

Key takeaways
  1. A Fuzhou employee is detained after police dismantle an online operation accused of telecom fraud.
  2. The employee worked in customer support and used company chat groups and payment tools but says she did not know the broader scheme was fraudulent.
  3. Investigators treat the business as an organized network.
Cite this article
Article
Defending a Telecom-Fraud Case in China: Role Attribution, Electronic Evidence and the Boundary Between Knowing Assistance and Fraud
Author
Lin Ying
Last updated
7 Sep 2026
Publisher
China Legal Portal

Lin Ying. “Defending a Telecom-Fraud Case in China: Role Attribution, Electronic Evidence and the Boundary Between Knowing Assistance and Fraud.” China Legal Portal, updated 7 Sep 2026. https://chinalegalportal.com/defending-telecom-fraud-case-china-role-electronic-evidence

A Fuzhou employee is detained after police dismantle an online operation accused of telecom fraud. The employee worked in customer support and used company chat groups and payment tools but says she did not know the broader scheme was fraudulent. Investigators treat the business as an organized network. The Criminal Law governs fraud and related offenses, the Criminal Procedure Law governs investigation and defense, and national rules regulate collection and assessment of electronic data.[1][2][3] The 2016 judicial/procuratorial/public-security opinion on telecom-network fraud adds offense-specific guidance for these cases.[5] The defense has to answer three different questions: what the operation did, what this client did, and what this client knew. Group-level wrongdoing cannot replace individual proof.

The defense needs to identify the client’s title, actual tasks, supervisors, compensation, access and duration. An organizational chart created after arrest may be unreliable. Counsel needs to use employment records, chat groups, permissions, payroll and actual work product. Who designed scripts? Who controlled victim communications? Who could withdraw funds? Who trained the client? Did the client receive a fixed salary or a share of proceeds? None of these facts is conclusive alone, but together they show how the person fitted into the operation. The role map should also identify when the client joined. A late entrant may not be responsible for earlier conduct. A precise map prevents the case from treating everyone in the office as interchangeable. A short evidentiary matrix linking co-defendant statements, device attribution, and client-specific transaction data is usually more persuasive than a broad narrative. That discipline makes alternative legal positions easier to maintain without contradicting the factual record. Legal analysis is incomplete until the team identifies what concrete procedural or economic consequence the point is meant to produce. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion.

The specific problem

In China, treat defending a telecom-fraud case as a question of role attribution, electronic evidence and the boundary between knowing assistance and fraud. Naming the city does not replace the papers, approvals or forum that actually control the outcome.

The Business Impact

In China, confirm the documents, authority and local filings for this defending a telecom-fraud case matter before you pay, transfer or sue. The city name is not a substitute for the file.

Build a role map before arguing the law

Knowledge must be inferred from evidence, not job association

Fraud liability generally requires proof of the relevant subjective state as well as objective conduct. The prosecution may infer knowledge from scripts, warnings from customers, unusual payment methods, false identities or instructions to conceal activity. The defense needs to test each inference. A customer-service employee may receive complaints without understanding why the underlying product is fraudulent. Another employee may see explicit instructions showing that customers are being deceived. Messages should be read in context. Coded language can be significant, but counsel needs to avoid assuming a prosecution interpretation is the only possible meaning. Training materials, onboarding documents and ordinary product information may also illuminate what the client was told. The defense needs to identify both incriminating and exculpatory evidence so the legal argument is credible. Where accounts conflict, device attribution and client-specific transaction data provide an objective baseline, while co-defendant statements supplies context. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion. An adverse document should be analyzed directly; ignoring it usually weakens the rest of the submission. That link between proof and consequence is particularly important when several alternative arguments remain open.

Electronic data requires authenticity, integrity and attribution

The 2016 electronic-data rules define electronic evidence broadly and require attention to authenticity, legality and relevance.[3] A chat screenshot is not the same as a forensic extraction. Counsel needs to examine how data was collected, whether the device was identified, whether the account belonged to the client and whether messages are complete. Cloud synchronization can place the same information on several devices. Shared accounts create further attribution issues. Transaction logs may show an account received money without proving that the defendant controlled withdrawals or knew the source. The defense needs to build an evidence table: item, source, collection method, account or device attribution, relevant fact and objection if any. Technical questions should be connected to the legal elements rather than raised merely because the evidence is digital.

Electronic data requires authenticity, integrity and attribution should be approached as a proof problem with a defined beginning and end. Counsel can narrow the factual dispute by reconciling chat context with device attribution before turning to payment flows. An adverse document should be analyzed directly; ignoring it usually weakens the rest of the submission. A sound position should also survive the practical question of how it will be implemented the month after the decision. Where work permissions materially changes the picture, it should be addressed separately rather than folded into a global conclusion. The section then serves a concrete purpose: individualize knowledge, conduct and loss instead of importing the whole network's conduct.

Co-defendant statements need corroboration

Group cases often rely heavily on statements from other suspects. A co-defendant may say the client knew everything, while the client denies it. Counsel needs to compare those statements with messages, payment data and formal authority. If the alleged organizer gave contradictory descriptions of the client’s role at different times, that inconsistency may matter. The defense needs to avoid attacking every co-defendant as a liar. Some statements may be accurate and corroborated. The relevant question is which parts are supported by objective evidence. A structured comparison can show where several witnesses independently describe the same conduct and where allegations appear only in one self-protective statement. Corroboration analysis helps isolate the client’s actual responsibility.

Co-defendant statements need corroboration is strongest when counsel can show why a particular record matters, not merely that many records exist. payment flows establishes one part of the picture; device attribution and client-specific transaction data can confirm or challenge it. The legal team can then decide whether the remaining uncertainty warrants a court request, an expert, negotiation, or a revised position. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion. A sound position should also survive the practical question of how it will be implemented the month after the decision. In this telecom-fraud defense, the objective is to individualize knowledge, conduct and loss instead of importing the whole network's conduct.

Criminal amount should be tied to the client’s conduct

Large telecom-fraud cases may involve very high total losses. The defense needs to examine how the prosecution attributes amount to individual participants under the relevant legal framework. The client’s period of participation, role, knowledge and connection to particular transactions may all matter. Financial records should be reconciled so that duplicate victim payments, refunds or transactions outside the relevant period are not counted incorrectly. If the client worked in one business unit, the defense needs to understand whether losses from other units are being attributed and on what basis. Amount analysis can affect charge, sentencing and restitution strategy. A clear spreadsheet linked to source evidence is often more useful than arguing about one global figure.

With Criminal amount should be tied to the client’s conduct, chronology often matters more than the parties' broad descriptions of one another. The first comparison should place payment flows beside co-defendant statements; chat context then tests whether the explanation is consistent. If those sources point in different directions, the disagreement should be stated expressly rather than hidden. Where device attribution materially changes the picture, it should be addressed separately rather than folded into a global conclusion. Legal analysis is incomplete until the team identifies what concrete procedural or economic consequence the point is meant to produce. The discipline matters because the broader aim is to individualize knowledge, conduct and loss instead of importing the whole network's conduct.

Assistance offenses and fraud participation require careful characterization

Some defendants provide accounts, technology, communications or other assistance without directly making false statements to victims. The legal characterization depends on the facts, knowledge and applicable offense provisions. The defense should not assume that a peripheral role automatically means a lesser offense, but should test whether the alleged elements of fraud participation are actually proved. What did the client know about the scheme? Did the client share the fraudulent purpose? Did the client receive instructions that revealed it? Was the assistance indispensable or routine? The prosecution may change characterization as evidence develops. Counsel needs to preserve alternative arguments where appropriate: no knowledge, limited participation, different offense characterization or secondary role. Accuracy matters more than labels such as “technical staff” or “helper.” The most useful cross-check usually comes from reading payment flows together with device attribution and then testing the result against co-defendant statements. Once the sources are reconciled, counsel can separate facts that are established from those still genuinely contested. Legal analysis is incomplete until the team identifies what concrete procedural or economic consequence the point is meant to produce. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion.

Restitution and leniency need accurate role and amount first

Families may want to return money quickly. Restitution can be important, but the defense needs to know the amount reasonably attributable to the client and keep complete payment records. The 2026 national guidance on confession and acceptance of punishment emphasizes proportionality and accurate application.[4] A client considering that procedure should understand the admitted facts, charge and likely sentencing consequences. Role and amount arguments should not be surrendered merely to obtain a quick recommendation if the evidence remains disputed. Conversely, where the evidence is strong, an informed resolution can be more realistic than pursuing an unsupported complete denial. Defense advice should change as the evidentiary picture becomes clearer.

Restitution and leniency need accurate role and amount first is strongest when counsel can show why a particular record matters, not merely that many records exist. The first comparison should place payment flows beside work permissions; device attribution then tests whether the explanation is consistent. Later explanations carry more weight when they fit records created before litigation or investigation began. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion. The file should state whether the issue affects ownership, value, custody, charge, role, amount, coercive measure, or sentence. The practical payoff is a clearer route to individualize knowledge, conduct and loss instead of importing the whole network's conduct.

Device ownership and account control should be mapped separately

A phone, SIM card, social-media account and payment account may all have different formal owners. The prosecution may infer that one person controlled them because they were seized together. The defense needs to verify registration, passwords, login history and actual use. Company phones are often shared during shifts. Workstations may have saved credentials. These facts can create reasonable attribution questions. At the same time, a client cannot defeat evidence merely by showing the account was registered to someone else if messages and usage patterns clearly identify the client. The defense map should therefore list each device and account with formal owner, actual user, access period and evidence of control. This is particularly useful in telecom-fraud cases where hundreds of accounts can be linked to one office. Clear attribution can narrow both the conduct alleged and the financial amount associated with the client. A short evidentiary matrix linking chat context, client-specific transaction data, and co-defendant statements is usually more persuasive than a broad narrative. Missing material should be identified as a gap, not replaced with an assumption favorable to either side. Where device attribution materially changes the picture, it should be addressed separately rather than folded into a global conclusion. That link between proof and consequence is particularly important when several alternative arguments remain open.

Scripts and training materials can reveal the knowledge environment

Customer-facing scripts are important because they show what employees were instructed to say. Counsel needs to compare official training documents with actual chat practices. A script containing explicit false statements may make knowledge easier to infer for employees who used it repeatedly. A neutral customer-service script may support a different analysis. Training recordings or onboarding messages can show whether supervisors disclosed the true business model. The defense needs to also identify changes over time. A company may begin with lawful marketing and later introduce deceptive practices. An employee who left before that change may be differently situated from one who continued afterward. Conversely, a client who helped rewrite deceptive scripts may have a more significant role than job title suggests. Training evidence therefore connects organization-level conduct to individual knowledge more directly than general allegations about company culture. Instead of starting with conclusions, the file can align co-defendant statements, device attribution, and work permissions on the same timeline. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion. Once the sources are reconciled, counsel can separate facts that are established from those still genuinely contested. The file should state whether the issue affects ownership, value, custody, charge, role, amount, coercive measure, or sentence.

Victim records should be reconciled with communication evidence

A large case can include victim statements that describe different salespeople and promises. The defense needs to match each identified victim to chat accounts, calls, payment records and the client’s work schedule. Some transactions may have no connection to the client despite occurring in the same company. Other victims may identify the client specifically. A transaction matrix helps prevent aggregate allegations from obscuring individual proof. It can also identify inconsistent dates or duplicate losses. Counsel needs to treat victim statements respectfully and avoid unnecessary contact. The purpose is evidentiary reconciliation, not pressure. Where a victim’s communication record is incomplete, the defense can seek the full context through appropriate procedure. This work often becomes central to both role and amount arguments. Where accounts conflict, client-specific transaction data and work permissions provide an objective baseline, while co-defendant statements supplies context. The legal team can then decide whether the remaining uncertainty warrants a court request, an expert, negotiation, or a revised position. Where device attribution materially changes the picture, it should be addressed separately rather than folded into a global conclusion. That link between proof and consequence is particularly important when several alternative arguments remain open.

Sentencing mitigation should be built from verifiable facts

If the evidence ultimately supports liability, counsel needs to transition from liability analysis to mitigation without abandoning accuracy. Relevant facts may include secondary role, short duration, limited profit, restitution, victim forgiveness and voluntary cooperation, subject to the legal framework. Employment and family circumstances can be included where relevant but should not dominate the submission. The defense can also show steps taken to prevent recurrence, such as surrendering illegal proceeds or assisting in asset recovery, where lawful and supported. The 2026 leniency guidance emphasizes proportionality, so the submission should connect mitigation to the specific offense and harm. A credible mitigation file acknowledges proven misconduct while explaining why the individual’s culpability differs from organizers. This is more persuasive than a generic collection of character letters.

For Sentencing mitigation should be built from verifiable facts, the most revealing material is often ordinary contemporaneous paperwork rather than later advocacy. Three sources deserve priority: co-defendant statements, device attribution, and payment flows. Contradictions are useful because they show exactly where further evidence or expert work is justified. Where chat context materially changes the picture, it should be addressed separately rather than folded into a global conclusion. The next question is implementation: what order, payment, parenting term, charging position, or evidentiary ruling would follow if the point is accepted? This keeps the analysis directed toward one outcome: individualize knowledge, conduct and loss instead of importing the whole network's conduct.

Case study: customer-support employee

Assume the client worked for six months in a 40-person operation. She used a customer-service account and knew customers were being told that an investment product was guaranteed. She received a fixed salary and had no access to company bank accounts. Some messages show her asking supervisors whether customer complaints were legitimate. A strong defense would not argue that she “only answered messages.” It would analyze whether the scripts and complaints proved knowledge, how her communications affected victims and whether she shared the organizers’ purpose. Electronic-data attribution and the client’s limited financial role would be tested separately. The final position might be no fraud participation, a different legal characterization, or a secondary role depending on the full record.

Suppose forensic review also shows that the employee used a shared customer-service account and that several incriminating messages were sent during shifts when she was not working. Other messages from her own device, however, show that she understood customers were being given false guarantees. The defense would then have a mixed record: attribution weakens part of the prosecution case, but knowledge may still be proved through separate evidence. The correct response is not to demand exclusion of the entire digital record. It is to identify which messages can reliably be attributed, what they show about knowledge, and whether her conduct satisfies fraud participation or a narrower form of criminal assistance under the applicable law.[1][2][3] A victim-by-victim transaction table can then test whether losses attributed to the wider network are actually connected to her period and communications.

Conclusion

Telecom-fraud defense requires individualization. The existence of a criminal network does not answer what a particular employee knew, did or caused. The Criminal Procedure Law and electronic-data rules give counsel tools to test collection and attribution, while substantive criminal law determines whether the client’s knowledge and participation satisfy the charged offense.[1][2][3] The strongest defense builds a role map, tests digital evidence, reconciles amount and keeps any leniency decision tied to accurate facts.

[1] Criminal Law of the People’s Republic of China — [official legislative portal](https://flk.npc.gov.cn/) [2] Criminal Procedure Law of the People’s Republic of China — [official source](https://www.npc.gov.cn/c2/c12435/201905/t20190521_276591.html) [3] Supreme People’s Court, Supreme People’s Procuratorate and Ministry of Public Security, Provisions on Collection, Extraction and Review of Electronic Data in Criminal Cases — [official source](https://www.court.gov.cn/fabu/xiangqing/26431.html) [4] Five Authorities, Guiding Opinions on Leniency for Confession and Acceptance of Punishment (2026) — [official source](https://www.spp.gov.cn/xwfbh/wsfbt/202607/t20260717_732076.shtml) [5] Supreme People’s Court, Supreme People’s Procuratorate and Ministry of Public Security, Opinion on Several Issues Concerning the Application of Law in Handling Criminal Cases of Telecom and Network Fraud — [official source](https://gongbao.court.gov.cn/Details/32a0db4cedc11baf82bca07681fa0e.html)

General legal information only; not legal advice for a specific telecom-fraud case.

READER DISCUSSION

Discussion

Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.

Have a question after reading? Leave it here, or Ask a Lawyer for a free initial intake.

Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.

End of brief

Lin Ying, Criminal Defense lawyer

Author

Lin Ying

Fujian Zhongyin Law Firm (Fuzhou) · Criminal Defense

Fujian Zhongyin Law Firm (Fuzhou) · Verified listing. This insight is educational and does not create an attorney–client relationship.

View lawyer profile

Criminal Defense

Need a next step?

Take a focused intake, or browse listed criminal defense practitioners.

Submit an initial enquiry Find listed counsel

In the library

Go deeper on this topic

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

Disclaimer Editorial policy AI content policy