endangering cybersecurity are caused, a fine of no less than CNY100,000 but no more than CNY1 million shall be imposed; as for the persons directly in charge, a fine of no less than CNY10,000 but no more than CNY100,000 shall be imposed. Article 60 Where any person conducts any of the following acts in violation of Paragraph 1 and Paragraph 2 of Article 22, Paragraph 1 of Article 48 hereof, he shall be ordered to effect rectification and be warned by the relevant competent departments; where he refuses to effect rectification or such consequences as endangering cybersecurity are caused, a fine of no less than CNY50,000 but no more than CNY500,000 shall be imposed; as for the persons directly in charge, a fine of no less than CNY10,000 but no more than CNY100,000 shall be imposed, 1. Installing malwares; 2. Failing to take remedial measures immediately against risks, such as security defects and bugs of their products or services; or failing to promptly inform users of such risks and reporting the same to the relevant competent departments in accordance with the relevant provisions; or 3. Arbitrarily terminating the provision of security maintenance for their products and services. Article 61 Network operators who in violation of Paragraph 1 of Article 24 hereof, fail to request users to provide authentic identity information, or provide services for those failing to provide authentic identity information, shall be ordered to effect rectification by the relevant competent departments; where they refuse to effect rectification or if the circumstances are serious, a fine of no less than CNY50,000 but no more than CNY500,000 shall be imposed, and the relevant competent departments may order them to suspend operation, stop doing business for internal rectification, close down the website, or may revoke relevant business permits or their business licenses; and a fine of no less than CNY10,000 but no more than CNY100,000 shall be imposed on the persons directly in charge and other directly responsible persons. Article 62 Anyone that carries out cybersecurity authentication, detection, risk evaluation and other activities or released system bugs, computer viruses, network attacks and intrusions and other cybersecurity information to the public in violation of Article 26 hereof, shall be ordered by the relevant competent departments to make rectification; where they refuse to make rectification or if the circumstances are serious, a fine of between CNY10,000 and CNY100,000 shall be imposed, and the relevant competent departments may order them to suspend the relevant operation, suspend business for internal rectification, close down the website, or may revoke the relevant business permits or their business licenses; and a fine of between CNY5,000 and CNY50,000 shall be imposed on any directly liable manager or any other directly liable person. Article 63 Where, in violation of Article 27 hereof, anyone is engaged in activities endangering cybersecurity, provides programs or tools specifically used for conducting activities endangering cybersecurity, or provides technical support, advertising promotion, payment and settlement support or other kinds of assistance to others for conducting activities endangering cybersecurity, if such activities do not constitute a crime, public security organs shall confiscate their illegal gains, enforce detention of up to five days and may, in addition, impose a fine of between CNY50,000 and CNY500,000, and if the circumstances are serious, the period of detention shall be no less than 5 days but no more than 15 days and, in addition, the fine imposed may be no less than CNY100,000 but no more than CNY1,000,000. Where an entity commits any of the violations stipulated in the preceding paragraph, public security organs shall confiscate its illegal gains, impose a fine of no less than CNY100,000 but no more than CNY1,000,000, and punish the persons directly in charge and the other directly responsible persons in accordance with the provisions of the preceding paragraph. Any person who violates Article 27 hereof shall be forbidden from practicing cybersecurity management and taking key positions in the field of network operation either within five years if he or she is subject to public security punishment or for life if he or she is subject to criminal punishment. 10

Select target paragraph3