Computer fraud laws can impose serious consequences when someone knowingly accesses protected systems without authorization, crosses access boundaries to obtain information, damages computers, or uses systems in furtherance of fraud. At the federal level, the Computer Fraud and Abuse Act is one of the central statutes governing unauthorized computer access.
The CFAA, codified at 18 U.S.C. § 1030, contains several offenses involving unauthorized access, obtaining information, fraud, damage, password trafficking, and related conduct. The exact elements vary by subsection, so “computer fraud” is not one single offense.
The Justice Department publishes a current CFAA charging policy for federal prosecutors. General public legal documentation can help readers encounter related legal topics, but criminal liability must be assessed under the applicable statute and facts.
A key distinction is whether someone was allowed to enter the computer or particular area of the system in the first place. DOJ policy states that federal prosecutors should focus on access a person knew was unauthorized, rather than treating every misuse of information or every website-rule violation as a CFAA crime.
That distinction often depends on technical restrictions, credentials, internal permissions, and communications defining access. Structured legal records may show how access disputes reach courts, but each authorization arrangement can be different.
| Conduct | Key Legal Question | Evidence Often Relevant |
|---|---|---|
| Using stolen credentials | Was access authorized? | Login records |
| Entering restricted files | Was that area permitted? | Access controls |
| Damaging systems | What harm was caused? | Forensic logs |
| Security testing | Was it genuinely authorized? | Scope and written permission |
The DOJ’s CFAA charging policy states that good-faith security research should not be charged when it fits the policy’s definition and is conducted to test, investigate, or correct vulnerabilities while avoiding harm. The policy also makes clear that calling harmful conduct “research” does not create automatic protection.
Teams reading marketing strategy guidance or operating public websites should still define testing permissions separately from ordinary business access. A publicly reachable system is not necessarily an invitation to bypass restrictions.
Computer-related conduct can trigger more than the CFAA. Depending on the facts, prosecutors may consider fraud, identity theft, extortion, trade-secret, or other federal and state offenses.
Intent matters. Accidentally reaching information through an ordinary feature presents a different question from knowingly using stolen credentials, defeating a restriction, or damaging systems after being told access is prohibited.
A common mistake is saying that any website terms-of-service violation is automatically federal hacking. DOJ’s current charging policy specifically rejects treating several ordinary terms-of-service violations, standing alone, as CFAA crimes.
The opposite mistake is assuming authorization is unlimited once a person has any valid account. Access to one account, folder, database, or network area does not necessarily authorize entry into every other restricted area.
Seek legal guidance promptly if law enforcement contacts you, a company alleges unauthorized access or data theft, forensic evidence is being collected, or you receive a preservation demand, subpoena, civil complaint, or criminal charging document.
Organizations should preserve logs, access-control records, employee permissions, security alerts, and relevant communications. Do not destroy or modify evidence once litigation or investigation is reasonably foreseeable.
It can lead to liability when the password is used to obtain access without authorization. The precise offense depends on what was accessed, the person’s knowledge and intent, and which federal or state statutes apply.
Not automatically. DOJ policy says ordinary terms-of-service violations alone generally should not be charged as unauthorized access under the CFAA, although other conduct may still create liability.
No. Good intentions do not automatically create authorization. Security researchers should understand the permitted scope of testing, applicable law, program rules, and whether the system owner actually authorized the activity.
Computer-fraud disputes often come down to boundaries that should have been clear before anyone logged in. Organizations should document permissions and technical restrictions, while employees, contractors, and researchers should confirm the scope of authorized access before testing or retrieving sensitive information.
This article is for general informational purposes and is not a substitute for professional legal advice.
Force majeure laws become relevant when an extraordinary event interferes with contractual performance, but disruption…
Conspiracy law can impose criminal liability before the planned offense is successfully completed. At the…
A civil complaint formally begins many lawsuits by stating who is suing, why the court…
A profitable company sale usually begins long before an owner speaks with potential buyers. A…
Customer acquisition strategies work best when they connect the right audience with a clear offer…
Putting two names on property can change far more than who is allowed to use…