18 U.S.C. § 1030(a)(4) is a federal felony statute under the Computer Fraud and Abuse Act (CFAA) that prohibits accessing a protected computer without authorization—or exceeding authorized access—with the intent to defraud and obtain something of value.
Often prosecuted alongside trade secret theft and wire fraud, this statute is the federal government's primary weapon against current and former employees, executives, and contractors accused of corporate data theft and digital espionage.
What Does 18 U.S.C. § 1030(a)(4) Prohibit?
Section 1030(a)(4) is part of the Computer Fraud and Abuse Act (CFAA). Unlike some CFAA provisions, subsection (a)(4) is not simply an unauthorized-access statute.
The government must prove the required mental state, the unauthorized access or excess of authorized access, the connection between that conduct and the intended fraud, and the obtaining of something of value.
The statute contains a limited $5,000 exception when the object of the fraud and the thing obtained consist only of computer use during a one-year period.
For a person accused after leaving a company, the distinction between authorized access and unauthorized access can determine whether the alleged conduct falls within § 1030(a)(4).
What Must Federal Prosecutors Prove?
A § 1030(a)(4) prosecution requires proof beyond a reasonable doubt that the defendant
- Knowingly accessed a protected computer without authorization or exceeded authorized access
- Acted with intent to defraud
- Furthered the intended fraud through that computer conduct
- Obtained something of value
A protected computer is broadly defined to include computers used in or affecting interstate or foreign commerce or communication.
That definition reaches most modern business systems, cloud platforms, corporate networks, and internet-connected devices. The intent-to-defraud requirement also matters.
Prosecutors must connect the alleged computer access to a fraudulent purpose and show that the computer conduct furthered that intended fraud.
How Does Authorized Access Affect a Former Employee Case?
Authorization is one of the most important issues in a § 1030(a)(4) prosecution involving a current or former employee. The statute covers two different forms of prohibited access:
- Accessing a protected computer “without authorization” and
- Accessing a computer with authorization but exceeding the scope of that authorization.
The statute defines “exceeds authorized access” as accessing a computer with authorization and using that access to obtain or alter information that the person is not entitled to obtain or alter.
For a former employee, the timing and scope of the person's computer permissions can therefore become central to the case.
If an employer has terminated an employee's access to a corporate system and the employee subsequently uses credentials, circumvents controls, or otherwise gains entry without permission, prosecutors may characterize that conduct as access without authorization.
The analysis is different when an employee still has legitimate credentials and permission to access the relevant system or information but allegedly uses that information for an improper purpose.
A company's internal policies, confidentiality agreements, or employment restrictions may prohibit particular uses of information, but those restrictions do not automatically establish that the underlying computer access was unauthorized under § 1030.
That distinction matters in corporate data investigations. An executive may have been permitted to access customer databases, source code, financial records, or other confidential files as part of the person's job.
If prosecutors later allege that the executive downloaded those files to prepare to join a competitor or start a competing business, the government still must establish the statutory requirements for § 1030(a)(4).
The employer's view that the subsequent use was improper does not, standing alone, establish that the defendant accessed the computer without authorization or exceeded authorized access.
The question can become more difficult when access permissions changed during an employee's departure. Investigators may examine:
- When the employee was placed on administrative leave,
- When credentials were disabled,
- Which systems remained accessible,
- Whether particular files had restricted permissions, and
- Whether the employee used another person's credentials after access was revoked.
Those details can distinguish authorized access from access that exceeded the permissions actually granted.
Is the $5,000 Requirement a Threshold for Every § 1030(a)(4) Case?
No. The statute does not require the thing obtained to be worth more than $5,000 in every prosecution.
Instead, it excludes conduct where the object of the fraud and the thing obtained consist only of computer use and the value of that use is not more than $5,000 during any one-year period.
The first-offense maximum under § 1030(a)(4) is five years regardless of whether the allegedly obtained property itself exceeds $5,000.
Value can still become important when prosecutors characterize the alleged benefit or economic objective. The charging theory should be examined closely rather than assuming that a corporate data set has a particular dollar value because the company assigns one to it.
Related Federal Laws
Understanding related federal statutes is critical because prosecutors frequently pair Computer Fraud and Abuse Act (CFAA) charges with broader mail, wire, and IP theft offenses to stack potential prison sentences and expand their evidentiary theories.
-
18 U.S.C. § 1343 – Wire Fraud: Wire fraud is commonly charged alongside computer fraud whenever interstate electronic communications or network transmissions are used to execute the underlying scheme.
-
18 U.S.C. § 1832 – Theft of Trade Secrets: This statute applies when the confidential data allegedly accessed or downloaded without authorization constitutes proprietary commercial trade secrets intended for economic benefit.
-
18 U.S.C. § 1030(a)(2) – Unauthorized Access to Obtain Information: Prosecutors often charge this misdemeanor or felony CFAA subsection as an alternative to § 1030(a)(4) when they can prove unauthorized access to data but lack clear evidence of intent to defraud.
-
18 U.S.C. § 1028A – Aggravated Identity Theft: This charge carries a mandatory consecutive two-year prison sentence if an employee or actor uses another individual's credentials or personal identification to gain unauthorized system entry.
-
18 U.S.C. § 2314 – Interstate Transportation of Stolen Property: Federal authorities use this law when corporate property, trade secrets, or stolen assets valued at $5,000 or more are moved across state lines or transferred via network connections.
Frequently Asked Questions (FAQs)
Reviewing common questions regarding federal computer fraud provides vital clarity on how prosecutors distinguish between internal employment disputes and severe federal felonies.
What is the main difference between simple unauthorized access and 18 U.S.C. § 1030(a)(4)?
Simple unauthorized access under other provisions of the CFAA only requires obtaining information without permission, whereas § 1030(a)(4) requires prosecutors to prove a specific intent to defraud and that the computer access directly furthered that fraudulent scheme.
Can an employer sue or prosecute an employee under § 1030(a)(4) for violating a company network policy?
No, internal company policy violations or breach of employment contracts alone do not establish a federal crime under § 1030(a)(4) if the employee maintained actual technical permission to access those files at the time of entry.
Does the $5,000 threshold apply to every 18 U.S.C. § 1030(a)(4) prosecution?
No, the $5,000 threshold applies only as a narrow statutory exception when the sole object of the fraud and the thing obtained consist exclusively of computer time or usage over a one-year period.
How do prosecutors prove "exceeding authorized access" for a current employee?
Prosecutors must show that an individual had valid permission to access certain areas of a computer system, but used that access to obtain or alter specific information they were explicitly restricted from accessing.
What happens if an employee downloads company files right before resigning?
If the employee still had valid system credentials and authorization when they downloaded the files, the conduct may violate non-compete or confidentiality agreements, but it does not automatically constitute unauthorized access under federal criminal law.
Can using a coworker's login credentials result in federal computer fraud charges?
Yes, using another employee's credentials—especially after your own access has been revoked or restricted—is routinely characterized by federal prosecutors as accessing a protected computer without authorization.
What Defense Strategies Apply to 18 U.S.C. § 1030(a)(4)?
A defense to federal computer fraud should address the precise conduct alleged, the permissions that existed at the relevant time, and the evidence prosecutors intend to use to establish intent and attribution. Depending on the facts, important issues may include:
- Whether the defendant was authorized to access the computer or particular files
- Whether access occurred before or after credentials were revoked
- Whether prosecutors are treating an internal use restriction as an access restriction
- Whether the evidence establishes an intent to defraud rather than merely copying or possessing information
- Whether the computer conduct actually furthered the alleged fraud
- Whether the item allegedly obtained qualifies as something of value
- Whether forensic evidence reliably establishes who accessed, downloaded, transferred, or deleted files
- Whether shared credentials, administrator privileges, remote access, or automated processes complicate attribution
Digital evidence can appear precise while still requiring interpretation. A login timestamp does not necessarily show who was at the keyboard, and an IP address does not, by itself, identify the person behind the screen. Examine cloud logs, endpoint records, file metadata, and forensic images in context.
Hypothetical Case Study: Former Technology Executive Accused of Stealing Proprietary Data
A former chief technology officer of a publicly traded software company is indicted after the company discovers that approximately 40 gigabytes of source code, customer records, pricing models, product roadmaps, internal financial projections, and technical documentation were downloaded during the executive's final six weeks with the company.
Prosecutors allege that the executive was preparing to launch a competing software company and intended to use the information to:
- Obtain financing,
- Recruit several of the company's largest customers, and
- Accelerate development of a competing product.
The indictment alleges violations of 18 U.S.C. § 1030(a)(4), wire fraud under 18 U.S.C. § 1343, and trade secret theft under 18 U.S.C. § 1832.
The government's evidence initially appears substantial. Security logs show that the executive's account accessed the source-code repository repeatedly between midnight and 4:00 a.m. on several occasions. A forensic image shows that thousands of files were copied to an encrypted external drive.
Investigators also obtained emails in which the executive discussed forming a new company and identified several existing customers as potential clients.
One company witness claims the executive was told that the information was “strictly confidential” and could not be used outside the company.
Case Examination by Eisner Gorin LLP
Our attorneys at Eisner Gorin LLP would examine the authorization question at a much more granular level. The executive remained employed when most of the downloads occurred, and the company's access-control system continued to give the executive full credentials to the source-code repository.
The company had a written policy prohibiting employees from using confidential information for a competing business, but the repository did not contain separate technical restrictions preventing the executive from opening or downloading the files.
A prohibition against using information for a competing purpose is not necessarily the same as a restriction on access to that information. The timeline would also become central to the case.
If the company revoked the executive's credentials on a particular date, our attorneys would separate all alleged computer activity occurring before and after that revocation.
Post-revocation access could raise a substantially different CFAA issue, particularly if the executive used another employee's credentials or bypassed technical controls. The forensic evidence would also be tested to determine:
- Whether the executive personally performed each alleged download,
- Whether administrator or shared credentials were involved, and
- Whether automated synchronization or backup processes accounted for some of the activity.
The alleged fraudulent purpose would require separate analysis. Plans to compete with a former employer, possession of confidential information, and discussions with potential investors may provide prosecutors with circumstantial evidence.
But § 1030(a)(4) requires the government to prove that the defendant knowingly accessed the protected computer without authorization or exceeded authorized access with intent to defraud, that the access furthered the intended fraud, and that the defendant obtained something of value. Ultimately, the government cannot do that.
The criminal defense attorneys at Eisner Gorin LLP can help you. Schedule your consultation by calling (818) 781-1570 or using the contact form. Our law firm is based in Los Angeles.
