Contact Us for an Immediate Consultation (818) 781-1570

Computer Hacking

Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030

The Computer Fraud and Abuse Act (CFAA), codified as 18 U.S.C. § 1030, is the primary federal cybercrime statute used to prosecute computer-related offenses

Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030

Enacted in 1986 and periodically amended to address evolving digital threats, the CFAA criminalizes unauthorized access to computers, data theft, system sabotage, password trafficking, and cyber-extortion.

Understanding its legal thresholds, statutory language, potential penalties, and legal defenses is essential for anyone facing federal cybercrime investigations.

Statutory Text (18 U.S.C. § 1030(a)(1))

Whoever, having knowingly accessed a computer without authorization or exceeding authorized access, and using such conduct having obtained information that has been determined by the United States Government pursuant to Executive order or statute to require protection against unauthorized disclosure for reasons of national defense or foreign relations, or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with reason to believe that such information so obtained could be used to the injury of the United States or the advantage of any foreign nation willfully communicates, delivers, transmits, or causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it, or willfully retains the same and fails to deliver it to the officer or employee of the United States entitled to receive it... shall be punished as provided in subsection (c) of this section. 

Key Statutory Definitions

These statutory definitions establish the precise legal boundaries between lawful computer use and federal criminal liability, determining whether federal prosecutors can assert jurisdiction and secure a conviction.

  • Without Authorization: Accessing a computer system, server, or network without any permission, right, or clearance to do so (often referred to as external hacking or breaking past security barriers).

  • Exceeding Authorized Access: Accessing a computer with permission, but using that access to obtain or alter information in the computer system that the user is not entitled to obtain or alter under 18 U.S.C. § 1030(e)(6).

  • Protected Computer: Under 18 U.S.C. § 1030(e)(2), a "protected computer" refers to any computer exclusively for the use of a financial institution or the U.S. government, or any computer used in or affecting interstate or foreign commerce or communication (including systems used in elections and voting infrastructure).

Major Offenses Under 18 U.S.C. § 1030

The CFAA encompasses several specific federal computer offenses, ranging from minor unauthorized access to high-level espionage and extortion:

  • Obtaining National Security Information (18 U.S.C. § 1030(a)(1)): Accessing a protected system to obtain classified defense, foreign relations, or nuclear data with intent or reason to believe it could harm the United States.

  • Unauthorized Access / Theft of Information (18 U.S.C. § 1030(a)(2)): Intentionally accessing a computer without authorization or exceeding authorization to obtain financial records, government data, or information from any protected computer.

  • Trespassing in a Government Computer (18 U.S.C. § 1030(a)(3)): Non-public access to computers used by or for the United States government without permission.

  • Accessing to Defraud and Obtain Value (18 U.S.C. § 1030(a)(4)): Accessing a protected computer with intent to defraud and obtaining anything of value worth more than $5,000 in a one-year period.

  • Intentionally Damaging a Protected Computer (18 U.S.C. § 1030(a)(5)(A)): Knowingly causing the transmission of a program, information, code, or command (e.g., malware, ransomware, or DDoS attacks) that intentionally causes damage without authorization.

  • Reckless or Negligent Damage (18 U.S.C. § 1030(a)(5)(B)-(C)): Intentionally accessing a protected computer and recklessly or negligently causing damage or loss.

  • Trafficking in Passwords (18 U.S.C. § 1030(a)(6)): Knowingly trafficking in passwords or similar access credentials affecting a government system or interstate commerce.

  • Cyber-Extortion (18 U.S.C. § 1030(a)(7)): Transmitting threats to damage a protected computer, steal data, or publicly release confidential information in exchange for money or consideration.

What Must Be Proven to Convict

To secure a federal conviction under 18 U.S.C. § 1030, federal prosecutors must establish each required statutory element beyond a reasonable doubt:

  1. Access to a Protected Computer: The defendant accessed a system meeting the statutory definition of a "protected computer" (e.g., connected to the internet or belonging to a bank/government agency).

  2. Lack of Authorization: The defendant acted without authorization or intentionally exceeded authorized access granted to them.

  3. Requisite Mental State (Mens Rea): The defendant acted knowingly, intentionally, or willfully, depending on the specific subsection charged. Unintentional errors or accidental system access do not satisfy this standard.

  4. Statutory Harm, Loss, or Value: For felony-level offenses, prosecutors must prove a minimum financial loss (typically $5,000 or more over a 1-year period), intent to commit another crime, or obtaining value/classified information.

Statutory Penalties for CFAA Violations

Penalties under the CFAA vary significantly depending on the nature of the violation, prior criminal history, and whether aggravating factors are present.

Violation Type

Potential Federal Imprisonment

Simple Unauthorized Access / Password Trafficking Up to 1 year in federal prison
Access to Defraud / Cyber-Extortion Up to 5 years in federal prison
Intentional Damage (Malware/Ransomware) 1 to 10 years in federal prison
Obtaining Classified National Security Data Up to 10 years in federal prison
Repeat / Subsequent Offenses Sentences generally double (up to 10–20 years)
Aggravated Offense (Causing Serious Bodily Injury) Up to 20 years in federal prison
Aggravated Offense (Causing Death) Up to Life imprisonment

Defense Strategies in CFAA Prosecutions

  • Authorization & Scope of Access: Establishing that the defendant had express permission, implied authorization, or a good-faith belief that their actions fell within authorized boundaries (e.g., authorized security penetration testing or IT consulting).

  • Lack of Intent / Accidental Access: Demonstrating that system access, data transfers, or network disruptions resulted from honest technical errors, software bugs, or accidental user actions rather than intentional hacking.

  • Misidentification / Third-Party Intrusion: Showing that the unauthorized access was carried out by another party using a spoofed IP address, compromised credentials, or malware on the defendant's hardware.

  • Challenging Loss Calculations: Contesting government claims regarding financial harm or repair costs to reduce felony counts down to misdemeanor levels or defeat loss-based sentencing enhancements.

  • Challenging Expert Testimony (Daubert Motions): Filing pre-trial motions under Federal Rule of Evidence 702 to challenge the scientific validity and methodology of government forensic experts and digital evidence.

Related Laws & Statutes

Understanding these statutes is critical because they establish the specific legal boundaries, jurisdiction, and potential criminal or civil penalties governing the case.

Hypothetical Examples

  • Exceeding Authorization: An employee uses their valid corporate credentials to download confidential trade secrets from a restricted server to sell to a competitor before resigning.

  • Ransomware & System Sabotage: An outside hacker deploys malicious software to encrypt a hospital system's database and demands payment to restore access.

  • Credential Trafficking: A former system administrator posts active login credentials and administrative passwords for a government portal onto an online forum.

Frequently Asked Questions

What is the difference between accessing a computer without authorization and exceeding authorized access?

Accessing without authorization means entering a computer system without any right or permission (similar to digital trespassing). Exceeding authorized access occurs when an individual has legitimate permission to access certain areas of a computer system but accesses restricted files or databases outside their designated clearance.

Can an employee be charged under the CFAA for violating a company's computer usage policy?

In Van Buren v. United States, the U.S. Supreme Court ruled that an individual does not "exceed authorized access" under the CFAA simply by accessing information on a computer for an improper purpose if they were otherwise authorized to retrieve that information. A simple breach of terms of service or workplace policies, without exceeding actual technical authorization boundaries, generally does not trigger criminal CFAA liability.

What qualifies as a "protected computer" under 18 U.S.C. § 1030?

A protected computer includes any computer used exclusively by a financial institution or the U.S. government, as well as any computer connected to the internet or used in interstate or foreign commerce. Virtually all modern laptops, servers, smartphones, and connected devices qualify.

Are ethical hackers or penetration testers protected from CFAA prosecution?

Ethical hackers and penetration testers operating within a clearly defined, authorized Scope of Work (SOW) are protected because they have explicit consent. However, exceeding agreed testing parameters, accessing unauthorized servers, or retaining client data without consent can lead to criminal charges under the CFAA.

How does the government calculate financial loss in a CFAA case?

Under 18 U.S.C. § 1030(e)(11), "loss" includes any reasonable cost to a victim, such as responding to an offense, conducting damage assessments, restoring data, or lost revenue caused by system interruption. Proving aggregate losses over $5,000 within a one-year period allows prosecutors to elevate misdemeanor offenses to federal felonies.

Can a CFAA violation result in civil lawsuits in addition to criminal charges?

Yes. Under 18 U.S.C. § 1030(g), any person or entity that suffers damage or loss from a CFAA violation can file a private civil lawsuit in federal court to seek compensatory damages, injunctive relief, or other equitable remedies.

For the best chance at a positive outcome, contact an experienced federal criminal defense attorney at Eisner Gorin LLP. To schedule a consultation, call (818) 781-1570 or fill out the contact form.

Related Content

Contact Us Today

Eisner Gorin LLP is committed to answering your questions about Criminal Defense law issues in Los Angeles, California.

We'll gladly discuss your case with you at your convenience. Contact us today to schedule an appointment.

Make A Payment | LawPay

Menu