Under 18 U.S.C. 2701, unlawful access to stored communications is a federal crime that reaches anyone who intentionally breaks into a system holding electronic messages without permission, or who has some permission but goes beyond it. A basic violation carries up to one year in prison; a violation committed for commercial gain, malicious destruction, or to further another crime carries up to five years, rising to ten for repeat offenders. Victims can also sue in federal court, with a statutory damages floor of $1,000.
The statute is the criminal core of the Stored Communications Act, which shields emails, text messages, voicemails, and other digital content held by service providers from unauthorized intrusion.
What Section 2701 Prohibits
The statute reaches three distinct types of conduct. First, intentionally accessing a facility that provides electronic communication service without any authorization at all. Second, having some legitimate access but intentionally going beyond it. Third, altering stored communications or preventing an authorized user from reaching them. In every case, the communication must be in “electronic storage” when the violation occurs.
The first category is the most familiar: hacking into a provider’s servers, logging in with stolen credentials, or exploiting a vulnerability to read messages you were never permitted to see. Courts have found that even using a password someone once shared with you, after that person revoked permission, can qualify as unauthorized access.
The second category generates more litigation. An IT administrator who has system-wide access to a company’s email server but reads an executive’s private messages out of curiosity is not “authorized” to view those specific communications, even though nothing technical stopped them. The boundary turns on what the person was permitted to do, not what the system physically allowed.
The third category covers interference short of reading. Deleting a coworker’s archived emails to bury evidence, altering stored messages, or locking someone out of their own account can all trigger liability if the conduct blocks authorized access to a stored communication.
What Counts as Electronic Storage
The entire statute hinges on whether the communication was in “electronic storage” when accessed. Federal law defines the term with two prongs: temporary or intermediate storage of a communication while it is being transmitted, and storage by an electronic communication service for backup protection.1Office of the Law Revision Counsel. 18 USC 2510 – Definitions An email sitting on a provider’s server waiting for you to download it fits the first prong. The harder question is what happens after you open it.
Federal courts are split. The Ninth Circuit held in Theofel v. Farey-Jones that emails received, read, and left on the server remained stored “for purposes of backup protection” and stayed within the statute’s reach.2FindLaw. Theofel v Farey-Jones Other courts have disagreed, reasoning that once an email reaches its recipient and is read, the only copy left on the server is not really a backup of anything because there is no primary copy stored elsewhere. Under that view, opened emails in a webmail inbox are not protected by Section 2701 at all.
The split matters. In a jurisdiction following the narrower reading, someone who reads your old webmail messages may face no SCA liability, though other laws could still apply. In a jurisdiction following the Ninth Circuit’s view, those same messages remain covered. Whether a communication is in electronic storage is often the first question courts resolve, and the answer can decide the case.
When Access Exceeds Authorization
The Supreme Court’s 2021 decision in Van Buren v. United States reshaped how courts read the “exceeds authorized access” language in federal computer-crime law. Although the case involved the Computer Fraud and Abuse Act, lower courts have applied the framework more broadly. The Court held that a person exceeds authorized access by reaching areas of a system that are off-limits, not by using permitted access for an improper purpose.3Supreme Court of the United States. Van Buren v United States
The Court described this as a “gates-up-or-down” inquiry: either the gate to a particular file, folder, or database is up (you can access it) or down (you cannot). If the gate is up, using the information for an unapproved reason does not trigger federal criminal liability, even if the conduct violates a company policy or an employment agreement. Only reaching areas where the gate is down counts as exceeding authorization.
Applied to Section 2701, this means an employee with legitimate access to a shared email system probably does not violate the statute by opening folders they are technically able to open, even if company policy says otherwise. But an employee who bypasses a password-protected mailbox they have no credentials for is entering a system where the gate is clearly down. Employers who want internal communications protected should rely on technical access controls, not policy documents alone.
Criminal Penalties
The statute has two penalty tiers, and both include a repeat-offense enhancement.4Office of the Law Revision Counsel. 18 USC 2701 – Unlawful Access to Stored Communications
A basic violation with no aggravating purpose carries a fine and up to one year in prison for a first offense. A second or subsequent basic offense carries up to five years.
When the offense is committed for commercial advantage, private financial gain, malicious destruction, or to further another crime, the ceiling rises. A first aggravated offense carries up to five years. A repeat aggravated offense carries up to ten. Prosecutors do not need to prove the defendant actually profited; acting with a commercial purpose is enough, even if the scheme failed.
The aggravating purposes reach further than most people expect:
- Commercial advantage or private gain covers corporate espionage, stealing trade secrets from a competitor’s email, or an employee harvesting customer lists before moving to a rival.
- Malicious destruction covers deleting or corrupting stored communications to cause harm, even without any financial motive.
- Furthering another crime pulls in the enhanced range whenever unauthorized access is a stepping stone to fraud, identity theft, stalking, or any other offense.
Federal sentencing guidelines add further considerations on top of these statutory maximums, including the volume of data accessed, the financial harm inflicted, whether the target was a government system, and the defendant’s criminal history. Access to government-stored communications can also trigger separate charges under other statutes.
Civil Lawsuits Under Section 2707
Any service provider, subscriber, or other person harmed by an SCA violation can sue the violator, as long as the violator acted knowingly or intentionally. The statute bars civil suits against the United States itself, though individual government employees are not immune.5Office of the Law Revision Counsel. 18 USC 2707 – Civil Action
Available remedies include actual damages plus any profits the violator earned from the violation, a statutory minimum of $1,000 per person entitled to recover, punitive damages when the conduct was willful or intentional, reasonable attorney’s fees and litigation costs, and equitable relief such as injunctions.
The $1,000 floor is a per-person figure, not per message or per access. That distinction matters when a single act of unauthorized access exposes communications belonging to multiple users.
Civil suits are not limited to corporate disputes or hacking. Courts have applied liability in domestic situations where one spouse accessed the other’s stored email or messaging accounts during a separation. The statute does not care about the relationship between the parties. If the access was unauthorized, knowing, and directed at communications in electronic storage, a remedy is available.
Statute of Limitations
A civil claim must be filed within two years of the date the claimant first discovered the violation or had a reasonable opportunity to discover it. The clock starts on discovery, not on the intrusion itself, which matters because unauthorized access often goes undetected for months.
Exceptions and Defenses
The statute carves out three categories of conduct that do not violate the prohibition, plus a separate good-faith defense that can defeat both criminal and civil liability.
Service Provider Access
A provider of wire or electronic communication service can authorize access to communications stored on its own systems. This allows providers to perform maintenance, investigate abuse, enforce terms of service, and protect their infrastructure. Courts have upheld provider access to user emails for fraud detection and policy enforcement, so long as the conduct fits the provider’s legitimate operational needs and is not carried out for an improper purpose.
User Consent
The statute does not apply when a user authorizes access to their own communications or to communications intended for them. If you give someone your login credentials and tell them to check your email, their access is authorized. The exception is narrower than it looks, though: it only covers communications “of or intended for” that user. Permission to see your own messages on a shared system does not extend to browsing other people’s.
Lawful Government Process
Access authorized under 18 U.S.C. 2703 (compelled disclosure), 18 U.S.C. 2704 (backup preservation), or 18 U.S.C. 2518 (wiretap orders) falls outside Section 2701’s prohibition. These are the legal mechanisms law enforcement and other government entities must use when they need stored communications.
Good-Faith Reliance
Section 2707(e) creates a complete defense to any civil or criminal action for anyone who acted in good-faith reliance on a court warrant or order, a grand jury subpoena, a legislative or statutory authorization, or an emergency request from law enforcement. This defense primarily protects service providers who turn over communications in response to what appears to be a valid legal demand. Even if the warrant or subpoena later proves defective, the provider is shielded as long as the reliance was genuine.