18 U.S.C. § 1030, better known as the Computer Fraud and Abuse Act, is the primary federal statute that criminalizes unauthorized access to computers. It defines seven categories of prohibited conduct, sets prison terms ranging from one year to twenty, and lets victims file civil lawsuits when their losses reach $5,000 or certain other harms occur. Enacted in 1986 and amended repeatedly since, it now covers everything from classic hacking to ransomware and data theft.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
Which Computers the Statute Covers
Section 1030 applies to “protected computers.” The statute defines that term to include computers used exclusively by or for a financial institution or the federal government, computers used in or affecting interstate or foreign commerce or communication, and certain voting systems used in federal elections.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers Courts read the interstate-commerce clause broadly. In practice, that reaches virtually any internet-connected computer, including personal laptops, corporate servers, cloud platforms, and devices located outside the United States when they affect U.S. commerce or communications.
The Seven Prohibited Acts
Subsection (a) lays out seven separate offenses. They overlap, and prosecutors often charge more than one from the same conduct.
- (a)(1) National security information. Accessing a computer without authorization or exceeding authorized access, obtaining classified or restricted data, and sharing it with someone not entitled to receive it or keeping it instead of returning it to the appropriate government official.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(2) Unauthorized access to obtain information. Accessing a computer without authorization or exceeding authorized access and obtaining information from a financial institution, any federal agency, or any protected computer. This is the broadest access offense and the one most commonly charged.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(3) Trespassing in a government computer. Accessing a nonpublic federal government computer without authorization. Narrower than (a)(2) because it applies only to government systems not open to the public.
- (a)(4) Computer fraud. Accessing a protected computer without authorization with intent to defraud, and obtaining something of value through that access. The provision does not apply if the only thing obtained is the use of the computer itself and that use is worth less than $5,000 in a year.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(5) Damaging a protected computer. Three tiers. The most serious covers knowingly transmitting code or commands that intentionally cause damage. The middle tier covers intentionally accessing a computer without authorization and recklessly causing damage. The lowest tier covers the same unauthorized access when damage results without intent or recklessness.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
- (a)(6) Trafficking in passwords. Knowingly trafficking in passwords or similar access credentials with intent to defraud, when the trafficking affects interstate commerce or involves a government computer.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(7) Extortion. Transmitting a threat to damage a protected computer, a threat to steal or expose data obtained without authorization, or a demand for payment related to damage already caused. This is the provision most directly applicable to ransomware.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
What “Unauthorized Access” Actually Means
For decades the phrase “exceeds authorized access” divided the federal courts. Some read it broadly to cover any misuse of access, including looking up permitted information for an improper purpose. That reading would have turned routine terms-of-service violations into potential federal crimes.
The Supreme Court rejected that view in Van Buren v. United States (2021), ruling 6–3 that a person “exceeds authorized access” only when they reach areas of a computer that are off-limits to them, not when they access permitted areas for an improper purpose.3Supreme Court of the United States. Van Buren v. United States The case involved a police officer who ran a license plate search in a law enforcement database for personal reasons. He had legitimate access to the database but used it for a prohibited purpose. The Court held he didn’t violate the CFAA because the information sat in a system he was otherwise authorized to access. The majority noted that the government’s broader reading would criminalize “everything from embellishing an online-dating profile to using a pseudonym on Facebook.”
The practical effect falls on employers. A company that wants CFAA protection needs actual technical restrictions on what users can reach, not just policy language telling employees to use systems only for work purposes.4American Constitution Society. The Computer Fraud and Abuse Act After Van Buren The scraping cases follow the same logic. The Ninth Circuit held in hiQ Labs v. LinkedIn that accessing data on a public website likely is not access “without authorization” because there is no permission barrier to circumvent.5United States Court of Appeals for the Ninth Circuit. HiQ Labs v. LinkedIn Corp. By contrast, in Facebook, Inc. v. Power Ventures, Inc., the court held that continuing to access Facebook after receiving a cease-and-desist letter did violate the statute because Facebook had explicitly revoked permission.6UNITED STATES COURT OF APPEALS FOR THE NINTH CIRCUIT. Facebook, Inc. v. Power Ventures, Inc., No. 13-17102
Prison Time by Offense
Maximum prison terms depend on which subsection was violated, whether the defendant has a prior CFAA conviction, and what harm resulted.
- (a)(1) National security offenses: Up to 10 years for a first offense; up to 20 years for a repeat offense.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(2) Unauthorized access to obtain information: Up to 1 year as a baseline first offense. That jumps to 5 years if the access was for commercial gain, furthered another crime, or the stolen information exceeded $5,000 in value. A repeat offense carries up to 10 years.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
- (a)(3) Government computer trespass and (a)(6) password trafficking: Up to 1 year for a first offense; up to 10 years for a repeat offense.
- (a)(4) Computer fraud and (a)(7) extortion: Up to 5 years for a first offense; up to 10 years for a repeat offense.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
- (a)(5)(A) Intentional damage: Up to 10 years for a first offense; up to 20 years for a repeat offense. This is the heaviest damage penalty and typically covers malware deployment and destructive hacking.
- (a)(5)(B) Reckless damage: Up to 5 years for a first offense if the conduct caused qualifying harm; up to 20 years for a repeat offense.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
- (a)(5)(C) Other damage: Up to 1 year for a first offense; up to 10 years for a repeat offense.
For damage offenses, aggravating factors trigger the higher penalties. Those factors include causing losses of at least $5,000 in a one-year period, impairing medical care, causing physical injury, threatening public health or safety, damaging government systems used for justice or national security, or affecting 10 or more protected computers in a year.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
Sentencing Enhancements That Add Time
Statutory maximums are only part of the picture. Federal sentencing guidelines under § 2B1.1 add enhancements that can push a real sentence well beyond what the bare offense suggests. The U.S. Sentencing Commission lists several that recur in computer crime cases:
- A 2-level increase for offenses involving 10 or more victims or committed through mass solicitation by phone, email, or internet. If 25 or more victims suffered substantial financial hardship, the increase is 6 levels.7United States Sentencing Commission. Primer on Computer Crimes
- A 2-level increase for sophisticated means (techniques like botnets, advanced obfuscation, or schemes partly operated from outside the United States), with a minimum offense level of 12.7United States Sentencing Commission. Primer on Computer Crimes
- A 2-level increase for the unauthorized public disclosure of personal information.
- A 6-level increase, with a minimum offense level of 24, if the offense substantially disrupted critical infrastructure.7United States Sentencing Commission. Primer on Computer Crimes
Large-scale ransomware attacks routinely stack several of these enhancements at once.
Civil Lawsuits Under Subsection (g)
Section 1030 gives victims a private right of action, but not for every violation. A civil suit is available only when the conduct involved at least one of these factors: aggregate losses of $5,000 or more in a one-year period, impairment of medical care, physical injury, a threat to public health or safety, or damage to a government computer used for justice, defense, or national security purposes.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers Most civil cases rely on the $5,000 loss threshold because the other factors are harder to prove in a business dispute.
The statute defines “loss” broadly. It covers any reasonable cost to a victim, including the cost of responding to the offense, conducting a damage assessment, restoring data or systems to their pre-offense condition, any lost revenue, and other consequential costs caused by interruption of service.8Legal Information Institute (LII). Definition: Loss From 18 USC 1030(e)(11) Fees for outside forensic investigators, the value of employee time spent investigating a breach, and the cost of patching exploited vulnerabilities can all count toward the $5,000 threshold. “Damage” is separate and covers any impairment to the integrity or availability of data, a program, a system, or information; it has no dollar threshold.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers
When the only qualifying factor is the $5,000 loss, damages in a civil suit are limited to economic losses. That covers forensic investigation, system restoration, and lost revenue, but not emotional distress or other non-economic harm. Courts can also grant injunctive relief ordering the defendant to stop accessing your systems or return stolen data. One category of claim is expressly excluded: you cannot sue under § 1030 for the negligent design or manufacture of computer hardware, software, or firmware.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
The typical civil fact patterns are corporate. Former employees who download customer lists before moving to a competitor, vendors who keep credentials after a contract ends, and competitors who scrape password-protected databases.
Deadlines to Sue or Charge
A civil lawsuit under § 1030 must be filed within two years of either the act itself or the date the victim discovered the damage, whichever is later.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers The discovery rule matters because intrusions often go undetected for months. Section 1030 contains no separate criminal limitations period, so the general federal five-year statute of limitations under 18 U.S.C. § 3282 applies to most offenses.9United States Department of Justice Archives. Criminal Resource Manual 650 – Length of Limitations Period
Good-Faith Security Research
In 2022, the Department of Justice formally revised its charging policy to state that good-faith security research should not be prosecuted under the CFAA. The policy defines good-faith research as accessing a computer solely to test, investigate, or fix a security flaw in a way designed to avoid harm, where the findings are used to improve security.10United States Department of Justice. Department of Justice Announces New Policy for Charging Cases Under the Computer Fraud and Abuse Act The policy does not change the text of the statute. It directs federal prosecutors to exercise discretion, and it does not bind civil plaintiffs or state prosecutors.