Zip bombs sit in an odd legal spot: the file itself isn’t outlawed, but sending one at someone else’s computer almost certainly is. Are zip bombs illegal to use? Yes. Deploying one against a system you don’t own or aren’t authorized to test violates the federal Computer Fraud and Abuse Act (CFAA), and a first offense can carry up to 10 years in federal prison and a $250,000 fine. The victim can also sue you separately in civil court.
What a Zip Bomb Is, in One Paragraph
A zip bomb is a small compressed archive engineered to expand to an enormous size when someone tries to unzip it. A tiny file balloons into terabytes or petabytes of junk data, consuming storage, memory, and CPU until the target system freezes. The classic example, “42.zip,” weighs 42 kilobytes and expands to roughly 4.5 petabytes.1Wikipedia. Zip Bomb No code executes; the attack weaponizes the decompression process itself, and the practical effect on the target is a denial of service.
Is It Illegal to Make or Have One?
Simply having a zip bomb on your hard drive is not a federal crime. Security researchers build and study them routinely to test how antivirus engines, extraction tools, and servers handle decompression attacks. Nobody is being indicted for a test file in a lab.
Intent changes the analysis. If you build a zip bomb as part of a plan to crash a specific server, disable someone’s security software, or disrupt an operation, the creation becomes evidence of a broader offense. Prosecutors don’t have to wait for detonation. An attempt to commit a CFAA offense carries the same maximum penalty as the completed offense.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers Building the file, writing a delivery script, and picking a target can add up to a chargeable attempt before anything leaves your machine.
The Federal Law That Applies
The controlling statute is 18 U.S.C. ยง 1030(a)(5), which makes it a crime to knowingly transmit a program, code, or command that intentionally causes damage to a protected computer without authorization.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers A zip bomb fits the language directly: you send a file, and the file is designed to crash the receiving system.
Two related provisions widen the net. One covers damage caused recklessly rather than intentionally. Another applies where someone accesses a protected computer without authorization and causes damage as a result, even without intending to harm. That third category can reach someone who sends a zip bomb as a “prank” without fully appreciating the fallout.
“Protected Computer” Covers Almost Everything
The term sounds narrow but isn’t. Under the statute, a protected computer includes any computer used by a financial institution or the federal government, any computer that is part of a voting system used in federal elections, and any computer used in or affecting interstate or foreign commerce or communication.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers Courts have consistently read the last category to include essentially any computer connected to the internet. A personal laptop, a small business server, and a cloud-hosted application all qualify.
What Counts as Damage and Loss
The CFAA defines damage as any impairment to the integrity or availability of data, a program, a system, or information. A zip bomb that fills a drive, crashes an operating system, or makes a server unavailable meets that definition easily.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers
Loss is broader. It includes the cost of responding to the attack, running a damage assessment, restoring systems to their pre-attack condition, and any revenue lost because of a service interruption.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers Twenty hours of IT labor to rebuild a server counts. Lost sales from a downed e-commerce site count. These numbers matter because certain penalty tiers and the right to sue civilly both require at least $5,000 in aggregate loss during a one-year period.
Prison Time and Fines
CFAA damage penalties tier by intent and prior record:
- Intentional damage, first offense: up to 10 years in prison and a fine, when the offense causes qualifying harm such as at least $5,000 in loss, damage to a government computer, physical injury, or a threat to public health or safety.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers
- Reckless damage, first offense: up to 5 years in prison and a fine, under the same qualifying-harm conditions.
- Any damage offense with a prior CFAA conviction: up to 20 years in prison and a fine.
- Damage offenses that don’t meet the qualifying-harm thresholds: up to 1 year in prison and a fine.
Fines follow the general provisions in Title 18. For an individual felony conviction, the maximum is $250,000. For an organization, it’s $500,000. And when the offense produced measurable gain or loss, the court can impose a fine of up to twice the gross gain or twice the gross loss, whichever is greater.3Office of the Law Revision Counsel. 18 USC 3571 – Sentence of Fine Crashing a system that handles significant transaction volume can produce a fine well above the $250,000 ceiling.
Getting Sued by the Victim
Criminal exposure isn’t the end of it. The CFAA gives victims a civil cause of action for compensatory damages and injunctive relief. To sue, the victim needs to show at least $5,000 in loss over a one-year period, or one of the other qualifying harms.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers
For loss-only claims (the usual zip bomb scenario), damages are limited to economic losses: incident response, system restoration, downtime revenue, and consequential damages flowing from the interruption. The victim has two years from the date of the attack or the date they discovered the damage to file.2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection with Computers
Separately, a criminal court can order mandatory restitution covering the victim’s response and restoration costs, along with lost income and expenses tied to the investigation and prosecution.4Office of the Law Revision Counsel. 18 USC 3663A – Mandatory Restitution to Victims of Certain Crimes A defendant can face criminal fines, civil damages, and restitution for the same incident.
What About Using One Defensively?
A common question in security circles: can you legally serve a zip bomb to scrapers, vulnerability scanners, or bots hammering your site? This is untested territory, and the risk is worse than most people assume.
The CFAA criminalizes knowingly transmitting code that intentionally damages a protected computer. If your defensive zip bomb crashes a bot operator’s machine, the fact that they were scraping you first doesn’t create a legal privilege to damage their system. The statute has no self-defense exception. Their conduct might also violate the law; that doesn’t immunize yours.
There’s a collateral damage problem, too. Legitimate users, search engine crawlers, or security researchers can trigger the trap and suffer real harm. At that point, you’ve intentionally deployed something that damages computers belonging to parties who weren’t doing anything wrong. Talk to a lawyer before going down this road.
State Laws Can Apply on Top
The CFAA is federal, but nearly every state has its own computer crime statute that operates independently. State laws vary in wording and penalty structure, and most criminalize unauthorized access, intentional damage to data or systems, and transmission of malicious code. Some states elevate the offense to a felony when loss exceeds a set threshold; others tier penalties by whether the target belongs to a government agency, critical infrastructure, or a private business.
State and federal charges can be brought for the same conduct. A zip bomb attack that crosses state lines or hits multiple systems can expose the sender to prosecution in more than one jurisdiction, with additional prison time, fines, and restitution at each level.
Job and Career Fallout
Even without charges or a lawsuit, testing a zip bomb on company hardware can end a career. In most states, an at-will employee can be fired for violating computer use policies, and corporate acceptable-use rules typically ban introducing malicious files onto the network. A termination for that kind of policy violation follows the person through background checks and references. For professionals holding certifications or security clearances, the consequences can extend to credential revocation or loss of eligibility.