The Computer Misuse Act 1990
Introduction
The Computer Misuse Act 1990 (CMA 1990) is the primary legislation governing cybercrime in the United Kingdom. The Act was enacted following the Law Commission’s report on computer misuse and the decision in R v Gold and Schifreen (1988), where the House of Lords held that the forgery legislation did not extend to hacking. The Act creates three principal offences: unauthorised access to computer material, unauthorised access with intent to commit or facilitate further offences, and unauthorised acts with intent to impair the operation of a computer. The Act has been amended by the Police and Justice Act 2006 and the Serious Crime Act 2015 to address evolving cyber threats.
Section 1: Unauthorised Access
Section 1 of the CMA 1990 makes it an offence to cause a computer to perform any function with intent to secure access to any program or data held in any computer, where the access is unauthorised and the person knows that it is unauthorised. The offence is summary only, carrying a maximum penalty of six months’ imprisonment or a fine.
The offence requires the prosecution to prove that the defendant caused a computer to perform a function — which may be as simple as pressing a key or clicking a mouse — with the intent to secure access. The access must be unauthorised, meaning that the defendant does not have the consent of the person entitled to control the computer, and the defendant must be aware that the access is unauthorised. The offence does not require the defendant to access any particular program or data; the intent to access any program or data is sufficient.
The offence covers a wide range of conduct, including guessing passwords, exploiting security vulnerabilities, and using another person’s login credentials without authorisation. It also covers accessing a computer without authorisation to browse files, even if no damage is caused and no further offence is committed.
Section 2: Unauthorised Access with Intent
Section 2 creates an aggravated form of the section 1 offence, requiring that the defendant commit the unauthorised access with intent to commit or facilitate a further offence. The further offence may be any offence for which the sentence is fixed by law or for which a person may be sentenced to imprisonment for a term of five years or more. The further offence need not be committed at the time of the unauthorised access; it is sufficient that the defendant had the intent to commit it at some future time.
The section 2 offence is triable either way and carries a maximum penalty of five years’ imprisonment and/or a fine. Typical examples of section 2 offences include hacking into a bank’s computer system intending to commit fraud, or accessing a database intending to obtain personal information for blackmail.
Section 3: Unauthorised Acts with Intent to Impair Operation
Section 3 makes it an offence to do any unauthorised act in relation to a computer, intending to impair the operation of any computer, to prevent or hinder access to any program or data, to impair the operation of any program or the reliability of any data, or to enable any of these things to be done. The defendant must know that the act is unauthorised.
The section 3 offence covers a broad range of conduct, including: launching denial of service attacks that overwhelm a computer or network; deploying malware, viruses, or ransomware; deleting or corrupting data; and interfering with the operation of critical infrastructure. The offence is triable either way and carries a maximum penalty of ten years’ imprisonment and/or a fine.
Section 3ZA, inserted by the Serious Crime Act 2015, creates an additional offence of unauthorised acts causing, or creating a significant risk of, serious damage. The offence applies where the unauthorised act causes or creates a significant risk of serious damage to the economy, the environment, national security, or human welfare, or damage to property of significant value. The offence carries a maximum penalty of 14 years’ imprisonment, or life imprisonment where the damage causes or creates a significant risk of loss of human life.
Section 3A: Making, Supplying, or Obtaining Articles for Use in Offences
Section 3A, inserted by the Police and Justice Act 2006, creates offences relating to the making, supplying, or obtaining of articles for use in computer misuse offences. The section covers: making, adapting, supplying, or offering to supply an article intending it to be used to commit a section 1, 3, or 3ZA offence; supplying or offering to supply an article believing that it is likely to be used to commit such an offence; and obtaining an article with the intention of using it to commit such an offence.
The section targets the market for hacking tools, including password crackers, vulnerability scanners, and exploit kits. The offence is triable either way and carries a maximum penalty of two years’ imprisonment and/or a fine.
Extra-Territorial Application
The CMA 1990 has broad extra-territorial application. Section 4 provides that the Act applies where the defendant was in the United Kingdom at the time of the act, even if the computer targeted was outside the UK. Section 5 extends jurisdiction to cases where the unauthorised act caused damage or created a significant risk of damage within the UK, even if the defendant was outside the UK.
Sentencing and Culpability
Sentencing for computer misuse offences is guided by the Sentencing Council’s guidelines, which identify three categories of culpability: high (where the offence was planned, targeted, and sophisticated, with a significant role for the offender); medium (where the offence was opportunistic or the offender played a lesser role); and lower (where the offender was acting under coercion or their involvement was minimal). Harm categories are assessed by reference to the nature and value of the data accessed, the damage caused, and the impact on the victim.
Conclusion
The Computer Misuse Act 1990 provides a comprehensive framework for prosecuting cybercrime in the United Kingdom, addressing unauthorised access, hacking with intent to commit further offences, and malicious acts impairing computer operations. The Act has been amended to address evolving threats, including denial of service attacks, ransomware, and the proliferation of hacking tools, while the extra-territorial provisions ensure that offenders cannot evade liability by targeting UK computers from abroad.