Computer Fraud and Abuse Act
Introduction
The Computer Fraud and Abuse Act (CFAA) , codified at 18 USC § 1030, is the primary federal statute prohibiting unauthorized access to computers. Enacted in 1984 as the first major federal computer crime law, the CFAA has been amended multiple times to address evolving technologies and threats. The statute criminalizes various forms of computer intrusion, including hacking, trafficking in passwords, and causing damage through computer access.
The CFAA’s Core Provisions
Section 1030(a) defines seven categories of prohibited conduct. Section 1030(a)(2) prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain information from protected computers. Section 1030(a)(4) prohibits accessing a protected computer with intent to defraud. Section 1030(a)(5) prohibits causing damage to a protected computer through intentional access without authorization.
The statute defines a protected computer broadly to include computers used in or affecting interstate or foreign commerce. This definition reaches virtually any computer connected to the internet. The CFAA authorizes both criminal penalties and private civil actions for damages and injunctive relief.
Van Buren v. United States
The Supreme Court’s decision in Van Buren v. United States (2021) significantly narrowed the CFAA’s scope. The case involved a police officer who accessed a law enforcement database for an improper purpose but was authorized to use the database. The Court held that a person exceeds authorized access when they access a computer with authorization but obtain information they lack authorization to obtain, not when they misuse information they are authorized to access.
The Court rejected the government’s broad interpretation that would have made every violation of a computer-use policy a federal crime. Van Buren established that the CFAA’s “exceeds authorized access” provision prohibits access, not misuse. The decision limited the CFAA’s application in contexts where employees or others with authorized access use that access for improper purposes.
Civil Liability Under the CFAA
The CFAA provides a private right of action for any person who suffers damage or loss as a result of a violation. Damage includes any impairment to the integrity or availability of data, programs, or systems. Loss includes reasonable costs incurred for investigation, response, and damage restoration.
To recover in a civil action, the plaintiff must prove that the conduct caused loss of at least $5,000 in value during a one-year period, affected medical treatment or public safety, caused physical injury, or threatened public health or safety. Employers have used the CFAA against former employees who accessed company computers without authorization, though Van Buren has limited such claims.
Computer Intrusion and Hacking
The CFAA prohibits intentional access without authorization —gaining entry to a computer that the person is not permitted to use. Simple hacking involves breaking into a computer system by circumventing access controls. The statute also prohibits trafficking in passwords and other access information.
Penalties vary based on the offense. Basic violations under § 1030(a)(2) carry penalties of up to one year in prison for first offenses, with increased penalties for aggravated offenses involving national security, financial gain, or serious damage. The maximum penalty for aggravated offenses is up to twenty years.
The CFAA Reform Debate
The CFAA has been criticized for its breadth and vagueness. Critics argue that terms such as “exceeds authorized access” and “without authorization” are ill-defined and that the statute can be applied to ordinary online behavior, such as violating a website’s terms of service. Reform proposals have sought to narrow the CFAA’s scope, clarify key definitions, and reduce penalties for non-serious violations.
Conclusion
The CFAA is the primary federal statute addressing computer intrusion and hacking. The Supreme Court’s decision in Van Buren narrowed the statute’s reach by distinguishing between unauthorized access and misuse of authorized access. The CFAA continues to evolve through judicial interpretation and legislative proposals, reflecting ongoing debates about the appropriate scope of computer crime legislation.