WSJ logo
Forbes logo
Fox News logo
CNN logo
Bloomberg logo
Los Angeles Times logo
Washington Post logo
The Epoch Times logo
Telemundo logo
New York Times
NY Post logo
NBC logo
Daily Beast logo
USA Today logo
Miami Herald logo
CNBC logo
Dallas News logo
Quick Practice Area Locator

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

The Ultimate Guide to the Federal Computer Fraud and Abuse Act (CFAA)

The Ultimate Guide to the Federal Computer Fraud and Abuse Act (CFAA)

We recently published our Ultimate Guide to the Federal Computer and Internet Fraud Statutes; and, in that guide, we included an overview of the Computer Fraud and Abuse Act (CFAA). However, as the CFAA is a complex and lengthy statute—and one of federal prosecutors’ primary tools for prosecuting computer-related crimes—it is worthy of an Ultimate Guide of its own.

If you are facing federal prosecution for a computer-related crime, you are most likely facing prosecution under the CFAA (although you may be facing prosecution under a variety of other federal statutes as well). As a result, it will be important for you to understand what the CFAA prohibits, what it doesn’t, and what defenses you have available.

Computer Fraud and Abuse Act (18 U.S.C. Section 1030): Understanding the Key Concepts

The Computer Fraud and Abuse Act (18 U.S.C. Section 1030) has 10 main sections—18 U.S.C. Section 1030(a) through 18 U.S.C. Section 1030(j). However, the three most important sections of the statute are Sections 1030(a), (b), and (c). Sections 1030(a) and (b) identify the types of conduct that violate the statute, while Section 1030(c) establishes the criminal penalties for CFAA violations.

Accessing a Computer or Data “Without Authorization” or By “Exceeding Authorized Access”

The majority of the provisions in Section 1030(a) establish criminal offenses that involve accessing a computer or data “without authorization” or by “exceeding authorized access.” While “without authorization” is fairly clear (though questions regarding authorization can establish defenses in CFAA prosecutions in some cases), Section 1030(e)(6) defines what it means to exceed authorized access:

“[T]he term “exceeds authorized access” means to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser (sic) is not entitled so to obtain or alter.”

The U.S. Department of Justice (DOJ) handles cases involving access without authorization and cases that involve exceeding authorized access differently. As explained in Section 9-48.000 of the DOJ’s Justice Manual:

“The Department will not charge defendants for accessing ‘without authorization’ . . . unless . . . at the time of the defendant’s conduct, (1) the defendant was not authorized to access the protected computer under any circumstances by any person or entity with the authority to grant such authorization; (2) the defendant knew of the facts that made the defendant’s access without authorization; and (3) prosecution would serve the Department’s goals for CFAA enforcement . . . .

“The Department will not charge defendants with ‘exceeding authorized access’ . . . unless, at the time of the defendant’s conduct, (1) a protected computer is divided into areas, such as files, folders, user accounts, or databases; (2) that division is established in a computational sense, that is, through computer code or configuration, rather than through contracts, terms of service agreements, or employee policies; (3) a defendant is authorized to access some areas, but unconditionally prohibited from accessing other areas of the computer; (4) the defendant accessed an area of the computer to which his authorized access did not extend; (5) the defendant knew of the facts that made his access unauthorized; and (6) prosecution would serve the Department’s goals for CFAA enforcement . . . .”

These differences are critical to keep in mind when facing charges under the CFAA. It is also critical to know the specific provision of the CFAA under which you are being charged. Defending against allegations of exceeding authorized access in order to defraud and using unauthorized access to obtain national security information, for example, are two very different offenses. It isn’t always (or often) easy to discern the specific allegations you are facing under the CFAA; and, when you hire an experienced federal white-collar defense lawyer to represent you, discerning the focus of the government’s case will be one of the first steps your lawyer takes on your behalf.

Computers and Information Protected Under the CFAA

Another key distinction in CFAA cases is that between a “computer” and a “protected computer.” Some provisions of the CFAA apply to “computers,” while others apply to “protected computers” exclusively. For example, while Section 1030(a)(2)(A) makes it a federal offense to “intentionally access a computer . . . and thereby obtain[] . . . information contained in a financial record . . . .,” Section 1030(a)(4) makes it a federal offense to “knowingly and with intent to defraud, access[] a protected computer without authorization, or exceed[] authorized access . . . .”

In the CFAA, the term “computer” is used to describe any type of device that is commonly understood to constitute (or contain) a computer today. This includes laptops, desktops, tablets, phones, and servers—among many other things. However, the term “protected computer” has a much more specific definition. Under Section 1030(e)(2), a “protected computer” is a computer that is:

“(A) exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government; (B) . . . used in or affecting interstate or foreign commerce or communication, including a computer located outside the United States . . . ; or (C) that . . . is part of a voting system . . . .”

Crucially, however, despite this specific definition, most computers today are “protected computers” under subpart (B) of this definition. This is because virtually any computer that is connected to the internet will be considered to be “used in or affecting interstate or foreign commerce.” So, while the distinction between “computers” and “protected computers” in the CFAA is important, the definition of “protected computers” is not as limiting today as it was 30 years ago.

Since the CFAA’s prohibitions broadly apply to “computers” and “protected computers,” virtually all data stored on one of these devices are protected under the statute. However, certain provisions of the statute treat certain types of data differently as well. For example, Section 1030(a)(1) imposes some of the CFAA’s harshest penalties, and it applies specifically to obtaining unauthorized access to a computer that houses national security information.

Summary of Computer Fraud and Abuse Act (CFAA) Offenses and Penalties

With these overarching considerations in mind, we can now take a look at the specific prohibitions in the Computer Fraud and Abuse Act. Here are brief summaries of each of the statute’s operative sections and the associated penalties under Section 1030(c):

  • 18 U.S.C. Section 1030(a)(1) – Illegally obtaining access to national security information carries statutory fines and a maximum prison sentence of 10 or 20 years.
  • 18 U.S.C. Section 1030(a)(2) – Illegally accessing a computer and gaining unauthorized access to information carries statutory fines and a maximum prison sentence of one to 10 years.
  • 18 U.S.C. Section 1030(a)(3) – Illegally accessing a government computer carries statutory fines and a maximum prison sentence of one to 10 years.
  • 18 U.S.C. Section 1030(a)(4) – Illegally accessing a computer to engage in fraud or obtain anything of value carries statutory fines and a maximum prison sentence of five or 10 years.
  • 18 U.S.C. Section 1030(a)(5)(A) – Intentionally damaging a computer or data carries statutory fines and a maximum prison sentence of one to 10 years in most cases.
  • 18 U.S.C. Section 1030(a)(5)(B) – Recklessly damaging a computer or data by intentional access carries statutory fines and a maximum prison sentence of one to five years in most cases.
  • 18 U.S.C. Section 1030(a)(5)(C) – Negligently damaging a computer or data carries statutory fines and one year of prison time in most cases.
  • 18 U.S.C. Section 1030(a)(6) – Illegally trafficking in passwords “or similar information” carries statutory fines and a prison sentence of one to 10 years.
  • 18 U.S.C. Section 1030(a)(7) – Extortion involving use of computers or the internet carries statutory fines and a prison sentence of five to 10 years.
  • 18 U.S.C. Section 1030(b) – Attempt or conspiracy to commit any violation of Section 1030(a) carries statutory fines and a prison term of up to 10 years in most cases.

Defending Against Federal White-Collar Charges Under the CFAA

When facing criminal charges under the CFAA, determining what defenses you have available—and determining how best to formulate your defense strategy—requires careful consideration of numerous factors.

Prosecutions under the CFAA are highly fact-specific, and challenging the sufficiency or admissibility of the DOJ’s evidence will be a key defense strategy in many cases. But, given the requirement for unauthorized access (or exceeding authorized access) and the various subjective elements of many of the CFAA’s prohibitions (i.e., requirements that the defendant act intentionally or knowingly), in many cases it will be possible to present an affirmative defense as well. Ultimately, determining how best to approach your case requires a clear understanding of the relevant facts and the available evidence as well as a thorough understanding of the law.

Contact the Federal White-Collar Defense Lawyers at Oberheiden P.C.

The federal white-collar defense lawyers at Oberheiden P.C. represent individuals in investigations and prosecutions under the Computer Fraud and Abuse Act nationwide. To discuss your case with a senior defense lawyer in confidence, call 888-680-1745 or request a complimentary consultation online now.

Contact Us Today

This field is for validation purposes and should be left unchanged.
I accept the Terms and Conditions.(Required)

Why Clients Trust Oberheiden P.C.

  • 2,000+ Cases Won
  • Available Nights & Weekends
  • Experienced Trial Attorneys
  • Former Department of Justice Trial Attorney
  • Former Federal Prosecutors, U.S. Attorney’s Office
  • Former Agents from FBI, OIG, DEA
  • Serving Clients Nationwide
Contact Us 888-680-1745 866-781-9539