Computer Fraud and Abuse Act
· About Computer Fraud and Abuse Act
Key Takeaways
- The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030, is the main federal anti-hacking statute and applies to unauthorized access, trafficking in passwords, and certain frauds involving protected computers[1][3].
- The statute reaches protected computers, which currently includes computers used in or affecting interstate or foreign commerce, so the practical scope is broad and not limited to government systems[1][3].
- The CFAA creates both criminal penalties and a civil cause of action for persons who suffer damage or loss from conduct that violates the statute[1][3][10].
- The Department of Justice’s current charging guidance says prosecutors should decline charges for good-faith security research and focus on cases involving no authorization or access beyond clearly defined limits[2][4].
- As of September 2026, there is no identified 2025–2026 statutory amendment changing the core CFAA framework, but the text has been updated to reflect existing law in force through September 2026[1][3].
- Maximum criminal exposure depends on the subsection and facts, and can range from misdemeanor-level penalties to substantial felonies, with repeat or serious-loss cases carrying the harshest sanctions[1][10].
What It Is
The CFAA is the federal computer crime statute in Chapter 47 of Title 18, covering unauthorized access and related conduct involving computers, credentials, fraud, extortion, and damage to data or systems[1][3]. It is enforced primarily by the Department of Justice, especially its Criminal Division and U.S. Attorneys’ Offices[2][14].
Congress first enacted the CFAA in 1984, and it has been amended repeatedly since then; the current codified text in the U.S. Code reflects the law in force as of 4 September 2026[1]. The most important modern scope expansion is the definition of protected computer, which now reaches computers used in or affecting interstate or foreign commerce, plus specific categories such as certain financial and government systems[1][9].
A significant recent policy change, not a statutory amendment, is the DOJ’s revised Justice Manual § 9-48.000, which instructs federal prosecutors not to bring CFAA charges where the available evidence shows good-faith security research[2][4]. That guidance was announced in May 2022 and remains the operative DOJ charging policy in 2026[2][4].
Who Must Comply
The CFAA applies to any person who engages in prohibited access or related conduct against a protected computer, regardless of industry or location, so long as the computer is within the statute’s jurisdictional reach[1][3]. Because “protected computer” includes systems used in interstate or foreign commerce, the law has broad extraterritorial practical reach for conduct affecting U.S. systems or commerce[1][9].
It applies most clearly to individuals and organizations that:
- access a computer without authorization;
- access a computer exceeding authorized access and obtain information, value, or cause damage;
- intentionally transmit code or commands that cause damage;
- traffic in passwords or similar access credentials for covered systems[1][3].
There is no general corporate exemption. However, the DOJ’s current criminal charging policy carves out good-faith security research if the activity is designed to avoid harm and is primarily aimed at improving security[2][4]. That policy is narrower than the statute and does not eliminate civil exposure under the CFAA[12].
The statute’s civil remedy is available to a person or entity that suffers qualifying damage or loss from a CFAA violation, which means companies may face both victim and defendant roles depending on the facts[1][10].
Core Requirements
- Do not access without authorization. Accessing a protected computer without any permission can trigger liability, especially where the conduct involves obtaining information, causing damage, or furthering fraud[1][3].
- Do not exceed authorized access. The statute still reaches certain over-limit access to protected systems where a person has access to some parts of a computer but knowingly crosses a clearly restricted boundary[1][2].
- Protect credentials and access tools. Trafficking in passwords or similar means of access for a protected computer is separately prohibited, even if no system intrusion has yet occurred[1][3].
- Prevent intentional damage. The CFAA covers intentionally causing damage, including by transmitting code or commands that harm systems, data, programs, or information[1][3].
- Track loss and remediation. Civil liability can attach when a CFAA violation causes “damage or loss,” so incident-response cost documentation matters for both prosecution and private litigation[1][10].
- Differentiate security testing from misuse. The DOJ guidance protects genuine security research only when the activity is done in good faith, aims to avoid harm, and seeks to improve the security of the target class of systems[2][4].
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | CFAA enacted | 1984 | Federal anti-hacking offenses introduced into Title 18[1] | | DOJ good-faith security research policy | 19 May 2022 | Prosecutors should decline charges for qualifying research[2][4] | | Current codified text reflects law in force | 4 September 2026 | Statutory text current as of this date[1] | | Current DOJ guidance last updated on DOJ page | 25 August 2026 | Charging manual page remains active and current[2] |
The statute’s maximum criminal penalties vary by subsection and aggravating factors. At the lower end, some first-offense conduct may be charged as a misdemeanor; at the higher end, CFAA offenses involving significant loss, repeat offenses, fraud, or damage can carry felony exposure and substantial prison terms[1][10]. The civil remedy can include compensatory damages and other relief, and the statutory threshold for some civil claims depends on the amount of loss incurred during a one-year period[1][10].
Other sanctions can include:
- forfeiture in appropriate cases under related statutory provisions or charging theories;
- probation, supervised release, and restitution;
- injunctions or private civil claims by affected parties[1][10].
How to Comply
- Map systems and access boundaries. Inventory assets, identify protected data and administrative interfaces, and document who is authorized to access what; this is consistent with ISO 27001 access-control and asset-management practices.
- Write and enforce clear access rules. Use role-based access, least privilege, and explicit permission scopes so “exceeding authorized access” boundaries are operationally visible.
- Log and retain access evidence. Maintain authentication, command, and administrative logs to support incident response and civil-loss calculations; this aligns with NIST CSF 2.0 Detect and Respond functions.
- Run a safe vulnerability-disclosure program. Adopt coordinated disclosure, scoped testing rules, and safe-harbor language for researchers; ISO 42001 governance controls can help document AI-assisted security testing and oversight where applicable.
- Separate research from production access. Use dedicated test environments, written authorization, and change controls before security teams or vendors probe live systems.
- Train staff on CFAA boundaries. Educate employees, contractors, and researchers that permitted access does not equal blanket access, and that policy violations can become legal exposure.
- Prepare incident-response and legal review playbooks. Include CFAA triage, evidence preservation, and a determination of whether conduct involves unauthorized access, credential misuse, or genuine security research.
- Review third-party and bug-bounty terms. Make sure contractual terms are precise about scope, methods, and prohibited actions so that access restrictions are enforceable and understandable[2][4].
Related Regulations
- Stored Communications Act: This law overlaps when unauthorized access involves electronic communications content, and it can add privacy and disclosure issues beyond CFAA hacking theories.
- Electronic Communications Privacy Act: ECPA can overlap where interception, access, or disclosure of electronic communications is involved, but it addresses different conduct than pure unauthorized access.
- Wire Fraud Statute: Prosecutors often pair wire-fraud counts with CFAA facts when a scheme to obtain money or property is alleged.
- State computer crime laws: Many states have parallel anti-hacking statutes that may be broader or narrower than the CFAA, creating dual exposure for the same incident.
- Copyright Act / DMCA: These laws may conflict or overlap when access restrictions, copying, or circumvention accompany the computer intrusion.
FAQ
Does the CFAA apply to companies outside the United States?
Yes. The key jurisdictional concept is whether the target is a protected computer, which includes systems used in or affecting interstate or foreign commerce[1][9]. That functional test gives the statute broad reach over foreign actors when the conduct touches U.S. systems or commerce[1][3].
Does good-faith security research create CFAA liability?
The DOJ’s current policy says prosecutors should decline charges when the available evidence shows true good-faith security research[2][4]. That does not repeal the statute, and it does not remove possible civil claims or non-CFAA legal exposure[12].
Is violating a website’s terms of service enough for CFAA liability?
Not by itself, in the ordinary case. DOJ guidance focuses on conduct where a defendant is either not authorized at all or knowingly accesses a restricted part of a computer beyond permission, rather than ordinary policy violations alone[2][4]. The precise risk still depends on the access limits, technical controls, and the facts of the case[1].
Can an employee violate the CFAA by using company systems in the wrong way?
Yes, if the employee accesses systems or data without authorization or beyond clearly defined authorization boundaries[1][3]. The analysis is fact-specific, and clear access policies, role boundaries, and technical restrictions matter because they help define what the person was authorized to do[2].
Is there a private right of action under the CFAA?
Yes. The statute allows a civil claim for qualifying damage or loss caused by a violation[1][10]. Civil suits often turn on whether the plaintiff can show the statutory threshold and a cognizable loss tied to the prohibited conduct[10].
Sources
- 18 U.S.C. § 1030, U.S. House Office of the Law Revision Counsel)
- 18 U.S.C. § 1030, GovInfo U.S. Code
- Justice Manual § 9-48.000, Computer Fraud and Abuse Act
- DOJ Press Release, Revised CFAA charging policy for good-faith security research
- Congressional Research Service, Cybercrime and the Law: Primer on the Computer Fraud and Abuse Act
- Congressional Research Service, An Overview of the Federal Computer Fraud and Abuse Statute and Related Provisions
- Cornell Legal Information Institute, 18 U.S. Code § 1030
- DOJ Criminal Division Cybersecurity Unit
- Crowell, DOJ’s revised prosecutorial guidelines and the ethical hacker exemption
Put it into practice
- Generate the policy: NIST CSF policy generator (generatepolicy.com)
- Buy the policy pack: Enterprise Security Bundle (cyberpolicy.shop)
- Build it yourself: Compliance Program Starter (ciso.diy)