Minnesota Computer Crime and Cyber Laws Explained

A practical, plain-language guide to Minnesota computer crime statutes, penalties, and your rights in the digital age.

By Medha deb
Created on

The growth of networked devices and online services means everyday activities now depend on computers and data. At the same time, Minnesota has developed a detailed framework of computer crime statutes designed to protect systems, networks, and electronic information from misuse and abuse. Understanding these rules is critical for individuals, businesses, and IT professionals who work with sensitive data or manage computer systems.

This guide explains how Minnesota law defines key computer-related offenses, the penalties associated with them, and what you should know if you are a victim or accused of a computer crime. It uses plain language but is grounded in Minnesota statutes and official explanations, so you can quickly grasp both your rights and your risks.

1. How Minnesota Law Defines Computer Crime

Minnesota does not treat computer crimes as a single, vague category. Instead, the criminal code breaks them into several distinct offenses, each covering a different type of harmful behavior. The key sections are:

  • Computer crime definitions – Minn. Stat. § 609.87
  • Computer damage – Minn. Stat. § 609.88
  • Computer or electronic data theft – Minn. Stat. § 609.89
  • Unauthorized computer access – Minn. Stat. § 609.891

These provisions work together to address different forms of cybercrime, from stealing data to breaking into systems or deliberately damaging hardware and software. Each statute has specific elements that prosecutors must prove and that defendants need to understand.

1.1 Key Terms in Minnesota Computer Crime Law

Before looking at individual offenses, it helps to understand some overarching concepts that appear repeatedly in the statutes:

  • Computer, computer system, computer network – These cover everything from personal laptops and smartphones to company servers, point-of-sale terminals, and connected corporate networks.
  • Computer software – Includes operating systems, applications, and any program or code stored or executed on a device.
  • Electronic data – Refers broadly to information stored or processed in digital form, including files, databases, and records.
  • Authorization / claim of right – Whether someone has legal permission or a legitimate belief they are allowed to access, retain, or use the system or data.

Most computer offenses hinge on the absence of authorization or a valid claim of right. If a person goes beyond the access or use they are permitted, or acts with intent to deprive or damage, that conduct may cross the line into criminal behavior.

2. Computer or Electronic Data Theft (Minn. Stat. § 609.89)

Computer or electronic data theft focuses on stealing or misusing computers, programs, or digital information. Under Minnesota law, a person commits this offense if they intentionally, and without authorization or claim of right, engage in specific acts involving computer systems, software, or data.

2.1 Conduct That Counts as Computer or Data Theft

Minnesota’s computer theft statute captures several different behaviors. A person may be guilty if they do any of the following:

  • Unauthorized access to obtain services or property – Intentionally accessing a computer, system, or network without permission to obtain services (like paid software or cloud access) or property (such as data or digital assets).
  • Taking or retaining computers or data – Intentionally taking, transferring, concealing, or retaining possession of any computer, computer system, or computer software or data, with intent to deprive the owner of its use or possession.
  • Copying and using data without authorization – Accessing or copying any computer software or electronic data without authorization or claim of right, then using, altering, transferring, retaining, or publishing that software or data.
  • Keeping copies beyond allowed authority – Intentionally retaining copies of computer software or electronic data beyond the individual’s authorized scope, even if the initial access was permitted.

Taken together, these provisions make clear that both the wrongful taking of devices and the misuse or retention of information can be treated as theft when done without proper authorization.

2.2 Penalties for Computer or Electronic Data Theft

The severity of punishment for computer theft depends largely on the financial loss to the owner or related parties. Minnesota law scales penalties based on the amount of loss resulting from the offense.

Loss Amount Maximum Jail / Prison Maximum Fine Level of Offense
More than $2,500 Up to 10 years Up to $50,000 Felony
More than $500 up to $2,500 Up to 5 years Up to $10,000 Felony
$500 or less Up to 90 days Up to $1,000 Misdemeanor

These thresholds mean that even relatively small computer thefts can lead to misdemeanor charges, while larger incidents involving substantial property or data losses may result in serious felony convictions.

3. Unauthorized Computer Access (Minn. Stat. § 609.891)

Unauthorized computer access is Minnesota’s core anti-hacking statute. It targets attempts to break into or bypass computer security protections, whether or not the intruder successfully steals data or causes damage.

3.1 What Counts as Unauthorized Access?

A person is guilty of unauthorized computer access if they intentionally and without authorization attempt to or actually penetrate a computer security system or electronic terminal. This can include:

  • Guessing or cracking passwords to log into restricted systems.
  • Installing devices on ATMs or payment terminals to capture card data.
  • Bypassing encryption or other access controls to reach protected files.
  • Using exploits to defeat security measures on a network or server.

Importantly, simply attempting to penetrate a security system—without full success—can still constitute a violation. The statute does not require that data be stolen or altered for criminal liability to arise.

3.2 Penalty Levels for Unauthorized Access

Minnesota law recognizes that unauthorized access can range from minor intrusion to extremely dangerous conduct. Penalties therefore vary based on the risk and circumstances of the violation.

  • Misdemeanor – For basic violations, a person may face up to 90 days in jail and a fine up to $1,000.
  • Gross misdemeanor – If the unauthorized access creates a risk to public health or safety, penalties can increase to up to 364 days in jail and a fine up to $3,000.
  • Felony – Certain aggravated circumstances can elevate the offense to a felony, with punishment up to 10 years in prison and fines up to $20,000.

Felony-level unauthorized access may apply, for example, when conduct creates a grave risk of causing death or when someone opens a panel or access door on an electronic terminal without authorization and attaches a device intended to capture or store access device information such as payment card details. Repeat gross misdemeanor violations can also be treated as felonies.

4. Related Cyber Offenses and Overlapping Laws

Computer crime statutes often interact with other Minnesota laws that protect privacy, financial integrity, and public safety. Some common related offenses include identity theft, privacy invasions, and data interception.

4.1 Identity Theft and Misuse of Personal Information

While the primary identity theft provisions are separate from the computer crime chapter, many modern identity theft cases involve computers and digital networks. The Minnesota Attorney General defines identity theft as using another person’s private information to commit fraud, such as opening bank accounts or obtaining loans in that person’s name.

Computer systems can be used to:

  • Steal Social Security numbers or financial account information.
  • Phish login credentials from unsuspecting users.
  • Access existing accounts without authorization and divert funds.

Victims are advised to report identity theft to local law enforcement, place fraud alerts or freezes on credit reports, and notify relevant federal agencies such as the Federal Trade Commission. When identity theft is carried out through hacking or unauthorized access, the computer crime statutes may apply in addition to identity theft laws.

4.2 Privacy, Interception, and Cybersecurity Statutes

Other Minnesota laws address specific privacy and interception concerns. For example, statutes cover interference with privacy and the interception of wire, electronic, or oral communications. These provisions can come into play when computer crimes involve:

  • Secretly recording or monitoring users without consent.
  • Intercepting email or online communications.
  • Installing surveillance software or hardware on devices.

Legal guidance materials from the Minnesota State Law Library provide overviews of privacy, identity theft, and cybersecurity resources to help the public understand how these laws work together.

5. Practical Implications for Individuals and Businesses

The technical language of statutes can make computer crime law seem distant from everyday life, but in practice these rules affect common activities in workplaces, schools, and homes. Understanding where lawful use ends and criminal conduct begins is essential.

5.1 Everyday Scenarios That Can Raise Legal Issues

Examples of situations that may implicate Minnesota computer crime laws include:

  • Using someone else’s login without permission – Signing into a coworker’s account or student portal by guessing their password could be viewed as unauthorized access, especially if sensitive data is viewed or altered.
  • Taking company data when leaving a job – Copying client lists, trade secrets, or proprietary software and using or retaining them beyond authorized limits may meet the elements of computer or electronic data theft.
  • Installing data-capturing devices on payment terminals – Attaching skimming devices to capture card information is specifically highlighted in the felony provisions for unauthorized access involving electronic terminals.
  • Sharing passwords knowing a crime will be committed – Facilitating someone else’s unauthorized access to commit data theft or fraud can lead to liability, including under aiding or abetting theories and related cybercrime laws.

In many cases, the person involved may not see themselves as a “hacker,” but the statutes look at intent, authorization, and impact, not job title or technical skill.

5.2 Compliance Tips for Organizations

Businesses, schools, and public agencies that manage computer systems in Minnesota can reduce legal risk by adopting clear policies and controls.

  • Define authorized access clearly – Written policies should specify who may access which systems and data, under what circumstances, and with what credentials.
  • Implement security measures – Encryption, access controls, logging, and regular security audits help prevent unauthorized penetration and make it easier to investigate suspected incidents.
  • Train staff and students – Education about password hygiene, data handling, and legal consequences of misuse can deter behavior that might constitute computer theft or unauthorized access.
  • Respond quickly to incidents – When a breach or misuse is detected, prompt reporting and remediation can limit harm and demonstrate good-faith efforts to comply with the law.

6. If You Are a Victim or Accused of a Computer Crime

Computer crimes can affect both individuals and organizations in serious ways. Victims may suffer financial loss, privacy invasions, or disruption of business operations. Accused individuals face potential jail time, fines, and long-term consequences.

6.1 Steps for Victims of Computer Crime

If you suspect you are a victim of identity theft or another computer-related offense, Minnesota authorities recommend taking action quickly.

  • Contact local law enforcement – Report suspected identity theft, hacking, or data misuse to your local police department or county sheriff. They have authority to investigate criminal wrongdoing under Minnesota law.
  • Notify financial institutions – For incidents involving bank accounts or credit cards, inform your bank or card issuer immediately to freeze or close affected accounts.
  • Use fraud alerts and credit freezes – Ask major credit bureaus to place fraud alerts or freezes on your credit file to prevent new accounts from being opened in your name.
  • Report to federal agencies – In cases of identity theft or widespread fraud, report to the Federal Trade Commission and other relevant federal bodies that collect complaints and assist law enforcement.

For serious incidents, you may also wish to consult an attorney experienced in computer crime or cybersecurity to explore civil remedies and to ensure your rights are protected during investigations.

6.2 Considerations for People Accused of Computer Crimes

Being accused of computer theft or unauthorized access in Minnesota is serious. Because many of these offenses are felonies, they can have long-lasting consequences for employment, licensing, and reputation.

  • Do not ignore the allegations – Failing to respond to charges or investigations can worsen your situation.
  • Seek legal counsel promptly – A criminal defense lawyer familiar with Minnesota computer crime statutes can help evaluate the evidence, explain the elements of the offense, and explore defenses or plea options.
  • Understand the role of intent and authorization – Many computer crime statutes require specific intent or the absence of authorization. Evidence about what you believed, what permissions you had, and how systems were configured can be important.
  • Preserve relevant records – Logs, emails, policies, and contracts may help clarify whether access or use was authorized and what level of harm occurred.

Because computer crime cases often involve technical details, expert analysis of digital evidence can be critical in both prosecution and defense.

7. Comparison of Major Minnesota Computer Crime Statutes

The following table summarizes how the main Minnesota computer crime statutes differ in focus and penalties.

Statute Primary Focus Key Conduct Penalty Range
§ 609.88 – Computer Damage Damage or destruction Altering, damaging, or destroying computers, systems, networks, or software. Varies by harm and circumstances (may reach felony level).
§ 609.89 – Computer or Electronic Data Theft Theft or misuse Unauthorized access for services or property; taking or retaining devices or data; copying and using software or data beyond authority. Misdemeanor to felony based on loss amount (up to 10 years, $50,000 fine).
§ 609.891 – Unauthorized Computer Access Penetration of security Intentional penetration or attempted penetration of a computer security system or electronic terminal without authorization. Misdemeanor to felony depending on risk and method (up to 10 years, $20,000 fine).

These statutes can be charged together in complex cases. For example, an incident may involve both unauthorized access and subsequent theft of data or damage to systems.

8. Frequently Asked Questions (FAQs)

8.1 Is simply guessing a coworker’s password illegal in Minnesota?

It can be. If you intentionally and without authorization attempt to penetrate a computer security system or log into someone else’s account, that conduct may fall under unauthorized computer access laws. Whether charges are filed depends on the facts, including intent, scope of access, and resulting harm.

8.2 Can accessing my employer’s data at home be a computer crime?

Accessing employer data from home is not inherently illegal. However, if you exceed the access your employer has authorized—such as retrieving confidential files for personal use, copying trade secrets, or retaining data after termination—computer or electronic data theft statutes may apply.

8.3 What if I find a security flaw and test it without telling the owner?

Unapproved security testing that involves attempts to penetrate or bypass protections can be treated as unauthorized computer access even if you believe you are helping. To avoid legal risk, obtain clear written permission before conducting any penetration testing or vulnerability research on systems you do not control.

8.4 Are employers liable if an employee commits a computer crime?

Liability depends on the circumstances. An employee who acts outside the scope of their job and without authorization may be personally liable, while employers may face civil exposure if they fail to protect data or supervise access. Whether criminal liability attaches to the organization will depend on factors like knowledge, authorization, and benefit.

8.5 How can I learn more about computer crime laws in other states?

The National Conference of State Legislatures provides an overview of computer crime statutes across the United States, highlighting common approaches to unauthorized access, computer trespass, and related offenses. This can help businesses operating in multiple states understand the broader legal landscape.

References

  1. Sec. 609.89 – Computer or Electronic Data Theft — Minnesota Office of the Revisor of Statutes. 2023-01-01. https://www.revisor.mn.gov/statutes/cite/609.89
  2. Sec. 609.891 – Unauthorized Computer Access — Minnesota Office of the Revisor of Statutes. 2023-01-01. https://www.revisor.mn.gov/statutes/cite/609.891
  3. Chapter 609 — Criminal Code — Minnesota Statutes (Justia summary). 2017-01-01. https://law.justia.com/codes/minnesota/2017/chapters-609-624/chapter-609/
  4. Identity Theft & Computers — Minnesota Attorney General’s Office. 2022-06-01. https://www.ag.state.mn.us/Consumer/IdentityTheft/
  5. Privacy/Identity Theft/Cybersecurity – Legal Topics — Minnesota State Law Library. 2021-05-01. https://mncourts.libguides.com/privacy
  6. Computer Crime Statutes — National Conference of State Legislatures (NCSL). 2022-03-01. https://www.ncsl.org/technology-and-communication/computer-crime-statutes
Medha Deb is an editor with a master's degree in Applied Linguistics from the University of Hyderabad. She believes that her qualification has helped her develop a deep understanding of language and its application in various contexts.

Read full bio of medha deb