Overview of New Jersey Computer Crime Laws

Understand how New Jersey defines, prosecutes, and penalizes computer and internet-related crimes under state law.

By Medha deb
Created on

New Jersey treats computer and internet-related misconduct as serious criminal activity, with specific statutes that address unauthorized access, data theft, cyber harassment, and other forms of digital wrongdoing. This guide explains how state law defines computer criminal activity, how offenses are graded, what penalties may apply, and how these rules interact with civil remedies and other cyber-related crimes.

1. How New Jersey Classifies Crimes and Computer Offenses

Unlike some states that distinguish between felonies and misdemeanors, New Jersey classifies crimes by degree rather than by those traditional labels. First-degree offenses are the most serious, and fourth-degree offenses are the least severe among indictable crimes.

Computer crimes fall within this degree-based system and may range from fourth-degree to first-degree offenses depending on the conduct and the value of property or data involved.

  • First-degree crimes – Most serious offenses, typically involving very high value or extreme harm.
  • Second-degree crimes – Serious offenses with substantial harm, including significant financial loss or extensive damage.
  • Third-degree crimes – Mid-level offenses, often involving moderate damage or unauthorized schemes to obtain property or services.
  • Fourth-degree crimes – Lower-level indictable offenses, still punishable by prison and fines but involving less severe conduct or damage.

Computer-related offenses can fit anywhere in this range depending on the details of the incident, including the type of access, the intent, and the monetary value of the services, data, or damage involved.

2. Core Statute: Computer Criminal Activity (NJSA 2C:20-25)

The main criminal provision addressing computer misuse is New Jersey Statutes Annotated (NJSA) 2C:20-25, often referred to as the computer criminal activity statute. It focuses on conduct that involves accessing or manipulating computers, systems, or data without proper authorization.

2.1. What Counts as Computer Criminal Activity?

Under NJSA 2C:20-25, a person may be guilty of computer criminal activity if they act purposely or knowingly and either without authorization or beyond the scope of authorization in relation to computer systems or data. The statute covers several categories of behavior, including:

  • Unauthorized access to any computer, computer system, network, database, or software.
  • Altering, damaging, or destroying data, hardware, or software, or disrupting computer services or network access.
  • Accessing systems to carry out a scheme to defraud or to obtain services, property, money, or personal identifying information.
  • Copying, taking, or using data or personal identifying information stored on a computer system or storage medium.
  • Recklessly altering, damaging, or destroying data or systems after gaining access.

The statute is intentionally broad, covering both direct tampering with systems and more subtle misuse such as copying or extracting data for unauthorized purposes.

2.2. Degree of Crime Based on Conduct and Value

The degree of the computer crime under NJSA 2C:20-25 depends on the specific subsection violated and, in many cases, the value of the property, services, or damage involved.

Illustrative Degrees for Computer Criminal Activity
Type of Conduct Typical Degree Key Factor
Unauthorized access alone Third-degree crime Accessing without authorization or exceeding authorization.
Altering or damaging data or systems; denying or disrupting service Second-degree crime Impact on availability and integrity of computer services.
Access to execute a scheme to defraud or obtain property/services Third-degree, elevated to second-degree when value exceeds $5,000 Monetary value of services, property, or information obtained or sought.
Reckless alteration or destruction of data or systems Fourth-degree, elevated to third-degree when damage exceeds $5,000 Extent and value of damage caused.

Because the statute ties degree to value thresholds, conduct involving large-scale data theft, substantial business disruption, or significant financial loss may be prosecuted at a higher degree than smaller or isolated incidents.

3. Penalties for Computer Crime Convictions in New Jersey

Computer crimes carry penalties similar to other New Jersey criminal offenses of the same degree, including potential imprisonment and significant fines.

3.1. Standard Sentencing Ranges by Degree

  • Fourth-degree crime – Up to 18 months in prison and fines up to $10,000.
  • Third-degree crime – Typically 3 to 5 years in prison and fines up to $15,000.
  • Second-degree crime – Generally 5 to 10 years of imprisonment and fines up to $150,000.
  • First-degree crime – Between 10 and 20 years of imprisonment and fines up to $200,000.

In addition to these standard ranges, New Jersey law allows for an extra fine specifically tied to computer crime convictions, typically between $500 and $2,000 per offense depending on the severity and degree.

3.2. Separate Judgments and Non-Merger of Computer Crimes

Computer crime statutes in New Jersey often specify that offenses cannot be merged, meaning that each distinct computer crime charge may lead to a separate judgment, sentence, and fine. For example, a person who both accesses a system without authorization and then uses that access to steal data might face multiple charges instead of a single merged offense.

This non-merger approach can significantly increase exposure to penalties when multiple acts are alleged within the same incident or course of conduct.

4. Civil Remedies: The Computer Related Offenses Act (NJSA 2A:38A)

While New Jersey’s main computer crime statute focuses on criminal liability, the state also provides a civil remedy through the Computer Related Offenses Act, NJSA 2A:38A-1 et seq. This law allows victims to pursue civil damages against actors who wrongfully access or misuse computer data and systems.

4.1. Scope of the Civil Computer Act

The Computer Related Offenses Act creates liability for an actor who purposely or knowingly accesses, alters, damages, takes, or destroys computer information without authorization. Importantly:

  • The statute protects any data held on computer systems, not only proprietary or confidential information.
  • The plaintiff must usually show some activity involving the information beyond merely gaining access; for example, copying, altering, or deleting data.
  • Liability can arise even if the conduct does not meet the threshold for criminal prosecution under NJSA 2C:20-25.

4.2. Available Damages and Remedies

The act allows recovery of:

  • Compensatory damages for actual economic harm suffered.
  • Punitive damages where warranted, to punish particularly harmful or malicious conduct.
  • Litigation costs, including reasonable attorney’s fees and court costs.

This civil framework can be especially useful for businesses and organizations seeking financial redress after unauthorized access, theft of electronic information, or damage to systems.

5. Cyber Harassment and Other Internet-Based Crimes

Computer misuse often intersects with broader internet-related offenses. New Jersey has enacted laws specifically addressing cyber harassment, alongside general computer crime statutes.

5.1. Cyber Harassment Under NJSA 2C:33-4.1

New Jersey’s cyber harassment statute, NJSA 2C:33-4.1, creates a stand-alone offense for harassment carried out through electronic communications or social networking sites. The statute applies when a person uses online communication with the purpose to harass another by:

  • Threatening to inflict injury or physical harm on a person or their property.
  • Sending or posting lewd, indecent, or obscene material with the intent to cause emotional harm or fear of harm.
  • Threatening to commit a crime against a person or their property.

Certain factors, such as the age of the defendant, can affect the degree of the cyber harassment offense. For example, charges are generally fourth-degree but may be elevated to third-degree if the actor is over 21 years old.

5.2. Other Common Internet-Related Offenses

In practice, New Jersey prosecutors may rely on a variety of statutes to address digital misconduct, including:

  • Identity theft and unauthorized use of personal identifying information.
  • Phishing schemes, typically prosecuted under fraud and computer criminal activity statutes because the state does not have a phishing-specific law.
  • Unauthorized account access for email or social networking profiles.
  • Internet sex crimes and child exploitation offenses, which carry separate and often severe penalties.

New Jersey also maintains specialized units, such as the Cyber Crimes Unit, to investigate and support enforcement of internet-based offenses.

6. Reporting and Enforcement in New Jersey

Effective enforcement of computer crime laws depends on timely reporting and investigation. New Jersey encourages individuals and organizations to report cyber incidents, particularly data breaches and significant system compromises.

6.1. Reporting Cyber Incidents

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) provides public guidance and reporting mechanisms for cyber incidents. Under certain laws, New Jersey organizations are required to report data breaches, especially those involving personal information.

  • Organizations should promptly report breaches involving personal data.
  • Reports support statewide situational awareness and threat analysis.
  • Timely reporting can also help coordinate law enforcement and regulatory responses.

6.2. Interaction Between Criminal and Civil Processes

Computer misuse can trigger both criminal and civil proceedings. Authorities may prosecute under NJSA 2C:20-25 or related statutes, while victims may separately pursue civil remedies under the Computer Related Offenses Act.

Criminal proceedings focus on punishment and deterrence, whereas civil actions aim to compensate victims and, where appropriate, impose punitive damages for harmful conduct.

7. Key Takeaways for Individuals and Businesses

New Jersey’s computer crime framework underscores that digital misconduct carries real and potentially severe legal consequences. Both individuals and organizations should be aware of the basic contours of these laws.

  • Unauthorized access is itself a crime when done purposely or knowingly, even if no data is destroyed.
  • Value matters: Larger schemes, higher monetary losses, or extensive damage often lead to higher-degree charges and stronger penalties.
  • Civil remedies exist through the Computer Related Offenses Act, allowing victims to seek damages and litigation costs in addition to any criminal proceedings.
  • Cyber harassment and other online conduct are addressed through separate statutes, reflecting the state’s focus on harassment and threats in digital spaces.
  • Reporting obligations, particularly for data breaches, play an important role in enforcement and cybersecurity risk management.

Because specific outcomes depend on detailed facts and the application of multiple statutes, anyone facing potential exposure to New Jersey computer crime laws should consider consulting qualified legal counsel for advice tailored to their situation.

8. Frequently Asked Questions (FAQs)

8.1. Is simply guessing someone’s password a computer crime in New Jersey?

If guessing a password is used to access a computer, system, or account without authorization or beyond permitted use, that access may fall within NJSA 2C:20-25’s definition of computer criminal activity. The statute focuses on unauthorized access, regardless of whether technical hacking tools or simple password guessing were used.

8.2. Can a business sue an employee for taking data before leaving the company?

Yes, in addition to any potential criminal investigation, a business may seek civil remedies under the Computer Related Offenses Act if an employee intentionally accesses, takes, alters, or destroys data without authorization. The act is not limited to confidential information and can apply to any data stored on the company’s systems.

8.3. Are phishing emails specifically illegal under New Jersey law?

New Jersey does not have a statute dedicated solely to phishing, but phishing schemes are typically prosecuted under fraud-related statutes and NJSA 2C:20-25 when they involve unauthorized access or the use of computer systems to obtain property or personal information.

8.4. Does New Jersey law allow civil lawsuits for all computer crimes?

The criminal statutes themselves do not create a direct civil cause of action; however, the Computer Related Offenses Act provides a separate civil vehicle for claims related to wrongful access or misuse of computer data. Whether a particular incident supports civil claims will depend on the facts and applicable statutes.

8.5. How serious is a fourth-degree computer crime?

A fourth-degree computer crime is the lowest degree among indictable offenses but still serious, carrying up to 18 months of imprisonment and significant fines. Damage exceeding certain monetary thresholds or more egregious misconduct can lead to higher-degree charges.

References

  1. NJ Rev Stat § 2C:20-25 (Computer criminal activity) — New Jersey Legislature / Justia. 2023-01-01. https://law.justia.com/codes/new-jersey/title-2c/section-2c-20-25/
  2. New Jersey Computer Crimes Defense & Offense Lawyer — The Law Offices of David Jay Glassman. 2022-05-01. https://www.newjerseycriminallawattorney.com/white-collar-crime/computer-crimes-attorney/
  3. The Computer Related Offenses Act Protects Against Theft of ESI — Meyner and Landis LLP / New Jersey Law Journal. 2021-09-01. https://meyner.com/wp-content/uploads/2021/09/Computer-Related-Offenses-Act-Protects-Agaisnt-Thefy-of-ESI.pdf
  4. New Jersey Computer Crimes Laws — FindLaw. 2023-06-15. https://www.findlaw.com/state/new-jersey-law/new-jersey-computer-crimes-laws.html
  5. New Jersey Internet Crimes — LLF Law Firm. 2023-04-01. https://www.njcriminaldefensellc.com/internet-crimes
  6. New Jersey Computer Crimes Attorney Discusses Phishing — Tim Anderson Law. 2022-03-01. https://timandersonlaw.com/blog/new-jersey-computer-crimes-attorney-phishing/
  7. Report Cyber Incidents — New Jersey Cybersecurity & Communications Integration Cell (NJCCIC). 2024-01-10. https://www.cyber.nj.gov/report
Medha Deb is an editor with a master's degree in Applied Linguistics from the University of Hyderabad. She believes that her qualification has helped her develop a deep understanding of language and its application in various contexts.

Read full bio of medha deb