Understanding Computer Crime Laws in the United States
A practical guide to hacking, online fraud, and other digital offenses and how U.S. computer crime laws respond.
Computer crime laws in the United States govern a wide range of misconduct involving computers, networks, and digital data, from hacking and malware to online fraud and cyberstalking.[10] These laws combine federal statutes and state-level provisions to address both traditional crimes carried out with technology and offenses that exist only in the digital environment.
As everyday life, business, and government functions increasingly rely on connected systems, understanding how computer crimes are defined, prosecuted, and punished has become essential for individuals, organizations, and legal practitioners.
What Counts as a Computer Crime?
In U.S. law, the term computer crime generally refers to offenses where a computer, network, or digital system is central to the unlawful conduct or to the harm caused. These offenses may involve direct attacks on computers or the use of technology as a tool to commit other crimes.
- Direct computer misuse – activities such as unauthorized access, data theft, and malware deployment where the computer itself is the primary target.[10]
- Technology-enabled crimes – traditional offenses like fraud, extortion, or harassment that are carried out using email, social media, messaging platforms, or other digital channels.
- Data and network interference – actions that disrupt, damage, or disable systems, including denial-of-service attacks and destruction or alteration of data.
At the federal level, many computer-related offenses are prosecuted under statutes that focus on unauthorized access, fraud, and interference with protected computers and communications. States supplement these provisions with their own computer crime statutes that often mirror or expand on federal concepts.[10]
Key Categories of Computer Crimes
While terminology varies by statute and jurisdiction, most computer crime laws include several recurring categories of misconduct.[10]
Unauthorized Access and Hacking
Unauthorized access generally involves entering a computer system or network without permission or exceeding the access rights a user has legitimately been given. The federal Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030, is the core statute addressing this type of behavior.
- Breaking into password-protected systems without consent (classic “hacking”).
- Using someone else’s credentials to log into a restricted network.
- Accessing data or parts of a system that a user is technically able to reach but clearly prohibited from entering under policy and configuration.
According to Department of Justice guidance, prosecutors must show that a defendant knowingly accessed a computer or a restricted area of a computer without authorization or beyond their authorized access in order to obtain or alter information stored there. This means mere misuse of information obtained through legitimate access generally does not qualify as unauthorized access under the CFAA.
Computer-Related Fraud and Financial Crimes
Computer crime laws also cover a wide range of fraud and financial offenses, particularly where computers or networks are used to carry out schemes or steal value.
- Phishing campaigns that trick users into revealing banking or login credentials.
- Business email compromise schemes that redirect payments or invoices.
- Online marketplace scams and payment card fraud carried out through compromised systems.
Under the CFAA, accessing a computer to defraud and obtain value is a distinct offense, separate from simple unauthorized access. Other federal laws, such as statutes addressing identity theft and credit reporting, also apply when personal or financial data is misused in the course of computer-related fraud.
Damage to Computers, Networks, and Data
Another major category is intentional or reckless damage to computers and data, which includes distributing malware, deleting files, or disrupting systems.
- Deploying ransomware that encrypts data and blocks access to systems.
- Launching distributed denial-of-service (DDoS) attacks to overwhelm servers and take services offline.
- Destroying or corrupting data stored on a computer or network.
The CFAA distinguishes between intentional damage, reckless damage, and negligent damage caused through intentional access, with penalties that increase as the severity and intent of the conduct rise.
Cyberstalking, Harassment, and Exploitation
Computer crime laws also reach into the realm of cyberstalking, online harassment, and exploitation, particularly when digital tools are used to threaten, intimidate, or exploit victims.
- Persistent online monitoring or harassment that causes fear or substantial emotional distress.
- Bullying or threats communicated through social media and messaging platforms.
- Technology-facilitated child predation, including grooming and exploitation through online services.
These behaviors may be prosecuted under specific cyberstalking statutes, child protection laws, or more general criminal provisions that address threats, harassment, and exploitation.
Federal vs. State Computer Crime Laws
Computer crimes in the United States are regulated by a mixture of federal and state laws.[10] The choice of forum and charges often depends on the nature of the conduct, the systems affected, and the scope of harm.
Federal Framework
At the federal level, enforcement focuses on conduct that affects interstate or foreign communications, federal systems, or significant economic or social interests.
| Federal Statute | Primary Focus |
|---|---|
| Computer Fraud and Abuse Act (18 U.S.C. § 1030) | Unauthorized access, computer fraud, damage to protected computers. |
| Federal Information Security Modernization Act (FISMA) | Security obligations for federal agencies and oversight of federal information systems. |
| Cybersecurity Information Sharing Act (CISA) | Sharing of cybersecurity threat data between private sector and government. |
| Sector-specific privacy and security laws (HIPAA, GLBA, COPPA) | Protection of health, financial, and children’s personal data and security practices. |
Federal statutes not only create criminal liability but, in some cases, allow civil actions, enabling victims to recover losses from unauthorized access or other computer-related harms.
State Computer Crime Statutes
All 50 states, Puerto Rico, and the Virgin Islands have enacted computer crime statutes, many of which address unauthorized access or computer trespass.[10] States also frequently include provisions targeting data theft, system interference, and misuse of computer services.[10]
- State laws may use terminology such as “computer trespass” or “computer tampering” to describe unauthorized access and system interference.[10]
- Penalties often vary by the amount of loss, the type of system affected (e.g., government vs. private), and whether personal data was exposed.[10]
- Some states include enhanced penalties where the victim is a minor or where critical infrastructure is involved.
Because computer crimes frequently cross borders, investigations often involve coordination between state and federal authorities and may result in charges under both frameworks.
The Computer Fraud and Abuse Act: Core Concepts
The Computer Fraud and Abuse Act (CFAA) is the centerpiece of federal computer crime law and has been amended several times to address evolving forms of cybercrime. It applies to “protected computers,” a term that includes systems used in or affecting interstate or foreign commerce and communications.
Types of Offenses under the CFAA
The CFAA contains multiple distinct offenses, including obtaining information without authorization, defrauding through computer access, damaging systems, trafficking in passwords, and extortion involving computers.
- Obtaining information from protected computers – accessing a computer without authorization and obtaining information, including national security data or information from financial institutions.
- Computer fraud – accessing a computer to further a fraud and obtain anything of value.
- Intentional damage by transmission – knowingly causing the transmission of code or commands that intentionally damage a protected computer, such as malware or destructive scripts.
- Trafficking in passwords – trading or distributing passwords or similar access information that enables unauthorized access.
- Computer-related extortion – extorting money or value by threatening to damage a computer or disclose sensitive information.
Authorization and Access Limits
The DOJ has issued guidance clarifying how “without authorization” and “exceeds authorized access” should be interpreted. This guidance is intended to prevent overbroad charging decisions, especially in cases involving terms of service violations or employee misuse.
- In “without authorization” cases, the government generally must show that the defendant had no permission to access the system under any circumstances and knew that their access was not permitted.
- In “exceeds authorized access” cases, the computer must be divided into distinct technical areas (such as files, folders, or user accounts), and the defendant must access an area they were technically and clearly barred from entering.
- Prosecutors must be prepared to prove that the defendant knowingly accessed a restricted area to obtain or alter information, not just that they later misused lawfully obtained data.
This interpretation aims to align CFAA enforcement with core notions of trespass and unauthorized entry, rather than ordinary policy violations.
Penalties and Sentencing for Computer Crimes
Penalties for computer crimes vary widely, reflecting differences in statutory language, levels of intent, and the amount of harm or loss caused.[10]
Federal Sentencing Considerations
The United States Sentencing Commission has developed sentencing guidelines and primers to assist courts in applying consistent punishments for computer-related offenses. Key factors often include:
- Scope of damage or loss (such as financial loss, number of victims, and volume of compromised data).
- Role of the defendant (for example, organizer, leader, or participant).
- Use of special skills or abuse of a position of trust, which can result in sentencing enhancements in cases involving computers or the internet.
- Nature of the targeted systems, including critical infrastructure or government computers, which may trigger higher penalties.
Under the CFAA, maximum sentences range from one year for certain low-level offenses to significantly longer terms for more serious conduct, especially where national security or widespread economic harm is involved.
State-Level Penalties
State computer crime statutes typically classify offenses as misdemeanors or felonies based on the value of loss, intent, and impact of the conduct.[10]
- Minor unauthorized access without significant damage may be treated as a misdemeanor.
- Large-scale data breaches, interference with government systems, or exploitation of minors may carry felony penalties and substantial prison terms.[10]
- Many states allow for restitution orders requiring defendants to compensate victims for tangible losses, such as incident response costs and lost business.[10]
Given the complexity of statutes and the rapid evolution of technology, sentencing for computer crimes often requires careful legal analysis and expert input.
Practical Implications for Individuals and Businesses
Computer crime laws have practical consequences for everyday users and organizations that rely on information technology. Understanding these implications can help reduce legal risk and improve cybersecurity posture.
For Individual Users
- Avoid attempting to access accounts, systems, or data that you do not have clear, technical authorization to use.
- Recognize that sharing passwords, using someone else’s credentials without consent, or bypassing security controls can carry criminal consequences.
- Be cautious with software tools (such as scanning or penetration testing utilities) and only use them with explicit permission from the system owner.
- Report suspected cybercrime incidents to appropriate authorities instead of trying to investigate or retaliate on your own.
For Organizations and Employers
- Implement clear access controls that technically separate sensitive data and systems from general users, aligning with DOJ guidance on authorization.
- Develop and regularly update cybersecurity policies, including acceptable use, incident response, and data protection procedures.
- Ensure compliance with sector-specific laws such as HIPAA, GLBA, and COPPA where applicable, especially with regard to data security and breach notification obligations.
- Consider civil remedies available under the CFAA and other statutes if your organization suffers losses due to unauthorized access or other computer crimes.
Organizations should also be aware that inadequate security measures and failure to comply with relevant cybersecurity laws can result in regulatory penalties, civil suits, and reputational harm.
Frequently Asked Questions (FAQs)
Is simply violating a website’s terms of service a computer crime?
In most cases, merely violating terms of service or internal policies does not, by itself, constitute a computer crime under federal law. DOJ guidance emphasizes that prosecution under the CFAA should focus on clear unauthorized access to technical areas of a computer, rather than ordinary contractual or policy violations.
What is a “protected computer” under federal law?
A “protected computer” under the CFAA generally includes any computer used in or affecting interstate or foreign commerce or communication, a definition broad enough to cover most internet-connected systems. This category also includes certain government and financial institution computers.
Can victims sue for damages after a cyberattack?
Yes. In addition to criminal prosecution, the CFAA and other statutes allow certain victims to bring civil actions for damages resulting from unauthorized access or computer-related misconduct. These suits can seek recovery of costs such as incident response, system repair, and business interruption.
Do all states have specific computer crime laws?
All U.S. states, as well as Puerto Rico and the Virgin Islands, have enacted computer crime statutes that typically address unauthorized access, computer trespass, and related offenses.[10] The details and terminology vary, so local statutes should be consulted for precise definitions and penalties.
Are cybersecurity failures by a business ever treated as crimes?
Most cybersecurity failures are handled through regulatory enforcement and civil liability rather than criminal prosecution. However, in serious cases where negligence or willful disregard of legal obligations leads to significant harm, criminal charges may be possible under certain statutes.
References
- Computer Crimes Primer — United States Sentencing Commission. 2025-08-01. https://www.ussc.gov/guidelines/primers/computer-crimes
- 9-48.000 – Computer Fraud and Abuse Act — U.S. Department of Justice, Justice Manual. 2022-05-19. https://www.justice.gov/jm/jm-9-48000-computer-fraud-and-abuse-act
- Provisions of the Computer Fraud & Abuse Act, 18 U.S.C. § 1030 — National Association of Criminal Defense Lawyers. 2021-01-01. https://www.nacdl.org/Landing/ComputerFraudandAbuseAct
- Cybercrime and the Law: Primer on the Computer Fraud and Abuse Act (CFAA) — Congressional Research Service. 2024-03-26. https://www.congress.gov/crs-product/R47557
- Computer Crime Statutes — National Conference of State Legislatures. 2022-07-12. https://www.ncsl.org/technology-and-communication/computer-crime-statutes
- Cybercrimes — National Association of Attorneys General. 2023-02-15. https://www.naag.org/issues/cyber-and-technology/cybercrimes/
- Cybersecurity and Data Privacy: Federal Law — American University Washington College of Law Library. 2023-05-10. https://wcl.american.libguides.com/cybersecurity-and-data-privacy/federal-law
Read full bio of Sneha Tete





